Security Risk Assessment for Patient Portals of Hospitals: A Case Study of Taiwan
Pei-Cheng Yeh,Kuen-Wei Yeh,Jiun-Lang Huang
DOI: https://doi.org/10.2147/rmhp.s463408
2024-06-19
Risk Management and Healthcare Policy
Abstract:Pei-Cheng Yeh, 1, 2 Kuen-Wei Yeh, 3– 5 Jiun-Lang Huang 6, 7 1 Graduate Institute of Clinical Dentistry, School of Dentistry, College of Medicine, National Taiwan University, Taipei, Taiwan, Republic of China; 2 Division of Endodontics, Department of Stomatology, Taichung Veterans General Hospital, Taichung, Taiwan, Republic of China; 3 Investigation Bureau, Ministry of Justice, New Taipei City, Taiwan, Republic of China; 4 Department of Electrical Engineering, Chinese Culture University, Taipei, Taiwan, Republic of China; 5 Department of Information, Chinese Culture University, Taipei, Taiwan, Republic of China; 6 Department of Electrical Engineering, National Taiwan University, Taipei, Taiwan, Republic of China; 7 Graduate Institute of Electronics Engineering, National Taiwan University, Taipei, Taiwan, Republic of China Correspondence: Kuen-Wei Yeh, Email Background: Growing cyberattacks have made it more challenging to maintain healthcare information system (HIS) security in medical institutes, especially for hospitals that provide patient portals to access patient information, such as electronic health record (EHR). Objective: This work aims to evaluate the patient portal security risk of Taiwan's EEC (EMR Exchange Center) member hospitals and analyze the association between patient portal security, hospital location, contract category and hospital type. Methods: We first collected the basic information of EEC member hospitals, including hospital location, contract category and hospital type. Then, the patient portal security of individual hospitals was evaluated by a well-known vulnerability scanner, UPGUARD, to assess website if vulnerable to high-level attacks such as denial of service attacks or ransomware attacks. Based on their UPSCAN scores, hospitals were classified into four security ratings: absolute low risk, low to medium risk, medium to high risk and high risk. Finally, the associations between security rating, contract category and hospital type were analyzed using chi-square tests. Results: We surveyed a total of 373 EEC member hospitals. Among them, 20 hospital patient portals were rated as "absolute low risk", 104 hospital patient portals as "low to medium risk", 99 hospital patient portals as "medium to high risk" and 150 hospital patient portals as "high risk". Further investigation revealed that the patient portal security of EEC member hospitals was significantly associated with the contract category and hospital type ( P < 0.001). Conclusion: The analysis results showed that large-scale hospitals generally had higher security levels, implying that the security of low-tier and small-scale hospitals may warrant reinforcement or strengthening. We suggest that hospitals should pay attention to the security risk assessment of their patient portals to preserve patient information privacy. Keywords: security risk assessment, healthcare information system, electronic health record, electronic medical record, EMR Exchange Center, vulnerability scanner Patient information privacy has emerged as a critical issue in recent years. 1–3 Large volumes of potentially sensitive patient information, such as name, ID, birth date, contact phone and health record, are preserved in medical institutes. The electronic health record (EHR) 1–7 is a digital version of the traditional paper-based personal health record. Using EHR, personal health records can be accessed with online services and shared between hospitals and patients. A healthcare information system (HIS) 1–3 refers to a system designed to manage and utilize patient information. In general, HIS consists of internal physician systems and external patient portal. Physician systems are designed to support medical diagnosis and treatment of healthcare professionals. The doctors can trace patient medical records through physician systems. Due to safety considerations, physician systems are only for internal use and disable connections from the Internet. Compared to physician systems, patient portals 3–6 are utilized to serve hospital patients. The main purpose of patient portals is to give patients easy access to their medical records to enhance patient engagement. Patient portals are web-based platforms or mobile APPs to offer online reservations, in-time consultation, patient data maintenance and instant EHR search. To obtain permission to use patient portals, patients should apply for a portal account from the hospital. If the application is approved, the hospital will assign one unique portal account to patients for portal login. Figure 1 shows an example of a patient port -Abstract Truncated-
health care sciences & services,health policy & services