The human factor in hospital cybersecurity: a high-reliability organization-based maturity model.
other · Level V
Where this comes from
- Record sourced from PubMed, PMID 42721802.
- Also identified by DOI 10.1016/j.ijmedinf.2026.106706.
- No licence information is recorded for this record.
- Because redistribution is not established, this page shows the abstract only. Follow the links below for the full text.
Abstract
Cyberattacks increasingly threaten healthcare systems, where disruption can compromise both organizational continuity and patient care. Although human factors are widely recognized as an important component of cybersecurity vulnerability, little is known about whether human-factor incidents recur in general, and within the same organizations. This study examines recurrence as a potential diagnostic signal of persistent organizational vulnerability and considers its implications through a High Reliability Organization (HRO) perspective. We analyzed 5,752 cyber incidents reported by U.S. healthcare organizations, comprising 3,740 human-factor and 2,012 non-human-factor incidents. Human-factor involvement was identified using a deterministic rule-based classification based on multiple incident metadata fields. Recurrence was defined as a subsequent incident within the same broad category and organization within a three-year window. Robustness was assessed using alternative recurrence windows, increasingly restrictive classification criteria, and organization-level analyses. Human-factor incidents showed a significantly higher recurrence rate than non-human-factor incidents. This pattern remained statistically significant across alternative recurrence windows and another restrictive classification criteria, and was also evident in organization-level analyses, including a paired analysis of organizations experiencing both incident types. Human-factor cyber incidents show a greater tendency to recur within healthcare organizations, making recurrence a potentially useful diagnostic signal of persistent vulnerability, although it does not identify the underlying organizational mechanisms. Building on this empirical pattern, we propose an HRO-informed conceptual maturity model describing progressive organizational capacity to recognize recurring vulnerabilities, learn from incidents, coordinate responses, and adapt practices. The framework provides a basis for future empirical validation of organizational cybersecurity maturity in healthcare.