Mapping Global Cybersecurity Policies in Healthcare in WHO Member States and their alignment to the WHO Digital Strategy, the National Institute of Standards and Technology and the WHO Health Systems Frameworks.
More details
Hide details
1
Health Policy and Research, South African Medical Association, Pretoria, South Africa
Popul. Med. 2026;8(Supplement Supplement 1):A922
ABSTRACT
INTRODUCTION:
Evidence-based decision-making is imperative for health system planning, a process largely informed by health information. The global movement towards Universal Health Coverage (UHC) relies heavily on robust information systems and effective data management. However, the healthcare industry’s reliance on these digital assets has positioned it as one of the largest targets of cyber-attacks, threatening patient data integrity and continuity of care.
OBJECTIVES:
This study aimed to systematically describe the landscape of existing cybersecurity policies within the health sectors of WHO Member States. The core objective was to identify similarities, critical differences, and fundamental gaps in data protection strategies and cybersecurity governance to support the implementation of UHC worldwide.
METHODS:
A scoping review was conducted to map the extent and nature of cybersecurity in health policies. The review involved a comprehensive search across governmental and intergovernmental websites, academic databases (including PubMed, Scopus, Web of Science, and CINAHL), and grey literature published between 2013 and 2023. Policy documents were subjected to thematic content analysis and mapped against the WHO Digital Strategy, the NIST Framework, and the WHO Health Systems Frameworks.
RESULTS:
The findings indicated that only 31 (16%) of 194 WHO Member States possess dedicated national cybersecurity policies specific to the health sector. Existing policies predominantly emphasise administrative controls but show significant deficiencies in technical and physical controls. Furthermore, alignment with the NIST framework was weak, and integration across the six WHO Health Systems Framework building blocks was inconsistent, neglecting workforce training and financing.
CONCLUSIONS:
The widespread absence of dedicated cybersecurity in health policies among WHO Member States constitutes a major risk to global UHC and digital health transformation. This review highlights the urgent necessity for a harmonised, globally applicable framework to guide countries in developing robust, integrated cybersecurity policies, thereby safeguarding health information systems and enabling digital health implementation worldwide.