Submitted:
08 June 2025
Posted:
09 June 2025
You are already at the latest version
Abstract
Keywords:
1. Introduction
2. Background
2.1. Overview “EHR System & Security Requirement:
- Confidentiality: The patient record during the collection, storage, and access stages must be private and confidential so that no unauthorized person or entity may be able to inspect the content of the patient record [3].
- Integrity: Good data integrity must be defined so that only authorized persons can modify patient records, and proper auditing is put in place to enforce nonrepudiation. A data integrity policy must be implemented and enforced since a patient’s previous record is paramount to their care [3].
- Availability: Necessary care ensuring systems are robust and redundant is taken. First, it must be guaranteed that EHR systems are available anytime, any day. Second, the EHR system must have close to 0% downtime due to its critical role during patient care. Third, all necessary efforts must be implemented to defend against attacks such as Denial of Service, Distributed Denial of Service, and others. Lastly, the hosting server must have the redundant capability to accommodate hardware failure and ensure healthcare providers have continuous access to health records [3].
2.2. General Background about AIoT
2.3. Data Ownership
2.4. Confidentiality and Privacy of Data
3. Related Work
3.1. EHR System Security and Data Breaches
3.2. Artificial Intelligence of Things (AIoT) Integrated Healthcare Security and Privacy
4. Methodology
- Collect, analyze, and interpret observations about current EHR systems, design to look for specific phenomena in EHR data breaches, and look for patterns to determine relative importance to Cyberattack.
- Identify shows that EHR systems serve as a goldmine for an attacker, lack sufficient control to guarantee patient privacy and hospital operation continuity during a Cyberattack, and require integration, implementation, and application of essential security principles, controls, and strategies necessary to safeguard patient data generated through the EHR systems life cycle.
- To understand why a particular type of attack occurs, how the attack is conducted, whom it affects, how it impacts stakeholders, the mood of the attack, affected systems, period of attack (if IT staff is around), location of breached information on the Network/System, type of breach, and the number of affected records, and privacy of safety impact.
Data Description
5. Descriptive Analysis
5.1. Covered Entities
5.2. Type of Breaches
5.3. Point of Breaches
6. Trend Analysis
6.1. Type of Breach
6.2. Point of Breach
7. Discussion & Conclusions
Conflicts of Interest
References
- Sherman, G.; Towards Electronic Health Record. Health Canada: Office of Health and the Information Highway 2001. Available online: https://publications.gc.ca/collections/Collection/H21-166-2001E.pdf (accessed on day month year).
- CDC. Electronic Medical Records/Electronic Health Records. Available online: https://www.cdc.gov/nchs/fastats/electronic-medical-records.htm (accessed on 5 December 2021).
- Camps, C.J.R.; Wainer, J.; Salinas, M.D.U.; Sigulem, D.; Security Requirements for a Lifelong Electronic Health Record System: An Opinion. The Open Medical Informatics Journal 2008 2, 160-165. Available online: http://www.ncbi.nlm.nih.gov/pmc/articles/PMC2669643/ (accessed on 5 December 2021).
- Frampton, S.; and Guastello, S. Patient-Centered Care Guide. (accessed on 5-Dec-2021]. Available online: http://www.patient-centeredcare.org/inside/practical.html (accessed on 5 December 2021).
- Chromium, P. The Chromium Projects: System Hardening. 28 March 2021. Available online: http://www.chromium.org/chromium-os/chromiumos-design-docs/system-hardening (accessed on 28 March 2021).
- Humphries, M. AI Leaks Over 2.5M Medical Records. Available online: https://uk.pcmag.com/encryption/128228/report-ai-company-leaks-over-25m-medical-records (accessed on day month year).
- Clmpanu, C. AMCA data breach has now gone over the 20 million mark”. Available online: https://www.zdnet.com/article/amca-data-breach-has-now-gone-over-the-20-million-mark/ (accessed on 20 November 2021).
- Tidy, J. Hackers Threaten to Leak Plastic Surgery Pictures. Available online: https://www.bbc.com/news/technology-55439190 (accessed on 1 November 2021).
- Murphy, H. Why a Dat Breach at a Genealogy Site Has Privacy Expert Worried. Available online: https://www.nytimes.com/2020/08/01/technology/gedmatch-breach-privacy.html?referringSource=articleShare (accessed on 20 Octomber 2021).
- Iwin, L. ; Breach at Norway’s Largest Healthcare Authority Was a Disaster Waiting to Happen. Available online: https://www.itgovernance.eu/blog/en/breach-at-norways-largest-healthcare-authority-was-a-disaster-waiting-to-happen (accessed on 24 October 2021).
- Sailpoint. SailPoint Market Pulse Survey: The Data Breach Battle. Available online: http://assets.fiercemarkets.net/public/newsletter/fierceemr/sailpoint.pdf (accessed on 5 November 2021).
- ________. Implementation of Electronic Records. Available online: http://openonlinecourses.com/ehr/ImplementationOfInformationSystems.asp (accessed on 23 August 2021).
- _________. Data Sharing Principles.” The Canadian Medical Protective Association. Available online: https://www.cmpa-acpm.ca/static-assets/pdf/advice-and-publications/handbooks/com_electronic_records_handbook-e.pdf (accessed on 15 October 2021).
- ______. Healthcare in Digital Age: Who owns data.” The Wall Street Journal. Available online: http://live.wsj.com/video/health-care-in-the-digital-age-who-owns-the-data/28B6E0AD-8506-40B2-A65920A9B696F524.html?goback=%2Egna_2890588%2Egde_2890588_member_191525235#!28B6E0AD-8506-40B2-A659-20A9B696F524 (accessed on 5 December 2021).
- Sharma, R. Who Really owns You’re your Health Data? Available online: https://www.forbes.com/sites/forbestechcouncil/2018/04/23/who-really-owns-your-health-data/?sh=3bf0587c6d62 (accessed on 23 November 2021).
- King, M. Who Owns Your Banking Data? Available online: https://iveybusinessjournal.com/who-owns-your-banking-data/ (accessed on September 2021).
- _______. When law and medicine intersect: Influential court decision still relevant to patient's access to medical records.” The Canadian Medical Protective Association December 2011. Available online: http://www.cmpa-acpm.ca/cmpapd04/docs/resource_files/perspective/2011/04/com_p1104_3-e.cfm (accessed on 23 Octomber 2021).
- Takach, G. Computer Law, 2nd ed.; Irwin Law: Toronto, ON, Canada, 2003; p. 515. [Google Scholar]
- Saksena, N.; Matthan, R.; Bhan, A.; et al. Rebooting consent in the digital age: A governance framework for health data exchange. BMJ Global Health 2021, 6, e005057. [Google Scholar] [CrossRef] [PubMed]
- _______. Health Services in Your Community. Available online: http://www.health.gov.on.ca/english/public/contact/hosp/hospfaq_dt.html (accessed on 23 August 2021).
- Valerius, J.D. The Electronic Health Record: What Every Information Manager Should Know. Available online: http://www.arma.org/bookstore/files/Valerius.pdf (accessed on 15 February 2013).
- ______. Frank Abagnale. Wikipedia. Available online: http://en.wikipedia.org/wiki/Frank_Abagnale (accessed on 16 February 2013).
- Young, D. Electronic Health Records-Privacy and Security Issues. McMillan. 2010. Available online: http://www.mcmillan.ca/Electronic-Health-Records--Privacy-and-Security-Issues (accessed on 12 June 2012).
- ___________. Electronic Health Records in Canada: An Overview of Federal and Provincial Reports.” Office of the Auditor General of Canada. April 2010. Available online: http://www.oag-bvg.gc.ca/internet/English/parl_oag_201004_07_e_33720.html (accessed on 2 July 2012).
- Yankson, B. Ubiquitous Biometrics NOW: Identity Management Solution for the Canadian Government, Canadian Business, and You. UOIT MITS Course Project December 2011.
- ________. Hospital Treating Kate Middleton falls for a prank call.” Toronto Star December 5th, 2012. Available online: http://www.thestar.com/news/world/article/1297749--hospital-treating-kate-middleton-falls-for-prank-call-gives-out-health-information (accessed on 18 January 2013).
- McMurch, T. EHEALTH SASKATCHEWAN SECURITY REVIEWS UNDER WAY FOLLOWING COMPUTER DISPOSAL ERROR. Government of Saskatchewan March 27, 2012. Available online: http://www.gov.sk.ca/news?newsId=202531cf-0596-40fa-9434-5d2c4aa6135a (accessed on 15 January 2013).
- Priest, L. A sickening side-effect of the eHealth revolution. Globe and Mail September 6, 2012. Available online: http://m.theglobeandmail.com/news/politics/a-sickening-side-effect-of-the-ehealth-revolution/article2315265/?service=mobile (accessed on 17 January 2013).
- _________________. Electronic Health Record Infostructure (EHRi): Privacy and Security Conceptual Architecture.” Health Canada Infoway June 2005. Available online: https://knowledge.infoway-inforoute.ca/EHRSRA/doc/EHR-Privacy-Security.pdf (accessed on 15 July 2012).
- Shultz, D. As Patients’ records Go Digital, Theft and Hacking Problem grow. Kaiser Health News June 3rd, 2012. Available online: http://www.kaiserhealthnews.org/Stories/2012/June/04/electronic-health-records-theft-hacking.aspx (accessed on 20 July 2012).
- ___________________. Guide to Privacy and Security of Health Information. Office of the National Coordinator for Health Information Technology. Available online: http://www.healthit.gov/sites/default/files/pdf/privacy/privacy-and-security-guide.pdf (accessed on 2 July 2012).
- Khin, T.W. A Review of Security of Electronic Health Records. Health Information Management 2005, 34, 13–17. Available online: https://www.cs.uwaterloo.ca/twiki/pub/Main/MaxwellYoung/Review_Win.pdf (accessed on 12 August 2012).
- Available online: https://ocrportal.hhs.gov/ocr/breach/breach_report.jsf.
- Available online: https://www.onespan.com/topics/biometric-authentication.
- Treasury Board of Canada Secretariat: Federating Identity Management in the Government of Canada: A Backgrounder. Available online: http://www.tbs-sct.gc.ca/sim-gsi/publications/docs/2011/fimgc-fgigc/fimgc-fgigctb-eng.asp (accessed on day month year).
- El-Khatib, Khalil: Biometric, Access Control, and Smart Card Technology: Lecture 1 page 15. University of Ontario Institute of Technology, Oshawa Ontario, September 2012.
- Feldman, Robin: Considerations on the Emerging Implementation of Biometric Technology, 2004. Available online: http://papers.ssrn.com/sol3/papers.cfm?abstract_id=492444 (accessed on 21 November 2013).
- Available online: https://www.onespan.com/blog/behavioral-biometric-authentication-will-kick-passwords-curb-sooner-you-think.
- Reeder, W. Expandable Grids for Visualizing and Authoring Computer Security Policies. Available online: http://dl.acm.org/citation.cfm?id=1357285 (accessed on 22 January 2013).
- Saltzer & Schrober. The Protection of Information in Computer Systems. The University of Virginia, Department of Computer Science. Available online: http://www.cs.virginia.edu/~evans/cs551/saltzer/ (accessed on 30 January 2013).
- Warfield, C. The Disaster Management Cycle. Available online: http://www.gdrc.org/uem/disasters/1-dm_cycle.html (accessed on 1 March 2013).
- Baker, S.; Xiang, W. Artificial intelligence of things for smarter Healthcare: A survey of advancements, challenges, and opportunities. IEEE Communications Surveys & Tutorials 2023, 25, 1261–1293. [Google Scholar] [CrossRef]
- Pandey, N.K.; Kumar, K.; Saini, G.; Mishra, A.K. Security issues and challenges in cloud of things-based applications for industrial automation. Annals of Operations Research 2023, 1–20. [Google Scholar] [CrossRef] [PubMed]
- Pappakrishnan, V.; Mythili, R.; Kavitha, V.; Parthiban, N. Role of artificial intelligence of things (AIoT) in COVID-19 pandemic: A brief survey. In Proceedings of the 6th International Conference on Internet of Things, Big Data and Security; 2021. [Google Scholar]
- Pise, A.A.; Almuzaini, K.K.; Ahanger, T.A.; Farouk, A.; Pant, K.; Pareek, P.K.; Nuagah, S.J. Enabling artificial intelligence of Things (AIoT) healthcare architectures and listing security issues. Computational Intelligence and Neuroscience 2022, 2022, 8421434. [Google Scholar] [CrossRef] [PubMed]
- Rajeswari, S.V.K.R.; Ponnusamy, V. Internet of Things and artificial intelligence in biomedical systems. In Artificial Intelligence for Innovative Healthcare Informatics; Springer International Publishing:, 2022; pp. 153–177. [Google Scholar]
- Yankson, B.; Ottah, A. Investigating HIPAA Cybersecurity & Privacy Breach Compliance Reporting During Covid-19. 18th Annual Symposium on Information Assurance 2023, 18, 14–21. [Google Scholar]
- Barati, M.; Yankson, B. Predicting the occurrence of a data breach. International Journal of Information Management Data Insights 2022, 2, 100128. [Google Scholar] [CrossRef]
- Reegu, F.A.; et al. Interoperability Requirements for Blockchain-Enabled Electronic Health Records in Healthcare: A Systematic Review and Open Research Challenges. Secur. Commun. Networks 2022, 2022. [Google Scholar] [CrossRef]
- Reegu, F.A.; Abas, H.; Gulzar, Y.; Xin, Q.; Alwan, A.A.; Jabbari, A.; Sonkamble, R.G.; Dziyauddin, R.A. Blockchain-Based Framework for Interoperable Electronic Health Records for an Improved Healthcare System. Sustainability 2023, 15, 6337. [Google Scholar] [CrossRef]












| Company | Number of Records | Date Of Incident |
| Cense AI | 2.5 million [5] | August 2020 |
| AMCA | 20 million [6] | July 2019 |
| The Hospital Group | 1 million [7] | December 2020 |
| GED Match | 1.4 million [8] | September 2020 |
| Helse SOR RF | 3 million [9] | February 2018 |
| SingHealth | 1.5 million [10] | July 2018 |
![]() |
| Type of breach | Estimated coefficient of trend | Std. Error | Pr(>|z|) |
| Hacking/IT | 0.840171 | 0.044555 | < 2.2e-16 *** |
| Improper | 0.01127 | 0.11505 | 0.922 |
| Loss | 0.156042 | 0.090562 | 0.08488 |
| Theft | 0.614571 | 0.063672 | < 2.2e-16 *** |
| Unauthorized | 0.451533 | 0.074445 | 1.317e-09 *** |
| Type of breach | Estimated coefficient of trend | Std. Error | Pr(>|z|) |
| Hacking/IT | -0.077193 | 0.084671 | 0.3619 |
| Improper | -0.10844 | 0.11410 | 0.3419 |
| Loss | 0.13771 | 0.09043 | 0.1278 |
| Theft | 0.128829 | 0.082791 | 0.1197 |
| Unauthorized | -0.078189 | 0.084124 | 0.3527 |
| Type of breach | Estimated coefficient of trend | Std. Error | Pr(>|z|) |
| Desktop | 0.103898 | 0.086204 | 0.2281 |
| Electronic Medical Records | 0.338120 | 0.087418 | 0.0001098 *** |
| 0.710749 | 0.060864 | < 2.2e-16 *** | |
| Laptop | 0.580497 | 0.070579 | < 2.2e-16 *** |
| Network Server | 0.798605 | 0.048785 | < 2.2e-16 *** |
| Other | -0.131208 | 0.081523 | 0.1075 |
| Paper/Films | 0.16941 | 0.08015 | 0.03455 * |
| Type of breach | Estimated coefficient of trend | Std. Error | Pr(>|z|) |
| Desktop | -0.088588 | 0.085918 | 0.3025 |
| Electronic Medical Records | -0.060469 | 0.092490 | 0.5132 |
| 0.084694 | 0.087770 | 0.3346 | |
| Laptop | 0.117752 | 0.086477 | 0.1733 |
| Network Server | -0.108294 | 0.082448 | 0.189 |
| Other | 0.048517 | 0.082562 | 0.5568 |
| Paper/Films | -0.048713 | 0.080478 | 0.545 |
Disclaimer/Publisher’s Note: The statements, opinions and data contained in all publications are solely those of the individual author(s) and contributor(s) and not of MDPI and/or the editor(s). MDPI and/or the editor(s) disclaim responsibility for any injury to people or property resulting from any ideas, methods, instructions or products referred to in the content. |
© 2025 by the authors. Licensee MDPI, Basel, Switzerland. This article is an open access article distributed under the terms and conditions of the Creative Commons Attribution (CC BY) license (https://creativecommons.org/licenses/by/4.0/).
