Assessing the impact of health information exchange on hospital data breach risk

•Hospital engagement in Health Information Exchange (HIE) linked to a 0.672%-point rise in IT-related data breach after three years.•External data sharing raises long-term breach risk.•HIE impacts cybersecurity, and protecting patient data is crucial. Widespread electronic health information exchang...

Full description

Saved in:
Bibliographic Details
Published inInternational journal of medical informatics (Shannon, Ireland) Vol. 177; p. 105149
Main Authors Choi, Sung J, Chen, Min, Tan, Xuan
Format Journal Article
LanguageEnglish
Published Ireland Elsevier B.V 01.09.2023
Subjects
Online AccessGet full text

Cover

Loading…
More Information
Summary:•Hospital engagement in Health Information Exchange (HIE) linked to a 0.672%-point rise in IT-related data breach after three years.•External data sharing raises long-term breach risk.•HIE impacts cybersecurity, and protecting patient data is crucial. Widespread electronic health information exchange (HIE) across hospitals remains an important policy goal for reducing costs and improving the quality of care. Meanwhile, cybersecurity incidents are a growing threat to hospitals. The relationship between the electronic sharing of health information and cybersecurity incidents is not well understood. The objective of this study was to empirically examine the impact of hospitals’ HIE engagement on their data breach risk. A balanced panel dataset included 4,936 US community hospitals spanning the period 2010–2017, which was assembled by linking the American Hospital Association annual survey database and the Information Technology (IT) supplement, and the Department of Health and Human Services reports of health data breaches. The relationship between HIE engagement and hospital data breaches was modeled using a difference-in-differences specification controlling for time-varying hospital characteristics. The percentage of hospitals electronically exchanging information has more than tripled (from 18% to 68%) from 2010 to 2017. Hospital data breaches increased concurrently, largely due to the rise in hacking and unauthorized access. HIE engagement was associated with a 0.672 percentage point increase in the probability of an IT breach three years after the engagement. Hospitals actively engaging in a health information organization and exchanging data with outside providers were associated with a higher risk of IT related breaches in the long run; however, hospitals actively engaging in HIE and exchanging data with inside providers were not associated with any significant risk of IT related breaches. Over time, the increasing amount and complexity of patient information being exchanged can create challenges for cybersecurity if data protection is not up to date. Additionally, data security depends on the weakest link of HIE, and providers with fewer resources for data governance and infrastructure are more vulnerable to data breaches. Moving toward widespread health information exchange has important cybersecurity implications that can significantly impact both patients and healthcare organizations.
Bibliography:ObjectType-Article-1
SourceType-Scholarly Journals-1
ObjectType-Feature-2
content type line 23
ISSN:1386-5056
1872-8243
DOI:10.1016/j.ijmedinf.2023.105149