<?xml version="1.0" encoding="UTF-8"?><!DOCTYPE article PUBLIC "-//NLM//DTD Journal Publishing DTD v3.0 20080202//EN" "http://dtd.nlm.nih.gov/publishing/3.0/journalpublishing3.dtd">
<article xmlns:mml="http://www.w3.org/1998/Math/MathML" xmlns:xlink="http://www.w3.org/1999/xlink" dtd-version="3.0" xml:lang="en" article-type="research article">
 <front>
  <journal-meta>
   <journal-id journal-id-type="publisher-id">
    jis
   </journal-id>
   <journal-title-group>
    <journal-title>
     Journal of Information Security
    </journal-title>
   </journal-title-group>
   <issn pub-type="epub">
    2153-1234
   </issn>
   <issn publication-format="print">
    2153-1242
   </issn>
   <publisher>
    <publisher-name>
     Scientific Research Publishing
    </publisher-name>
   </publisher>
  </journal-meta>
  <article-meta>
   <article-id pub-id-type="doi">
    10.4236/jis.2024.152014
   </article-id>
   <article-id pub-id-type="publisher-id">
    jis-132826
   </article-id>
   <article-categories>
    <subj-group subj-group-type="heading">
     <subject>
      Articles
     </subject>
    </subj-group>
    <subj-group subj-group-type="Discipline-v2">
     <subject>
      Computer Science 
     </subject>
     <subject>
       Communications
     </subject>
    </subj-group>
   </article-categories>
   <title-group>
    United States Healthcare Data Breaches: Insights for NIST SP 800-66 Revision 2 from a Review of the NIST SP 800-66 Revision 1
   </title-group>
   <contrib-group>
    <contrib contrib-type="author" xlink:type="simple">
     <name name-style="western">
      <surname>
       Mohammed Mohammed
      </surname>
      <given-names>
       Raoof
      </given-names>
     </name>
    </contrib>
   </contrib-group> 
   <aff id="affnull">
    <addr-line>
     aCenter for Information Systems&amp;Technology, Claremont Graduate University, Claremont, USA
    </addr-line> 
   </aff> 
   <pub-date pub-type="epub">
    <day>
     27
    </day> 
    <month>
     02
    </month>
    <year>
     2024
    </year>
   </pub-date> 
   <volume>
    15
   </volume> 
   <issue>
    02
   </issue>
   <fpage>
    232
   </fpage>
   <lpage>
    244
   </lpage>
   <history>
    <date date-type="received">
     <day>
      30,
     </day>
     <month>
      March
     </month>
     <year>
      2024
     </year>
    </date>
    <date date-type="published">
     <day>
      26,
     </day>
     <month>
      March
     </month>
     <year>
      2024
     </year> 
    </date> 
    <date date-type="accepted">
     <day>
      26,
     </day>
     <month>
      April
     </month>
     <year>
      2024
     </year> 
    </date>
   </history>
   <permissions>
    <copyright-statement>
     © Copyright 2014 by authors and Scientific Research Publishing Inc. 
    </copyright-statement>
    <copyright-year>
     2014
    </copyright-year>
    <license>
     <license-p>
      This work is licensed under the Creative Commons Attribution International License (CC BY). http://creativecommons.org/licenses/by/4.0/
     </license-p>
    </license>
   </permissions>
   <abstract>
    Healthcare security and privacy breaches are occurring in the United States (US), and increased substantially during the pandemic. This paper reviews the National Institute of Standards and Technology (NIST) publication base as an effective solution. The NIST Special Publication 800-66 Revision 1 was an essential standard in US healthcare, which was withdrawn in February 2024 and superseded by SP 800-66 Revision 2. This review investigates the academic papers concerning the application of the NIST SP 800-66 Revision 1 standard in the US healthcare literature. A systematic review method was used in this study to determine current knowledge gaps of the SP 800-66 Revision 1. Some limitations were employed in the search to enforce validity. A total of eleven articles were found eligible for the study. Consequently, this study suggests the necessity for additional academic papers pertaining to SP 800-66 Revision 2 in the US healthcare literature. In turn, it will enhance awareness of safeguarding electronic protected health information (ePHI), help to mitigate potential future risks, and eventually reduce breaches.
   </abstract>
   <kwd-group> 
    <kwd>
     SP 800-66 Revision 1
    </kwd> 
    <kwd>
      SP 800-66 Revision 2
    </kwd> 
    <kwd>
      HIPAA Compliance
    </kwd> 
    <kwd>
      Security Breaches
    </kwd> 
    <kwd>
      Risk Management Framework (RMF)
    </kwd> 
    <kwd>
      Internet of Things (IoT)
    </kwd> 
    <kwd>
      Artificial Intelligence (AI)
    </kwd>
   </kwd-group>
  </article-meta>
 </front>
 <body>
  <sec id="s1">
   <title>1. Introduction</title>
   <p>In view of various facets of the situations, circumstances, and technology abuse, healthcare data breaches have remained elevated in the United States (US). A recent study <xref ref-type="bibr" rid="scirp.132826-1">
     [1]
    </xref> stated that the US healthcare industry observed an increment of 25 percent in successful cybersecurity attacks during the COVID-19 pandemic. Technology abuse is exemplified by ransomware and many other technological techniques attacks; Another study <xref ref-type="bibr" rid="scirp.132826-2">
     [2]
    </xref> fueled the growth of data breaches in US healthcare delivery organizations. Moreover, further study <xref ref-type="bibr" rid="scirp.132826-3">
     [3]
    </xref> noted that US healthcare breaches frequently occur at extraordinary rates, resulting in financial loss, reputation loss, and the possibility of losing the business.</p>
   <p>As one of the essential solutions, the National Institute of Standards and Technology (NIST) published a wide variety of publications on information security; one of those publications was the 2008 NIST Special Publication SP 800-66 Revision 1, “An Introductory Resource Guide for Implementing the Health Insurance Portability and Accountability Act (HIPAA) Security Rule” <xref ref-type="bibr" rid="scirp.132826-4">
     [4]
    </xref>.</p>
   <p>As stated in NIST’s introduction to HIPAA security implementation <xref ref-type="bibr" rid="scirp.132826-4">
     [4]
    </xref>: “This Special Publication summarizes the HIPAA security standards and explains some of the structure and organization of the Security Rule. The publication helps to educate readers about information security terms used in the HIPAA Security Rule and to improve understanding of the meaning of the security standards set out in the Security Rule. It is also designed to direct readers to helpful information in other NIST publications on individual topics addressed by the HIPAA Security Rule.” We conclude that SP 800-66 Revision 1 targets readers' awareness of US healthcare security. Moreover, under the HIPAA Security Rules, covered entities are required to evaluate risks and vulnerabilities in their environments and to implement security controls to address those risks and vulnerabilities <xref ref-type="bibr" rid="scirp.132826-4">
     [4]
    </xref>.</p>
   <p>According to the Department of Health and Human Services (HHS), the covered entity is any one of the following displayed in <xref ref-type="table" rid="table1">
     Table 1
    </xref>. <xref ref-type="bibr" rid="scirp.132826-5">
     [5]
    </xref></p>
   <p>The SP 800-66 Revision 1 standard has a Risk Management Framework (RMF). The NIST RMF, “provides the covered entity with a disciplined, structured, extensible, and repeatable process for achieving risk-based protection related to the operation and use of information systems and the protection of” Electronic Protected Health Information (EPHI) <xref ref-type="bibr" rid="scirp.132826-4">
     [4]
    </xref>.</p>
   <table-wrap id="table1">
    <label>
     <xref ref-type="table" rid="table1">
      Table 1
     </xref></label>
    <caption>
     <title>
      <xref ref-type="bibr" rid="scirp.132826-"></xref>Table 1. The types of covered entities.</title>
    </caption>
    <table class="MsoTableGrid custom-table" border="0" cellspacing="0" cellpadding="0"> 
     <tr> 
      <td class="aleft" width="23.92%">A Health Care Provider<p style="text-align:left"></p></td> 
      <td class="aleft" width="76.08%">This includes providers such as doctors, clinics, psychologists, dentists, chiropractors, nursing homes, and pharmacies, but only if they transmit any information in an electronic form in connection with a transaction for which HHS has adopted a standard.<p style="text-align:left"></p></td> 
     </tr> 
     <tr> 
      <td class="aleft" width="23.92%">A Health Plan<p style="text-align:left"></p></td> 
      <td class="aleft" width="76.08%">This includes Health insurance companies, Health Maintenance Organizations (HMOs), company health plans, and Government programs that pay for health care, such as Medicare, Medicaid, and the military and veterans’ health care programs.<p style="text-align:left"></p></td> 
     </tr> 
     <tr> 
      <td class="aleft" width="23.92%">A Health Care Clearinghouse<p style="text-align:left"></p></td> 
      <td class="aleft" width="76.08%">This includes entities that process nonstandard health information they receive from another entity into a standard (i.e., standard electronic format or data content), or vice versa.<p style="text-align:left"></p></td> 
     </tr> 
    </table>
   </table-wrap>
   <p>
    <xref ref-type="fig" rid="fig1">
     Figure 1
    </xref> illustrates the NIST Risk Management Framework (RMF). As mentioned in SP 800-66 Revision 1 <xref ref-type="bibr" rid="scirp.132826-4">
     [4]
    </xref>, “It represents an information security life cycle that facilitates continuous monitoring and improvement in the security state of the information systems within the organization.”</p>
   <p>The RMF includes the following six steps:</p>
   <fig id="fig1" position="float">
    <label>Figure 1</label>
    <caption>
     <title>Figure 1. NIST risk management framework.</title>
    </caption>
    <graphic mimetype="image" position="float" xlink:type="simple" xlink:href="https://html.scirp.org/file/7801009-rId13.jpeg?20240918044103" />
   </fig>
   <p>the System Development Lifecycle (SDLC), and various NIST publications to guide the implementation of security controls in organizational information systems.”</p>
   <p>The variety of standards involved in the RMF (e.g., FIPS 199 and NIST SP 800-60) is also used by industries other than healthcare. However, the SP 800-66 Revision 1 was withdrawn in February 2024 and superseded by SP 800-66 Revision 2. As indicated in the SP 800-66 Revision 2, “this publication provides practical guidance and resources that can be used by regulated entities of all sizes to protect ePHI and better understand the security concepts discussed in the HIPAA Security Rule” <xref ref-type="bibr" rid="scirp.132826-6">
     [6]
    </xref>. Since it is in draft form and not ready for use in production, papers that reference Revision 2 and not Revision 1 will be excluded.</p>
   <p>As defined above, the research problem concerns the incidence rate of US healthcare breaches. However, in reviewing the former studies on relevant problems, A study conducted in 2020 <xref ref-type="bibr" rid="scirp.132826-7">
     [7]
    </xref> addressed the role of awareness of Health Information Technologies (HIT) standards for industry policy and decision-makers. Their study targeted the factors influencing the adoption of HIT standards in healthcare organizations. They found that, among other things, awareness of the standard and reporting on adoption can raise awareness and promote further adoption.”</p>
   <p>Moreover, Rogers <xref ref-type="bibr" rid="scirp.132826-8">
     [8]
    </xref> posited that diffusion of innovation was fundamentally based on awareness of innovation, which explores how new ideas spread within societies. Rogers identifies different types of factors and adopters influencing adoption rates. Additionally, Hasani, O’Reilly, Dehghantanha, Rezania, and Levallet studied the problem concerning the role of cybersecurity adoption in enhancing organizational performance. Their finding had a positive impact on the relationship between the adoption of cybersecurity technologies and organizational performance <xref ref-type="bibr" rid="scirp.132826-9">
     [9]
    </xref>.</p>
   <p>From an awareness standpoint, this study aims to examine and assess the inclusion of SP 800-66 Revision 1 in the US healthcare academic literature. Potentially, we can understand the current impact of the literature on the awareness of US healthcare security practitioners. Understanding the literature can possibly help to predict whether additional academic papers pertaining to SP 800-66 Revision 2 in the US healthcare literature are needed.</p>
  </sec><sec id="s2">
   <title>2. Methodology</title>
   <p>A systematic review research method was used in this study. According to Jalonen <xref ref-type="bibr" rid="scirp.132826-10">
     [10]
    </xref>, “A systematic literature review is a trustworthy, rigorous, and auditable methodology for evaluating and interpreting previous research relevant to a particular phenomenon of interest.” This study aims to include eligible academic papers based on advanced search criteria, and the data is collected from the existing literature. Therefore, this study employed a systematic literature review method. One of the significant advantages of this method is its ability to reduce bias in addressing the research question <xref ref-type="bibr" rid="scirp.132826-11">
     [11]
    </xref>. This section includes sub-sections that explain the eligibility criteria, research question, data collection, and inclusion and exclusion of the studies.</p>
   <sec id="s2_1">
    <title>2.1. Definition of the Eligibility Criteria</title>
    <p>Since the research problem is targeting the breaches in the US healthcare industry, the reviewer set the eligibility requirements for the study to select and review all papers addressing the healthcare domain and settings in the US, except those papers that are non-related to the Health Information Systems (HIS), such as disease academic papers. Typical examples of the HIS are Electronic Medical Records (EMR) <xref ref-type="bibr" rid="scirp.132826-12">
      [12]
     </xref>, Personal Health Records (PHR) <xref ref-type="bibr" rid="scirp.132826-13">
      [13]
     </xref>, and Electronic Health Records (EHR) <xref ref-type="bibr" rid="scirp.132826-14">
      [14]
     </xref>.</p>
   </sec>
   <sec id="s2_2">
    <title>2.2. Research Question</title>
    <p>As mentioned in the introduction section, the SP 800-66 Revision 1 standard clearly targets the readers’ healthcare security awareness. Our research question is formed based on readers’ awareness. The readers could be any type of people, including healthcare security practitioners. However, Schlögl and Stock <xref ref-type="bibr" rid="scirp.132826-15">
      [15]
     </xref> found a low level of information exchange between practitioners and academic journals.</p>
    <p>In this study, the researcher wondered how the National Institute of Standards and Technology (NIST) Special Publication 800-66 Revision 1 was utilized in academic studies within the existing literature, specifically within the US healthcare industry.</p>
   </sec>
   <sec id="s2_3">
    <title>2.3. Data Collection Sources &amp; Strategy</title>
    <p>This study relies on secondary data sources from the existing literature. The search was for the keyword “SP 800-66” in the Google Scholar database engine conducted in June 2023. The date range of the search was set from 2008 to 2024. The reason behind setting 2024 as an end date is to show all of the existing papers. In addition, the author attempts to search in the Google Trends search engine, but it shows no results for the period from January 1, 2008, to January 1, 2023, when searching for the SP 800-66 keyword. However, the data collected for this study is sourced from the Google Scholar database engine only. The data collection processes for the study have an inclusion perspective and an exclusion perspective.</p>
   </sec>
   <sec id="s2_4">
    <title>2.4. Inclusion &amp; Exclusion of the Studies</title>
    <p>The exclusion perspective rejects papers with SP 800-66 Revision 2, non-English academic papers generally, papers with no publishing dates, and non-academic papers such as books and class research projects. In addition, the exclusion is also applied to papers that mention SP 800-66 in the reference section and are not cited in the paper’s content.</p>
    <p>The inclusion perspective includes the academic papers that are:</p>
    <p>
     <xref ref-type="fig" rid="fig2">
      Figure 2
     </xref> illustrates a systematic review flow diagram, which contains the identification phase, inclusion phase, and exclusion phase; it shows the structure and the total number of papers found in the systematic review study. As shown, the inclusion phase represented the selected eligible studies, while the exclusion phase represented the non-eligible studies.</p>
    <p>A total of 540 studies were identified in the preliminary search in the Google Scholar Database. The researcher excluded 529 studies from this review because</p>
    <fig id="fig2" position="float">
     <label>Figure 2</label>
     <caption>
      <title>Figure 2. The flow diagram of the systematic review.</title>
     </caption>
     <graphic mimetype="image" position="float" xlink:type="simple" xlink:href="https://html.scirp.org/file/7801009-rId14.jpeg?20240918044104" />
    </fig>
    <p>they did not meet the study’s eligibility criteria. That reduced the identified papers from 540 studies to 11 eligible studies, which represent the sample data, and they are listed in <xref ref-type="table" rid="table2">
      Table 2
     </xref>. Details of the excluded paper triggers are in the discussion section below.</p>
   </sec>
  </sec><sec id="s3">
   <title>3. Results</title>
   <p>Eleven eligible papers were reviewed, and their data were synthesized and analyzed in the study. <xref ref-type="table" rid="table2">
     Table 2
    </xref> displays the overview of these articles; they are listed chronologically by publishing year.</p>
   <p>From the perspective of reflexivity in evaluating intercoder reliability, O’Connor and Joffe <xref ref-type="bibr" rid="scirp.132826-16">
     [16]
    </xref> discussed that the same researcher returns to the data at another time. However, the reviewer reviewed these eligible studies three times over three different periods. The researcher added the “what specific topics are covered?” column in <xref ref-type="table" rid="table2">
     Table 2
    </xref> for reliability, the researcher documented the</p>
   <table-wrap id="table2">
    <label>
     <xref ref-type="table" rid="table2">
      Table 2
     </xref></label>
    <caption>
     <title>
      <xref ref-type="bibr" rid="scirp.132826-"></xref>Table 2. The observation of the eligible papers.</title>
    </caption>
    <table class="MsoTableGrid custom-table" border="0" cellspacing="0" cellpadding="0"> 
     <tr> 
      <td class="custom-bottom-td aleft" width="21.35%">Authors’ citation<p style="text-align:left"></p></td> 
      <td class="custom-bottom-td aleft" width="18.74%">What specific topics are covered?<p style="text-align:left"></p></td> 
      <td class="custom-bottom-td aleft" width="50.24%">How was SP 800-66 Revision 1 used?<p style="text-align:left"></p></td> 
      <td class="custom-bottom-td aleft" width="9.67%">Publishing Year<p style="text-align:left"></p></td> 
     </tr> 
     <tr> 
      <td class="custom-top-td aleft" width="21.35%">(Gikas, 2010) <xref ref-type="bibr" rid="scirp.132826-17">
        [17]
       </xref><p style="text-align:left"></p></td> 
      <td class="custom-top-td aleft" width="18.74%">Regulatory Compliance Requirements<p style="text-align:left"></p></td> 
      <td class="custom-top-td aleft" width="50.24%">It was used as an example of one of the sources for implementing the requirements of the HIPAA Security Rule.<p style="text-align:left"></p></td> 
      <td class="custom-top-td aleft" width="9.67%">2010<p style="text-align:left"></p></td> 
     </tr> 
     <tr> 
      <td class="aleft" width="21.35%">(Pagano &amp; Peterson, 2010) <xref ref-type="bibr" rid="scirp.132826-18">
        [18]
       </xref><p style="text-align:left"></p></td> 
      <td class="aleft" width="18.74%">Regulatory Compliance<p style="text-align:left"></p>Requirements<p style="text-align:left"></p></td> 
      <td class="aleft" width="50.24%">It was used as a reference for access controls on electronic devices<p style="text-align:left"></p></td> 
      <td class="aleft" width="9.67%">2010<p style="text-align:left"></p></td> 
     </tr> 
     <tr> 
      <td class="aleft" width="21.35%">(Ghafarian &amp; Smith, 2011) <xref ref-type="bibr" rid="scirp.132826-19">
        [19]
       </xref><p style="text-align:left"></p></td> 
      <td class="aleft" width="18.74%">Risk Assessment<p style="text-align:left"></p></td> 
      <td class="aleft" width="50.24%">It was used as an example of one of the risk assessment methodologies used by United States healthcare<p style="text-align:left"></p></td> 
      <td class="aleft" width="9.67%">2011<p style="text-align:left"></p></td> 
     </tr> 
     <tr> 
      <td class="aleft" width="21.35%">(Avancha et al., 2012) <xref ref-type="bibr" rid="scirp.132826-20">
        [20]
       </xref><p style="text-align:left"></p></td> 
      <td class="aleft" width="18.74%">Confidentiality, Integrity, Availability (CIA).<p style="text-align:left"></p></td> 
      <td class="aleft" width="50.24%">It was used as a source to address privacy. Particularly in healthcare mobile technology<p style="text-align:left"></p></td> 
      <td class="aleft" width="9.67%">2012<p style="text-align:left"></p></td> 
     </tr> 
     <tr> 
      <td class="aleft" width="21.35%">(Rahman &amp; Kreider, 2012) <xref ref-type="bibr" rid="scirp.132826-21">
        [21]
       </xref><p style="text-align:left"></p></td> 
      <td class="aleft" width="18.74%">Electronic Medical Record (EMR)<p style="text-align:left"></p></td> 
      <td class="aleft" width="50.24%">It was used as a source to explain confidentiality in healthcare organizations<p style="text-align:left"></p></td> 
      <td class="aleft" width="9.67%">2012<p style="text-align:left"></p></td> 
     </tr> 
     <tr> 
      <td class="aleft" width="21.35%">(Alaqili, 2013) <xref ref-type="bibr" rid="scirp.132826-22">
        [22]
       </xref><p style="text-align:left"></p></td> 
      <td class="aleft" width="18.74%">HIPAA Security Rule.<p style="text-align:left"></p></td> 
      <td class="aleft" width="50.24%">It was used as a source in developing questionnaires for risk assessment reports in the healthcare domain<p style="text-align:left"></p></td> 
      <td class="aleft" width="9.67%">2013<p style="text-align:left"></p></td> 
     </tr> 
     <tr> 
      <td class="aleft" width="21.35%">(Meyer et al., 2016) <xref ref-type="bibr" rid="scirp.132826-23">
        [23]
       </xref><p style="text-align:left"></p></td> 
      <td class="aleft" width="18.74%">Security Controls<p style="text-align:left"></p></td> 
      <td class="aleft" width="50.24%">It was used as a Security and privacy requirement for systems, including healthcare organizations<p style="text-align:left"></p></td> 
      <td class="aleft" width="9.67%">2016<p style="text-align:left"></p></td> 
     </tr> 
     <tr> 
      <td class="aleft" width="21.35%">(Aranha et al., 2019) <xref ref-type="bibr" rid="scirp.132826-24">
        [24]
       </xref><p style="text-align:left"></p></td> 
      <td class="aleft" width="18.74%">Industrial Internet of Things (IIoT) and Interoperability<p style="text-align:left"></p></td> 
      <td class="aleft" width="50.24%">It was used as a security standard to describe the security requirements for all types of healthcare environments including medical devices.<p style="text-align:left"></p></td> 
      <td class="aleft" width="9.67%">2019<p style="text-align:left"></p></td> 
     </tr> 
     <tr> 
      <td class="aleft" width="21.35%">(Valluripally et al., 2019) <xref ref-type="bibr" rid="scirp.132826-25">
        [25]
       </xref><p style="text-align:left"></p></td> 
      <td class="aleft" width="18.74%">Regulatory Compliance Requirements<p style="text-align:left"></p></td> 
      <td class="aleft" width="50.24%">It was used as a security standard to configure cloud-based system healthcare domain involving Big Data<p style="text-align:left"></p></td> 
      <td class="aleft" width="9.67%">2019<p style="text-align:left"></p></td> 
     </tr> 
     <tr> 
      <td class="aleft" width="21.35%">(Jabangwe &amp; Nguyen-Duc, 2020) <xref ref-type="bibr" rid="scirp.132826-26">
        [26]
       </xref><p style="text-align:left"></p></td> 
      <td class="aleft" width="18.74%">IoT healthcare software<p style="text-align:left"></p></td> 
      <td class="aleft" width="50.24%">It was used as an example of the security standard in the United States, particularly from the regulation of the healthcare domain<p style="text-align:left"></p></td> 
      <td class="aleft" width="9.67%">2020<p style="text-align:left"></p></td> 
     </tr> 
     <tr> 
      <td class="aleft" width="21.35%">(Wilkinson et al., 2021)<p style="text-align:left"></p><xref ref-type="bibr" rid="scirp.132826-27">
        [27]
       </xref><p style="text-align:left"></p></td> 
      <td class="aleft" width="18.74%">HIPAA Security Rule Requirements for the Electronic Medical Record (EMR)<p style="text-align:left"></p></td> 
      <td class="aleft" width="50.24%">It was used as a reference for the Health Insurance Portability and Accountability Act (HIPAA) because EMRs contain patient event logging data, and Protected Health Information (PHI), which are originally mandated by the Security Rule in HIPAA<p style="text-align:left"></p></td> 
      <td class="aleft" width="9.67%">2021<p style="text-align:left"></p></td> 
     </tr> 
    </table>
   </table-wrap>
   <p>inclusion reasons of eligible articles to help the readers understand and evaluate the reliability of this review.</p>
  </sec><sec id="s4">
   <title>4. Discussions</title>
   <sec id="s4_1">
    <title>4.1. From an Exclusion Paper Perspective</title>
    <p>This study found that 529 papers were non-eligible for review. As previously stated, the author’s criteria required that the non-United States papers be excluded from the study. In accordance with what was observed, many non-United States relevant healthcare papers mentioned the keyword SP 800-66, such as Australia <xref ref-type="bibr" rid="scirp.132826-28">
      [28]
     </xref>, Canada <xref ref-type="bibr" rid="scirp.132826-29">
      [29]
     </xref>, Italy <xref ref-type="bibr" rid="scirp.132826-30">
      [30]
     </xref>, Korea <xref ref-type="bibr" rid="scirp.132826-31">
      [31]
     </xref> <xref ref-type="bibr" rid="scirp.132826-32">
      [32]
     </xref>, Malaysia <xref ref-type="bibr" rid="scirp.132826-33">
      [33]
     </xref>, and Pakistan <xref ref-type="bibr" rid="scirp.132826-34">
      [34]
     </xref>.</p>
    <p>Nevertheless, it was difficult to determine the relevance of certain papers to the US healthcare industry, especially for healthcare technology papers, such as health Internet of Things (IoT) devices. Health IoT devices are growing in usage everywhere nowadays, not only in the US, such as the implantable pacemakers. There were challenges due to the absence of country mentions within these papers, making it unclear whether they pertained to the US or not. For example, Ngamboé et al. <xref ref-type="bibr" rid="scirp.132826-35">
      [35]
     </xref> primarily focused on the security scope of telemetry-enabled cardiac implantable electronic devices (CIED).</p>
    <p>In addition, the SP 800-66 was found in a security education paper <xref ref-type="bibr" rid="scirp.132826-36">
      [36]
     </xref>. Spears <xref ref-type="bibr" rid="scirp.132826-36">
      [36]
     </xref> developed a course syllabus targeting IT students interested in health care. The course aims to provide students with real-world service-learning in risk assessment, and it includes SP 800-66 Revision 1 as free reading material, as one of many industry security standards in general.</p>
   </sec>
   <sec id="s4_2">
    <title>4.2. From an Inclusion Paper Perspective</title>
    <p>Eleven papers were eligible for review; the papers explored various technological domains in healthcare, including topics in Big Data analytics <xref ref-type="bibr" rid="scirp.132826-25">
      [25]
     </xref>, Electronic Medical Record (EMR) <xref ref-type="bibr" rid="scirp.132826-27">
      [27]
     </xref>, Risk Assessment <xref ref-type="bibr" rid="scirp.132826-19">
      [19]
     </xref>, Mobile Technology <xref ref-type="bibr" rid="scirp.132826-20">
      [20]
     </xref>, Industrial Internet of Things (IIoT) and Interoperability <xref ref-type="bibr" rid="scirp.132826-24">
      [24]
     </xref>, Internet of Things (IoT) and Software <xref ref-type="bibr" rid="scirp.132826-26">
      [26]
     </xref>.</p>
    <p>Overall, the citations of NIST SP 800-66 Revision 1 address several quotations in eligible papers, the majority of them are about:</p>
    <p>
     <xref ref-type="fig" rid="fig3">
      Figure 3
     </xref> shows the publishing years of these papers were as follows: 2010 (two papers), 2011 (one paper), 2012 (two papers), 2013 (one paper), 2016 (one paper), 2019 (two papers), 2020 (one paper), and 2021 (one paper). The study did not find any eligible published papers in these years: 2008-09, 2014-15, 2017-18, 2022, and 2023.</p>
    <fig id="fig3" position="float">
     <label>Figure 3</label>
     <caption>
      <title>Figure 3. Number of eligible papers by publishing year.</title>
     </caption>
     <graphic mimetype="image" position="float" xlink:type="simple" xlink:href="https://html.scirp.org/file/7801009-rId15.jpeg?20240918044105" />
    </fig>
    <p>Lebek et al. <xref ref-type="bibr" rid="scirp.132826-37">
      [37]
     </xref> conducted a study on employees’ Information Security (IS) awareness and behavior, they stated “in literature, there is consent (sic; consensus) that employees are the weakest link” in information systems security; they concluded, “the literature review might also be useful for practitioners that need information about behavioral factors that are critical to the success of an organization’s security awareness.”</p>
    <p>
     <xref ref-type="bibr" rid="scirp.132826-"></xref>However, based on the findings in this study, the reviewer believes it is essential to get greater academic visibility for SP 800-66 Revision 2 via citations in US healthcare papers since SP 800-66 Revision 1 has been retired. This study suggests using the SP 800-66 Revision 2 more frequently in academic papers that target the US healthcare industry. In turn, it will help to achieve the original objectives of the SP 800-66 Revision 2 and minimize future data breaches.</p>
    <p>To illustrate, IoT and Artificial Intelligence (AI) are currently among the trending areas in healthcare, and their integration and development are ongoing. Presently, these areas have many gaps in terms of security and privacy breaches. Therefore, addressing the SP 800-66 Revision 2 in the IoT and AI, specifically in the US healthcare paper, will increase awareness of the security requirements.</p>
    <p>Additionally, the author observed that not all health IoT papers address the country name or specify the US healthcare regulations. Therefore, the author suggests using the 800-66 Revision 2 in health IoT security papers to address health regulations for health IoT security and privacy papers. Moreover, the manuscript of the 800-66 Revision 2 indicated the scope of risk assessment “should include all removable media and portable computing devices (e.g., laptops, mobile devices) as well as the myriad of medical devices (e.g., Internet of Things [IoT] used in healthcare) that can store, process, or transmit ePHI” <xref ref-type="bibr" rid="scirp.132826-6">
      [6]
     </xref>.</p>
   </sec>
  </sec><sec id="s5">
   <title>5. Limitations and Future Directions</title>
   <p>This study selected the eligible papers based on the keyword search “SP 800-66” on the Google Search Engine. However, the following identified limitations may potentially impact the validity of this study:</p>
  </sec><sec id="s6">
   <title>6. Conclusions</title>
   <p>With healthcare data breaches continuing to occur in the US, it is important to investigate how the NIST SP 800-66 Revision 1 is expanded in academic papers targeting US healthcare. The NIST SP 800-66 Revision 1 was written in 2008, mainly to help reduce incidents in the US healthcare industry. However, this study looked for SP 800-66 Revision 1 in the literature; a keyword search was conducted within the Google Scholar search engine, with the specified data range spanning from 2008 to 2024.</p>
   <p>This review shows that the SP 800-66 Revision 1 manuscript was used in the literature of other countries and for different industries. Only 11 papers targeted US healthcare in the following areas: Big Data analytics, Electronic Medical Record (EMR), Risk Assessment, Mobile Technology, Industrial Internet of Things (IIoT), Interoperability, Internet of Things (IoT), and Software.</p>
   <p>The study concluded that more studies are needed to raise awareness of SP 800-66 Revision 2, which will help reduce the potential for future healthcare data breaches in the United States. Moreover, this study underscores the need for an increased volume of academic papers pertaining to NIST SP 800-66 Revision 2 in US healthcare and broadening their scope to encompass other US healthcare technology applications such as the Internet of Things (IoT) and Artificial Intelligence (AI).</p>
  </sec><sec id="s7">
   <title>Acknowledgements</title>
   <p>The researcher expresses gratitude to all peer reviewers for their comments and feedback.</p>
  </sec>
 </body><back>
  <ref-list>
   <title>References</title>
   <ref id="scirp.132826-ref1">
    <label>1</label>
    <mixed-citation publication-type="other" xlink:type="simple">
     Ignatovski, M. (2022) Healthcare Breaches during COVID-19: The Effect of the Healthcare Entity Type on the Number of Impacted Individuals. Perspectives in Health Information Management, 19, 1c.
    </mixed-citation>
   </ref>
   <ref id="scirp.132826-ref2">
    <label>2</label>
    <mixed-citation publication-type="other" xlink:type="simple">
     Neprash, H.T., McGlave, C.C., Cross, D.A., Virnig, B.A., Puskarich, M.A., Huling, J.D., Rozenshtein, A.Z. and Nikpay, S.S. (2022) Trends in Ransomware Attacks on US Hospitals, Clinics, and Other Health Care Delivery Organizations, 2016-2021. JAMA Health Forum, 3, e224873. &gt;https://doi.org/10.1001/jamahealthforum.2022.4873
    </mixed-citation>
   </ref>
   <ref id="scirp.132826-ref3">
    <label>3</label>
    <mixed-citation publication-type="other" xlink:type="simple">
     Dolezel, D. and McLeod, A. (2019) Cyber-Analytics: Identifying Discriminants of Data Breaches. Perspectives in Health Information Management, 16, 1a.
    </mixed-citation>
   </ref>
   <ref id="scirp.132826-ref4">
    <label>4</label>
    <mixed-citation publication-type="other" xlink:type="simple">
     Scholl, M., Stine, K., Hash, J., Bowen, P., Johnson, L., Dancy, C. and Steinberg, D. (2008) An Introductory Resource Guide for Implementing the Health Insurance Portability and Accountability Act (HIPAA) Security Rule, Special Publication (NIST SP). National Institute of Standards and Technology, Gaithersburg.&gt;https://Tsapps.Nist.Gov/Publication/Get_Pdf.Cfm?Pub_Id=890098 
    </mixed-citation>
   </ref>
   <ref id="scirp.132826-ref5">
    <label>5</label>
    <mixed-citation publication-type="other" xlink:type="simple">
     Department of Health and Human Services (2017) Covered Entities and Business Associates. Department of Health and Human Services, Content Created by Office for Civil Rights (OCR).
    </mixed-citation>
   </ref>
   <ref id="scirp.132826-ref6">
    <label>6</label>
    <mixed-citation publication-type="other" xlink:type="simple">
     Marron, J. (2024) Implementing the Health Insurance Portability and Accountability Act (HIPAA) Security Rule: A Cybersecurity Resource Guide. &gt;https://doi.org/10.6028/NIST.SP.800-66r2
    </mixed-citation>
   </ref>
   <ref id="scirp.132826-ref7">
    <label>7</label>
    <mixed-citation publication-type="other" xlink:type="simple">
     Han, L., et al. (2020) Factors Influencing the Adoption of Health Information Standards in Health Care Organizations: A Systematic Review Based on Best Fit Framework Synthesis. JMIR Medical Informatics, 8, e17334. &gt;https://doi.org/10.2196/17334
    </mixed-citation>
   </ref>
   <ref id="scirp.132826-ref8">
    <label>8</label>
    <mixed-citation publication-type="other" xlink:type="simple">
     Rogers, E.M. (1995) Diffusion of Innovations: Modifications of a Model for Telecommunications. In: Stoetzer, M.W. and Mahler, A., Eds., Die Diffusion von Innovationen in der Telekommunikation, Springer, Berlin, 25-38. &gt;https://doi.org/10.1007/978-3-642-79868-9_2
    </mixed-citation>
   </ref>
   <ref id="scirp.132826-ref9">
    <label>9</label>
    <mixed-citation publication-type="other" xlink:type="simple">
     Hasani, T., O’Reilly, N., Dehghantanha, A., Rezania, D. and Levallet, N. (2023) Evaluating the Adoption of Cybersecurity and Its Influence on Organizational Performance. SN Business&amp;Economics, 3, Article No. 97. &gt;https://doi.org/10.1007/s43546-023-00477-6
    </mixed-citation>
   </ref>
   <ref id="scirp.132826-ref10">
    <label>10</label>
    <mixed-citation publication-type="other" xlink:type="simple">
     Jalonen, H. (2012) The Uncertainty of Innovation: A Systematic Review of the Literature. Journal of Management Research, 4, E12. &gt;https://doi.org/10.5296/jmr.v4i1.1039
    </mixed-citation>
   </ref>
   <ref id="scirp.132826-ref11">
    <label>11</label>
    <mixed-citation publication-type="other" xlink:type="simple">
     Turney, S. (2024) Systematic Review: Definition, Example,&amp;Guide. Scribbr. &gt;https://www.scribbr.com/methodology/systematic-review/ 
    </mixed-citation>
   </ref>
   <ref id="scirp.132826-ref12">
    <label>12</label>
    <mixed-citation publication-type="other" xlink:type="simple">
     Ludwick, D.A. and Doucette, J. (2009) Adopting Electronic Medical Records in Primary Care: Lessons Learned from Health Information Systems Implementation Experience in Seven Countries. International Journal of Medical Informatics, 78, 22-31. &gt;https://doi.org/10.1016/j.ijmedinf.2008.06.005
    </mixed-citation>
   </ref>
   <ref id="scirp.132826-ref13">
    <label>13</label>
    <mixed-citation publication-type="other" xlink:type="simple">
     Lafky, D.B., Tulu, B. and Horan, T.A. (2006) Information Systems and Health Care X: A User-Driven Approach to Personal Health Records. Communications of the Association for Information Systems, 17, Article 46. &gt;https://doi.org/10.17705/1CAIS.01746
    </mixed-citation>
   </ref>
   <ref id="scirp.132826-ref14">
    <label>14</label>
    <mixed-citation publication-type="other" xlink:type="simple">
     Jardim, S.V. (2013) The Electronic Health Record and Its Contribution to Healthcare Information Systems Interoperability. Procedia Technology, 9, 940-948. &gt;https://doi.org/10.1016/j.protcy.2013.12.105
    </mixed-citation>
   </ref>
   <ref id="scirp.132826-ref15">
    <label>15</label>
    <mixed-citation publication-type="other" xlink:type="simple">
     Schlögl, C. and Stock, W.G. (2008) Practitioners and Academics as Authors and Readers: The Case of LIS Journals. Journal of Documentation, 64, 643-666. &gt;https://doi.org/10.1108/00220410810899691
    </mixed-citation>
   </ref>
   <ref id="scirp.132826-ref16">
    <label>16</label>
    <mixed-citation publication-type="other" xlink:type="simple">
     O’Connor, C. and Joffe, H. (2020) Intercoder Reliability in Qualitative Research: Debates and Practical Guidelines. International Journal of Qualitative Methods, 19, 2. &gt;https://doi.org/10.1177/1609406919899220
    </mixed-citation>
   </ref>
   <ref id="scirp.132826-ref17">
    <label>17</label>
    <mixed-citation publication-type="other" xlink:type="simple">
     Gikas, C. (2010) A General Comparison of FISMA, HIPAA, ISO 27000 and PCIDSS Standards. Information Security Journal: A Global Perspective, 19, 132-141. &gt;https://doi.org/10.1080/19393551003657019
    </mixed-citation>
   </ref>
   <ref id="scirp.132826-ref18">
    <label>18</label>
    <mixed-citation publication-type="other" xlink:type="simple">
     Pagano, M.W. and Peterson, Z.N. (2010) Design and Implementation of Views: Isolated Perspectives of a File System. &gt;https://jscholarship.library.jhu.edu/server/api/core/bitstreams/e3d79a3e-b346-4d6c-8b4a-a5e401db2776/content
    </mixed-citation>
   </ref>
   <ref id="scirp.132826-ref19">
    <label>19</label>
    <mixed-citation publication-type="other" xlink:type="simple">
     Ghafarian, A. and Smith, T. (2011) Information Security Risk Assessment Analysis. SAM 2011: Proceedings of the 2011 International Conference on Security&amp;Management, Las Vegas NV, 18-21 July 2011, 1.
    </mixed-citation>
   </ref>
   <ref id="scirp.132826-ref20">
    <label>20</label>
    <mixed-citation publication-type="other" xlink:type="simple">
     Avancha, S., Baxi, A. and Kotz, D. (2012) Privacy in Mobile Technology for Personal Healthcare. ACM Computing Surveys, 45, 1-54. &gt;https://doi.org/10.1145/2379776.2379779
    </mixed-citation>
   </ref>
   <ref id="scirp.132826-ref21">
    <label>21</label>
    <mixed-citation publication-type="other" xlink:type="simple">
     Rahman, M. and Kreider, C. (2012) Information Security Principles for Electronic Medical Record (EMR) Systems. &gt;https://aisel.aisnet.org/amcis2012/proceedings/ISHealthcare/9/ 
    </mixed-citation>
   </ref>
   <ref id="scirp.132826-ref22">
    <label>22</label>
    <mixed-citation publication-type="other" xlink:type="simple">
     Alaqili, M.Z. (2013) Road Map to HIPAA Security Rules Compliance: Risk Analysis at Orbit Clinics. 
    </mixed-citation>
   </ref>
   <ref id="scirp.132826-ref23">
    <label>23</label>
    <mixed-citation publication-type="other" xlink:type="simple">
     Meyer, A., Green, L., Faulk, C., Galla, S. and Meyer, A.M. (2016) Framework for Deploying a Virtualized Computing Environment for Collaborative and Secure Data Analytics. eGEMs (Generating Evidence&amp;Methods to Improve Patient Outcomes), 4, Article 4. &gt;https://doi.org/10.13063/2327-9214.1224
    </mixed-citation>
   </ref>
   <ref id="scirp.132826-ref24">
    <label>24</label>
    <mixed-citation publication-type="other" xlink:type="simple">
     Aranha, H., Masi, M., Pavleska, T. and Sellitto, G.P. (2019) Securing Mobile E-Health Environments by Design: A Holistic Architectural Approach. 2019 International Conference on Wireless and Mobile Computing, Networking and Communications (WiMob), Barcelona, 21-23 October 2019, 1-6. &gt;https://doi.org/10.1109/WiMOB.2019.8923479
    </mixed-citation>
   </ref>
   <ref id="scirp.132826-ref25">
    <label>25</label>
    <mixed-citation publication-type="other" xlink:type="simple">
     Valluripally, S., Raju, M., Calyam, P., Chisholm, M., Sivarathri, S.S., Mosa, A. and Joshi, T. (2019) Community Cloud Architecture to Improve Use Accessibility with Security Compliance in Health Big Data Applications. Proceedings of the 20th International Conference on Distributed Computing and Networking, Bangalore, 4-7 January 2019, 377-380. &gt;https://doi.org/10.1145/3288599.3295594
    </mixed-citation>
   </ref>
   <ref id="scirp.132826-ref26">
    <label>26</label>
    <mixed-citation publication-type="other" xlink:type="simple">
     Jabangwe, R. and Nguyen-Duc, A. (2020) SIoT Framework: Towards an Approach for Early Identification of Security Requirements for Internet-of-Things Applications. e-Informatica Software Engineering Journal, 14, 77-95. &gt;https://doi.org/10.37190/e-Inf200103
    </mixed-citation>
   </ref>
   <ref id="scirp.132826-ref27">
    <label>27</label>
    <mixed-citation publication-type="other" xlink:type="simple">
     Wilkinson, K., Seo, K., Pierce, R., Tonellato, P., Kim, J.H. and Myers, D. (2021) Electronic Medical Record Specialty Group Comparison by Multinomial Logistic Regression. 2021 IEEE 9th International Conference on Healthcare Informatics (ICHI), Victoria, 9-12 August 2021, 415-421. &gt;https://doi.org/10.1109/ICHI52183.2021.00067
    </mixed-citation>
   </ref>
   <ref id="scirp.132826-ref28">
    <label>28</label>
    <mixed-citation publication-type="other" xlink:type="simple">
     Liu, V., Caelli, W., Yang, Y. and May, L. (2011) A Test Vehicle for Compliance with Resilience Requirements in Index-Based E-Health Systems. Pacific Asia Conference on Information Systems, PACIS 2011: Quality Research in Pacific Asia, Brisbane, 7-11 July 2011, 13.
    </mixed-citation>
   </ref>
   <ref id="scirp.132826-ref29">
    <label>29</label>
    <mixed-citation publication-type="other" xlink:type="simple">
     Patel, A. (2011) Baseline Security Controls for HIA-Compliant EMR Systems Using a Tailored NIST RMF Approach. &gt;https://doi.org/10.7939/r3-zas1-ej88
    </mixed-citation>
   </ref>
   <ref id="scirp.132826-ref30">
    <label>30</label>
    <mixed-citation publication-type="other" xlink:type="simple">
     Carello, M.P., Spaccamela, A.M., Querzoni, L. and Angelini, M. (2023) A Systematization of Cybersecurity Regulations, Standards and Guidelines for the Healthcare Sector. arXiv: 2304.14955.
    </mixed-citation>
   </ref>
   <ref id="scirp.132826-ref31">
    <label>31</label>
    <mixed-citation publication-type="other" xlink:type="simple">
     Choi, A., Chung, K., Chung, S.P., Lee, K., Hyun, H. and Kim, J.H. (2022) Advantage of Vital Sign Monitoring Using a Wireless Wearable Device for Predicting Septic Shock in Febrile Patients in the Emergency Department: A Machine Learning-Based Analysis. Sensors, 22, Article 7054. &gt;https://doi.org/10.3390/s22187054
    </mixed-citation>
   </ref>
   <ref id="scirp.132826-ref32">
    <label>32</label>
    <mixed-citation publication-type="other" xlink:type="simple">
     Kim, J. and Chang, H. (2020) A Study on Security Evaluation Model of Small and Medium-Size Healthcare Institutions. ICIC Express Letters, Part B: Applications, 11, 705-712.
    </mixed-citation>
   </ref>
   <ref id="scirp.132826-ref33">
    <label>33</label>
    <mixed-citation publication-type="other" xlink:type="simple">
     Khan, S., Gani, A., Wahab, A.W.A., Bagiwa, M.A., Shiraz, M., Khan, S.U., Buyya, R. and Zomaya, A.Y. (2016) Cloud Log Forensics: Foundations, State of the Art, and Future Directions. ACM Computing Surveys, 49, 1-42. &gt;https://doi.org/10.1145/2906149
    </mixed-citation>
   </ref>
   <ref id="scirp.132826-ref34">
    <label>34</label>
    <mixed-citation publication-type="other" xlink:type="simple">
     Gardazi, S.U. and Shahid, A.A. (2017) Compliance-Driven Architecture for Healthcare Industry. International Journal of Advanced Computer Science and Applications, 8, 568-577. &gt;https://doi.org/10.14569/IJACSA.2017.080571
    </mixed-citation>
   </ref>
   <ref id="scirp.132826-ref35">
    <label>35</label>
    <mixed-citation publication-type="other" xlink:type="simple">
     Ngamboé, M., Berthier, P., Ammari, N., Dyrda, K. and Fernandez, J.M. (2021) Risk Assessment of Cyber-Attacks on Telemetry-Enabled Cardiac Implantable Electronic Devices (CIED). International Journal of Information Security, 20, 621-645. &gt;https://doi.org/10.1007/s10207-020-00522-7
    </mixed-citation>
   </ref>
   <ref id="scirp.132826-ref36">
    <label>36</label>
    <mixed-citation publication-type="other" xlink:type="simple">
     Spears, J.L. (2018) Gaining Real-World Experience in Information Security: A Roadmap for a Service-Learning Course. Journal of Information Systems Education, 29, 183-202.
    </mixed-citation>
   </ref>
   <ref id="scirp.132826-ref37">
    <label>37</label>
    <mixed-citation publication-type="other" xlink:type="simple">
     Lebek, B., Uffen, J., Breitner, M.H., Neumann, M. and Hohler, B. (2013) Employees’ Information Security Awareness and Behavior: A Literature Review. 2013 46th Hawaii International Conference on System Sciences, Wailea, 7-10 January 2013, 2978-2987. &gt;https://doi.org/10.1109/HICSS.2013.192
    </mixed-citation>
   </ref>
  </ref-list>
 </back>
</article>