{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,6,10]],"date-time":"2026-06-10T15:11:11Z","timestamp":1781104271069,"version":"3.54.1"},"reference-count":31,"publisher":"IGI Global Scientific Publishing","issue":"4","content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2017,10]]},"abstract":"<jats:p>Cloud computing has been massively adopted in healthcare, where it attracts economic, operational, and functional advantages beneficial to insurance providers. However, according to Identity Theft Resource Centre, over twenty-five percent of data breaches in the US targeted healthcare. The HIPAA Journal reported an increase in healthcare data breaches in the US in 2016, exposing over 16 million health records. The growing incidents of cyberattacks in healthcare are compelling insurance providers to implement mitigating controls. Addressing data security and privacy issues before cloud adoption protects from monetary and reputation losses. This article provides an assessment tool for health insurance providers when adopting cloud vendor solutions. The final deliverable is a proposed framework derived from prominent cloud computing and governance sources, such as the Cloud Security Alliance, Cloud Control Matrix (CSA, CCM) v 3.0.1 and COBIT 5 Cloud Assurance.<\/jats:p>","DOI":"10.4018\/ijmstr.2017100101","type":"journal-article","created":{"date-parts":[[2018,4,24]],"date-time":"2018-04-24T05:10:37Z","timestamp":1524546637000},"page":"1-22","source":"Crossref","is-referenced-by-count":1,"title":["Data Security and Privacy Assurance Considerations in Cloud Computing for Health Insurance Providers"],"prefix":"10.4018","volume":"5","author":[{"given":"Amavey","family":"Tamunobarafiri","sequence":"first","affiliation":[{"name":"Concordia University of Edmonton, Edmonton, Canada"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Shaun","family":"Aghili","sequence":"additional","affiliation":[{"name":"Concordia University of Edmonton, Edmonton, Canada"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Sergey","family":"Butakov","sequence":"additional","affiliation":[{"name":"Concordia University of Edmonton, Edmonton, Canada"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"2432","reference":[{"key":"IJMSTR.2017100101-0","unstructured":"Accenture. (2015). The Revenue Risk and Human Impact of Healthcare Provider Cyber Security Inaction."},{"key":"IJMSTR.2017100101-1","first-page":"8","article-title":"A Survey of the State of Cloud Computing in Healthcare.","volume":"1","author":"S. P.Ahuja","year":"2012","journal-title":"Canadian Center of Science and Education"},{"key":"IJMSTR.2017100101-2","unstructured":"Becker, J. D., & Bailey, E. (2014). A Comparison of IT Governance & Control Frameworks in Cloud Computing. In Twentieth Americas Conference on Information Systems (AMCIS) (pp. 1825\u20131840). Savanah: Association for Information Systems (AIS)."},{"key":"IJMSTR.2017100101-3","unstructured":"Canadian Life Health Insurance Association (CLHIA). (n.d.). A guide to supplementary health insurance."},{"key":"IJMSTR.2017100101-4","first-page":"20","article-title":"Impact of Cloud Computing in Healthcare IT.","volume":"2","year":"2017","journal-title":"Cloud Standards Customer Council"},{"key":"IJMSTR.2017100101-5","article-title":"Security Issues in Cloud Computing for Healthcare.","author":"R.Daman","year":"2016","journal-title":"2016 International Conference on Computing for Sustainable Global Development (INDIAcom)"},{"key":"IJMSTR.2017100101-6","first-page":"6","article-title":"Aspirations to Reality: Filling the Cloud Computing Performance Gap.","volume":"2","author":"V.Gatewood","year":"2013","journal-title":"ISACA"},{"key":"IJMSTR.2017100101-7","unstructured":"Gavrilov, G., & Trajkovik, V. (2012). Security and Privacy Issues and Requirements for Healthcare Cloud Computing. In ICT Innovations 2012 proceedings."},{"key":"IJMSTR.2017100101-8","doi-asserted-by":"publisher","DOI":"10.1007\/s12243-017-0568-5"},{"key":"IJMSTR.2017100101-9","doi-asserted-by":"publisher","DOI":"10.1109\/MSP.2010.186"},{"key":"IJMSTR.2017100101-10","year":"2017","journal-title":"Data Breaches increase by 40 percent in 2016"},{"key":"IJMSTR.2017100101-11","year":"2017","journal-title":"The Breach of Anthem Health-The largest healthcare breach in history"},{"key":"IJMSTR.2017100101-12","article-title":"The Value and Importance of Health Information Privacy","author":"J. N.Sharyl","year":"2009","journal-title":"Beyond the HIPAA Privacy Rule: Enhancing Privacy, Improving Health Through Research. Washington, DC"},{"key":"IJMSTR.2017100101-13","unstructured":"Intel IT Center. (2013, January). Healthcare Cloud Security. Intel IT Center: Industry Brief, 10\u201315."},{"key":"IJMSTR.2017100101-14","unstructured":"ISACA. (2012). Security Considerations for Cloud Computing. ISACA, 50\u201380."},{"key":"IJMSTR.2017100101-15","unstructured":"HIPAA Journal. (2017, Jan 4). Largest Healthcare Data Breaches Of2016. Retrieved from https:\/\/www.hipaajournal.com\/largest-healthcare-data-breaches-of-2016-8631\/"},{"key":"IJMSTR.2017100101-16","first-page":"13","article-title":"Opportunities and Challenges of Cloud Computing to Improve health care services.","author":"A. M.-H.Kuo","year":"2011","journal-title":"Journal of Medical Internet Research"},{"key":"IJMSTR.2017100101-17","first-page":"7","article-title":"The NIST Definition of Cloud Computing.","volume":"15","author":"P.Meli","year":"2011","journal-title":"NIST Special Publication"},{"key":"IJMSTR.2017100101-18","unstructured":"Mennes, F. (2016, June 2). The Impact of Data Breaches Within the Healthcare Industries. Vasco Worldwide."},{"issue":"3","key":"IJMSTR.2017100101-19","first-page":"233","article-title":"Security Management in Inter-cloud.","volume":"1","author":"C.Priya","year":"2012","journal-title":"International Journal of Emerging Trends of Technology in Computer Science"},{"key":"IJMSTR.2017100101-20","article-title":"Measuring the Security Compliance Using Cloud Control Matrix.","author":"T.Ravi","year":"2015","journal-title":"Middle East Journal of Scientific Research"},{"key":"IJMSTR.2017100101-21","unstructured":"Reuters. (2017, June 23). Anthem to Pay Record $115M to Settle Law Suits Over Data Breach. Retrieved November 2017, from https:\/\/www.nbcnews.com\/news\/us-news\/anthem-pay-record-115m-settle-lawsuits-over-data-breach-n776246"},{"issue":"155","key":"IJMSTR.2017100101-22","article-title":"Data Privacy in Cloud-assisted Healthcare Systems: State of Art and Future Challenges.","volume":"40","author":"A.Sajib","year":"2016","journal-title":"Journal of Medical Systems"},{"key":"IJMSTR.2017100101-23","doi-asserted-by":"crossref","unstructured":"Shariati, S. M. & Ahmadzadegan, M. H. (2015). Challenges and Security Issues in Cloud Computing from two Perspectives: Data Security and Privacy Protection. Tehran, Iran: IEEE.","DOI":"10.1109\/KBEI.2015.7436196"},{"key":"IJMSTR.2017100101-24","article-title":"Security and Privacy Challenges in Cloud Computing Environments.","author":"H.Takabi","journal-title":"University of Pittsburgh."},{"key":"IJMSTR.2017100101-25","doi-asserted-by":"crossref","unstructured":"Takabi, H., & Joshi, J. B. (2012). Policy Management as a Service: An Approach to Manage Policy Heterogeneity in Cloud Computing Environment. In 2012 45th Hawaii International Conference On System Sciences.","DOI":"10.1109\/HICSS.2012.475"},{"key":"IJMSTR.2017100101-26","doi-asserted-by":"publisher","DOI":"10.1109\/CloudCom.2013.31"},{"key":"IJMSTR.2017100101-27","unstructured":"Wan, D., Greenway, A., Harris, J. G., & Alter, A. E. (2010). Six questions every health industry executive should ask about cloud computing. Accenture. Retrieved from http:\/\/newsroom.accenture.com\/images\/20020\/HealthcareCloud.pdf"},{"key":"IJMSTR.2017100101-28","doi-asserted-by":"crossref","unstructured":"Wang, C., Ren, K., Lou, W., & Li, J. (2010, July\/August). Toward Publicly Auditable Secure Cloud Data Storage Services. Retrieved from http:\/\/ieeexplore.ieee.org\/stamp\/stamp.jsp?tp=&arnumber=5510914","DOI":"10.1109\/MNET.2010.5510914"},{"key":"IJMSTR.2017100101-29","doi-asserted-by":"crossref","unstructured":"Xiao, Z., & Xiao, Y. (2013, June). Security and Privacy in Cloud Computing. IEEE Communication surveys & tutorials, 15(2).","DOI":"10.1109\/SURV.2012.060912.00182"},{"key":"IJMSTR.2017100101-30","doi-asserted-by":"crossref","unstructured":"Zhang, R., & Lui, L. (2010). Security Models and Requirements for Healthcare Application Clouds. In IEEE 3rd International Conference on Cloud Computing (pp. 268\u2013275). Miami, Florida: IEEE.","DOI":"10.1109\/CLOUD.2010.62"}],"container-title":["International Journal of Monitoring and Surveillance Technologies Research"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/www.igi-global.com\/viewtitle.aspx?TitleId=204942","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2022,5,5]],"date-time":"2022-05-05T20:21:08Z","timestamp":1651782068000},"score":1,"resource":{"primary":{"URL":"http:\/\/services.igi-global.com\/resolvedoi\/resolve.aspx?doi=10.4018\/IJMSTR.2017100101"}},"subtitle":[""],"short-title":[],"issued":{"date-parts":[[2017,10]]},"references-count":31,"journal-issue":{"issue":"4"},"URL":"https:\/\/doi.org\/10.4018\/ijmstr.2017100101","relation":{},"ISSN":["2166-7241","2166-725X"],"issn-type":[{"value":"2166-7241","type":"print"},{"value":"2166-725X","type":"electronic"}],"subject":[],"published":{"date-parts":[[2017,10]]}}}