STRIDE AND PRIVACY ATTACKS IN THE HEALTHCARE INDUSTRY 3
STRIDE and Privacy Attacks in the Healthcare Industry
The world today is rapidly evolving towards the world of digitalization in which
information is no longer stored in drawers and cabinets rather than in information systems. In
this case, the information from the business environment is collected over time and it is used
in creating the profile of its customers. Within the healthcare industry, much as changed
thanks to the availability of technology and information systems that have facilitated a
number of operations such as decision making and evidence-based practices to be enhanced.
However, as much as a number of advantages are being accrued from deploying the use of
information systems within the healthcare industry, the biggest challenge that comes with the
utilization of these systems is cyber threats. According to Mucchi, Jayousi, Martinelli,
Caputo, & Marcocci (2018), each year, the amount of IT budget that is being allocated in
protecting system keeps on increasing based on the fact that IT related breaches are costly to
these organizations. One of the main reasons that the healthcare industry is always under
constant attacks is the type of information that this industry houses which contains highly
sensitive information of the population (Bharati & Pattnaik, 2015). When one goes to any
healthcare facility, they provide more information such as their names, physical addresses,
email addresses, next of kin and their details, and even bank details. When such information
is collected, it results in the building of a patient’s data that can be collected over time and
when more and more data is collected from other patients, it accumulates to create a database.
STRIDE and Privacy Attacks
When dealing with cyber-attacks, they come in different forms as defined by the
concept f STRIDE. As per Supriya & Padaki (2016), STRIDE refers to attacks that are
related to spoofing, tampering, repudiation, information disclosure, denial of service, and
escalation of privileges.
Spoofing