---
title: "Raising data privacy awareness in healthcare organizations"
language: "de"
type: "post"
original_url: "https://www.atlas-digitale-gesundheitswirtschaft.de/blog/2025/02/12/raising-healthcare-data-privacy/"
human_version: "../../../../../mensch/blog/2025/02/12/raising-healthcare-data-privacy/"
date: "2025-02-12"
section: "Science Digest (engl.)"
categories: ["Cybersecurity"]
author: "Grigori Rogge [Qualitätssicherung: J.-P. Novoa Lill]"
reading_time: "5 Min."
description: "The cyber hygiene methodology assists healthcare organizations in raising healthcare data privacy awareness"
publisher: "Lehrstuhl für Management und Innovation im Gesundheitswesen, Universität Witten/Herdecke"
---

# Raising data privacy awareness in healthcare organizations

*12.02.2025 · Science Digest (engl.) · Von Grigori Rogge [Qualitätssicherung: J.-P. Novoa Lill]*

*The human factor significantly contributes to healthcare data privacy breaches, emphasizing the need for everyone’s involvement in cybersecurity. But how can cybersecurity and data privacy awareness be effectively raised?*

## Human factors in connected cybersecurity environments

The healthcare industry is increasingly digitalized, introducing benefits for patient care [1], like real-time decision support for clinicians [2]. However, this shift heightens cybersecurity risks as data exchange volume and points increase [1]. Healthcare data is highly valued on the black market, even more than credit card data [3], making healthcare a prime target for cybercriminals [4].

Research shows the human factor is a primary contributor to cybersecurity risks in healthcare [5]. Therefore, using network devices requires sufficient security controls, sophisticated usability, and adequate training and awareness programs for healthcare staff [6].

Another critical topic are social engineering attacks, particularly phishing attempts [7], with one in seven phishing attempts in hospitals succeeding [8]. Additionally, high workloads for clinical staff increase the likelihood of human errors [9]. Given the priority of the human factor in cybersecurity, there is broad consensus on the need for cybersecurity training for healthcare professionals. However, limited research exists on how hospital-implemented cybersecurity controls influence employee behavior [10].

## Cyber hygiene methodology in healthcare data privacy

Cyber hygiene is a principle organizations use to maintain cybersecurity, by raising employee awareness through continuous campaigns, constantly evaluating risks, and implementing optimized cybersecurity measures and controls [11]. In their study, Argyridou et al. used a five-step cyber hygiene methodology similar to classic risk management methodologies (illustrated in Figure 1) [10].

![Raising healthcare data privacy awareness in healthcare organizations](https://www.atlas-digitale-gesundheitswirtschaft.de/mensch/assets/bilder/wp-content/uploads/sites/2/2024/11/Cyber-Hygiene.png)

Figure 1: Cyber hygiene methodology based on survey and risk assessment

They tested their methodology in three different European healthcare institutions. The baseline was a survey, in which they investigated the employee’s cybersecurity education and awareness. Based on the survey results, risk profiles were created and mitigation strategies, for example for phishing risks, were developed. These strategies focused on promoting desirable employee behaviors through human-centric controls in the areas of training, awareness, motivation, and reward [10].

## **Observed risk areas and proposed controls** in healthcare data privacy

The survey in the three healthcare institutions revealed a general medium to high-risk profile across all institutions. Argyridou et al. observed that employees from the IT and technical personnel group showed high awareness about cyber hygiene but also exhibited a higher risk in secure connections and device usage, indicating they were not following or not aware of policies for secure device connection. To address these issues, the authors proposed integrating human-centric controls focused on data privacy awareness, training in authentication methods, data handling, and prevention of unintentional data exposure [10].

The medical and clinical group across all monitored healthcare institutions displayed high risks in the category of communication channels, indicating they used a limited number of channels and exchanged information with IT professionals on a limited basis. The authors recommended establishing controls focused on cybersecurity and data privacy awareness programs, as well as introducing champions for these areas within the group [10].

## **Potential of incorporating cyber hygiene in healthcare institutions**

As cybersecurity risks, particularly those involving human factors, continue to grow in importance, the cyber hygiene methodology presented could assist healthcare organizations in strengthening their cybersecurity strategies and fostering a cybersecurity culture. The survey, serving as the foundation for this methodology, primarily focused on phishing attacks. To broaden the approach to a wider range of cyber risks, the survey questions should be appropriately adjusted. For further research, it should be evaluated whether the risk situation in the analyzed healthcare organizations changes upon implementing the proposed controls.

References

1. Choi SJ, Chen M, Tan X. Assessing the impact of health information exchange on hospital data breach risk. Int J Med Inform. 2023;177:105149. doi:10.1016/j.ijmedinf.2023.105149.

2. Toh Z an, Berg B, Han QYC, Hey HWD, Pikkarainen M, Grotle M, He H-G. Clinical Decision Support System Used in Spinal Disorders: Scoping Review. J Med Internet Res. 2024;26:e53951. doi:10.2196/53951.

3. Sulleyan A. NHS cyber attack: Why stolen medical information is so much more valuable than financial data: Medical information can be worth ten times more than credit card numbers on the deep web. The Independent. 12.05.2017.

4. Dolezel D, Beauvais B, Stigler Granados P, Fulton L, Kruse CS. Effects of Internal and External Factors on Hospital Data Breaches: Quantitative Study. J Med Internet Res. 2023;25:e51471. doi:10.2196/51471.

5. Wasserman L, Wasserman Y. Hospital cybersecurity risks and gaps: Review (for the non-cyber professional). Front Digit Health 2022. doi:10.3389/fdgth.2022.862221.

6. Wani TA, Mendoza A, Gray K. Hospital Bring-Your-Own-Device Security Challenges and Solutions: Systematic Review of Gray Literature. JMIR Mhealth Uhealth. 2020;8:e18175. doi:10.2196/18175.

7. Venkatesha S, Reddy KR, Chandavarkar BR. Social Engineering Attacks During the COVID-19 Pandemic. SN Comput Sci. 2021;2:78. doi:10.1007/s42979-020-00443-1.

8. Gordon WJ, Wright A, Aiyagari R, Corbo L, Glynn RJ, Kadakia J, et al. Assessment of Employee Susceptibility to Phishing Attacks at US Health Care Institutions. JAMA Netw Open. 2019;2:e190393. doi:10.1001/jamanetworkopen.2019.0393.

9. Nifakos S, Chandramouli K, Nikolaou CK, Papachristou P, Koch S, Panaousis E, Bonacina S. Influence of Human Factors on Cyber Security within Healthcare Organisations: A Systematic Review. Sensors (Basel) 2021. doi:10.3390/s21155119.

10. Argyridou E, Nifakos S, Laoudias C, Panda S, Panaousis E, Chandramouli K, et al. Cyber Hygiene Methodology for Raising Cybersecurity and Data Privacy Awareness in Health Care Organizations: Concept Study. J Med Internet Res 2023. doi:10.2196/41294. 11. Review of cyber hygiene practices. Heraklion: ENISA; 2016.





#### Verwandte Artikel

- [Recovering from a Cyberattack: How can Hospitals react?](recovering-from-a-cyber-incident-how-can-hospitals-react.md)
- [Cybersicherheit im stationären Umfeld – eine beherrschbare Aufgabe?](../../../2020/07/27/cybersicherheit-im-stationaeren-umfeld.md)


**Kategorien:** Cybersecurity

## Bilder auf dieser Seite

- Raising healthcare data privacy awareness in healthcare organizations: ../../../../../mensch/assets/bilder/wp-content/uploads/sites/2/2024/11/Cyber-Hygiene.png
- shutterstock_1113781856-1320x1320.jpg: ../../../../../mensch/assets/bilder/wp-content/uploads/2024/02/shutterstock_1113781856-1320x1320.jpg

---
Diese Seite ist für KI-Systeme optimiert. Version für Menschen: [Raising data privacy awareness in healthcare organizations](../../../../../mensch/blog/2025/02/12/raising-healthcare-data-privacy/)
