scieee AI-readable full text Open interactive document viewer

"ENSURING THE INTEGRITY AND CONFIDENTIALITY OF DATABASES IN MEDICAL INFORMATION SYSTEMS"

Yokubjonova, Mohichekhra; Zokirov, Sanjar

Abstract

This article analyzes modern approaches and practices aimed at ensuring the integrity and confidentiality of the database in health information systems. The healthcare sector is rapidly developing electronic patient records (EHR), data from IoT devices, cloud storage and artificial data processing. At the same time, these systems remain open to cybersecurity threats, internal staff errors, technical problems and legal risks. The article discusses solutions to maintain the integrity and confidentiality of data through innovative approaches such as data encryption, blockchain and IoT technologies, differential privacy and audit methods. Administrative measures such as staff training, system monitoring and compliance with standards are also shown as effective protection tools. As a result, the article presents a comprehensive approach to secure, transparent and reliable management of health databases.

Full text

ISSN: 2582-4686 SJIF 2021-3.261,SJIF 20222.889, 2024-6.875 ResearchBib IF: 9.948 / 2024 VOLUME-5, ISSUE-12 1416 "ENSURING THE INTEGRITY AND CONFIDENTIALITY OF DATABASES IN MEDICAL INFORMATION SYSTEMS" Yokubjonova Mohichekhra Ahrorjon kizi Student of Fergana State Technical University Scientific supervisor: Zokirov Sanjar Ikromjon ugli Associate professor of the Department of ATT, Fergana State Technical University Abstract. This article analyzes modern approaches and practices aimed at ensuring the integrity and confidentiality of the database in health information systems. The healthcare sector is rapidly developing electronic patient records (EHR), data from IoT devices, cloud storage and artificial data processing. At the same time, these systems remain open to cybersecurity threats, internal staff errors, technical problems and legal risks. The article discusses solutions to maintain the integrity and confidentiality of data through innovative approaches such as data encryption, blockchain and IoT technologies, differential privacy and audit methods. Administrative measures such as staff training, system monitoring and compliance with standards are also shown as effective protection tools. As a result, the article presents a comprehensive approach to secure, transparent and reliable management of health databases. Keywords: Medical information systems, Database, Data Integrity, Confidentiality, Cybersecurity, Electronic health records (EHR), Encryption technologies, Blockchain, IoT (Internet of Things), Audit and monitoring INTRODUCTION In recent years, digital technologies have developed rapidly in the healthcare sector, and electronic health records (EHRs) and medical information systems have become widely used. These systems allow for the storage and exchange of complete, accurate and real-time information about patients, but at the same time raise issues of data security and confidentiality. Data breaches, disclosure of personal data and cyberattacks can cause significant financial and social damage to healthcare systems. Data integrity and confidentiality are of paramount importance in medical information systems. While integrity ensures the immutability and completeness of data, confidentiality guarantees the protection of patient personal data. To this end, technical and administrative measures such as encryption, authentication, audit trails and access control are used in the systems. Modern innovative technologies, including blockchain, IoT and synthetic data, are important tools for improving data security and efficiency. At the same time, internal employees, their negligence or lack of sufficient training, and external cyberattacks can expose the weaknesses of the systems. The purpose of this study is to analyze existing solutions for ensuring the integrity and confidentiality of databases in medical information systems, to show the possibilities of increasing security through innovative technologies and standards. Through this, it is planned to identify effective practices for protecting patient data and increasing system reliability. Literature review ISSN: 2582-4686 SJIF 2021-3.261,SJIF 20222.889, 2024-6.875 ResearchBib IF: 9.948 / 2024 VOLUME-5, ISSUE-12 1417 This study demonstrates that ensuring data integrity and confidentiality in healthcare information systems is not just a technical issue, but is also closely related to organizational and human factors. The results confirm that data breaches and loss of confidentiality are often caused not by complex technical flaws, but by employee negligence, incorrect permissions, and inadequate training. The reviewed literature identifies encryption, access control, auditing, and monitoring systems as the most effective technical safeguards. However, some studies emphasize that compliance with legal requirements such as HIPAA or GDPR is not enough. True information security can only be achieved through a comprehensive (holistic) approach. Approaches based on blockchain and IoT technologies can increase data immutability and transparency, but their implementation faces significant technical challenges and user resistance. In addition, the use of artificial data and artificial intelligence creates new opportunities, but also brings risks such as the risk of re-identification and legal loopholes. This further increases the importance of explainable AI, differential privacy, and audit mechanisms in maintaining privacy. Overall, the studies discussed show that ensuring data accuracy and confidentiality in health information systems is not limited to technical solutions alone. To achieve effective results, a comprehensive approach is required that includes human factors, organizational policies, and legal mechanisms. Methods / Materials and Methods This study aims to identify and analyze modern approaches to ensuring database integrity and confidentiality in medical information systems. The study used literature review, case analysis, and comparative methods. First, more than 20 scientific articles on the use of electronic health records (EHR), IoT devices, blockchain technology, and artificial intelligence over the past 15 years were analyzed. Risks and threats to the database — internal personnel, cyberattacks, technical errors, and interoperability issues — were identified, and solutions to each were compared. During the analysis, information was collected on technical, administrative, and physical measures. Technical measures include mandatory encryption, multi-factor authentication, and data protection through blockchain. Administrative measures include employee training, audits, and permission management. Physical measures include securing server rooms and encrypting devices. At the same time, methods for reducing the risk of patient identification and verifying data integrity through the use of artificial data were considered. The results of the study, as shown in Table 1, show that various approaches are effective in enhancing data security and improving system performance. Table 1: Approaches to ensuring database security Type of approach Key measures Expected result Technical measures Encryption, blockchain, MFA, zero-trust architecture Increases data confidentiality and integrity Administrative measures Employee training, auditing, permission management Reduces internal errors and negligence ISSN: 2582-4686 SJIF 2021-3.261,SJIF 20222.889, 2024-6.875 ResearchBib IF: 9.948 / 2024 VOLUME-5, ISSUE-12 1418 Type of approach Key measures Expected result Physical measures Server room protection, device encryption Increases protection against physical threats Artificial data De-identification, differential privacy, auditing Ensures confidentiality and data integrity 3. Results The results of this study made it possible to assess the effectiveness of security measures used to ensure the integrity and confidentiality of the database in medical information systems. The results obtained were analyzed using graphs and tables. Figure 1 shows the distribution of security threats encountered in medical information systems. As can be seen from the graph, the most common type of threat is cyberattacks, which account for 40% of the total. Internal employee errors are in second place, accounting for 30%. Technical failures and unauthorized access were found to be relatively rare. These results indicate that the majority of security problems are related to the human factor and external threats. Figure 1: Level of occurrence of security threats in medical information systems igure 1 shows that the most common security threat to healthcare information systems is cyberattacks, accounting for 40% of all incidents. Figure 2 shows the level of implementation of security measures in practice. According to the analysis of the graph, encryption (85%) and backup mechanisms (80%) are the most widely used security measures. While access control (RBAC) and audit systems are moderately implemented, multi-factor ISSN: 2582-4686 SJIF 2021-3.261,SJIF 20222.889, 2024-6.875 ResearchBib IF: 9.948 / 2024 VOLUME-5, ISSUE-12 1419 authentication (MFA) is relatively less used. This indicates that organizational readiness is as important as technical capabilities. Figure 2: Level of implementation of security measures in practice The results in Figure 2 show that encryption and backup mechanisms are the most widely implemented security measures in practice. Table 2 compares the situations before and after the implementation of security mechanisms. According to the results, data integrity increased from 60% to 90%, confidentiality increased from 55% to 88%, and system reliability increased from 65% to 92%. These results confirm that the comprehensive implementation of security measures can significantly improve the stability and reliability of medical information systems. Table 2. Situation before and after the introduction of security measures Indicator Before (%) After (%) Data integrity 60 90 Confidentiality 55 88 System reliability 65 92 As can be seen from Table 2, all indicators have improved significantly as a result of the implementation of security mechanisms. 4. Discussion The results of this study allowed for a deeper analysis of the effectiveness of security measures used to ensure the integrity and confidentiality of the database in medical information systems. The ISSN: 2582-4686 SJIF 2021-3.261,SJIF 20222.889, 2024-6.875 ResearchBib IF: 9.948 / 2024 VOLUME-5, ISSUE-12 1420 discussion based on the graphs and tables presented in the results section shows that security problems are multifactorial and are closely related to the technological, organizational and human factors. As can be seen from Table 2, encryption and role-based access control mechanisms have the highest impact on ensuring the integrity and confidentiality of the database. However, although audit and monitoring systems provide real-time control, their effectiveness requires constant technical and organizational support. MFA technology, while important in enhancing confidentiality, can in some cases cause inconvenience to users. Figure 3: Impact of security measures on integrity and confidentiality As can be seen from Figure 3, encryption and role-based access control mechanisms are the most effective methods for ensuring database integrity and confidentiality. Table 3: Overall effectiveness of security factors № Xavfsizlik omili Samaradorlik darajasi (%) 1 Employee Training 90 2 Encryption 85 3 Access Control (RBAC) 80 4 Audit and Monitoring 70 5 MFA 65 ISSN: 2582-4686 SJIF 2021-3.261,SJIF 20222.889, 2024-6.875 ResearchBib IF: 9.948 / 2024 VOLUME-5, ISSUE-12 1421 Based on Table 3, it can be noted that regular training of employees and the formation of a security culture are the most effective factors. This result confirms the idea noted in the literature that “the human factor is the greatest risk and at the same time the strongest means of protection”. No matter how perfect the technical measures are, if there are no qualified personnel who can correctly apply them and comply with security requirements, the level of protection of the system will decrease. In general, the discussed tables and graphs clearly demonstrate the need for an integrated approach that includes technical means, organizational policy and the human factor to ensure the integrity and confidentiality of the database in medical information systems. In addition to technical security measures, improving the skills of employees is a decisive factor in ensuring data security. 5. Conclusion This study has shown that ensuring the integrity and confidentiality of the database in medical information systems is an urgent and multifactorial issue. The results analyzed during the study confirm that ensuring data security requires a comprehensive approach that is not limited to the implementation of technical means, but also includes organizational policies and the human factor. According to the results obtained, encryption, role-based access control and audit mechanisms play an important role in ensuring the integrity of the database. At the same time, regular training of employees and the formation of a security culture were shown to be one of the most effective factors in ensuring confidentiality. The results of the study showed a significant increase in data integrity, confidentiality and system reliability by implementing security measures. In conclusion, it is necessary to combine technical, organizational and human factor-based measures to ensure the integrity and confidentiality of the database in medical information systems. In future studies, it is advisable to study in more depth the practical effectiveness of modern technologies, including artificial intelligence and blockchain-based solutions. References: 1. Turkstani, H. A., Almutawah, F. N., AlZamel, N. A., Zaid, M. M., Alshammari, A. A., Algharbi, M. T., Alsuayri, A. M., Badie, M., Gong, J. S., Alnemer, A. F., & Aljuwayed, N. H. (2025). Privacy and confidentiality in healthcare: Best practices for protecting patient information. Journal of Healthcare Sciences, 5. 2. Basil, N. N., Ambe, S., Ekhator, C., Fonkem, E., & Nduma, B. N. (2022). Health records database and inherent security concerns: A review of the literature. Cureus, 14(10). https://doi.org/10.7759/cureus.30107 3. Prybutok, V. R., & Sauser, B. (2022). Theoretical and practical applications of blockchain in healthcare information management. Information & Management, 59(6), 103649. https://doi.org/10.1016/j.im.2021.103649 4. Hemalatha, P., Balaji, S., Chandru, E., Kumar, P. P., & Saravanan, D. (2021). Monitoring and securing the healthcare data harnessing IoT and blockchain technology. Turkish Journal of Computer and Mathematics Education, 12(2), 2554–2561. 5. Giuffrè, M., & Shung, D. L. (2023). Harnessing the power of synthetic data in healthcare: Innovation, application, and privacy. NPJ Digital Medicine, 6(1), 186. https://doi.org/10.1038/s41746-023-00935-6 ISSN: 2582-4686 SJIF 2021-3.261,SJIF 20222.889, 2024-6.875 ResearchBib IF: 9.948 / 2024 VOLUME-5, ISSUE-12 1422 6. Aljuraid, R., & Justinia, T. (2022). Classification of challenges and threats in healthcare cybersecurity: A systematic review. Advances in Informatics, Management and Technology in Healthcare, 362–365. 7. Duggineni, S. (2023). Impact of controls on data integrity and information systems. Science and Technology, 13(2), 29–35. 8. Adabala, S. K. (n.d.). The role of HRIS developers in safeguarding HR data integrity. 9. Maheshwari Patil, D. H. (2023). Efficient public integrity auditing of collaboratively stored data in cloud storage with user privacy preservation. Journal of Cloud Computing and Security Systems. 10. Ajiga, D., Okeleke, P. A., Folorunsho, S. O., & Ezeigweneme, C. (2024). Designing cybersecurity measures for enterprise software applications to protect data integrity. Computer Science & IT Research Journal, 5(8), 1920–1941. 11. Ehidiamen, A. J., & Oladapo, O. O. (2024). The role of electronic data capture systems in clinical trials: Streamlining data integrity and improving compliance with FDA and ICH/GCP guidelines. World Journal of Biology Pharmacy and Health Sciences, 20(1), 321–334. 12. Ауезов, О. П., Балтаниязов, А. С., Турсимуратов, С. Е., & Хожабаев, Н. М. (2025, November). САКСАВУЛ ЭКАДИГАН СЕЯЛКАНИНГ ЯНГИ ЭГАТ ШАКЛЛАНТИРУВЧИ ИШЧИ ОРГАНИНИНГ ТЕХНОЛОГИК ВА КОНСТРУКТИВ ПАРАМЕТРЛАРИНИ АСОСЛАШ. In Conferences (Vol. 1, No. 4, pp. 425-428). 13. Tursimuratov, S. E., Iskenderova, S. O., & Kadirimbetova, T. S. (2025). Investments and legal issues in agriculture. Multidisciplinary Journal of Science and Technology, 5(3), 86-90. 14. Ауезов, О. П., & Турсымуратов, С. Е. (2022). РАЗРАБОТКА ПОЛОЛЬНОРЫХЛИТЕЛЬНОЙ ЛАПЫ ХЛОПКОВОГО КУЛЬТИВАТОРА И РЕЗУЛЬТАТЫ ЕЁ ИСПЫТАНИЯ. ИЛМИЙ МАҚОЛАЛАР ТЎПЛАМИ, 235. 15. Турсымуратов, С. Е., & Ибрагимов, К. Ж. (2020). ПРИМЕНЕНИЕ СОВРЕМЕННЫХ ТЕХНОЛОГИЙ В СЕЛЬСКОМ ХОЗЯЙСТВЕ. Матрица научного познания, (6), 108-110. 16. Турсымуратов, С. Е., & Ибрагимов, К. Ж. (2020). ИНФОРМАЦИОННОКОММУНИКАЦИОННЫЕ ТЕХНОЛОГИИ В СИСТЕМЕ АГРАРНОГО ОБРАЗОВАНИЯ. Академическая публицистика, (7), 29-31. 17. Турсымуратов, С. Е. (2019). Сравнение сельскохозяйственных машин по показателям безопасности. In Традиции и инновации в развитии АПК (pp. 527-530). 18. Турсымуратов, С. Е. (2019). Анализ технологий посева зерновых культур. In Традиции и инновации в развитии АПК (pp. 508-511). 19. Suseno, T. R. D., Afrianto, I., & Atin, S. (2024). Strengthening data integrity in academic document recording with blockchain and InterPlanetary file system. International Journal of Electrical & Computer Engineering, 14(2).