Abstract
BackgroundCybersecurity in healthcare has become increasingly important as the COVID-19 pandemic has increased the use of digital technologies in healthcare provision around the world, while simultaneously encouraged cybercriminals to target healthcare organisations in greater numbers. Despite the threat of cyberattack to patient safety and the provision of healthcare, cybersecurity in the health sector lags behind other industries. Additionally, no adequate cybersecurity framework exists which considers the unique needs of the health sector.MethodsAn online Delphi was carried out to develop a globally relevant and applicable readiness framework to guide cybersecurity planning in healthcare. Experts (n=42) in the areas of cybersecurity, information communications and technology and health informatics were invited to list the components they felt were essential to a framework and subsequently agree with consensus on a final framework based on the identified components.ResultsAfter two rounds, the Essentials of Cybersecurity in Healthcare Organizations (ECHO) framework with 51 components, grouped into six categories, was regarded by the experts as an acceptable planning tool to guide cybersecurity in healthcare at the global level.ConclusionsThe ECHO framework, designed based on components chosen by international experts to meet the challenges of cybersecurity scale-up in the health and care sector globally, can help guide policymakers and health and care organisations in strengthening their cybersecurity infrastructure and deliver safe and effective care.
Funder
NIHR Imperial Biomedical Research Centre
Qatar Foundation
Fritz Thyssen Stiftung
Reference29 articles.
1. Covid-19 and Health Care’s Digital Revolution
2. Verizon . 2020 Data Breach Investigations Report [online]. Verizon, 2020. Available: https://enterprise.verizon.com/en-gb/resources/reports/dbir/
3. Interpol . Cybercriminals targeting critical healthcare institutions with ransomware [online]. Interpol, 2020. Available: https://www.interpol.int/en/News-and-Events/News/2020/Cybercriminals-targeting-critical-healthcare-institutions-with-ransomware
4. A retrospective impact analysis of the WannaCry cyberattack on the NHS;Ghafur;NPJ Digit Med,2019
5. Life Healthcare . Life Healthcare Announces Cyber Incident [online]. Life Healthcare, 2020. Available: https://www.lifehealthcare.co.za/news-and-info-hub/latest-news/life-healthcare-announces-cyber-incident/