Diese Seite ist für Menschen und Suchmaschinen gestaltet. Zur Version für KI-Systeme (LLM) →

Does more Health Information Exchange lead to more Cybersecurity Incidents?

As more and more hospitals are adopting electronic health information exchange (HIE), the question arises whether this trend might lead to an increased number of cybersecurity incidents.

Use of electronic health information exchange (HIE)

Digitalization, particularly via Electronic Health Records (EHR), allows healthcare institutions to exchange patient information electronically and therefore optimize patient treatment. A primary mechanism for this is the Health Information Exchange (HIE) [1]. Healthcare institutions can either manage HIEs themselves or outsource this function to Health Information Organizations (HIOs) that manage and store data [2]. Figure 1 illustrates the structure of an HIE involving an HIO [2].

Figure 1: Structure of Health Information Exchange (HIE)

HIE is used in different countries globally, including Germany and the USA [1, 3]. Patient-consent laws, governing HIE can vary significantly. In Germany, patients need to actively agree in using their data in HIE (opt-in). This is also the case in certain US-states, while in other states, patients who don’t want their data to be used in HIE, need to actively opt-out [1, 4].

With increasing interoperability among healthcare institutions, challenges such as data standards, privacy concerns, and adequate policies arise [1]. Cybersecurity is a major concern, as cybercrime poses a significant threat to the healthcare industry. In 2023, the USA recorded 809 data breaches in healthcare, the highest among all sectors [5]. Criminals primarily obtained patient data through theft, unauthorized access, or hacking/IT incidents [6].

In context of growing cybersecurity threats hospital management needs to assess whether the use of HIE in combination with the required security standards, increases the risk of data breaches. Likewise, patients need to understand the benefits and security concerns regarding HIE, as their consent is required to share their electronic health data within the system.

Monitoring the connection of HIE engagement and cybersecurity threats

Choi et al. investigated, whether increased use of HIE raises the risk of data breaches. They included 4,936 community hospitals (non-federal, short-term general, and specialty hospitals) and 39,488 unique hospital-year observations from 2010 to 2017 in their study. Data was collected from two main sources: the annual survey by the American Hospital Association (AHA) and the Department of Health and Human Services (HHS) reports on health data breaches [7].

Increased HIE engagement does lead to a higher data breach risk

Between 2010 and 2017, the use of Health Information Exchange (HIE) in hospitals within the study population more than tripled, increasing from 18% to 68%. In comparison, the occurrence of data breaches in these hospitals rose by about 1.5 times, from 34 in 2010 to 52 in 2017, with unauthorized access and hacking identified as the primary threats [7].

Choi et al. discovered that hospitals exchanging data face a higher risk of IT-related data breaches compared to those not exchanging data, while hospitals that exchanged data only via an HIO, and not directly with other healthcare institutions, had a lower long-term risk of data breaches. Providers with fewer cybersecurity resources were more prone to be targeted [7].

Interestingly, the risk of breaches significantly increased after three years of HIE engagement. For the initial implementation of Health Information Exchange (HIE), hospitals must adhere to additional cybersecurity measures. However, during this early phase, the limited volume and complexity of exchanged data do not significantly impact the overall cybersecurity risk exposure. The three-year mark is a critical point, as hospitals may adopt HIE in a broader scope, increasing the amount of data access points, as well as the information flow, without adequately enhancing their security protocols. After this point, the risk of data breaches tends to decrease, suggesting that hospitals adapt to the heightened cybersecurity risks by implementing more robust and comprehensive security measures [7].

Conclusion

HIE enables clinicians and administrators to access critical patient information quickly, but it can initially also increase the risk of data breaches [7]. An integrated risk management approach for continuously identifying potential cyberthreats, formulating cybersecurity measures, and raising employee awareness, helps hospitals in ensuring data integrity [8] while maximizing the benefits of HIE in the long-term.

References

  1. Holmgren AJ, Esdar M, Hüsers J, Coutinho-Almeida J. Health Information Exchange: Understanding the Policy Landscape and Future of Data Interoperability. Yearb Med Inform 2023; 32(1): 184–94 [https://doi.org/10.1055/s-0043-1768719][PMID: 37414031]
  2. Akhlaq A, Sheikh A, Pagliari C. Defining Health Information Exchange: Scoping Review of Published Definitions. J Innov Health Inform 2017; 23(4): 838 [https://doi.org/10.14236/jhi.v23i4.838][PMID: 28346130]
  3. Payne TH, Lovis C, Gutteridge C*, et al.*Status of health information exchange: a comparison of six countries. J Glob Health 2019; 9(2): 204279 [https://doi.org/10.7189/jogh.09.020427][PMID: 31673351]
  4. Apathy NC, Holmgren AJ. Opt-in consent policies: potential barriers to hospital health information exchange. Am J Manag Care 2020; 26(1): e14-e20 [https://doi.org/10.37765/ajmc.2020.42148][PMID: 31951362]
  5. ITRC. 2023 Data Breach Report. Identity Theft Ressource Center 01.2024.
  6. Jiang JX, Bai G. Evaluation of Causes of Protected Health Information Breaches. JAMA Intern Med 2019; 179(2): 265–7 [https://doi.org/10.1001/jamainternmed.2018.5295][PMID: 30453327]
  7. Choi SJ, Chen M, Tan X. Assessing the impact of health information exchange on hospital data breach risk. Int J Med Inform 2023; 177: 105149 [https://doi.org/10.1016/j.ijmedinf.2023.105149][PMID: 37453177]
  8. Argyridou E, Nifakos S, Laoudias C*, et al.*Cyber Hygiene Methodology for Raising Cybersecurity and Data Privacy Awareness in Health Care Organizations: Concept Study. J Med Internet Res 2023; 25: e41294 [https://doi.org/10.2196/41294][PMID: 37498644]

Verwandte Artikel