<?xml version="1.0" encoding="UTF-8"?><?xml-stylesheet type="text/xsl" href="static/style.xsl"?><OAI-PMH xmlns="http://www.openarchives.org/OAI/2.0/" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xsi:schemaLocation="http://www.openarchives.org/OAI/2.0/ http://www.openarchives.org/OAI/2.0/OAI-PMH.xsd"><responseDate>2026-04-18T04:34:30Z</responseDate><request verb="GetRecord" identifier="oai:uvadoc.uva.es:10324/79507" metadataPrefix="mods">https://uvadoc.uva.es/oai/request</request><GetRecord><record><header><identifier>oai:uvadoc.uva.es:10324/79507</identifier><datestamp>2025-11-10T20:01:12Z</datestamp><setSpec>com_10324_1191</setSpec><setSpec>com_10324_931</setSpec><setSpec>com_10324_894</setSpec><setSpec>col_10324_1379</setSpec></header><metadata><mods:mods xmlns:mods="http://www.loc.gov/mods/v3" xmlns:doc="http://www.lyncode.com/xoai" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xsi:schemaLocation="http://www.loc.gov/mods/v3 http://www.loc.gov/standards/mods/v3/mods-3-1.xsd">
<mods:name>
<mods:namePart>Herrera Montano, Isabel</mods:namePart>
</mods:name>
<mods:name>
<mods:namePart>Góngora Alonso, Susel</mods:namePart>
</mods:name>
<mods:name>
<mods:namePart>Sañudo García, Soledad</mods:namePart>
</mods:name>
<mods:name>
<mods:namePart>García Aranda, José Javier</mods:namePart>
</mods:name>
<mods:name>
<mods:namePart>Rodrígues, Joel J.P.C.</mods:namePart>
</mods:name>
<mods:name>
<mods:namePart>Torre Díez, Isabel de la</mods:namePart>
</mods:name>
<mods:extension>
<mods:dateAvailable encoding="iso8601">2025-11-10T11:43:17Z</mods:dateAvailable>
</mods:extension>
<mods:extension>
<mods:dateAccessioned encoding="iso8601">2025-11-10T11:43:17Z</mods:dateAccessioned>
</mods:extension>
<mods:originInfo>
<mods:dateIssued encoding="iso8601">2026</mods:dateIssued>
</mods:originInfo>
<mods:identifier type="citation">International Journal of Medical Informatics, 2025, vol. 205, p. 106107</mods:identifier>
<mods:identifier type="issn">1386-5056</mods:identifier>
<mods:identifier type="uri">https://uvadoc.uva.es/handle/10324/79507</mods:identifier>
<mods:identifier type="doi">10.1016/j.ijmedinf.2025.106107</mods:identifier>
<mods:identifier type="publicationfirstpage">106107</mods:identifier>
<mods:identifier type="publicationtitle">International Journal of Medical Informatics</mods:identifier>
<mods:identifier type="publicationvolume">205</mods:identifier>
<mods:abstract>Introduction: Insider threats pose a critical risk in healthcare environments, where Hospital Information Systems&#xd;
(HIS) manage sensitive patients data. Authorized users may intentionally or accidentally compromise data&#xd;
confidentiality, integrity, and availability. This study assessed information security practices from the perspec-&#xd;
tive of healthcare professionals in Spanish medical centers.&#xd;
Methods: A descriptive, analytical, cross-sectional study was conducted using a survey administered to 41&#xd;
healthcare professionals with access to confidential data. The survey covered access control, encryption at rest&#xd;
and in transit, communication channels, and data usage control. Descriptive statistics, Chi-square tests, and&#xd;
Cram´er’s V were applied to identify significant associations. K-means clustering and Silhouette coefficient were&#xd;
used to define user profiles. Principal Component Analysis (PCA) was used to visualize behavior patterns. A&#xd;
Random Forest model identified the most relevant predictive variables.&#xd;
Results: Critical security gaps were detected, 31.7 % reported no control over data usage. Only 29.3 % encrypted&#xd;
data at rest and 36.6 % during transmission. Over 40 % used personal email or messaging apps to share sensitive&#xd;
data, and 97.6 % relied solely on passwords for authentication. These practices are inadequate to mitigate insider&#xd;
threats.&#xd;
Conclusion: There is an urgent need to strengthen insider data protection. Security strategies should be tailored to&#xd;
user risk profiles. Measures must include strong authentication, full encryption, and stricter control of data&#xd;
transmission to reduce exposure to insider threats (intentionally or unintentionally) in healthcare settings.&#xd;
Additionally, there is a need to promote continuous cybersecurity training.</mods:abstract>
<mods:language>
<mods:languageTerm>eng</mods:languageTerm>
</mods:language>
<mods:accessCondition type="useAndReproduction">info:eu-repo/semantics/openAccess</mods:accessCondition>
<mods:accessCondition type="useAndReproduction">http://creativecommons.org/licenses/by-nc-nd/4.0/</mods:accessCondition>
<mods:accessCondition type="useAndReproduction">© 2025 The Author(s)</mods:accessCondition>
<mods:accessCondition type="useAndReproduction">Attribution-NonCommercial-NoDerivatives 4.0 Internacional</mods:accessCondition>
<mods:titleInfo>
<mods:title>Security practices and insider threats in Spanish healthcare centers: a survey-based risk assessment</mods:title>
</mods:titleInfo>
<mods:genre>info:eu-repo/semantics/article</mods:genre>
</mods:mods></metadata></record></GetRecord></OAI-PMH>