<?xml version="1.0" encoding="UTF-8"?>
<!DOCTYPE article PUBLIC "-//NLM//DTD JATS (Z39.96) Journal Publishing DTD v1.1 20151215//EN" "http://jats.nlm.nih.gov/publishing/1.1/JATS-journalpublishing1.dtd">
<article xmlns:xlink="http://www.w3.org/1999/xlink" xmlns:mml="http://www.w3.org/1998/Math/MathML" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" article-type="research-article" dtd-version="1.1">
<front>
<journal-meta>
<journal-id journal-id-type="pmc">JCS</journal-id>
<journal-id journal-id-type="nlm-ta">JCS</journal-id>
<journal-id journal-id-type="publisher-id">JCS</journal-id>
<journal-title-group>
<journal-title>Journal of Cyber Security</journal-title>
</journal-title-group>
<issn pub-type="epub">2579-0064</issn>
<issn pub-type="ppub">2579-0072</issn>
<publisher>
<publisher-name>Tech Science Press</publisher-name>
<publisher-loc>USA</publisher-loc>
</publisher>
</journal-meta>
<article-meta>
<article-id pub-id-type="publisher-id">35446</article-id>
<article-id pub-id-type="doi">10.32604/jcs.2022.035446</article-id>
<article-categories>
<subj-group subj-group-type="heading">
<subject>Article</subject>
</subj-group>
</article-categories>
<title-group>
<article-title>Cybersecurity Plan for a Healthcare Cloud-Based Solutions</article-title>
<alt-title alt-title-type="left-running-head">Cybersecurity Plan for a Healthcare Cloud-Based Solutions</alt-title>
<alt-title alt-title-type="right-running-head">Cybersecurity Plan for a Healthcare Cloud-Based Solutions</alt-title>
</title-group>
<contrib-group content-type="authors">
<contrib id="author-1" contrib-type="author" corresp="yes">
<name name-style="western"><surname>Yusuf</surname><given-names>A. S.</given-names></name><xref ref-type="aff" rid="aff-1">1</xref><email>coloabiodun@gmail.com</email></contrib>
<contrib id="author-2" contrib-type="author">
<name name-style="western"><surname>Ayinde</surname><given-names>A. Q.</given-names></name><xref ref-type="aff" rid="aff-2">2</xref></contrib>
<aff id="aff-1"><label>1</label><institution>New York Institute of Technology</institution>, <addr-line>Old Westbury, NY, 11568</addr-line>, <country>USA</country></aff>
<aff id="aff-2"><label>2</label><institution>Northcentral University</institution>, <addr-line>Scottsdale, AZ, 85255</addr-line>, <country>USA</country></aff>
</contrib-group>
<author-notes>
<corresp id="cor1"><label>&#x002A;</label>Corresponding Author: A. S. Yusuf. Email: <email>coloabiodun@gmail.com</email></corresp>
</author-notes>
<pub-date publication-format="print" date-type="pub" iso-8601-date="2023-01-11"><day>11</day><month>01</month><year>2023</year></pub-date>
<volume>4</volume>
<issue>3</issue>
<fpage>185</fpage>
<lpage>188</lpage>
<history>
<date date-type="received"><day>01</day><month>9</month><year>2022</year></date>
<date date-type="accepted"><day>02</day><month>10</month><year>2022</year></date>
</history>
<permissions>
<copyright-statement>&#x00A9; 2022 Yusuf and Ayinde</copyright-statement>
<copyright-year>2022</copyright-year>
<copyright-holder>Yusuf and Ayinde</copyright-holder>
<license xlink:href="https://creativecommons.org/licenses/by/4.0/">
<license-p>This work is licensed under a <ext-link ext-link-type="uri" xlink:type="simple" xlink:href="https://creativecommons.org/licenses/by/4.0/">Creative Commons Attribution 4.0 International License</ext-link>, which permits unrestricted use, distribution, and reproduction in any medium, provided the original work is properly cited.</license-p>
</license>
</permissions>
<self-uri content-type="pdf" xlink:href="TSP_JCS_35446.pdf"></self-uri>
<abstract>
<p>Hospitals provide daily health services for thousands of patients. People, processes, and technologies drive the objectives and goals of the hospitals to ensure optimal and satisfactory health care services are rendered to their customers. Due to the sensitivity of the organization data and patient data, it is essential to ensure that the confidentiality, integrity, availability, and security of these data are considered. The leadership of the organization (managers and executives) must integrate a robust security plan when choosing the technologies that will be used to drive the organization&#x2019;s processes. This paper will evaluate the existing technologies risk assessment, and the importance of adopting new technologies will be discussed. Security plans will be integrated for inventoried technologies and the latest technologies to be adopted while assessing the risk assessment and providing mitigation plans for the technologies.</p>
</abstract>
<kwd-group kwd-group-type="author">
<kwd>Risk assessment</kwd>
<kwd>healthcare</kwd>
<kwd>cybersecurity</kwd>
<kwd>patient</kwd>
</kwd-group>
</article-meta>
</front>
<body>
<sec id="s1"><label>1</label><title>Introduction</title>
<p>Hospital network infrastructure consists of assets (hardware and software), people, and processes. The policies and industry standards need to be implemented across the hospital network to ensure that organization governance is enforced to prevent any incident of vulnerabilities or mitigate risks or threats. The security operation centers of the organization need to update, monitor, inspect, upgrade, patch, and discard any asset that is susceptible to vulnerabilities. For a proper risk assessment plan, the list of inventories must be monitored and tracked in real-time. Over the years, the data storage has predominantly been on-premises and with the growth in data virtualization, it is important that hospital should move its storage to cloud. Based on the literature reviewed, application managers need to document the vulnerability level for applications, systems, processes and practices that are used for business operation. EHS is one of the new technologies most organization have adopted to drive their clinical-technical business processes related to patient care and services. Electronic Health Systems (EHS) contains Patient MyChart used by the patient for payment and scheduling appointments (in-person and virtual), EHS used by clinicians to process, document, and analyze patient data for hospital consumption, EHS databases are used by analysts to build a real-time dashboard, crystal reports and reporting applications that can be used for appropriate decision making by managers and executives across the healthcare industry to improve the quality of health care services. Despite the vast functionalities of the EHS, there are emergent worries that cybersecurity within healthcare is not robust and has led to a lack of confidentiality and availability [<xref ref-type="bibr" rid="ref-1">1</xref>] and integrity and security of electronic health records [<xref ref-type="bibr" rid="ref-2">2</xref>].</p>
</sec>
<sec id="s2"><label>2</label><title>Technology Reviews and Analysis</title>
<p>Since the adoption of the electronic health technologies by hospital to drive their business, the organization&#x2019;s business operations have been scaled by 400 percent, and the revenue of the organization has grown tremendously due to operation digitalization and network virtualization. The EHS provided a payment platform where patients can pay for their medical bills in the comfort of their homes, Clinicians (Physicians, Nurse Practitioners, and Nurses) can send medication orders to a nearby pharmacy closer to the patient&#x2019;s address. Also, patients can access and print their medical records online with their approved and authorized credentials. The EHS is presently deployed as an on-premises application, leading to its unavailability, inadequate data security, poor data storage and maintenance culture, and poor optimization of the EHS resources.</p>
<p>Data protection is not guaranteed because the IT department manually maintains the on-premises solutions by the employees&#x2019; productivity server on-premises, backing up data, and maintaining log data will not only reduce the productivity of the employees but is highly expensive as more funds and resources will have to be channeled to the process across the hospital network. This can cause a potential data breach because the process is manual, and the hardware specifications must be reviewed timely as the number of patients being served grows exponentially. Since each dedicated IT associate is attached to each of the on-premises systems at each hospital location, the cost of setting up the hardware, upgrading the hardware, or changing the hardware will not only put excessive work on the employees but also comes with a negative cost implication for the organization [<xref ref-type="bibr" rid="ref-3">3</xref>]. Each location has its own database; merging it into a centralized database will be an additional cost to the organization.</p>
<p>A cloud based EHS must be adopted by most hospitals to ensure that the system&#x2019;s functionalities are optimized and to integrate a robust security plan across the organization. The cloud-based solution will be based on the Software-as-a-service (SaaS) model, which solves most of the problems encountered by the existing on-premises solution deployed for the EHS. The hardware requirements for the cloud-based solution are lower since the software runs on the vendor&#x2019;s (cloud provider) hardware. Maintenance and data backup is automated and done by the provider, reducing the workload on the IT department. This solution is cost-friendly and scalable because additional licenses can be other as the number of users within the organization grows.</p>
<p>It is essential to understand the setback that comes with the adoption of a cloud-based solution for the EHS before it is deployed across the organization. The risk assessment plan must be evaluated, and mitigation strategies must be in place after the cloud-based solution has been adopted or the existing infrastructure will be migrated to the cloud service. During the assessment process, the data breach, insecure interfaces, denial of service, user account compromise, and cloud misconfiguration were identified as the potential risk or threats to the cloud-based service to be adopted.</p>
<p>EHS data breaches can either be internal (within the organization) or external when an attacker uses ransomware via a link to gain access to the organization&#x2019;s sensitive data or via other means to take advantage of the system&#x2019;s vulnerability. A security plan that will enforce industry standards, policies, and processes that tore that both organization and customer data are protected and prevented from getting into the hands of unauthorized users must be adopted. A credential authentication technology must be deployed to monitor the user&#x2019;s logging activities automatically. Users will be registered within the system and, roles will be assigned to prevent who has access to the EHS. Password security questions will be set up within the system during the user (patient or clinician) registration phase, this process will prevent account hijacking by hackers.</p>
<p>Inbound and Outbound ports must be restricted to avoid cloud misconfiguration. To prevent attackers from sniffing the User Datagram Protocol (UDP) or Transmission Control Protocol (TCP) ports it is vital to track all the open ports to create security events like data exfiltration and scanning of the entire network whenever the EHS is compromised. Outbound access should permanently be restricted to Secure Shell (SSH) or Remote Desktop Protocol (RDP), a cloud misconfiguration example. Less privilege principle must be adopted to prevent unwarranted use of open ports for SSH. Understandably, an insecure cloud-based solution will expose the EHS to threats. The organization needs to conduct oversight to evaluate the API vulnerabilities on or before adoption. The API should provide relevant feedback whenever the API is us. Should an incident occur, the API must notify the monitoring team so that the incident can be contained and fixed immediately, preventing unwanted exposure to the organization&#x2019;s sensitive data.</p>
<p>The cloud-based environment is experiencing an increase in denial-of-service (DDoS) attacks, one of the most wrecking cyber-attacks. The cloud service provider must provide adequate security solutions for the organization to prevent attackers from targeting the organization domain in the cloud, which may result in a traffic bottleneck when the traffic across the network increases geometrically within a short period. These attacks may cause the EHS servers and the network devices powering the system to shut down. Since most of the EHS will be virtualized, it will make the system susceptible to attackers because it requires securing the extra layer [<xref ref-type="bibr" rid="ref-4">4</xref>]. The security of the virtual machine powering the EHS is essential to prevent unavailability or data breaches should the machine is attacked by the attackers. Instance learning classifiers can be applied in training and testing the virtual machine when analyzing the data to detect the patterns or trends of attacks and predict future threats using the data coming from the EHS system [<xref ref-type="bibr" rid="ref-5">5</xref>,<xref ref-type="bibr" rid="ref-6">6</xref>]. The virtualized environment is highly vulnerable when the virtual machine monitor is isolated and compromised.</p>
</sec>
<sec id="s3"><label>3</label><title>Conclusion</title>
<p>The network security team must understand that malware is a significant threat to cloud-based solutions, primarily when the client-side and endpoint security software has been implemented. The network security team needs to implement-layer security to detect and prevent malware. This double-layer security will contain the malware in the cloud from spreading quickly in the EHS that has been infiltrated. If the malware is not immediately detected, it will weaken the system and cause a severe attack. The vendor must provide the cloud infrastructural services to protect the cloud infrastructure attack.</p>
<p>To ensure that cloud infrastructure is fully secured, the network monitoring team must block all access to confirm the system using least privilege and multi-factor authentication. Network segmentation must be enforced and mandated across the network because should an incident occurs, only a small segment will be affected in the EHS.</p>
</sec>
</body>
<back>
<fn-group>
<fn fn-type="other"><p><bold>Funding statement:</bold> The authors received no specific funding for this study.</p></fn>
<fn fn-type="conflict"><p><bold>Conflicts of Interest:</bold> The authors declare that they have no conflicts of interest to report regarding the present study.</p></fn>
</fn-group>
<ref-list content-type="authoryear">
<title>References</title>
<ref id="ref-1"><label>[1]</label><mixed-citation publication-type="book"><person-group person-group-type="author"><string-name><given-names>D. V.</given-names> <surname>Dimitrov</surname></string-name></person-group>, &#x201C;<article-title>Medical internet of things and big data in healthcare</article-title>,&#x201D; <source>International Journal of E-Health and Medical Communications</source>, vol. <volume>22</volume>, pp. <fpage>156</fpage>&#x2013;<lpage>163</lpage>, <year>2016</year>. <publisher-name>References-Scientific Research Publishing</publisher-name>.</mixed-citation></ref>
<ref id="ref-2"><label>[2]</label><mixed-citation publication-type="web"><person-group person-group-type="author"><string-name><given-names>T.</given-names> <surname>Walker</surname></string-name></person-group>, &#x201C;<article-title>Interoperability a must for hospitals, but it comes with risks</article-title>,&#x201D; <year>2017</year>. [Online]. Available: <ext-link ext-link-type="uri" xlink:href="https://www.managedhealthcareexecutive.com/view/interoperability-must-hospitals-it-comes-risks">https://www.managedhealthcareexecutive.com/view/interoperability-must-hospitals-it-comes-risks</ext-link>.</mixed-citation></ref>
<ref id="ref-3"><label>[3]</label><mixed-citation publication-type="web"><person-group person-group-type="author"><string-name><given-names>S. I.</given-names> <surname>Bairagi</surname></string-name> and <string-name><given-names>A. O.</given-names> <surname>Bang</surname></string-name></person-group>, &#x201C;<article-title>Cloud computing: History, architecture, security issues</article-title>,&#x201D; <source>International Journal of Advent Research in Computer and Electronics</source>, <year>2015</year>. <ext-link ext-link-type="uri" xlink:href="https://www.researchgate.net/publication/323967455_Cloud_Computing_History_Architecture_Security_Issues">https://www.researchgate.net/publication/323967455_Cloud_Computing_History_Architecture_Security_Issues</ext-link>.</mixed-citation></ref>
<ref id="ref-4"><label>[4]</label><mixed-citation publication-type="web"><person-group person-group-type="author"><string-name><given-names>D.</given-names> <surname>Owens</surname></string-name></person-group>, &#x201C;<article-title>Securing elasticity in the cloud</article-title>,&#x201D; <year>2010</year>. [Online]. Available: <ext-link ext-link-type="uri" xlink:href="https://www.sciepub.com/reference/144783">https://www.sciepub.com/reference/144783</ext-link>.</mixed-citation></ref>
<ref id="ref-5"><label>[5]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>N.</given-names> <surname>Urenna</surname></string-name>, <string-name><given-names>A.</given-names> <surname>Abiodun</surname></string-name> and <string-name><given-names>O.</given-names> <surname>Yemisi</surname></string-name></person-group>, &#x201C;<article-title>Application of instance learning algorithms to analyze logistics data</article-title>,&#x201D; <source>International Journal of Engineering Research &#x0026; Technology (IJERT)</source>, vol. <volume>10</volume>, no. <issue>7</issue>, pp. <fpage>11</fpage>&#x2013;<lpage>12</lpage>, <year>2021</year>.</mixed-citation></ref>
<ref id="ref-6"><label>[6]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>N.</given-names> <surname>Urenna</surname></string-name>, <string-name><given-names>A.</given-names> <surname>Abiodun</surname></string-name>, <string-name><given-names>K.</given-names> <surname>Isolagbenla</surname></string-name> and <string-name><given-names>A.</given-names> <surname>Yusuf</surname></string-name></person-group>, &#x201C;<article-title>Pattern mining of hospitalization data of COVID-19 patients with underlying conditions</article-title>,&#x201D; <source>International Journal of Engineering Research &#x0026; Technology (IJERT)</source>, vol. <volume>11</volume>, no. <issue>5</issue>, pp. <fpage>131</fpage>, <year>2022</year>.</mixed-citation></ref>
</ref-list>
</back>
</article>