Can Cyber Risk Of Health Care Firms Be Insured? A Multinomial Logistic Regression Model

Swati Jain,Arunabha Mukhopadhyay,Saloni Jain
DOI: https://doi.org/10.1080/10919392.2023.2244386
IF: 2.2368
2023-08-12
Journal of Organizational Computing and Electronic Commerce
Abstract:The healthcare sector is prone to Distributed Denial-of-Service and Ransomware attacks owing to unsecured networks and software. This results in stalling of outpatient and inpatient operations of a hospital. In this study, we propose an H-CRAM model that computes the risk of a cyber-attack based on the threat appraisal component of the Protection Motivation Theory (PMT) using multinomial logistic regression. We also hypothesize that training the healthcare staff, implementing IT governance, and intervening technology will decrease the probability of the occurrence of a cyber threat. The severity of the risk is computed using Collective Risk Modelling. Next, based on the coping appraisal component of PMT, Rational Choice Theory, and NIST guidelines, we propose that the CIO of a healthcare firm should first reduce the cyber-risk by investing in encrypting Electronic Health Records, Security Incident and Event Management (SIEM) and Security Orchestration, Automation and Response (SOAR) tools. Then pass the residual cyber risk to a cyber insurer.
computer science, information systems, interdisciplinary applications
What problem does this paper attempt to address?