PubMed دسترسی آزاد

Business Associates' Involvement in US Health Care Data Breaches: Longitudinal Analysis.

استودیوی صوتی مقاله

پخش حرفه‌ای فارسی و انگلیسی

در حال بررسی نسخه‌های صوتی ذخیره‌شده…

صوت تولیدشده با هوش مصنوعی است. برای کاربرد علمی یا درمانی، متن و منبع اصلی را بررسی کنید.
خواندن هوشمند فارسی و انگلیسی در حال آماده‌سازی صداهای مرورگر…
تنظیم صدای طبیعی و سرعت

صداهایی که در نامشان «Natural»، «Neural» یا «Online» دیده می‌شود معمولاً طبیعی‌ترند. انتخاب صدا به صداهای نصب‌شده در ویندوز و مرورگر شما بستگی دارد.

چکیده اصلی

BACKGROUND: Health care organizations increasingly rely on business associates (BAs) to provide clinical, administrative, and technology services that require access to protected health information. While the Health Information Technology for Economic and Clinical Health (HITECH) Act and the Health Insurance Portability and Accountability Act (HIPAA) Omnibus Rule extended legal liability to BAs, the frequency and characteristics of data breaches involving BAs have not been systematically tracked across the entire post-HITECH reporting era. Understanding these trends is critical for health information managers and cybersecurity professionals who are directly responsible for managing third-party risk. OBJECTIVE: The author examined the longitudinal trends in BA involvement in health care data breaches reported to the US Department of Health and Human Services (HHS) Office for Civil Rights (OCR) from 2009 to 2025, including changes in frequency, breach mechanisms, breach locations, and severity profiles of BA-involved incidents across 3 regulatory periods. METHODS: The author conducted a retrospective longitudinal analysis of health care data breaches (N=6612) reported to the HHS OCR breach portal between October 2009 and December 2025. The author operationalized BA involvement as breaches reported by BA entities or flagged as BA-related. Using logistic regression models, the author estimated annual trends in BA involvement, breach mechanism, and breach location. Chi-square tests assessed associations between BA status and breach characteristics across 3 regulatory periods: pre-Omnibus (2009-2013), post-Omnibus (2014-2019), and 2020-2025. Proportion tests compared BA-involvement rates across periods. RESULTS: BA-involved breaches accounted for 1950 of 6612 (29.5%) incidents and 285,718,494 (48.8%) of all affected individuals. The annual BA-involvement rate increased from 22.1% in the pre-Omnibus period to 36.6% in the 2020-2025 period (z score=8.29, P<.001). Logistic regression confirmed an 8% annual increase in the odds of BA involvement (odds ratio [OR] 1.08, 95% CI 1.07-1.10; P<.001). Hacking/IT incidents shifted from a minority of incidents to the dominant breach mechanism (OR 1.41 per year, 95% CI 1.39-1.44; P<.001), and the odds of network server breaches increased by 29% per year (OR 1.29, 95% CI 1.26-1.31; P<.001). BA-involved breaches were significantly more concentrated in hacking (1282/1950, 65.7% vs 2351/4662, 50.4%) and network server locations (1084/1950, 55.6% vs 1435/4662, 30.8%) compared with non-BA breaches (P<.001). The proportion of mega breaches (≥100,000 individuals) also increased annually (OR 1.16, 95% CI 1.13-1.19; P<.001), with BA-involved breaches exhibiting a significantly higher rate of mega breaches (12.4% vs 8.2%; χ21=28.44; P<.001). CONCLUSIONS: Building on prior evidence linking BA involvement to breach severity, this study demonstrates that BA-involved health care data breaches accelerated substantially across the post-HITECH reporting era, with the steepest increase beginning in 2020. The concurrent growth of hacking and the concentration of breaches on network servers coincided with digital transformation, cloud migration, and the ransomware epidemic, which may have amplified third-party risk exposure. Health information managers and cybersecurity professionals should prioritize BA risk management strategies that account for the evolving threat landscape, including enhanced vendor security assessments and data compartmentalization requirements.

نتیجه فارسی

درگیری شرکای تجاری (BAs) در نقض‌های داده‌های مراقبت‌های بهداشتی از 2009 تا 2025 به طور چشمگیری افزایش یافته است. این افزایش به ویژه از 2020 آغاز شد و با افزایش حملات سایبری و مهاجرت به ابرها همزمان بوده است. BAs مسئولیت قانونی دارند و نقض‌های آنها اغلب با تمرکز بر سرورهای شبکه و حملات سایبری رخ می‌دهند.

  • درگیری BAs در نقض‌ها از 22.1٪ به 36.6٪ افزایش یافته است.
  • نقض‌های BAs بیشتر در حملات سایبری (65.7٪) و سرورهای شبکه (55.6٪) رخ می‌دهند.
  • نقض‌های بزرگ (بیش از 100,000 فرد) در میان نقض‌های BAs بیشتر است.
  • هزینه‌های نقض‌های BAs شامل 48.8٪ از کل افراد تحت تاثیر بوده است.
  • تغییرات قانونی (قانون Omnibus) بر مسئولیت BAs تأثیر گذاشته است.

ترجمه فارسی چکیده

در حالی که سازمان‌های مراقبت‌های بهداشتی به شرکای تجاری (BAs) برای ارائه خدمات نیاز به دسترسی به اطلاعات محرمانه سلامت متکی هستند، تداوم و ویژگی‌های نقض‌های داده‌ای شامل BAs به طور سیستماتیک ردیابی نشده است. این مطالعه روند طولی درگیری BAs در نقض‌های داده‌های مراقبت‌های بهداشتی را از 2009 تا 2025 بررسی می‌کند. نتایج نشان می‌دهد که درگیری BAs در نقض‌ها از 22.1٪ در دوره قبل از قانون Omnibus به 36.6٪ در دوره 2020-2025 افزایش یافته است. نقض‌های مربوط به BAs بیشتر در حملات سایبری و سرورهای شبکه متمرکز بوده‌اند.

روش پژوهش

تحلیل طولی بازگشتی از 6612 نقض داده‌ای گزارش شده به اداره حقوق مدنی وزارت بهداشت و خدمات انسانی ایالات متحده (HHS OCR) از اکتبر 2009 تا دسامبر 2025 انجام شد. مدل‌های رگرسیون لجستیک برای برآورد روند سالانه استفاده شد.

محدودیت‌ها

محدودیت‌های گزارش‌دهی و عدم دسترسی به داده‌های جزئیات بیشتر برای تمام نقض‌ها ممکن است بر نتایج تأثیر بگذارد. تحلیل بر داده‌های گزارش شده به اداره حقوق مدنی تمرکز دارد.

استخراج ساختاریافته از متن منبع

نمای PICO و پیامدها

جمعیت
نقض‌های داده‌های مراقبت‌های بهداشتی گزارش شده به HHS OCR.
مداخله/مواجهه
درگیری شرکای تجاری (BAs) در نقض‌های داده‌ها.
مقایسه
نقض‌های داده‌ای بدون درگیری BAs.
حجم نمونه
6612 مورد نقض داده‌ای.

متن کامل اصلی

نسخه دارای مجوز در منبع علمی در دسترس است.

لینک مستقیم از metadata منبع گرفته شده و در تب جدید باز می‌شود.

باز کردن متن کامل

کلیدواژه‌ها

HIPAAHealth Insurance Portability and Accountability Actbusiness associatecomputer securitycybersecuritydata breachdata securityhealth carehealth information managementprotected health informationthird-party risk
در همین زیرشاخه

مقاله‌های مرتبط

PubMed2026

[THE EPISTEMOLOGY OF PSYCHIATRY: DISPOSITIF OF KNOWLEDGE AND PROFESSIONAL WORK].

The article offers systematic consideration of epistemology of psychiatry as section of medicine which examination permits to analyze dispositif of science successfully implementing conceptual theoretical constructs in everyday practice. The various versions and trends in this area are considered, from traditional history of medicine with its positive or negative models of development of psychiatry to historical epistemology and histor…

PubMed2026

Personality Disorder Diagnoses in Outpatient Forensic Mental Health: A Comprehensive Prevalence Study in the Netherlands.

Personality disorders (PDs) are associated with significant clinical and societal consequences and are highly comorbid with other psychiatric conditions. In forensic mental health settings, PD diagnoses are particularly relevant because they are linked to antisocial behavior, recidivism risk, and specific treatment needs. However, empirical knowledge about the prevalence of PD diagnoses in outpatient forensic mental health (OFMH) care …

PubMed2026

Neuropsychiatry genetics in Africa.

Across Africa, rising mental health needs coincide with rapid advances in genomics, digital health and continental policy reform. Yet research into the genetic, environmental and social determinants of neuropsychiatric illness remains sparse and underfunded. This review argues that African leadership in neuropsychiatric genetics can strengthen discovery, guide prevention and care, and support equitable precision public health, provided…

PubMed2026

Liability and Standard of Care in AI-Driven Psychiatric Practice: European Viewpoint.

AI is increasingly incorporated into psychiatric triage, risk prediction, passive monitoring, clinical documentation, and patient-facing conversational systems. These applications may improve access, continuity, efficiency, and pattern recognition, but they also redistribute epistemic authority and complicate responsibility when harm occurs. European regulation is developed in relation to market access, data governance, risk management…