58
Copyright © 2018, IGI Global. Copying or distributing in print or electronic forms without written permission of IGI Global is prohibited.
Chapter 4
DOI: 10.4018/978-1-5225-5460-8.ch004
ABSTRACT
The healthcare industry has been lagging behind other industries in protecting its vital data. Over the
past few years, researchers and practitioners have been trying to gain a better understanding of the
anatomy of healthcare data breaches. In this chapter, the authors show how Reason’s swiss cheese
model (SCM) provides a powerful analytic model to explain the human, technical, and organizational
factors of healthcare data breaches. They also show how the SCM brings forwards the latent condi-
tions of healthcare data breach incidents that have often been overlooked in previous studies. Based on
an extensive literature review and an analysis of reported breaches from credible sources, the authors
provide an explanation of the cheese layers and the associated holes. Since the SCM endorses the “de-
fenses in depth” approach, it can assist healthcare organizations and business associates in developing
a comprehensive and systematic approach to prevent and mitigate data breach incidents.
INTRODUCTION
Personal health records (PHR) and electronic medical records play an important role in managing health
information and enhancing the quality of patients’ healthcare through enhanced collection, compilation,
storage, tracking and dissemination of health records and medical history among healthcare provid-
ers (Kierkegaard, 2012). Health information is considered among the most confidential of all types of
personal information (Fernández-Alemán et al, 2013).The health sector is characterized by a wealth of
A New Perspective on the
Swiss Cheese Model Applied
to Understanding the Anatomy
of Healthcare Data Breaches
Faouzi Kamoun
ESPRIT School of Engineering, Tunisia
Mathew Nicho
Zayed University, UAE