• español
  • English
  • français
  • Deutsch
  • português (Brasil)
  • italiano
    • español
    • English
    • français
    • Deutsch
    • português (Brasil)
    • italiano
    • español
    • English
    • français
    • Deutsch
    • português (Brasil)
    • italiano
    JavaScript is disabled for your browser. Some features of this site may not work without it.

    Parcourir

    Tout UVaDOCCommunautésPar date de publicationAuteursSujetsTitres

    Mon compte

    Ouvrir une session

    Statistiques

    Statistiques d'usage de visualisation

    Compartir

    Voir le document 
    •   Accueil de UVaDOC
    • PUBLICATIONS SCIENTIFIQUES
    • Departamentos
    • Dpto. Teoría de la Señal y Comunicaciones e Ingeniería Telemática
    • DEP71 - Artículos de revista
    • Voir le document
    •   Accueil de UVaDOC
    • PUBLICATIONS SCIENTIFIQUES
    • Departamentos
    • Dpto. Teoría de la Señal y Comunicaciones e Ingeniería Telemática
    • DEP71 - Artículos de revista
    • Voir le document
    • español
    • English
    • français
    • Deutsch
    • português (Brasil)
    • italiano

    Exportar

    RISMendeleyRefworksZotero
    • edm
    • marc
    • xoai
    • qdc
    • ore
    • ese
    • dim
    • uketd_dc
    • oai_dc
    • etdms
    • rdf
    • mods
    • mets
    • didl
    • premis

    Citas

    Por favor, use este identificador para citar o enlazar este ítem:https://uvadoc.uva.es/handle/10324/79507

    Título
    Security practices and insider threats in Spanish healthcare centers: a survey-based risk assessment
    Autor
    Herrera Montano, IsabelAutoridad UVA Orcid
    Góngora Alonso, SuselAutoridad UVA
    Sañudo García, Soledad
    García Aranda, José Javier
    Rodrígues, Joel J.P.C.
    Torre Díez, Isabel de laAutoridad UVA
    Año del Documento
    2026
    Editorial
    Elsevier
    Descripción
    Producción Científica
    Documento Fuente
    International Journal of Medical Informatics, 2025, vol. 205, p. 106107
    Résumé
    Introduction: Insider threats pose a critical risk in healthcare environments, where Hospital Information Systems (HIS) manage sensitive patients data. Authorized users may intentionally or accidentally compromise data confidentiality, integrity, and availability. This study assessed information security practices from the perspec- tive of healthcare professionals in Spanish medical centers. Methods: A descriptive, analytical, cross-sectional study was conducted using a survey administered to 41 healthcare professionals with access to confidential data. The survey covered access control, encryption at rest and in transit, communication channels, and data usage control. Descriptive statistics, Chi-square tests, and Cram´er’s V were applied to identify significant associations. K-means clustering and Silhouette coefficient were used to define user profiles. Principal Component Analysis (PCA) was used to visualize behavior patterns. A Random Forest model identified the most relevant predictive variables. Results: Critical security gaps were detected, 31.7 % reported no control over data usage. Only 29.3 % encrypted data at rest and 36.6 % during transmission. Over 40 % used personal email or messaging apps to share sensitive data, and 97.6 % relied solely on passwords for authentication. These practices are inadequate to mitigate insider threats. Conclusion: There is an urgent need to strengthen insider data protection. Security strategies should be tailored to user risk profiles. Measures must include strong authentication, full encryption, and stricter control of data transmission to reduce exposure to insider threats (intentionally or unintentionally) in healthcare settings. Additionally, there is a need to promote continuous cybersecurity training.
    Materias Unesco
    3304.13 Dispositivos de Transmisión de Datos
    Palabras Clave
    Cybersecurity
    Healthcare
    Insider threats
    Information security
    Survey
    ISSN
    1386-5056
    Revisión por pares
    SI
    DOI
    10.1016/j.ijmedinf.2025.106107
    Patrocinador
    Instituto da Telecomunicações da Delegação da Covilhã, Portugal. This work is partially funded by Brazilian National Council for Scientific and Technological Development - CNPq, via Grant No. 306607/2023-9.
    Ministerio de Ciencia, Innovación y Universidades (MICINN), a la Agencia Estatal de Investigación (AEI), así como al Fondo Europeo de Desarrollo Regional (FEDER, UE) M0CIN/AEI/10.13039/501100011033 y “FEDER Una manera de hacer Europa” (grant number PID2021-122210OB-I00)
    Version del Editor
    https://www.sciencedirect.com/science/article/pii/S1386505625003247
    Propietario de los Derechos
    © 2025 The Author(s)
    Idioma
    eng
    URI
    https://uvadoc.uva.es/handle/10324/79507
    Tipo de versión
    info:eu-repo/semantics/publishedVersion
    Derechos
    openAccess
    Aparece en las colecciones
    • DEP71 - Artículos de revista [371]
    Afficher la notice complète
    Fichier(s) constituant ce document
    Nombre:
    Security-practices-insider-threats-Spanish-healthcare-centers.pdf
    Tamaño:
    2.346Mo
    Formato:
    Adobe PDF
    Thumbnail
    Voir/Ouvrir
    Attribution-NonCommercial-NoDerivatives 4.0 InternacionalExcepté là où spécifié autrement, la license de ce document est décrite en tant que Attribution-NonCommercial-NoDerivatives 4.0 Internacional

    Universidad de Valladolid

    Powered by MIT's. DSpace software, Version 5.10