• español
  • English
  • français
  • Deutsch
  • português (Brasil)
  • italiano
    • español
    • English
    • français
    • Deutsch
    • português (Brasil)
    • italiano
    • español
    • English
    • français
    • Deutsch
    • português (Brasil)
    • italiano
    JavaScript is disabled for your browser. Some features of this site may not work without it.

    Navegar

    Todo o repositórioComunidadesPor data do documentoAutoresAssuntosTítulos

    Minha conta

    Entrar

    Estatística

    Ver as estatísticas de uso

    Compartir

    Ver item 
    •   Página inicial
    • PRODUÇÃO CIENTÍFICA
    • Departamentos
    • Dpto. Teoría de la Señal y Comunicaciones e Ingeniería Telemática
    • DEP71 - Artículos de revista
    • Ver item
    •   Página inicial
    • PRODUÇÃO CIENTÍFICA
    • Departamentos
    • Dpto. Teoría de la Señal y Comunicaciones e Ingeniería Telemática
    • DEP71 - Artículos de revista
    • Ver item
    • español
    • English
    • français
    • Deutsch
    • português (Brasil)
    • italiano

    Exportar

    RISMendeleyRefworksZotero
    • edm
    • marc
    • xoai
    • qdc
    • ore
    • ese
    • dim
    • uketd_dc
    • oai_dc
    • etdms
    • rdf
    • mods
    • mets
    • didl
    • premis

    Citas

    Por favor, use este identificador para citar o enlazar este ítem:https://uvadoc.uva.es/handle/10324/79507

    Título
    Security practices and insider threats in Spanish healthcare centers: a survey-based risk assessment
    Autor
    Herrera Montano, IsabelAutoridad UVA Orcid
    Góngora Alonso, SuselAutoridad UVA
    Sañudo García, Soledad
    García Aranda, José Javier
    Rodrígues, Joel J.P.C.
    Torre Díez, Isabel de laAutoridad UVA
    Año del Documento
    2026
    Editorial
    Elsevier
    Descripción
    Producción Científica
    Documento Fuente
    International Journal of Medical Informatics, 2025, vol. 205, p. 106107
    Resumo
    Introduction: Insider threats pose a critical risk in healthcare environments, where Hospital Information Systems (HIS) manage sensitive patients data. Authorized users may intentionally or accidentally compromise data confidentiality, integrity, and availability. This study assessed information security practices from the perspec- tive of healthcare professionals in Spanish medical centers. Methods: A descriptive, analytical, cross-sectional study was conducted using a survey administered to 41 healthcare professionals with access to confidential data. The survey covered access control, encryption at rest and in transit, communication channels, and data usage control. Descriptive statistics, Chi-square tests, and Cram´er’s V were applied to identify significant associations. K-means clustering and Silhouette coefficient were used to define user profiles. Principal Component Analysis (PCA) was used to visualize behavior patterns. A Random Forest model identified the most relevant predictive variables. Results: Critical security gaps were detected, 31.7 % reported no control over data usage. Only 29.3 % encrypted data at rest and 36.6 % during transmission. Over 40 % used personal email or messaging apps to share sensitive data, and 97.6 % relied solely on passwords for authentication. These practices are inadequate to mitigate insider threats. Conclusion: There is an urgent need to strengthen insider data protection. Security strategies should be tailored to user risk profiles. Measures must include strong authentication, full encryption, and stricter control of data transmission to reduce exposure to insider threats (intentionally or unintentionally) in healthcare settings. Additionally, there is a need to promote continuous cybersecurity training.
    Materias Unesco
    3304.13 Dispositivos de Transmisión de Datos
    Palabras Clave
    Cybersecurity
    Healthcare
    Insider threats
    Information security
    Survey
    ISSN
    1386-5056
    Revisión por pares
    SI
    DOI
    10.1016/j.ijmedinf.2025.106107
    Patrocinador
    Instituto da Telecomunicações da Delegação da Covilhã, Portugal. This work is partially funded by Brazilian National Council for Scientific and Technological Development - CNPq, via Grant No. 306607/2023-9.
    Ministerio de Ciencia, Innovación y Universidades (MICINN), a la Agencia Estatal de Investigación (AEI), así como al Fondo Europeo de Desarrollo Regional (FEDER, UE) M0CIN/AEI/10.13039/501100011033 y “FEDER Una manera de hacer Europa” (grant number PID2021-122210OB-I00)
    Version del Editor
    https://www.sciencedirect.com/science/article/pii/S1386505625003247
    Propietario de los Derechos
    © 2025 The Author(s)
    Idioma
    eng
    URI
    https://uvadoc.uva.es/handle/10324/79507
    Tipo de versión
    info:eu-repo/semantics/publishedVersion
    Derechos
    openAccess
    Aparece en las colecciones
    • DEP71 - Artículos de revista [371]
    Mostrar registro completo
    Arquivos deste item
    Nombre:
    Security-practices-insider-threats-Spanish-healthcare-centers.pdf
    Tamaño:
    2.346Mb
    Formato:
    Adobe PDF
    Thumbnail
    Visualizar/Abrir
    Attribution-NonCommercial-NoDerivatives 4.0 InternacionalExceto quando indicado o contrário, a licença deste item é descrito como Attribution-NonCommercial-NoDerivatives 4.0 Internacional

    Universidad de Valladolid

    Powered by MIT's. DSpace software, Version 5.10