Home / Current Issue / Paper 1723017
Cybersecurity Risk and Digital Resilience in Healthcare Information Systems: Strategies for Protecting Data Integrity and Patient Safety
Subject area: Science,Engineering and Technology · Area of research: Data Security in the Healthcare
DOI: 10.64388/IREV10I3-1723017
Abstract
The increasing reliance on digital technologies has transformed the delivery, management, and coordination of healthcare services. Electronic health records, connected medical devices, telehealth platforms, cloud computing, health information exchanges, and other digital systems have improved the availability and exchange of healthcare information while simultaneously increasing the number of systems and connections that must be protected against cybersecurity threats (Luna et al., 2016; World Health Organization [WHO], 2025). Cybersecurity incidents in healthcare can have consequences that extend beyond the loss of confidential information because disruption, unauthorized modification, or unavailability of health information may interfere with clinical workflows and patient care (Argaw et al., 2020; Kruse et al., 2017). This article examines the relationship between cybersecurity risk, data integrity, digital resilience, and patient safety in healthcare information systems. An integrative review of peer reviewed literature and authoritative cybersecurity guidance was used to identify recurring cybersecurity risks, organizational vulnerabilities, and resilience strategies. The literature indicates that ransomware, unauthorized access, vulnerabilities in connected medical devices, human factors, legacy systems, inadequate access controls, and weaknesses in third party environments remain important cybersecurity concerns in healthcare (Ewoh & Dua, 2024; Luna et al., 2016). Evidence also indicates that cyber incidents can disrupt emergency departments, increase patient volumes at neighboring facilities, delay clinical services, and create operational conditions that may affect patient safety (Choi et al., 2024; Neprash et al., 2024). Based on these findings, this article proposes a Digital Resilience and Patient Safety Framework that integrates risk identification, data integrity protection, preventive security, resilient response and recovery, and continuous organizational learning. The framework positions cybersecurity as an organizational and patient safety responsibility rather than solely an information technology function. The article concludes that healthcare organizations should evaluate cybersecurity controls according to their ability not only to protect information from unauthorized access but also to preserve the accuracy, availability, reliability, and continuity of information required for safe healthcare delivery.
Keywords
healthcare cybersecurity, digital resilience, healthcare information systems, data integrity, patient safety, electronic health records, ransomware, information security
References
[1] Abouelmehdi, K., Beni Hassan, S., Khaloufi, H., & Azzouazi, M. (2017). Access control and privilege management in electronic health records: A systematic literature review. Journal of Medical Systems, 41, Article 123.
[2] Aljuraid, R., & Justinia, T. (2022). Classification of challenges and threats in healthcare cybersecurity: A systematic review. Studies in Health Technology and Informatics, 295, 362–365. Crossref
[3] Argaw, S. T., Troncoso-Pastoriza, J. R., Lacey, D., Florin, M. V., Calcavecchia, F., Anderson, D., Burleson, W., Vogel, J. M., Eshaya-Chauvin, B., & Flahault, A. (2020). Cybersecurity of hospitals: Discussing the challenges and working towards mitigating the risks. BMC Medical Informatics and Decision Making, 20, 146. Crossref
[4] Choi, Y. J., Johnson, D., Koo, D. C., & colleagues. (2024). Ransomware attack associated with disruptions at adjacent emergency departments in the US. JAMA Network Open, 7(5), e2410824.
[5] Ewoh, P., & Dua, U. (2024). Vulnerability to cyberattacks and sociotechnical solutions for health care systems: Systematic review. Journal of Medical Internet Research, 26, e46904.
[6] Fernández Alemán, J. L., Señor, I. C., Lozoya, P. Á. O., & Toval, A. (2013). Security and privacy in electronic health records: A systematic literature review. Journal of Biomedical Informatics, 46(3), 541–562. Crossref
[7] Kierkegaard, P. (2011). Electronic health record: Wiring Europe's healthcare. Computer Law & Security Review, 27(5), 503–515. Crossref
[8] Kruse, C. S., Frederick, B., Jacobson, T., & Monticone, D. K. (2017). Cybersecurity in healthcare: A systematic review of modern threats and trends. Technology and Health Care, 25(1), 1–10. Crossref
[9] Kruse, C. S., Dolezel, D., & Shanmugam, R. (2026). Cybersecurity in healthcare: A systematic review and narrative analysis. Applied Clinical Informatics, 17(2), 315–328. Crossref
[10] Luna, R., Rhine, E., Myhra, M., Sullivan, R., & Kruse, C. S. (2016). Cyber threats to health information systems: A systematic review. Technology and Health Care, 24(1), 1–9. Crossref
[11] National Institute of Standards and Technology. (2024). The NIST cybersecurity framework (CSF) 2.0. U.S. Department of Commerce. Crossref
[12] Neprash, H. T., McGlave, C. C., Cross, D. A., Virnig, B. A., & Bohman, H. R. (2024). Trends in ransomware attacks on US hospitals, clinics, and other health care delivery organizations, 2016–2021. JAMA Health Forum, 5(1), e234782. Crossref
[13] Rezaeibagha, F., Win, K. T., & Susilo, W. (2015). A systematic literature review on security and privacy of electronic health record systems: Technical perspectives. Health Information Management Journal, 44(3), 23–38. Crossref
[14] Tully, J. L., et al. (2025). Patient care technology disruptions associated with the CrowdStrike outage. JAMA Network Open, 8(7), e2530226. Crossref
[15] U.S. Department of Health and Human Services. (2024). Healthcare and public health sector specific cybersecurity performance goals. https://hhscyber.hhs.gov/cybersecurity-performance-goals.html
[16] U.S. Food and Drug Administration. (2025). Cybersecurity in medical devices. https://www.fda.gov/medical-devices/digital-health-center-excellence/cybersecurity
[17] World Health Organization. (2025). Cybersecurity and privacy maturity assessment and strengthening for digital health information systems. WHO Regional Office for Europe. https://www.who.int/europe/publications/i/item/WHO-EURO-2025-11827-51599-78854
How to cite this paper
@article{1723017,
author = {Desire Emeka, Fidelia Ahiante},
title = {Cybersecurity Risk and Digital Resilience in Healthcare Information Systems: Strategies for Protecting Data Integrity and Patient Safety},
journal = {Iconic Research And Engineering Journals},
year = {2026},
volume = {10},
number = {3},
pages = {1440-1450},
issn = {2456-8880},
url = {https://www.irejournals.com/formatedpaper/1723017.pdf},
abstract = {The increasing reliance on digital technologies has transformed the delivery, management, and coordination of healthcare services. Electronic health records, connected medical devices, telehealth platforms, cloud computing, health information exchanges, and other digital systems have improved the availability and exchange of healthcare information while simultaneously increasing the number of systems and connections that must be protected against cybersecurity threats (Luna et al., 2016; World Health Organization [WHO], 2025). Cybersecurity incidents in healthcare can have consequences that extend beyond the loss of confidential information because disruption, unauthorized modification, or unavailability of health information may interfere with clinical workflows and patient care (Argaw et al., 2020; Kruse et al., 2017). This article examines the relationship between cybersecurity risk, data integrity, digital resilience, and patient safety in healthcare information systems. An integrative review of peer reviewed literature and authoritative cybersecurity guidance was used to identify recurring cybersecurity risks, organizational vulnerabilities, and resilience strategies. The literature indicates that ransomware, unauthorized access, vulnerabilities in connected medical devices, human factors, legacy systems, inadequate access controls, and weaknesses in third party environments remain important cybersecurity concerns in healthcare (Ewoh & Dua, 2024; Luna et al., 2016). Evidence also indicates that cyber incidents can disrupt emergency departments, increase patient volumes at neighboring facilities, delay clinical services, and create operational conditions that may affect patient safety (Choi et al., 2024; Neprash et al., 2024). Based on these findings, this article proposes a Digital Resilience and Patient Safety Framework that integrates risk identification, data integrity protection, preventive security, resilient response and recovery, and continuous organizational learning. The framework positions cybersecurity as an organizational and patient safety responsibility rather than solely an information technology function. The article concludes that healthcare organizations should evaluate cybersecurity controls according to their ability not only to protect information from unauthorized access but also to preserve the accuracy, availability, reliability, and continuity of information required for safe healthcare delivery.},
keywords = {healthcare cybersecurity, digital resilience, healthcare information systems, data integrity, patient safety, electronic health records, ransomware, information security},
month = {September},
doi = {https://doi.org/10.64388/IREV10I3-1723017}
}