2016
DOI: 10.2147/rmhp.s99908
|View full text |Cite
|
Sign up to set email alerts
|

Information security risk management for computerized health information systems in hospitals: a case study of Iran

Abstract: BackgroundIn recent years, hospitals in Iran – similar to those in other countries – have experienced growing use of computerized health information systems (CHISs), which play a significant role in the operations of hospitals. But, the major challenge of CHIS use is information security. This study attempts to evaluate CHIS information security risk management at hospitals of Iran.Materials and methodsThis applied study is a descriptive and cross-sectional research that has been conducted in 2015. The data we… Show more

Help me understand this report

Search citation statements

Order By: Relevance

Paper Sections

Select...
3
1
1

Citation Types

1
15
0
1

Year Published

2017
2017
2024
2024

Publication Types

Select...
6
1
1
1

Relationship

0
9

Authors

Journals

citations
Cited by 17 publications
(17 citation statements)
references
References 23 publications
1
15
0
1
Order By: Relevance
“…Similar vulnerabilities in hospitals are also observed in other countries [13][14][15][16]. Specifically, pressure from the board of directors appears to be essential in creating substantive cyber-resiliency, as research shows that hospital management support is essential for user compliance with information security policies, which in turn are written by healthcare IT security professionals [17,18].…”
Section: Introductionmentioning
confidence: 75%
“…Similar vulnerabilities in hospitals are also observed in other countries [13][14][15][16]. Specifically, pressure from the board of directors appears to be essential in creating substantive cyber-resiliency, as research shows that hospital management support is essential for user compliance with information security policies, which in turn are written by healthcare IT security professionals [17,18].…”
Section: Introductionmentioning
confidence: 75%
“…Furthermore, significant variability in cybersecurity as a priority has been observed throughout the hospital industry-in the United States, 70% of hospital boards include cybersecurity in their risk management oversight, and only 37% of hospitals perform annual incident response exercises [12]. Similar vulnerabilities in hospitals are also observed in other countries [13][14][15][16]. Specifically, pressure from the board of directors appears to be essential in creating substantive cyber resiliency, as research shows that hospital management support is essential for user compliance with information security policies, which in turn are written by health care IT security professionals [17,18].…”
Section: Introductionmentioning
confidence: 95%
“…Several studies has been performed to explore IS risk management in organization. Study [15] explores IS risk management for some hospitals in Iran. They found that only eight hospitals have framework for IS risk management, but lacks in systematic approach.…”
Section: Literature Reviewmentioning
confidence: 99%