DOI: https://doi.org/10.2147/jmdh.s609209
PMID: https://pubmed.ncbi.nlm.nih.gov/42158159
تاريخ النشر: 2026-05-01
المؤلف: Diane Dolezel وآخرون
الموضوع الرئيسي: أمن المعلومات والأمن السيبراني
نظرة عامة
تستقصي الدراسة تزايد تكرار وشدة خروقات بيانات الرعاية الصحية، من خلال تحليل 7,327 تقرير خرق تم تقديمه إلى مكتب الحقوق المدنية التابع لوزارة الصحة والخدمات الإنسانية الأمريكية من 2010 إلى 2025. باستخدام الانحدار اللوجستي، تحدد الأبحاث المؤشرات الرئيسية للخروقات واسعة النطاق، والتي تُعرف بأنها الحوادث التي تؤثر على 100,000 فرد أو أكثر. تكشف النتائج أن أحجام الخروقات تميل بشدة إلى اليمين، حيث يؤثر الخرق الوسيط على 3,892 فردًا. ومن الجدير بالذكر أن الحوادث المتعلقة بالقرصنة وتكنولوجيا المعلومات كانت مرتبطة بشكل كبير بالخروقات الشديدة (نسبة الأرجحية [OR] = 2.6)، وارتفعت انتشارها من 4% في 2010 إلى 80% في 2025. بالإضافة إلى ذلك، كانت الخروقات التي تشمل خوادم الشبكة أكبر من تلك الناتجة عن سرقة الأجهزة، وكان ارتباط الشركاء التجاريين مرتبطًا بزيادة حجم الخرق (نسبة معدل الحدوث [IRR] = 2.0).
تؤكد الخاتمة على أن زيادة حوادث القرصنة، وخاصة تلك التي تستهدف خوادم الشبكة وتشارك فيها الشركاء التجاريون، تشكل مخاطر كبيرة على خصوصية المرضى والمسؤولية التنظيمية. تدعو الدراسة إلى تعزيز استراتيجيات الأمن السيبراني، والمراقبة الاستباقية، وإشراف أكثر صرامة على معالجي البيانات من الأطراف الثالثة للتخفيف من هذه المخاطر. كما تقترح أن الأبحاث المستقبلية يجب أن تستكشف ممارسات الأمن السيبراني التنظيمية وديناميات علاقات بائعي الأطراف الثالثة لفهم ومعالجة العوامل التي تسهم في خروقات بيانات الرعاية الصحية واسعة النطاق بشكل أفضل.
مقدمة
تسلط المقدمة الضوء على الزيادة الكبيرة في خروقات البيانات داخل قطاع الرعاية الصحية، الذي تجاوز الآن تلك الموجودة في الصناعات الرئيسية الأخرى. على الرغم من التقدم في التقنيات الرقمية – مثل السجلات الصحية الإلكترونية، ومنصات الرعاية عن بُعد، والأجهزة الطبية المتصلة – التي حسنت من تقديم الرعاية، فإن هذه الابتكارات قد وسعت أيضًا من سطح الهجوم السيبراني. إن تزايد تعقيد المجرمين السيبرانيين الذين يستهدفون المعلومات الصحية المحمية (PHI) يبرز الحاجة الملحة إلى تدابير أمان بيانات قوية، حيث إن بيانات الصحة ذات قيمة خاصة لسرقة الهوية والاحتيال في التأمين بسبب مزيجها من المعرفات الدائمة والمعلومات السريرية الحساسة.
علاوة على ذلك، تم توثيق الانتقال من الخروقات التي تشمل السرقة المادية إلى حوادث القرصنة واسعة النطاق، مع وجود بيانات وطنية تشير إلى اتجاه مقلق. تشكل هجمات الفدية مخاطر شديدة من خلال تقييد الوصول إلى السجلات الصحية الإلكترونية (EHR)، مما قد يؤدي إلى تأخيرات في التشخيص وتعطيل سير العمل الأساسي في الرعاية الصحية، مما يعرض في النهاية سلامة المرضى للخطر. تعتبر هجمة الفدية على Change Healthcare في 2024 مثالًا مناسبًا على العواقب التشغيلية والسريرية لمثل هذه التهديدات السيبرانية، حيث أثرت على ملايين المرضى ومنظمات الرعاية الصحية.
طرق
توضح قسم “المواد والطرق” التصميم التجريبي والإجراءات المستخدمة في الدراسة. تتفصل المواد المستخدمة، بما في ذلك الكواشف المحددة، والمعدات، وأي عينات بيولوجية، لضمان إمكانية تكرار التجارب. تشمل المنهجية البروتوكولات المتبعة لجمع البيانات، بما في ذلك أي تحليلات إحصائية تم تطبيقها لتفسير النتائج.
بالإضافة إلى ذلك، قد يصف القسم الظروف التجريبية، مثل درجة الحرارة، والمدة، والضوابط المطبقة للتحقق من النتائج. يضمن هذا النهج الصارم أن تكون النتائج موثوقة ويمكن مقارنتها مع دراسات أخرى في هذا المجال. بشكل عام، تم تصميم الطرق لمعالجة أسئلة البحث بفعالية مع الحفاظ على النزاهة العلمية.
نتائج
تكشف نتائج الدراسة عن زيادة كبيرة في هجمات الفدية وغيرها من حوادث القرصنة/تكنولوجيا المعلومات داخل قطاع الرعاية الصحية، حيث تمثل هجمات الفدية الآن حصة كبيرة من الأفراد المتأثرين بخروقات البيانات واسعة النطاق. تشير النتائج إلى أن الأنظمة القديمة، والبنى التحتية المتصلة، وتوسع التقنيات الرقمية قد وسعت من سطح الهجوم، مما زاد من المخاطر السيبرانية وساهم في استمرار الخروقات. تؤكد هيمنة حوادث القرصنة/تكنولوجيا المعلومات على ضرورة التعاون بين التخصصات المختلفة بين فرق تكنولوجيا المعلومات، والسريرية، والقانونية، والإدارية لتعزيز تدابير الأمن السيبراني والتخفيف من المخاطر عبر عمليات الرعاية الصحية.
تشير التحليلات إلى أن حوادث خوادم الشبكة مرتبطة بعدد أكبر بكثير من الأفراد المتأثرين مقارنة بالخروقات التي تشمل الأجهزة المسروقة، على الأرجح بسبب تجميع البيانات الحساسة في أنظمة مركزية. علاوة على ذلك، يرتبط انخراط الشركاء التجاريين تقريبًا بضعف عدد الأفراد المتأثرين، حتى عند التحكم في نوع الخرق، والموقع، والسنة. بينما تسلط الدراسة الضوء على هذه الروابط، إلا أنها لا تؤسس علاقات سببية. قد تؤدي عواقب مثل هذه الخروقات إلى تعطيل سير العمل السريري وتأخير وصول المرضى إلى السجلات، مما قد يعرض سلامة المرضى للخطر من خلال تأخيرات في العلاج وتعطل الأجهزة الطبية الحيوية.
مناقشة
تسلط قسم المناقشة في الدراسة حول خروقات بيانات الرعاية الصحية القابلة للإبلاغ بموجب HIPAA الضوء على الحاجة الملحة للتنسيق بين مختلف التخصصات للتخفيف من المخاطر المرتبطة بالخروقات واسعة النطاق. تحدد الأبحاث المؤشرات الرئيسية للخروقات عالية الشدة، مع التركيز بشكل خاص على دور حوادث القرصنة/تكنولوجيا المعلومات، ومشاركة خوادم الشبكة، ومشاركة الشركاء التجاريين. تشير النتائج إلى أن حوادث القرصنة مرتبطة بشكل كبير بزيادة احتمالات الخروقات الشديدة، حيث يكشف الانحدار اللوجستي عن زيادة بمقدار 2.63 مرة في احتمال الحالة عالية الشدة مقارنةً بحوادث غير القرصنة. بالإضافة إلى ذلك، كانت الخروقات التي تشمل خوادم الشبكة مرتبطة بأحجام خروقات أكبر، بينما تلك المرتبطة بالشركاء التجاريين أثرت على عدد تقريبًا مضاعف من الأفراد.
تملأ الدراسة فجوة ملحوظة في الأدبيات من خلال فحص آليات الخرق، والمواقع، ومشاركة الشركاء التجاريين على مستوى وطني، مما يوفر رؤى حول العوامل التي تسهم في حجم الخرق. تتماشى النتائج مع الأبحاث السابقة التي تؤكد على ضعف الأنظمة الإلكترونية المركزية والمخاطر التي تشكلها الشركاء التجاريون. يدعو المؤلفون إلى تعزيز تدابير الأمن السيبراني، بما في ذلك تعزيز أمان خوادم الشبكة، وإدارة مخاطر البائعين بشكل صارم، واستراتيجيات المراقبة الاستباقية، للتصدي للتهديد المتزايد الذي تشكله حوادث القرصنة. يتم تشجيع الأبحاث المستقبلية لاستكشاف تأثير ممارسات الأمن السيبراني التنظيمية وتوقيت اكتشاف الخرق على نتائج الخرق، مما يوضح بشكل أكبر ديناميات خروقات بيانات الرعاية الصحية واسعة النطاق.
القيود
تحمل التحليلات المقدمة في هذا البحث عدة قيود ملحوظة تؤثر على نتائجها. أولاً، يحد التصميم الرصدي الرجعي من الاستنتاجات السببية، مما يجعل من الصعب تحديد ما إذا كانت الخصائص المحددة لخروقات البيانات تسهم مباشرة في نتائج أعلى شدة. قد يؤدي الاعتماد على الخروقات المبلغ عنها من قبل مكتب الحقوق المدنية (OCR) التي تؤثر على 500 فرد أو أكثر إلى إدخال تحيز في التقارير، مما قد يؤدي إلى تقليل تمثيل الحوادث الأصغر التي يمكن أن تؤثر بشكل كبير على التوزيعات الملحوظة لشدة الخرق.
بالإضافة إلى ذلك، فإن تصنيف الخروقات، مثل تلك التي تشمل القرصنة أو الشركاء التجاريين، يعتمد على الكيانات المبلغة، مما قد يؤدي إلى تصنيف خاطئ أو بيانات غير مكتملة. على سبيل المثال، تجمع فئة “القرصنة/تكنولوجيا المعلومات” الخاصة بـ OCR أنواعًا مختلفة من الهجمات السيبرانية، بما في ذلك هجمات الفدية والتصيد، مما يعيق تحديد طرق الهجوم المحددة المسؤولة عن الزيادات في حجم الخرق وشدته. تشمل القيود الأخرى احتمالية وجود أخطاء في مطابقة أسماء الكيانات، ونقص المتغيرات السياقية التفصيلية (مثل تدابير الأمان ونضج الأمن السيبراني التنظيمي)، وتأثير تطور ممارسات الإبلاغ والامتثال التنظيمي على المقارنات الزمنية. أخيرًا، فإن غياب تواريخ اكتشاف الخرق الدقيقة يزيد من تعقيد التحليل. بشكل عام، تشير هذه القيود إلى أن النتائج تعكس المخاطر السيبرانية العامة بدلاً من ديناميات الهجوم المحددة.
DOI: https://doi.org/10.2147/jmdh.s609209
PMID: https://pubmed.ncbi.nlm.nih.gov/42158159
Publication Date: 2026-05-01
Author(s): Diane Dolezel et al.
Primary Topic: Information and Cyber Security
Overview
The study investigates the increasing frequency and severity of healthcare data breaches, analyzing 7,327 breach reports submitted to the US Department of Health and Human Services Office of Civil Rights from 2010 to 2025. Using logistic regression, the research identifies key predictors of large-scale breaches, defined as incidents affecting 100,000 or more individuals. The findings reveal that breach sizes are highly right-skewed, with a median breach affecting 3,892 individuals. Notably, hacking and IT-related incidents were significantly associated with severe breaches (odds ratio [OR] = 2.6), and their prevalence surged from 4% in 2010 to 80% in 2025. Additionally, breaches involving network servers were larger than those resulting from device theft, and the involvement of business associates was linked to a higher breach magnitude (incidence rate ratio [IRR] = 2.0).
The conclusion emphasizes that the rise in hacking incidents, particularly those targeting network servers and involving business associates, poses substantial risks to patient privacy and organizational liability. The study advocates for enhanced cybersecurity strategies, proactive monitoring, and stricter oversight of third-party data handlers to mitigate these risks. It also suggests that future research should explore organizational cybersecurity practices and the dynamics of third-party vendor relationships to further understand and address the factors contributing to large-scale healthcare data breaches.
Introduction
The introduction highlights a significant rise in data breaches within the healthcare sector, which now surpasses those in other major industries. Despite advancements in digital technologies—such as electronic health records, telehealth platforms, and interconnected medical devices—that have enhanced care delivery, these innovations have also expanded the cybersecurity attack surface. The increasing sophistication of cybercriminals targeting protected health information (PHI) underscores the urgent need for robust data security measures, as health data is particularly valuable for identity theft and insurance fraud due to its combination of permanent identifiers and sensitive clinical information.
Moreover, the transition from breaches involving physical theft to large-scale hacking incidents has been documented, with national data indicating a concerning trend. Ransomware attacks pose severe risks by restricting access to electronic health records (EHR), which can lead to delays in diagnostics and disrupt essential healthcare workflows, ultimately jeopardizing patient safety. The 2024 Change Healthcare ransomware attack serves as a pertinent example of the operational and clinical ramifications of such cyber threats, affecting millions of patients and healthcare organizations.
Methods
The “Materials and Methods” section outlines the experimental design and procedures employed in the study. It details the materials used, including specific reagents, equipment, and any biological samples, ensuring reproducibility of the experiments. The methodology encompasses the protocols followed for data collection, including any statistical analyses applied to interpret the results.
Additionally, the section may describe the experimental conditions, such as temperature, duration, and controls implemented to validate the findings. This rigorous approach ensures that the results are reliable and can be compared with other studies in the field. Overall, the methods are designed to address the research questions effectively while maintaining scientific integrity.
Results
The results of the study reveal a significant rise in ransomware and other Hacking/IT incidents within the healthcare sector, with ransomware now representing a considerable share of individuals affected by large-scale data breaches. The findings suggest that legacy systems, interconnected infrastructures, and the expansion of digital technologies have broadened the attack surface, thereby increasing cyber risks and contributing to the persistence of breaches. The predominance of Hacking/IT incidents emphasizes the necessity for interdisciplinary collaboration among IT, clinical, legal, and administrative teams to bolster cybersecurity measures and mitigate risks across healthcare operations.
The analysis indicates that network server incidents are linked to a markedly higher number of affected individuals compared to breaches involving stolen devices, likely due to the aggregation of sensitive data in centralized systems. Furthermore, the involvement of business associates correlates with approximately double the number of affected individuals, even when controlling for breach type, location, and year. While the study highlights these associations, it does not establish causal relationships. The implications of such breaches may disrupt clinical workflows and delay patient access to records, potentially compromising patient safety through treatment delays and the malfunctioning of critical medical devices.
Discussion
The discussion section of the study on HIPAA-reportable healthcare data breaches highlights the critical need for coordinated efforts across various disciplines to mitigate the risks associated with large-scale breaches. The research identifies key predictors of high-severity breaches, particularly emphasizing the role of hacking/IT incidents, network server involvement, and business associate participation. Findings indicate that hacking incidents are significantly associated with higher odds of severe breaches, with logistic regression revealing a 2.63-fold increase in the likelihood of high-severity status compared to non-hacking incidents. Additionally, breaches involving network servers were linked to larger breach sizes, while those associated with business associates affected approximately twice as many individuals.
The study fills a notable gap in the literature by simultaneously examining breach mechanisms, locations, and business associate involvement at a national level, providing insights into the factors contributing to breach magnitude. The results align with previous research that underscores the vulnerabilities of centralized electronic systems and the risks posed by business associates. The authors advocate for enhanced cybersecurity measures, including stronger network server security, rigorous vendor risk management, and proactive monitoring strategies, to address the increasing threat landscape posed by hacking incidents. Future research is encouraged to explore the impact of organizational cybersecurity practices and the timing of breach detection on breach outcomes, further elucidating the dynamics of large-scale healthcare data breaches.
Limitations
The analysis presented in this research has several notable limitations that impact its findings. Firstly, the retrospective observational design restricts causal inferences, making it difficult to ascertain whether specific characteristics of data breaches directly contribute to higher severity outcomes. The reliance on breaches reported by the Office for Civil Rights (OCR) that affect 500 or more individuals may introduce reporting bias, potentially underrepresenting smaller incidents that could significantly influence the observed distributions of breach severity.
Additionally, the classification of breaches, such as those involving hacking or business associates, is contingent upon the reporting entities, which may lead to misclassification or incomplete data. For instance, the OCR’s “Hacking/IT” category aggregates various cyberattack types, including ransomware and phishing, obscuring the specific attack methods responsible for increases in breach size and severity. Other limitations include potential inaccuracies in entity name matching, a lack of detailed contextual variables (such as security measures and organizational cybersecurity maturity), and the influence of evolving reporting practices and regulatory compliance on temporal comparisons. Lastly, the absence of accurate breach discovery dates further complicates the analysis. Overall, these limitations suggest that the findings reflect general cyber risk rather than specific attack dynamics.
