Issue
Date Log
Copyright (c) 2024 Abdu Bakri Hassan Sumayli, Ahmed Mohammed Nasser Someli, Mohammed Ibrahim Ali Hakami, Fatimah Mohammed Ibrahim Hakami, Aisha Ali Ail Hakamy, Moudhi Alsaif, Mashael Waslallah Al-Otibi, Fadwa Mahmoud Kamel Jawda, Tahani Suliman Alzeed, Sara Hamdan Al Fahhad, Hissah Abdulaziz Alyahya, Ebtihaj Metab Mohsen Mutairi

This work is licensed under a Creative Commons Attribution 4.0 International License.
Cybersecurity of Electronic Health Records: Implications for Nursing Practice, Dental Services, and Patient Safety
Corresponding Author(s) : Abdu Bakri Hassan Sumayli
Saudi Journal of Medicine and Public Health, Vol. 1 No. 2 (2024)
Abstract
Background: The digital transformation of healthcare through Electronic Health Records (EHRs) has revolutionized clinical data management but simultaneously exposed the sector to escalating cybersecurity threats. Aim: This narrative review aims to synthesize recent evidence on the nature, frequency, and impact of cybersecurity threats to EHRs, with a specific focus on the clinical and operational implications for nursing practice and dental services. Methods: A structured literature review was conducted, analyzing peer-reviewed articles, governmental reports, and industry white papers published predominantly between 2015 and 2024. Databases including PubMed, CINAHL, and IEEE Xplore were searched using keywords related to EHR cybersecurity, data breaches, ransomware, and clinical practice. Results: Findings reveal a surge in sophisticated cyberattacks, notably ransomware, leading to significant data breaches, operational downtime, and financial losses. The clinical implications are profound, manifesting as workflow disruptions, clinician burnout, and increased patient safety risks due to diagnostic and treatment delays. The review identifies critical vulnerabilities in both hospital and dental practice settings, ranging from human factors to legacy system deficiencies. Conclusion: Cybersecurity is an emergent patient safety imperative, not merely a technical concern. A paradigm shift towards a resilient culture of security, encompassing robust technological safeguards, continuous interdisciplinary education, and clear regulatory compliance, is essential to mitigate these evolving threats and ensure continuity of safe, high-quality care.
Keywords
Download Citation
Endnote/Zotero/Mendeley (RIS)BibTeX
- Alanazi, A., Almutib, A., & Aldosari, B. (2023). Physicians’ Perspectives on a Multi-Dimensional Model for the Roles of Electronic Health Records in Approaching a Proper Differential Diagnosis. Journal of Personalized Medicine, 13(4), 680.
- Almas, A., Iqbal, W., Altaf, A., Saleem, K., Mussiraliyeva, S., & Iqbal, M. W. (2023). Context-based adaptive fog computing trust solution for time-critical smart healthcare systems. IEEE Internet of Things Journal, 10(12), 10575-10586.
- Ayala, L. (2016). Cybersecurity for hospitals and healthcare facilities.
- Bai, G., Jiang, J., & Flasher, R. (2017). Hospital risk of data breaches. JAMA internal medicine, 177(6), 878-880.
- Campbell, E. M., Sittig, D. F., Ash, J. S., Guappone, K. P., & Dykstra, R. H. (2006). Types of unintended consequences related to computerized provider order entry. Journal of the American Medical Informatics Association, 13(5), 547-556.
- Cohen, I. G., & Mello, M. M. (2018). HIPAA and protecting health information in the 21st century. Jama, 320(3), 6-7.
- Coventry, L., & Branley, D. (2018). Cybersecurity in healthcare: A narrative review of trends, threats and ways forward. Maturitas, 113, 48-52.
- Cruz-Correia, R., Ferreira, D., Bacelar, G., Marques, P., & Maranhão, P. (2018). Personalised medicine challenges: quality of data. International Journal of Data Science and Analytics, 6(3), 251-259.
- Dameff, C., Tully, J., Chan, T. C., Castillo, E. M., Savage, S., Maysent, P., ... & Longhurst, C. A. (2023). Ransomware attack associated with disruptions at adjacent emergency departments in the US. JAMA network open, 6(5), e2312270.
- Fernández-Alemán, J. L., Señor, I. C., Lozoya, P. Á. O., & Toval, A. (2013). Security and privacy in electronic health records: A systematic literature review. Journal of biomedical informatics, 46(3), 541-562.
- Franco, M. F., Lacerda, F. M., & Stiller, B. (2022). A framework for the planning and management of cybersecurity projects in small and medium-sized enterprises. Revista de Gestão e Projetos, 13(3), 10-37.
- Ghafur, S., Kristensen, S., Honeyford, K., Martin, G., Darzi, A., & Aylin, P. (2019). A retrospective impact analysis of the WannaCry cyberattack on the NHS. NPJ digital medicine, 2(1), 98.
- Gordon, W. J., Wright, A., Glynn, R. J., Kadakia, J., Mazzone, C., Leinbach, E., & Landman, A. (2019). Evaluation of a mandatory phishing training program for high-risk employees at a US healthcare system. Journal of the American Medical Informatics Association, 26(6), 547-552.
- Green, B. N., Johnson, C. D., & Adams, A. (2006). Writing narrative literature reviews for peer-reviewed journals: secrets of the trade. Journal of chiropractic medicine, 5(3), 101-117.
- Hassandoust, F., Techatassanasoontorn, A. A., & Tan, F. B. (2016). Factors influencing the infusion of information systems: A literature review. Pacific Asia Journal of the Association for Information Systems, 8(1), 2.
- Hassan, W. U., Bates, A., & Marino, D. (2020, May). Tactical provenance analysis for endpoint detection and response systems. In 2020 IEEE symposium on security and privacy (SP) (pp. 1172-1189). IEEE.
- Joda, T., Zarone, F., & Ferrari, M. (2017). The complete digital workflow in fixed prosthodontics: a systematic review. BMC oral health, 17(1), 124.
- Khan, F. (2023). Regulating the revolution: a legal roadmap to optimizing AI in healthcare. Minnesota Journal of Law, Science & Technology, 25(1), 49.
- Kim, J., Park, E. H., Park, Y. S., Chun, K. H., & Wiles, L. L. (2022). Prosocial rule breaking on health information security at healthcare organisations in South Korea. Information Systems Journal, 32(1), 164-191.
- Kruse, C. S., Frederick, B., Jacobson, T., & Monticone, D. K. (2017). Cybersecurity in healthcare: A systematic review of modern threats and trends. Technology and Health Care, 25(1), 1-10.
- Larsen, E., Fong, A., Wernz, C., & Ratwani, R. M. (2018). Implications of electronic health record downtime: an analysis of patient safety event reports. Journal of the American Medical Informatics Association, 25(2), 187-191.
- Melnick, E. R., Dyrbye, L. N., Sinsky, C. A., Trockel, M., West, C. P., Nedelec, L., ... & Shanafelt, T. (2020, March). The association between perceived electronic health record usability and professional burnout among US physicians. In Mayo Clinic Proceedings (Vol. 95, No. 3, pp. 476-487). Elsevier.
- Melon, E., & Hernandez, W. (2020). Cybersecurity in the dental healthcare sector: the need of knowledge for small practitioners. Issues in Information Systems, 21(1), 118.
- Neprash, H. T., McGlave, C. C., Cross, D. A., Virnig, B. A., Puskarich, M. A., Huling, J. D., ... & Nikpay, S. S. (2022, December). Trends in ransomware attacks on US hospitals, clinics, and other health care delivery organizations, 2016-2021. In JAMA Health Forum (Vol. 3, No. 12, p. e224873).
- Ponemon, I. (2021). Cost of a data breach report 2021. Risk Quantification, 73.
- Poon, E. G., Keohane, C. A., Yoon, C. S., Ditmore, M., Bane, A., Levtzion-Korach, O., ... & Gandhi, T. K. (2010). Effect of bar-code technology on the safety of medication administration. New England Journal of Medicine, 362(18), 1698-1707.
- Priestman, W., Anstis, T., Sebire, I. G., Sridharan, S., & Sebire, N. J. (2019). Phishing in healthcare organisations: Threats, mitigation and approaches. BMJ health & care informatics, 26(1), e100031.
- Rushton, C. H., Schoonover-Shoffner, K., & Kennedy, M. S. (2017). Executive summary: transforming moral distress into moral resilience in nursing. Journal of Christian Nursing, 34(2), 82-86.
- Santos, P. S., do Nascimento, L. P., Martorell, L. B., de Carvalho, R. B., & Finkler, M. (2021). Dental education and undue exposure of patients’ image in social media: A literature review. European Journal of Dental Education, 25(3), 556-572.
- Sittig, D. F., & Singh, H. (2016). A socio-technical approach to preventing, mitigating, and recovering from ransomware attacks. Applied clinical informatics, 7(02), 624-632.
- Sittig, D. F., Wright, A., Coiera, E., Magrabi, F., Ratwani, R., Bates, D. W., & Singh, H. (2020). Current challenges in health information technology–related patient safety. Health informatics journal, 26(1), 181-189.
- Slayton, T. B. (2018). Ransomware: the virus attacking the healthcare industry. Journal of Legal Medicine, 38(2), 287-311.
- Sulmasy, L. S., López, A. M., Horwitch, C. A., & , American College of Physicians Ethics, Professionalism and Human Rights Committee. (2017). Ethical implications of the electronic health record: in the service of the patient. Journal of general internal medicine, 32(8), 935-939.
- Tiongco, C. G. (2022). The clinical reasoning of occupational therapists in an oncology setting: An exploration of documentation following MOHO training.
- Triplett, W. (2022). Ransomware attacks on the healthcare industry. Journal of Business, Technology and Leadership, 4(1), 1-13.
- US Department of Health and Human Services. (2019). Breach portal: Notice to the secretary of hhs breach of unsecured protected health information. URL: https://ocrportal. hhs. gov/ocr/breach/breach_report. jsf [accessed 2016-10-20][WebCite Cache ID 6lPC5KlZ9].
- Varpio, L., Day, K., Elliot‐Miller, P., King, J. W., Kuziemsky, C., Parush, A., ... & Rashotte, J. (2015). The impact of adopting EHRs: how losing connectivity affects clinical reasoning. Medical Education, 49(5), 476-486.
- Whitman, M. E., & Mattord, H. J. (2009). Principles of information security (p. 656). Boston, MA: Thomson Course Technology.
- Wikina, S. B. (2014). What caused the breach? An examination of use of information technology and health data breaches. Perspectives in health information management, 11(Fall).
- Yeo, L. H., & Banfield, J. (2022). Human factors in electronic health records cybersecurity breach: an exploratory analysis. Perspectives in health information management, 19(2).
References
Alanazi, A., Almutib, A., & Aldosari, B. (2023). Physicians’ Perspectives on a Multi-Dimensional Model for the Roles of Electronic Health Records in Approaching a Proper Differential Diagnosis. Journal of Personalized Medicine, 13(4), 680.
Almas, A., Iqbal, W., Altaf, A., Saleem, K., Mussiraliyeva, S., & Iqbal, M. W. (2023). Context-based adaptive fog computing trust solution for time-critical smart healthcare systems. IEEE Internet of Things Journal, 10(12), 10575-10586.
Ayala, L. (2016). Cybersecurity for hospitals and healthcare facilities.
Bai, G., Jiang, J., & Flasher, R. (2017). Hospital risk of data breaches. JAMA internal medicine, 177(6), 878-880.
Campbell, E. M., Sittig, D. F., Ash, J. S., Guappone, K. P., & Dykstra, R. H. (2006). Types of unintended consequences related to computerized provider order entry. Journal of the American Medical Informatics Association, 13(5), 547-556.
Cohen, I. G., & Mello, M. M. (2018). HIPAA and protecting health information in the 21st century. Jama, 320(3), 6-7.
Coventry, L., & Branley, D. (2018). Cybersecurity in healthcare: A narrative review of trends, threats and ways forward. Maturitas, 113, 48-52.
Cruz-Correia, R., Ferreira, D., Bacelar, G., Marques, P., & Maranhão, P. (2018). Personalised medicine challenges: quality of data. International Journal of Data Science and Analytics, 6(3), 251-259.
Dameff, C., Tully, J., Chan, T. C., Castillo, E. M., Savage, S., Maysent, P., ... & Longhurst, C. A. (2023). Ransomware attack associated with disruptions at adjacent emergency departments in the US. JAMA network open, 6(5), e2312270.
Fernández-Alemán, J. L., Señor, I. C., Lozoya, P. Á. O., & Toval, A. (2013). Security and privacy in electronic health records: A systematic literature review. Journal of biomedical informatics, 46(3), 541-562.
Franco, M. F., Lacerda, F. M., & Stiller, B. (2022). A framework for the planning and management of cybersecurity projects in small and medium-sized enterprises. Revista de Gestão e Projetos, 13(3), 10-37.
Ghafur, S., Kristensen, S., Honeyford, K., Martin, G., Darzi, A., & Aylin, P. (2019). A retrospective impact analysis of the WannaCry cyberattack on the NHS. NPJ digital medicine, 2(1), 98.
Gordon, W. J., Wright, A., Glynn, R. J., Kadakia, J., Mazzone, C., Leinbach, E., & Landman, A. (2019). Evaluation of a mandatory phishing training program for high-risk employees at a US healthcare system. Journal of the American Medical Informatics Association, 26(6), 547-552.
Green, B. N., Johnson, C. D., & Adams, A. (2006). Writing narrative literature reviews for peer-reviewed journals: secrets of the trade. Journal of chiropractic medicine, 5(3), 101-117.
Hassandoust, F., Techatassanasoontorn, A. A., & Tan, F. B. (2016). Factors influencing the infusion of information systems: A literature review. Pacific Asia Journal of the Association for Information Systems, 8(1), 2.
Hassan, W. U., Bates, A., & Marino, D. (2020, May). Tactical provenance analysis for endpoint detection and response systems. In 2020 IEEE symposium on security and privacy (SP) (pp. 1172-1189). IEEE.
Joda, T., Zarone, F., & Ferrari, M. (2017). The complete digital workflow in fixed prosthodontics: a systematic review. BMC oral health, 17(1), 124.
Khan, F. (2023). Regulating the revolution: a legal roadmap to optimizing AI in healthcare. Minnesota Journal of Law, Science & Technology, 25(1), 49.
Kim, J., Park, E. H., Park, Y. S., Chun, K. H., & Wiles, L. L. (2022). Prosocial rule breaking on health information security at healthcare organisations in South Korea. Information Systems Journal, 32(1), 164-191.
Kruse, C. S., Frederick, B., Jacobson, T., & Monticone, D. K. (2017). Cybersecurity in healthcare: A systematic review of modern threats and trends. Technology and Health Care, 25(1), 1-10.
Larsen, E., Fong, A., Wernz, C., & Ratwani, R. M. (2018). Implications of electronic health record downtime: an analysis of patient safety event reports. Journal of the American Medical Informatics Association, 25(2), 187-191.
Melnick, E. R., Dyrbye, L. N., Sinsky, C. A., Trockel, M., West, C. P., Nedelec, L., ... & Shanafelt, T. (2020, March). The association between perceived electronic health record usability and professional burnout among US physicians. In Mayo Clinic Proceedings (Vol. 95, No. 3, pp. 476-487). Elsevier.
Melon, E., & Hernandez, W. (2020). Cybersecurity in the dental healthcare sector: the need of knowledge for small practitioners. Issues in Information Systems, 21(1), 118.
Neprash, H. T., McGlave, C. C., Cross, D. A., Virnig, B. A., Puskarich, M. A., Huling, J. D., ... & Nikpay, S. S. (2022, December). Trends in ransomware attacks on US hospitals, clinics, and other health care delivery organizations, 2016-2021. In JAMA Health Forum (Vol. 3, No. 12, p. e224873).
Ponemon, I. (2021). Cost of a data breach report 2021. Risk Quantification, 73.
Poon, E. G., Keohane, C. A., Yoon, C. S., Ditmore, M., Bane, A., Levtzion-Korach, O., ... & Gandhi, T. K. (2010). Effect of bar-code technology on the safety of medication administration. New England Journal of Medicine, 362(18), 1698-1707.
Priestman, W., Anstis, T., Sebire, I. G., Sridharan, S., & Sebire, N. J. (2019). Phishing in healthcare organisations: Threats, mitigation and approaches. BMJ health & care informatics, 26(1), e100031.
Rushton, C. H., Schoonover-Shoffner, K., & Kennedy, M. S. (2017). Executive summary: transforming moral distress into moral resilience in nursing. Journal of Christian Nursing, 34(2), 82-86.
Santos, P. S., do Nascimento, L. P., Martorell, L. B., de Carvalho, R. B., & Finkler, M. (2021). Dental education and undue exposure of patients’ image in social media: A literature review. European Journal of Dental Education, 25(3), 556-572.
Sittig, D. F., & Singh, H. (2016). A socio-technical approach to preventing, mitigating, and recovering from ransomware attacks. Applied clinical informatics, 7(02), 624-632.
Sittig, D. F., Wright, A., Coiera, E., Magrabi, F., Ratwani, R., Bates, D. W., & Singh, H. (2020). Current challenges in health information technology–related patient safety. Health informatics journal, 26(1), 181-189.
Slayton, T. B. (2018). Ransomware: the virus attacking the healthcare industry. Journal of Legal Medicine, 38(2), 287-311.
Sulmasy, L. S., López, A. M., Horwitch, C. A., & , American College of Physicians Ethics, Professionalism and Human Rights Committee. (2017). Ethical implications of the electronic health record: in the service of the patient. Journal of general internal medicine, 32(8), 935-939.
Tiongco, C. G. (2022). The clinical reasoning of occupational therapists in an oncology setting: An exploration of documentation following MOHO training.
Triplett, W. (2022). Ransomware attacks on the healthcare industry. Journal of Business, Technology and Leadership, 4(1), 1-13.
US Department of Health and Human Services. (2019). Breach portal: Notice to the secretary of hhs breach of unsecured protected health information. URL: https://ocrportal. hhs. gov/ocr/breach/breach_report. jsf [accessed 2016-10-20][WebCite Cache ID 6lPC5KlZ9].
Varpio, L., Day, K., Elliot‐Miller, P., King, J. W., Kuziemsky, C., Parush, A., ... & Rashotte, J. (2015). The impact of adopting EHRs: how losing connectivity affects clinical reasoning. Medical Education, 49(5), 476-486.
Whitman, M. E., & Mattord, H. J. (2009). Principles of information security (p. 656). Boston, MA: Thomson Course Technology.
Wikina, S. B. (2014). What caused the breach? An examination of use of information technology and health data breaches. Perspectives in health information management, 11(Fall).
Yeo, L. H., & Banfield, J. (2022). Human factors in electronic health records cybersecurity breach: an exploratory analysis. Perspectives in health information management, 19(2).