Who should do what to help mitigate cyber threats in health care: narrative review of practical approaches and actionable recommendations

Hrvoje Belani & Kristina Fišter

International Journal of Health Governance2025https://doi.org/10.1108/ijhg-03-2025-0030article
AJG 1
Weight
0.44

What the paper says

Purpose Cyber attacks on health care are ubiquitous, increasingly sophisticated and can cost lives. The health care sector has been lagging behind other industries in digital transformation, including investments in cybersecurity. Stakeholders’ awareness of their own responsibilities and those of others in mitigating cyber threats is often limited. Design/methodology/approach For this narrative literature review, on 30 April 2025, we searched without date, language or geographical restrictions PubMed, Web of Science, Scopus, IEEE Xplore and EBM Reviews for journal articles that reported practical approaches and actionable recommendations to improve cybersecurity in health care. Our initial search returned 720 articles; following supplementary searches and screening, a total of 45 relevant documents were included. Findings Described are the expected roles of key stakeholders in mitigating cyber threats, from governments and lawmakers to health care managers, information technology experts and clinical providers. Health care organisations must step up investments in cybersecurity. Each organisation must develop and implement a strong cybersecurity strategy. State-of-the-art approaches include training to resist phishing, as well as the use of the principle of least privilege for user and administrative access, traffic monitoring tools, endpoint detection and response technologies, along with timely security patching. Zero trust architecture is gaining in relevance and use. Best approaches to balancing cybersecurity with minimal disruption of workflows include user-centric solutions that utilise multi-factor authentication combined with one-time passwords, biometrics or smart cards. Originality/value A comprehensive overview of practical approaches and actionable recommendations for improving cybersecurity in health care, presented by key stakeholders’ roles, delineating state-of-the-art in this fast-moving field.

3 citations

Open paper page →

Cite this paper

https://doi.org/https://doi.org/10.1108/ijhg-03-2025-0030

Or copy a formatted citation

@article{hrvoje2025,
  title        = {{Who should do what to help mitigate cyber threats in health care: narrative review of practical approaches and actionable recommendations}},
  author       = {Hrvoje Belani & Kristina Fišter},
  journal      = {International Journal of Health Governance},
  year         = {2025},
  doi          = {https://doi.org/https://doi.org/10.1108/ijhg-03-2025-0030},
}

Paste directly into BibTeX, Zotero, or your reference manager.

Flag this paper

Who should do what to help mitigate cyber threats in health care: narrative review of practical approaches and actionable recommendations

Flags are reviewed by the Arbiter methodology team within 5 business days.


Evidence weight

0.44

Balanced mode · F 0.40 / M 0.15 / V 0.05 / R 0.40

F · citation impact0.32 × 0.4 = 0.13
M · momentum0.57 × 0.15 = 0.09
V · venue signal0.50 × 0.05 = 0.03
R · text relevance †0.50 × 0.4 = 0.20

† Text relevance is estimated at 0.50 on the detail page — for your query’s actual relevance score, open this paper from a search result.