A Study on the Response to Security Threats through Structural Analysis of Hospital Information Systems and Damage Prevention by Applying Cyber CPTED
Abstract
This study aims to propose a multi-layered, proactive damage prevention model by conducting an in-depth structural analysis of Hospital Information Systems (HIS), which have grown in complexity and interconnectivity due to accelerated digital transformation, and by systematically applying the principles of 'Cyber CPTED' (Crime Prevention Through Environmental Design). Although medical data containing patient history and unique identifiers possesses the highest level of sensitivity and requires uninterrupted availability in clinical settings, conventional boundary-centric security measures have failed to address the fundamental flaws within the architecture itself, leaving systems vulnerable to insider threats and sophisticated bypass attacks. Consequently, this research deconstructs the medical information system into four structural layers—infrastructure, data, application, and presentation—to identify inherent vulnerabilities such as flat network structures, plaintext data storage, insufficient secure coding, and non-intuitive user interfaces. To remedy these identified flaws, the core principles of Cyber CPTED established by Lee and Moon (2017)—namely, territorial reinforcement, natural access control, and natural surveillance—were organically mapped onto each technical layer. This resulted in a comprehensive preventive roadmap based on environmental design, encompassing logical network isolation through micro-segmentation, the establishment of multi-factor authentication (MFA) pathways under a zero-trust framework, and the implementation of immutable audit logs alongside highly visible UI/UX designs to maximize psychological deterrence. This study holds significant theoretical and practical value as it shifts the paradigm of healthcare security from reactive defense to proactive environmental construction, while providing a structural framework that medical institutions can practically implement to safeguard both patient lives and data.