Team Lead, Information Security Specialists, Hitachi Cyber.
* Corresponding Author
Global Journal of Engineering and Technology Advances, 2026, 28(02), 136–148
Article DOI: 10.30574/gjeta.2026.28.2.0221
Received on 13 July 2026; revised on 19 August 2026; accepted on 21 August 2026
Ransomware poses a significant risk to healthcare information systems, as successful attacks can lead to operational disruptions, compromise patient information, and pose a threat to the organization's operations. This research suggests a risk-based approach to cybersecurity that can help reduce the exposure to ransomware in a hospital or any other healthcare setting. The framework includes asset identification, threat and vulnerability assessment, risk prioritisation, access control, network segmentation, continuous monitoring, incident response, backup protection, and recovery planning. An approach in design oriented research methodology is used, and analyzed based on documented ransomware incidents, as well as representative scenarios of the healthcare system. The framework is measured through various factors including residual risk reduction, detection capability, containment time, recovery time, backup restorability, control coverage and operational resilience. It is expected that prioritizing controls based on criticality of asset, and the likelihood of attack, will help enhance ransomware preparedness and minimize service disruption. The research offers a systematic and practical proposal on how to enhance the cybersecurity resilience of healthcare systems, as well as safeguarding continuity of patient care in general.
Ransomware Risk, Healthcare Security, Network Protection, Data Encryption, Access Management, Cyber Resilience
Preview Article PDF
Luqman Ali. SECURING HEALTHCARE INFORMATION SYSTEMS AGAINST RANSOMWARE: A RISK-BASED FRAMEWORK. Global Journal of Engineering and Technology Advances, 2026, 28(02), 136–148. Article DOI: https://doi.org/10.30574/gjeta.2026.28.2.0221.





