Back to results

Virginia Tech

Essays on Human Error in Electronic Health Records (EHR) Information Security

Abstract

dc:description.abstract

This dissertation presents a management framework designed to mitigate human error in information security, aiming to enhance the resilience of EHR systems to make them less attractive to cybercriminals. The framework enhances Reason's Resiliency Model by incorporating a socially oriented management approach based on socio-technical systems (STS) principles. The information security literature presents evidence that human error is a significant contributor to cybersecurity incidents. Human error has increased the vulnerability of healthcare information, exposing it to persistent and increasingly sophisticated malicious cyberattacks that threaten the security and privacy of the American people. People continue to make mistakes and there is no single solution in cybersecurity that can reliably protect the system from vulnerabilities created by human-technology interface errors. This dissertation focuses on the impact of error, as a consequence of the human-technology interface, in the information security of the healthcare sector. The research investigates: the role of STS factors for developing solutions aiming to enhance the resilience of EHR systems; how the location where data are breached influence the severity of data breaches impacting the security and privacy of patient records; how unintended consequences from EHR adoption impact the productivity performance of the states healthcare systems (DMUs); and, how the Health Insurance Portability and Accountability Act (HIPAA) monetary penalties influence compromised patient records. This dissertation concludes that addressing EHR information security threats requires a fundamental shift in the healthcare sector's approach to data security. The research determines that integrating STS factors with Reason's layered approach offers a comprehensive management framework for mitigating human error challenges in healthcare information security. The findings show that network servers and emails are the two most common sites where healthcare data are breached capturing 95% of the 713 million compromised patient records since 2009. Empirical analysis indicates that despite privacy concerns resulting from data breaches, the overall productivity performance of the DMUs has improved over time. However, cybersecurity challenges continue to have an impact on the DMUs productivity performance. The findings also demonstrate that monetary penalties from HIPAA violations have not been effective in slowing down the number of compromised patient records in the sector.

Degree

thesis:*
Name thesis:degree_name
Doctor of Philosophy
Level thesis:degree_level
doctoral
Discipline thesis:degree_discipline
Industrial and Systems Engineering
Department dc:contributor.department
Industrial and Systems Engineering
Grantor dc:publisher
Virginia Tech
Year dc:date.issued
2025

Author and committee

dc:creator, dc:contributor.*
Author dc:creator
  • Alvarado, Wilmer
Chair dc:contributor.committeechair
  • Triantis, Konstantinos P.
Committee members dc:contributor.committeemember
  • Ghaffarzadegan, Navid
  • Pettis, Roy Carson
  • Hosseinichimeh, Niyousha

Subjects

dc:subject × 6

Rights

dc:rights
Statement dc:rights
  • In Copyright
Language dc:language.iso
en

Identifiers

dc:identifier.*
Dc Identifier Other
vt_gsexam:43625
OAI identifier oai:identifier
oai:vtechworks.lib.vt.edu:10919/134222

Chain of custody

source
Harvested from
Virginia Tech
Base URL
vtechworks.lib.vt.edu/oai/request
Last updated
2026-07-22
Source record
OAI-PMH GetRecord
citation

Alvarado, Wilmer. Essays on Human Error in Electronic Health Records (EHR) Information Security. doctoral thesis, Virginia Tech, 2025. https://hdl.handle.net/10919/134222