Sarcouncil Journal of Engineering and Computer Sciences
Sarcouncil Journal of Engineering and Computer Sciences
An Open access peer reviewed international Journal
Publication Frequency- Monthly
Publisher Name-SARC Publisher
ISSN Online- 2945-3585
Country of origin-PHILIPPINES
Impact Factor- 3.7
Language- English
Keywords
- Engineering and Technologies like- Civil Engineering, Construction Engineering, Structural Engineering, Electrical Engineering, Mechanical Engineering, Computer Engineering, Software Engineering, Electromechanical Engineering, Telecommunication Engineering, Communication Engineering, Chemical Engineering
Editors

Dr Hazim Abdul-Rahman
Associate Editor
Sarcouncil Journal of Applied Sciences

Entessar Al Jbawi
Associate Editor
Sarcouncil Journal of Multidisciplinary

Rishabh Rajesh Shanbhag
Associate Editor
Sarcouncil Journal of Engineering and Computer Sciences

Dr Md. Rezowan ur Rahman
Associate Editor
Sarcouncil Journal of Biomedical Sciences

Dr Ifeoma Christy
Associate Editor
Sarcouncil Journal of Entrepreneurship And Business Management
Designing Compliance-Driven Cybersecurity Governance Models for Hipaa-Regulated Healthcare Systems
Keywords: Healthcare cybersecurity, Ransomware risk, Data breaches, Information security governance, Regulatory enforcement.
Abstract: Healthcare organizations continue to experience escalating ransomware attacks, third-party breaches, and operational disruptions despite widespread compliance with the Health Insurance Portability and Accountability Act (HIPAA). This pattern suggests that regulatory adherence alone does not ensure effective cybersecurity risk reduction. This study argues that the persistent gap between formal HIPAA compliance and real-world security outcomes is fundamentally a governance failure rather than a regulatory deficiency. Drawing on breach trend data from the HHS Office for Civil Rights, the Verizon Data Breach Investigations Report, and ransomware impact studies published in JAMA Health Forum, this paper demonstrates that weak executive oversight, diffuse risk ownership, inadequate third-party governance, and slow escalation processes contribute materially to breach severity and operational disruption. In response, the paper proposes a compliance-driven cybersecurity governance model that operationalizes HIPAA safeguards through structured accountability, defined decision authority, continuous oversight, and measurable governance performance indicators. The model integrates board-level risk oversight, executive risk ownership, compliance–security alignment, and operational enforcement into a unified governance system designed for vendor-dependent, clinically sensitive healthcare environments. An evaluation framework is introduced to assess governance effectiveness using behavioral metrics such as risk ownership completeness, escalation timeliness, vendor monitoring coverage, and incident containment performance rather than audit artifact completion. By reframing HIPAA compliance as an enforceable governance system rather than a documentation exercise, this study contributes a structured model for strengthening healthcare cybersecurity resilience and establishes a foundation for future empirical validation of governance-driven risk reduction.
Author
- Nicholas Addotey
- Montana State University