FRAMEWORK FOR EMERGING E-HEALTH SYSTEMS SURVIVABILITY THREATS IN KENYA: CASE OF MOI TEACHING AND REFERRAL HOSPITAL.
Abstract
The integration of e-health presents numerous medical advantages; however, the safeguarding of these
valuable data sources is inadequate. They remain vulnerable to significant threats and attacks.
Moreover, the sheer volume of medical data necessitates technological solutions, yet the failure of e
health systems to prioritize security survivability renders them more susceptible to compromise. The
phenomenon of remote work persists as a contemporary reality; malicious actors are probing e-health
vulnerabilities to execute attacks, largely due to insufficient information security personnel and
inadequate systems frameworks. The multitude of security concerns may lead the system to experience
further degradation, ultimately undermining its ability to reassure users regarding their mission
objectives. In spite of initiatives aimed at ensuring the resilience and security of Kenya's cyber space,
ongoing attacks continue to threaten the confidentiality, credibility, reliability, and availability of e
health services for both providers and users. The emergence of e-health platforms has concurrently
given rise to novel forms of crime, which are intricately linked to the advent of various modern
technologies. Consequently, it is imperative that we focus on the resilience of systems in the aftermath
of an attack, rather than solely concentrating on security measures. Crimes within systems are
proliferating globally, and a significant number of internet users have, at some juncture, succumbed to
various forms of criminal activity. Many individuals endure hardship in silence, particularly within
healthcare institutions, as they are apprehensive about potential repercussions from the public.
Furthermore, the risks associated with criminal activities targeting healthcare equipment and electronic
healthcare technology are widespread globally, presenting significant opportunities to enhance clinical
outcomes and revolutionize the provision of care. This study developed a framework for enhancing
system survivability in the context of combating information systems crime within the health sector in
Kenya. This research study aimed to delineate the principal threats and vulnerabilities to system
survivability, formulate a framework for survivability and security, and validate its applicability for
integration within the health sector in Kenya to facilitate autonomous systems. The study employed a
descriptive research design. The demographic under examination Composed of personnel from the
hospitals. The research concentrated on senior and mid-tier IT personnel, as well as heads of various
departments within the hospital. The hospital accommodates a total of 2,056 individuals. This research
employed a convenience sampling method. The study sample comprised 332 employees drawn from
various departments within the hospital, as determined by the Fischer formula. Primary data was
received through a structured a questionnaire. The findings were articulated through the utilization of
frequency tables and percentages. Correlation and simple regression analysis were employed to
elucidate the straightforward relationships between individual constructs and the dependent variable.
Structural Equation Modelling (SEM) was employed for the evaluation of the framework. The research
indicated that Management commitment exerted a moderate effect on System survivability (r = .338, p
= .000), while organizational factors demonstrated a robust impact on system security survivability (r
= .604, p = .000). Conversely, IT policies revealed a weaker influence on security and survivability (r
= .209, p = .028), whereas IT literacy showed a significant effect on security and survivability (r = .642,
p = .000). This research deepens understanding in the domain of information system survivability and
highlights areas where knowledge is lacking, paving the way for future investigations. The research
provides a deeper understanding of critical matters related to the resilience of health facilities. The
research further empowers public sector policymakers to critically reassess and evaluate current
security strategies, aiming to establish a robust IT-based security infrastructure for prospective
applications. The research suggests that it is necessary to observe the functioning of security and
survivability systems, alongside implementing ongoing awareness and training initiatives on security
for all personnel.
