review Open access

Who should do what to help mitigate cyber threats in health care: narrative review of practical approaches and actionable recommendations

  • International Journal of Health Governance
  • Emerald Publishing Limited
Research footprint

At a glance

Citations
3
References
48
Comments
0
Paper overview

Abstract

Purpose Cyber attacks on health care are ubiquitous, increasingly sophisticated and can cost lives. The health care sector has been lagging behind other industries in digital transformation, including investments in cybersecurity. Stakeholders’ awareness of their own responsibilities and those of others in mitigating cyber threats is often limited. Design/methodology/approach For this narrative literature review, on 30 April 2025, we searched without date, language or geographical restrictions PubMed, Web of Science, Scopus, IEEE Xplore and EBM Reviews for journal articles that reported practical approaches and actionable recommendations to improve cybersecurity in health care. Our initial search returned 720 articles; following supplementary searches and screening, a total of 45 relevant documents were included. Findings Described are the expected roles of key stakeholders in mitigating cyber threats, from governments and lawmakers to health care managers, information technology experts and clinical providers. Health care organisations must step up investments in cybersecurity. Each organisation must develop and implement a strong cybersecurity strategy. State-of-the-art approaches include training to resist phishing, as well as the use of the principle of least privilege for user and administrative access, traffic monitoring tools, endpoint detection and response technologies, along with timely security patching. Zero trust architecture is gaining in relevance and use. Best approaches to balancing cybersecurity with minimal disruption of workflows include user-centric solutions that utilise multi-factor authentication combined with one-time passwords, biometrics or smart cards. Originality/value A comprehensive overview of practical approaches and actionable recommendations for improving cybersecurity in health care, presented by key stakeholders’ roles, delineating state-of-the-art in this fast-moving field.

Record transparency

Publication details

DOI
10.1108/ijhg-03-2025-0030
OpenAlex
W4411915686
Document type
review
Language
EN
Source
International Journal of Health Governance
Last metadata update
Community

Comments

Log in to join the discussion.

  1. No comments yet. Start the discussion.