Enhancing Data Resilience in Cloud-based Electronics Health Records through Ransomware Mitigation Strategies Using NIST and MITRE ATT&CK Frameworks
Seun Michael Oyekunle, Olufisayo Juliana Tiwo, Temilade Oluwatoyin Adesokan-Imran, Adekunbi Justina Ajayi, Ademola Oluwaseun Salako, Oluwaseun Oladeji Olaniyi
Journal of Engineering Research and Reports · pp. 436–457 · Published 15 Mar 2025
10.9734/jerr/2025/v27i31444Abstract
The increasing adoption of cloud-based Electronic Health Records (EHRs) has transformed healthcare by enhancing data accessibility, interoperability, and patient care efficiency. However, this transition has also introduced new cybersecurity vulnerabilities, with ransomware emerging as a critical threat to healthcare systems. Ransomware attacks disrupt medical services, compromise patient confidentiality, and impose significant financial burdens on institutions. This study comprehensively examines ransomware threats in cloud-based EHR environments by analyzing vulnerabilities, attack vectors, and mitigation strategies through the NIST Cybersecurity Framework and MITRE ATT&CK Framework. A quantitative analysis was conducted using datasets from the U.S. Department of Health and Human Services (HHS), the Cybersecurity & Infrastructure Security Agency (CISA), and the MITRE ATT&CK database. Key findings indicate a 67% increase in ransomware incidents from 2018 to 2023, with credential theft (33.3%) and phishing (26.7%) as the most exploited attack vectors. Recovery challenges were exacerbated by backup failures (hazard ratio = 0.000, p = 0.127) and third-party risks (hazard ratio = 0.000, p = 0.030). To mitigate these risks, the study advocates for a multi-layered cybersecurity approach, emphasizing Zero Trust Architecture, AI-driven threat detection, immutable backups, and vendor risk management. The findings underscore the need for collaboration among healthcare institutions, cybersecurity professionals, and policymakers to strengthen resilience against evolving ransomware threats. By integrating structured cybersecurity frameworks and proactive defense mechanisms, healthcare organizations can enhance data security, ensure compliance, and minimize operational disruptions.
Cited by 3
Xu Feng · Proceedings of the 2025 3rd International Conference on Artificial Intelligence, Systems and Network Security · 2025
Showing 1 of 3 known citations — external sources report more than can currently be individually listed.
Related research
- Artificial Intelligence and Global Security: Strengthening International Cooperation and Diplomatic Relations — shares topic coverage
- The Impact of Artificial Intelligence on Cyber Security in Digital Currency Transactions — shares topic coverage
- Securing AI-Powered Healthcare Decision Support Systems: A Comprehensive Review of Attack Vectors and Defensive Strategies — shares topic coverage
- Systematic Review of 6G-IoT Privacy Risks, Emerging Threats, Mitigation Strategies, and Cybersecurity — shares topic coverage
- Policy Framework for Responsible AI Deployment in the National Cybersecurity Strategy — shares topic coverage
Article metrics
Real usage data collected on this platform.
0
Page views
0
PDF downloads
0
Outbound clicks
3
Citations
Views by country
Approximate, from request IP at view time — not citizenship or institution. Countries with fewer than 5 views are grouped as "Other".
No views recorded yet.
Traffic sources
Referring site, by host.
No traffic recorded yet.
Views and downloads exclude known bots/crawlers. Citations combines this platform's own DOI-resolved index with each external source's own reported total — see Cited by above for individually listed citing works. Last refreshed 0 seconds ago.