Safeguarding Virtual Healthcare: A Novel Attacker-Centric Model for Data Security and Privacy

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Herath, Suvineetha, Gelman, Haywood, Hastings, John, Wang, Yong
Format: Preprint
Published: 2024
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866913765009653760
author Herath, Suvineetha
Gelman, Haywood
Hastings, John
Wang, Yong
author_facet Herath, Suvineetha
Gelman, Haywood
Hastings, John
Wang, Yong
contents The rapid growth of remote healthcare delivery has introduced significant security and privacy risks to protected health information (PHI). Analysis of a comprehensive healthcare security breach dataset covering 2009-2023 reveals their significant prevalence and impact. This study investigates the root causes of such security incidents and introduces the Attacker-Centric Approach (ACA), a novel threat model tailored to protect PHI. ACA addresses limitations in existing threat models and regulatory frameworks by adopting a holistic attacker-focused perspective, examining threats from the viewpoint of cyber adversaries, their motivations, tactics, and potential attack vectors. Leveraging established risk management frameworks, ACA provides a multi-layered approach to threat identification, risk assessment, and proactive mitigation strategies. A comprehensive threat library classifies physical, third-party, external, and internal threats. ACA's iterative nature and feedback mechanisms enable continuous adaptation to emerging threats, ensuring sustained effectiveness. ACA allows healthcare providers to proactively identify and mitigate vulnerabilities, fostering trust and supporting the secure adoption of virtual care technologies.
format Preprint
id arxiv_https___arxiv_org_abs_2412_13440
institution arXiv
publishDate 2024
record_format arxiv
spellingShingle Safeguarding Virtual Healthcare: A Novel Attacker-Centric Model for Data Security and Privacy
Herath, Suvineetha
Gelman, Haywood
Hastings, John
Wang, Yong
Cryptography and Security
K.6.5; H.2.7; D.4.6; J.3
The rapid growth of remote healthcare delivery has introduced significant security and privacy risks to protected health information (PHI). Analysis of a comprehensive healthcare security breach dataset covering 2009-2023 reveals their significant prevalence and impact. This study investigates the root causes of such security incidents and introduces the Attacker-Centric Approach (ACA), a novel threat model tailored to protect PHI. ACA addresses limitations in existing threat models and regulatory frameworks by adopting a holistic attacker-focused perspective, examining threats from the viewpoint of cyber adversaries, their motivations, tactics, and potential attack vectors. Leveraging established risk management frameworks, ACA provides a multi-layered approach to threat identification, risk assessment, and proactive mitigation strategies. A comprehensive threat library classifies physical, third-party, external, and internal threats. ACA's iterative nature and feedback mechanisms enable continuous adaptation to emerging threats, ensuring sustained effectiveness. ACA allows healthcare providers to proactively identify and mitigate vulnerabilities, fostering trust and supporting the secure adoption of virtual care technologies.
title Safeguarding Virtual Healthcare: A Novel Attacker-Centric Model for Data Security and Privacy
topic Cryptography and Security
K.6.5; H.2.7; D.4.6; J.3
url https://arxiv.org/abs/2412.13440