Mostrar el registro sencillo del ítem

dc.contributor.authorHerrera Montano, Isabel 
dc.contributor.authorGóngora Alonso, Susel 
dc.contributor.authorSañudo García, Soledad
dc.contributor.authorGarcía Aranda, José Javier
dc.contributor.authorRodrígues, Joel J.P.C.
dc.contributor.authorTorre Díez, Isabel de la 
dc.date.accessioned2025-11-10T11:43:17Z
dc.date.available2025-11-10T11:43:17Z
dc.date.issued2026
dc.identifier.citationInternational Journal of Medical Informatics, 2025, vol. 205, p. 106107es
dc.identifier.issn1386-5056es
dc.identifier.urihttps://uvadoc.uva.es/handle/10324/79507
dc.descriptionProducción Científicaes
dc.description.abstractIntroduction: Insider threats pose a critical risk in healthcare environments, where Hospital Information Systems (HIS) manage sensitive patients data. Authorized users may intentionally or accidentally compromise data confidentiality, integrity, and availability. This study assessed information security practices from the perspec- tive of healthcare professionals in Spanish medical centers. Methods: A descriptive, analytical, cross-sectional study was conducted using a survey administered to 41 healthcare professionals with access to confidential data. The survey covered access control, encryption at rest and in transit, communication channels, and data usage control. Descriptive statistics, Chi-square tests, and Cram´er’s V were applied to identify significant associations. K-means clustering and Silhouette coefficient were used to define user profiles. Principal Component Analysis (PCA) was used to visualize behavior patterns. A Random Forest model identified the most relevant predictive variables. Results: Critical security gaps were detected, 31.7 % reported no control over data usage. Only 29.3 % encrypted data at rest and 36.6 % during transmission. Over 40 % used personal email or messaging apps to share sensitive data, and 97.6 % relied solely on passwords for authentication. These practices are inadequate to mitigate insider threats. Conclusion: There is an urgent need to strengthen insider data protection. Security strategies should be tailored to user risk profiles. Measures must include strong authentication, full encryption, and stricter control of data transmission to reduce exposure to insider threats (intentionally or unintentionally) in healthcare settings. Additionally, there is a need to promote continuous cybersecurity training.es
dc.format.mimetypeapplication/pdfes
dc.language.isoenges
dc.publisherElsevieres
dc.rights.accessRightsinfo:eu-repo/semantics/openAccesses
dc.rights.urihttp://creativecommons.org/licenses/by-nc-nd/4.0/*
dc.subject.classificationCybersecurityes
dc.subject.classificationHealthcarees
dc.subject.classificationInsider threatses
dc.subject.classificationInformation securityes
dc.subject.classificationSurveyes
dc.titleSecurity practices and insider threats in Spanish healthcare centers: a survey-based risk assessmentes
dc.typeinfo:eu-repo/semantics/articlees
dc.rights.holder© 2025 The Author(s)es
dc.identifier.doi10.1016/j.ijmedinf.2025.106107es
dc.relation.publisherversionhttps://www.sciencedirect.com/science/article/pii/S1386505625003247es
dc.identifier.publicationfirstpage106107es
dc.identifier.publicationtitleInternational Journal of Medical Informaticses
dc.identifier.publicationvolume205es
dc.peerreviewedSIes
dc.description.projectInstituto da Telecomunicações da Delegação da Covilhã, Portugal. This work is partially funded by Brazilian National Council for Scientific and Technological Development - CNPq, via Grant No. 306607/2023-9.es
dc.description.projectMinisterio de Ciencia, Innovación y Universidades (MICINN), a la Agencia Estatal de Investigación (AEI), así como al Fondo Europeo de Desarrollo Regional (FEDER, UE) M0CIN/AEI/10.13039/501100011033 y “FEDER Una manera de hacer Europa” (grant number PID2021-122210OB-I00)es
dc.rightsAttribution-NonCommercial-NoDerivatives 4.0 Internacional*
dc.type.hasVersioninfo:eu-repo/semantics/publishedVersiones
dc.subject.unesco3304.13 Dispositivos de Transmisión de Datoses


Ficheros en el ítem

Thumbnail

Este ítem aparece en la(s) siguiente(s) colección(ones)

Mostrar el registro sencillo del ítem