{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,8,21]],"date-time":"2026-08-21T11:42:57Z","timestamp":1787312577752,"version":"build-2736575974"},"reference-count":48,"publisher":"MDPI AG","issue":"3","license":[{"start":{"date-parts":[[2025,9,5]],"date-time":"2025-09-05T00:00:00Z","timestamp":1757030400000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["JCP"],"abstract":"<jats:p>Electronic health record (EHR) data breaches create severe concerns for patients\u2019 privacy, safety, and risk of loss for healthcare entities responsible for managing patient health records. EHR systems collect a vast amount of user-sensitive data, requiring integration, implementation, and the application of essential security principles, controls, and strategies to safeguard against persistent adversary attacks. This research is an exploratory study into current integrated EHR cybersecurity attacks using United States Health Insurance Portability and Accountability Act (HIPAA) privacy and security breach reported data. This work investigates if current EHR implementation lacks the requisite security control to prevent a cyber breach and protect user privacy. We conduct descriptive and trend analysis to describe, demonstrate, summarize data points, and predict direction based on current and historical data by covered entity, type of breaches, and point of breaches (examine, attack methods, patterns, and location of breach information). An Autoregressive Integrated Moving Average (ARIMA) model is used to provide a detailed analysis of the data demonstrating breaches caused by hacking and IT incidents show a significant trend (coefficient 0.84, p-value &lt; 2.2 \u00d7 10\u221216 ***). The findings reveal a consistent rise in breaches\u2014particularly from hacking and IT incidents\u2014disproportionately affecting healthcare providers. The study highlights that EHR data breaches often follow recurring patterns, indicating common vulnerabilities, and underlines the need for prioritized, data-driven security investments. These findings validate the hypothesis that most EHR cybersecurity attacks are concentrated using similar attack methodologies and face common vulnerabilities and demonstrate the value of targeted mitigation strategies to strengthen healthcare cybersecurity. The findings highlight the urgent need for healthcare organizations and policymakers to prioritize targeted, data-driven security investments and enforce stricter controls to protect EHR systems from increasingly frequent and predictable cyberattacks.<\/jats:p>","DOI":"10.3390\/jcp5030070","type":"journal-article","created":{"date-parts":[[2025,9,5]],"date-time":"2025-09-05T12:18:18Z","timestamp":1757074698000},"page":"70","update-policy":"https:\/\/doi.org\/10.3390\/mdpi_crossmark_policy","source":"Crossref","is-referenced-by-count":4,"title":["The Rise of Hacking in Integrated EHR Systems: A Trend Analysis of U.S. Healthcare Data Breaches"],"prefix":"10.3390","volume":"5","author":[{"given":"Benjamin","family":"Yankson","sequence":"first","affiliation":[{"name":"HackIoT & PCCRT Lab, CCR Lab, Cybersecurity Department, University at Albany, State University of New York, 4700 Washington Ave., Albany, NY 12227, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Mehdi","family":"Barati","sequence":"additional","affiliation":[{"name":"HackIoT & PCCRT Lab, CCR Lab, Cybersecurity Department, University at Albany, State University of New York, 4700 Washington Ave., Albany, NY 12227, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Rebecca","family":"Bondzie","sequence":"additional","affiliation":[{"name":"HackIoT & PCCRT Lab, CCR Lab, Cybersecurity Department, University at Albany, State University of New York, 4700 Washington Ave., Albany, NY 12227, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Ram","family":"Madani","sequence":"additional","affiliation":[{"name":"HackIoT & PCCRT Lab, CCR Lab, Cybersecurity Department, University at Albany, State University of New York, 4700 Washington Ave., Albany, NY 12227, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"1968","published-online":{"date-parts":[[2025,9,5]]},"reference":[{"key":"ref_1","unstructured":"Sherman, G., and Health Canada: Office of Health and the Information Highway (2021, December 05). Towards Electronic Health Record. Available online: https:\/\/publications.gc.ca\/collections\/Collection\/H21-166-2001E.pdf."},{"key":"ref_2","unstructured":"CDC (2021, December 05). Electronic Medical Records\/Electronic Health Records, Available online: https:\/\/www.cdc.gov\/nchs\/fastats\/electronic-medical-records.htm."},{"key":"ref_3","doi-asserted-by":"crossref","first-page":"160","DOI":"10.2174\/1874431100802010160","article-title":"Security Requirements for a Lifelong Electronic Health Record System: An Opinion","volume":"2","author":"Camps","year":"2008","journal-title":"Open Med. Inform. J."},{"key":"ref_4","first-page":"100128","article-title":"Predicting the occurrence of a data breach","volume":"2","author":"Barati","year":"2022","journal-title":"Int. J. Inf. Manag. Data Insights"},{"key":"ref_5","unstructured":"Frampton, S., and Guastello, S. (2021, December 05). Patient-Centered Care Guide. Available online: http:\/\/www.patient-centeredcare.org\/inside\/practical.html."},{"key":"ref_6","unstructured":"Chromium, P. (2021, March 28). The Chromium Projects: System Hardening. Available online: http:\/\/www.chromium.org\/chromium-os\/chromiumos-design-docs\/system-hardening."},{"key":"ref_7","unstructured":"Humphries, M. (2021, November 21). AI Leaks Over 2.5M Medical Records. Available online: https:\/\/uk.pcmag.com\/encryption\/128228\/report-ai-company-leaks-over-25m-medical-records."},{"key":"ref_8","unstructured":"Clmpanu, C. (2021, November 20). AMCA Data Breach Has Now Gone Over The 20 Million Mark. Available online: https:\/\/www.zdnet.com\/article\/amca-data-breach-has-now-gone-over-the-20-million-mark."},{"key":"ref_9","unstructured":"Tidy, J. (2021, November 01). Hackers Threaten to Leak Plastic Surgery Pictures. Available online: https:\/\/www.bbc.com\/news\/technology-55439190."},{"key":"ref_10","unstructured":"Murphy, H. (2021, October 20). Why a Dat Breach at a Genealogy Site Has Privacy Expert Worried. Available online: https:\/\/www.nytimes.com\/2020\/08\/01\/technology\/gedmatch-breach-privacy.html?referringSource=articleShare."},{"key":"ref_11","unstructured":"Iwin, L. (2021, October 24). Breach at Norway\u2019s Largest Healthcare Authority Was a Disaster Waiting to Happen. Available online: https:\/\/www.itgovernance.eu\/blog\/en\/breach-at-norways-largest-healthcare-authority-was-a-disaster-waiting-to-happen."},{"key":"ref_12","unstructured":"Sailpoint (2021, November 05). SailPoint Market Pulse Survey: The Data Breach Battle. Available online: http:\/\/assets.fiercemarkets.net\/public\/newsletter\/fierceemr\/sailpoint.pdf."},{"key":"ref_13","unstructured":"Khalil, E.-K. (2012). Biometric, Access Control, and Smart Card Technology: Lecture 1, University of Ontario Institute of Technology."},{"key":"ref_14","unstructured":"Yankson, B., and Ottah, A. (2023, January 6\u20137). Investigating HIPAA Cybersecurity & Privacy Breach Compliance Reporting During COVID-19. Proceedings of the 18th Annual Symposium on Information Assurance, New York, NY, USA."},{"key":"ref_15","unstructured":"(2021, August 14). Implementation of Electronic Records. Available online: http:\/\/openonlinecourses.com\/ehr\/ImplementationOfInformationSystems.asp."},{"key":"ref_16","unstructured":"(2021, August 23). Health Services in Your Community. Available online: https:\/\/www.ontario.ca\/page\/public-health-unit-locations."},{"key":"ref_17","unstructured":"(2021, August 14). Available online: https:\/\/www.onespan.com\/topics\/biometric-authentication."},{"key":"ref_18","unstructured":"Sharma, R. (2021, November 23). Who Really Owns You\u2019re Your Health Data?. Available online: https:\/\/www.forbes.com\/sites\/forbestechcouncil\/2018\/04\/23\/who-really-owns-your-health-data\/?sh=3bf0587c6d62."},{"key":"ref_19","unstructured":"Canadian Medical Protective Association (2021, October 23). How to Manage Your Medical Records: Retention, Access, Security, Storage, Disposal, and Transfer. The Canadian Medical Protective Association December 2011. Available online: https:\/\/www.cmpa-acpm.ca\/en\/advice-publications\/browse-articles\/2003\/a-matter-of-records-retention-and-transfer-of-clinical-records."},{"key":"ref_20","unstructured":"King, M. (2021, September 04). Who Owns Your Banking Data?. Available online: https:\/\/iveybusinessjournal.com\/who-owns-your-banking-data."},{"key":"ref_21","unstructured":"Takach, G. (2003). Computer Law, Irwin Law. [2nd ed.]."},{"key":"ref_22","unstructured":"Healthcare in Digital Age: Who Owns Data (2021, December 05). The Wall Street Journal. Available online: https:\/\/www.wsj.com\/video\/health-care-in-the-digital-age-who-owns-the-data\/28B6E0AD-8506-40B2-A659-20A9B696F524."},{"key":"ref_23","unstructured":"Data Sharing Principles (2021, October 15). The Canadian Medical Protective Association. Available online: https:\/\/www.cmpa-acpm.ca\/static-assets\/pdf\/advice-and-publications\/handbooks\/com_electronic_records_handbook-e.pdf."},{"key":"ref_24","first-page":"56","article-title":"The Electronic Health Record: What Every Information Manager Should Know","volume":"41","author":"Valerius","year":"2007","journal-title":"Inf. Manag. J."},{"key":"ref_25","unstructured":"Wikipedia (2013, February 16). Frank Abagnale. Available online: http:\/\/en.wikipedia.org\/wiki\/Frank_Abagnale."},{"key":"ref_26","unstructured":"Young, D. (2012, June 12). Electronic Health Records-Privacy and Security Issues. McMillan. Available online: https:\/\/www.lexology.com\/library\/detail.aspx?g=ac5b1631-835b-44e8-9f8d-4590ece77a21."},{"key":"ref_27","unstructured":"Office of the Auditor General of Canada (2012, July 02). Electronic Health Records in Canada: An Overview of Federal and Provincial Reports. Available online: https:\/\/www.oag.bc.ca\/app\/uploads\/sites\/963\/2024\/08\/OAGBC-2010-02-03a-15008-e-health-records-report-en.pdf."},{"key":"ref_28","unstructured":"Yankson, B. (2011). Ubiquitous Biometrics NOW: Identity Management Solution for the Canadian Government, Canadian Business, and You [Unpublished Course Project], Ontario Tech University Library."},{"key":"ref_29","unstructured":"(2013, January 18). Hospital Treating Kate Middleton Falls for a Prank Call. Toronto Star, 5 December 2012. Available online: https:\/\/www.thestar.com\/news\/world\/hospital-treating-kate-middleton-falls-for-prank-call-gives-out-health-information\/article_e2b32615-eeeb-5fb2-b122-dedd48e57e40.html."},{"key":"ref_30","unstructured":"McMurch, T. (2013, January 15). Ehealth Saskatchewan Security Reviews Under Way Following Computer Disposal Error. Government of Saskatchewan. 27 March 2012, Available online: https:\/\/www.saskatchewan.ca\/government\/news-and-media\/2012\/march\/27\/ehealth-saskatchewan-security-review-under-way-following-computer-disposal-error."},{"key":"ref_31","unstructured":"Priest, L. (2013, January 17). A Sickening Side-Effect of the eHealth Revolution Globe and Mail. Available online: https:\/\/www.theglobeandmail.com\/news\/politics\/a-sickening-side-effect-of-the-ehealth-revolution\/article1359796\/."},{"key":"ref_32","unstructured":"Health Canada Infoway (2012, July 15). Electronic Health Record Infostructure (EHRi): Privacy and Security Conceptual Architecture. Available online: https:\/\/canadacommons.ca\/artifacts\/21650824\/electronic-health-record-infostructure-ehri-privacy-and-security-conceptual-architecture\/22551013\/."},{"key":"ref_33","first-page":"1022","article-title":"A blockchain-based healthcare records management framework","volume":"24","author":"Tahir","year":"2024","journal-title":"Sensors"},{"key":"ref_34","doi-asserted-by":"crossref","first-page":"e005057","DOI":"10.1136\/bmjgh-2021-005057","article-title":"Rebooting consent in the digital age: A governance framework for health data exchange","volume":"6","author":"Saksena","year":"2021","journal-title":"BMJ Glob. Health"},{"key":"ref_35","doi-asserted-by":"crossref","first-page":"2318164","DOI":"10.1080\/08839514.2024.2318164","article-title":"Designing a Block Chain Based Network for the Secure Exchange of Medical Data in Healthcare Systems","volume":"38","author":"Rao","year":"2024","journal-title":"Appl. Artif. Intell."},{"key":"ref_36","first-page":"1533","article-title":"An efficient and secure data audit scheme for cloud-based EHRs with recoverable and batch auditing","volume":"83","author":"Zhang","year":"2025","journal-title":"Comput. Mater. Contin."},{"key":"ref_37","unstructured":"Shultz, D. (2012, July 20). As Patients\u2019 Records Go Digital, Theft and Hacking Problem Grow. Kaiser Health News, 3 June 2012. Available online: http:\/\/www.kaiserhealthnews.org\/Stories\/2012\/June\/04\/electronic-health-records-theft-hacking.aspx."},{"key":"ref_38","unstructured":"The Office of the National Coordinator for Health Information Technology (2012, July 02). Guide to Privacy and Security of Health Information, Available online: http:\/\/www.healthit.gov\/sites\/default\/files\/pdf\/privacy\/privacy-and-security-guide.pdf."},{"key":"ref_39","first-page":"13","article-title":"A Review of Security of Electronic Health Records","volume":"34","author":"Khin","year":"2005","journal-title":"Health Inf. Manag."},{"key":"ref_40","doi-asserted-by":"crossref","unstructured":"Pise, A.A., Almuzaini, K.K., Ahanger, T.A., Farouk, A., Pant, K., Pareek, P.K., and Nuagah, S.J. (2022). Enabling artificial intelligence of Things (AIoT) healthcare architectures and listing security issues. Comput. Intell. Neurosci., 8421434.","DOI":"10.1155\/2022\/8421434"},{"key":"ref_41","doi-asserted-by":"crossref","first-page":"565","DOI":"10.1007\/s10479-023-05285-7","article-title":"Security issues and challenges in cloud of things-based applications for industrial automation","volume":"342","author":"Pandey","year":"2023","journal-title":"Ann. Oper. Res."},{"key":"ref_42","doi-asserted-by":"crossref","first-page":"1261","DOI":"10.1109\/COMST.2023.3256323","article-title":"Artificial intelligence of things for smarter Healthcare: A survey of advancements, challenges, and opportunities","volume":"25","author":"Baker","year":"2023","journal-title":"IEEE Commun. Surv. Tutor."},{"key":"ref_43","doi-asserted-by":"crossref","unstructured":"Rajeswari, S.V.K.R., and Ponnusamy, V. (2022). Internet of Things and artificial intelligence in biomedical systems. Artificial Intelligence for Innovative Healthcare Informatics, Springer International Publishing.","DOI":"10.1007\/978-3-030-96569-3_8"},{"key":"ref_44","unstructured":"(2025, July 15). Available online: https:\/\/ocrportal.hhs.gov\/ocr\/breach\/breach_report.jsf."},{"key":"ref_45","unstructured":"Federal Trade Commission (2025, May 22). FTC Enforcement Action to Bar GoodRx from Sharing Consumers\u2019 Sensitive Health Info for Advertising, Available online: https:\/\/www.ftc.gov\/news-events\/news\/press-releases\/2023\/02\/ftc-enforcement-action-bar-goodrx-sharing-consumers-sensitive-health-info-advertising."},{"key":"ref_46","unstructured":"Kruse, C., Frederick, B., Jacobson, T., and Monticone, D. (2025, May 22). Cybersecurity in healthcare: A systematic review of modern threats and trends. PubMed, Available online: https:\/\/pubmed.ncbi.nlm.nih.gov\/27689562\/."},{"key":"ref_47","doi-asserted-by":"crossref","first-page":"103185","DOI":"10.1016\/j.cose.2023.103185","article-title":"Analyzing Web Descriptions of Cybersecurity Breaches in the Healthcare Provider Sector: A Content Analytics Research Method","volume":"129","author":"Lee","year":"2023","journal-title":"Comput. Secur."},{"key":"ref_48","unstructured":"Verizon Business (2025, May 22). 2025 Data Breach Investigations Report. Available online: https:\/\/www.verizon.com\/business\/resources\/reports\/dbir\/."}],"container-title":["Journal of Cybersecurity and Privacy"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/www.mdpi.com\/2624-800X\/5\/3\/70\/pdf","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,10,9]],"date-time":"2025-10-09T18:40:16Z","timestamp":1760035216000},"score":1,"resource":{"primary":{"URL":"https:\/\/www.mdpi.com\/2624-800X\/5\/3\/70"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2025,9,5]]},"references-count":48,"journal-issue":{"issue":"3","published-online":{"date-parts":[[2025,9]]}},"alternative-id":["jcp5030070"],"URL":"https:\/\/doi.org\/10.3390\/jcp5030070","relation":{},"ISSN":["2624-800X"],"issn-type":[{"value":"2624-800X","type":"electronic"}],"subject":[],"published":{"date-parts":[[2025,9,5]]}}}