PulseExploreJournal ClubDebatesTrendingResearchersJournals
Instagram
HomeExploreJournal ClubTrending
Synapse
⌘+K
Synapse
September 24, 2025Journal of Computer Science and Technology Studies0 citationsOpen Access

Bridging the Gap Between Cybersecurity Governance and Regulatory Compliance: A Data-Driven Analysis of U.S. Healthcare Breaches

View Full Paper
TATabassum Sheikh AtkiaGPGomes Jenifar Prantica

Key Points

  • The analysis shows that hacking incidents constituted the majority of data breaches, increasing in severity over time.
  • Data from the U.S. Department of Health and Human Services indicates a significant rise in impacted individuals due to breaches.
  • A qualitative examination reveals a critical gap between compliance criteria and actual implementation in healthcare institutions.
  • Proactive governance and ongoing monitoring are essential for enhancing cybersecurity resilience across healthcare systems.

Abstract

Healthcare institutions frequently encounter serious cyberthreats, and data breaches persist despite regulatory frameworks such as the NIST Cybersecurity Framework and the Health Insurance Portability and Accountability Act (HIPAA). The issue highlights the discrepancy between the criteria for compliance and their implementation in the day-to-day operations of health institutions, making protected health information (PHI) susceptible. A qualitative examination of data breaches from January 2023 to August 2025 from the US Department of Health and Human Services' (HHS) Office for Civil Rights (OCR) Breach Portal is used in this study. The dataset was examined to determine the kind of breach, where it occurred, and how many people were impacted. With network servers as the most frequent point of exposure, the results demonstrate that hacking and IT incidents are both numerous and large enough to dominate healthcare breaches. As a result, the severity of the breach has grown over time, with a huge incident being held accountable for the most impacted individuals. According to the study's conclusion, proactive governance of the healthcare sector requires compliance with paperwork. Enhancing healthcare cybersecurity resilience can be measured using a suggested methodology that includes automation, ongoing monitoring, and employee training.

Ask AI
Helpful
Bookmark
Share
View Full Paper

Cite This Study

Atkia et al. (2025) studied this question.

synapsesocial.com/papers/68d6d82e8b2b6861e4c3e3abhttps://doi.org/10.32996/jcsts.2025.4.1.76
Ask AI
Helpful
Bookmark
Share
View Full Paper