📖 ABSTRACT/OVERVIEW
Private health insurance companies in Nigeria process sensitive policyholder data including medical histories, financial records, and identity information, making robust network security management a critical operational and regulatory obligation. This study surveys network security management practices among private health insurance firms operating in Abuja, FCT, where a concentration of NHIA-accredited insurers is located. Structured questionnaires were administered to IT security managers and compliance officers at 12 health insurance companies, assessing network perimeter defences, access control policies, incident response procedures, employee security training, and compliance with the National Health Insurance Authority Act 2022 and the Nigeria Data Protection Act 2023. Findings indicate that all 12 companies deploy firewalls and antivirus solutions, but only five have implemented intrusion detection systems and only four conduct regular penetration testing. Incident response plans exist in eight companies, but tabletop exercises to test these plans are conducted in only three. Data encryption for policyholder records at rest was confirmed in seven companies. The study proposes a Network Security Management Maturity Framework calibrated to the Nigerian health insurance context. Key recommendations include mandatory annual security audits, implementation of security information and event management systems, and increased regulatory scrutiny of network security standards by the National Health Insurance Authority. Keywords: network security, health insurance, Abuja, data protection, cybersecurity compliance.
Need Complete Chapters of the Above Topic?
Get high-quality, Zero-AI research materials with current citations.
Request via WhatsApp 💬