Multi-Factor Authentication for Secured Access Control to Electronic Health Records in South African Public Hospitals (Preprint)

Author:

Chuma Jr KabeloORCID,Msomi Jr MandisaORCID

Abstract

BACKGROUND

In this rapidly advancing digital landscape, the security of Electronic Health Records (EHRs) is increasingly dependent on robust authentication and access control measures. Despite advancements in cybersecurity, South African public hospitals are particularly vulnerable and targeted by cyber-attacks and data breaches due to vulnerabilities associated with username and password-based authentication. These vulnerabilities pose substantial risks to the security and privacy of EHRs and cause huge disruptions to public hospitals.

OBJECTIVE

With the potential to cause widespread disruption and harm, this study aims to propose a framework for integrating Multi-Factor Authentication (MFA) to enhance to user authentication and access control to EHRs in South African public hospitals.

METHODS

A qualitative research design was employed to understand security vulnerabilities and risks in password authentication within public hospitals. The study conducted semi-structured interviews with 15 purposively selected IT technicians, network controllers, and IT managers working in public hospitals. All interviews were audio-recorded, transcribed verbatim, and analyzed using thematic analysis and NVivo version 12. The study applied a conceptual framework grounded in Protection Motivation Theory.

RESULTS

The analysis revealed that public hospitals experienced authentication vulnerabilities such as username enumeration, broken authentication, weak credentials, and credential leakage. Phishing, cryptojacking, ransomware, and password attacks were among the security incidents encountered in public hospitals. Participants expressed that security vulnerabilities in hospitals are due to weak and easily guessable passwords created by staff, the reuse of the same password across multiple systems, irregular password updates, reliance on legacy systems, writing down passwords on paper, and the lack of regular updates to Windows Firewall and Microsoft Defender Antivirus.

CONCLUSIONS

The study emphasizes the need for developing robust password policies, modernizing legacy systems, and promoting cybersecurity awareness training in public hospitals. Furthermore, the study suggested a framework for public hospitals to effectively address authentication vulnerabilities. and reinforcing data security. The research underscores that, despite the ongoing vulnerabilities and weaknesses of password and username-based authentication, the study concludes that the integration of MFA offers a scalable solution to significantly improve the security and access control of EHRs in public hospitals.

Publisher

JMIR Publications Inc.

同舟云学术

1.学者识别学者识别

2.学术分析学术分析

3.人才评估人才评估

"同舟云学术"是以全球学者为主线,采集、加工和组织学术论文而形成的新型学术文献查询和分析系统,可以对全球学者进行文献检索和人才价值评估。用户可以通过关注某些学科领域的顶尖人物而持续追踪该领域的学科进展和研究前沿。经过近期的数据扩容,当前同舟云学术共收录了国内外主流学术期刊6万余种,收集的期刊论文及会议论文总量共计约1.5亿篇,并以每天添加12000余篇中外论文的速度递增。我们也可以为用户提供个性化、定制化的学者数据。欢迎来电咨询!咨询电话:010-8811{复制后删除}0370

www.globalauthorid.com

TOP

Copyright © 2019-2024 北京同舟云网络信息技术有限公司
京公网安备11010802033243号  京ICP备18003416号-3