IMT4016
IMT4016
SeHealth Security and Privacy
Did we learn from the past cyber security incidents in the healthcare domain? Do we understand the status and the current challenges that healthcare institutions and systems have? Are we ready for future threats and risks?
Cyber incidents in healthcare have increased in numbers and severity, causing adverse effects on the society and citizens. Such attacks can affect the confidentiality, integrity, and availability of sensitive and important healthcare assets, like the patient journal. Consequently, this affects the lives of patients and disrupts the functioning of healthcare institutions, a critical system of the society.
Relevant competency
This is an inter-disciplinary theme where the teams of students will have to understand and analyse problems and challenges from various points of view, including, but not restricted to, the following: information security, privacy, health care, computer science, design, engineering, sociology, psychology, law, and business. The nature of security and privacy is making these relevant to various backgrounds and positions in an organization. For example, a law background could be used to understand relevant legislation (e.g. of key terminology: GDPR or AI Act); a sociology background could be used to investigate how security is adopted by human users (e.g. of key terminology: usable security); a psychologist could try to get into the mind of the attacker (e.g. of key terminology: attacker profiles); business manager can investigate the economical trade-offs of security and privacy (e.g. of key terminology: risk management or cost-benefit analysis); engineers would try to think not only about safety, but also about security, if what they build includes something digital; etc.
About the village
In this village, the students are challenged to
- Explore the previous threats and risks that targeted the healthcare infrastructure in Norway in the last decade,
- Understand the advances and changes that the healthcare system in Norway undergoes and the security challenges that those changes cause and lead to, and finally
- Analyze and predict possible future risk and threats on the healthcare domain. The analysis could include, beside the technical aspect, other human, organizational, legal, and medical aspects.
As a result, the teams can develop scenarios, stories, systems, or any other products in general, of how operations and security of the healthcare actors can be affected, attacked, defended, etc.
Examples of cyber-attacks and incidents include the following links to media:
- Sykehus betaler 435 tusen under ransomware-angrep
- Datasystemene til Helse Sør-Øst angrepet
- PST: Vil ta flere måneder å få svar om helse-hacking
- NHO advarer norske pasienter - frykter nye IT-skandaler ved sykehusene
- Helse Sør-Øst stanset lønnsutbetaling for å hindre svindel
- Aker sykehus lammet av virus-angrep
At the same time, the healthcare domain undergoes digitalization at various levels. For example, the introduction of the 5G networks (https://www.telenor.no/om/teknologi-norge/dette-er-5g.jsp ) is meant to increase the efficiency and performance of the healthcare infrastructure. Regarding regulations and privacy, we noticed the introduction of the European GDPR (General Data Protection Regulation) regulation on privacy in 2016 and the adaptation of the Privacy by Design principles (https://www.datatilsynet.no/rettigheter-og-plikter/virksomhetenes-plikter/innebygd-personvern/programvareutvikling-med-innebygd-personvern/ ) in building privacy preserving eHealth applications. The IoT technologies bring health care into the homes with a wide range of sensors and application to make it possible to follow up the treatment of patients at home. You probably know or can imagine many other examples of changes in other eHealth areas, like to hospital buildings to make them “smart building”, medical devices to make them autonomous, treatment procedure to make them self/comunity-care, and others.
External partners
The student teams are not forced to work together with an external partner, but are encouraged to, if the topic/idea they define and their background networks allow for that (and it has happened). The teacher brings into the course the Norwegian Cyber Range as a partner where the teams can implement their ideas. It is common for health institution and health professionals to come into the Cyber Range to train on handling cyber incidents.
Facts
Course code: IMT4016
Village title: eHealth Security and Privacy
Type: Semester-based, virtual
Language: English
Assessment: Process report and project report
Village supervisor: Christian Johansen
Contact information: Christian.johansen@ntnu.no
Semester: Spring 2027
Location: Online
Host faculty: IE
Virtual Experts in teamwork (VEiT)
This village is virtual and students from all campuses meet here. All teaching and group work takes place using online collaboration tools. Students in virtual villages must take part both with their camera switched on and with a microphone available.
Attendance:
- Semester-based flexible village: Teaching and group meetings take place between 9.00-12.00 every Wednesday. In addition, each group has a 2–4-hour meeting during the week. Each group, after consultation with the teaching staff, decides the time for the group meeting (could be other days than Wednesday, also evenings). Individual work is also expected.