IT risk management for medical devices in hospital IT networks: a catalogue of measures and indicators

被引:3
作者
Richter, Stefan [1 ]
Ammenwerth, Elske [1 ]
机构
[1] UMIT TIROL Private Univ Hlth Sci & Hlth Technol, Inst Med Informat, Hall In Tirol, Austria
关键词
Medical Informatics; BMJ Health Informatics; Health Information Management; PATIENT SAFETY; HEALTH-CARE; CYBERSECURITY;
D O I
10.1136/bmjhci-2022-100639
中图分类号
R19 [保健组织与事业(卫生事业管理)];
学科分类号
摘要
ObjectivesConnecting medical devices to hospital IT networks can create threats that must be covered by IT risk management. In practice, implementing such risk management is not trivial because the IEC 80001-1, as the existing state-of-the-art, do not describe sufficiently concrete implementation measures or evaluation indicators. The aim of the present work was to develop and evaluate a catalogue of measures and indicators to help hospitals implement and evaluate risk management in accordance with IEC 80001-1.MethodsWe conducted a Delphi study with 22 experts. In the first round, we performed interviews to identify implementation measures and evaluation indicators using qualitative content analysis. In the second round, a quantitative experts' survey confirmed the results of the first survey round and identified relationships between the measures and indicators. Based on these results, we then developed a catalogue containing the identified measures and indicators. Finally, we performed a case study to verify the practicability of this catalogue.ResultsWe developed and verified a catalogue of 49 measures and 18 indicators to help hospitals implement and evaluate risk management following IEC 80001-1. The case study confirmed the practicability of the catalogue.DiscussionCompared with IEC 80001-1, our catalogue goes into further detail to offer hospitals a stepwise implementation and evaluation approach. However, the catalogue must be tested in further case studies and evaluated in terms of generalisation.ConclusionsThe catalogue will enable hospitals to overcome recent difficulties in implementing and evaluating IT risk management for medical devices according to IEC 80001-1.
引用
收藏
页数:9
相关论文
共 50 条
[21]   A Method of Assessing Data Quality in Publicly Available Cybersecurity Data Sources for Use in Medical Device Cybersecurity Risk Management [J].
Curran, Barry ;
Egan, James .
2023 CYBER RESEARCH CONFERENCE-IRELAND, CYBER-RCI 2023, 2023,
[22]   Internet of Medical Things Security Frameworks for Risk Assessment and Management: A Scoping Review [J].
Svandova, Katerina ;
Smutny, Zdenek .
JOURNAL OF MULTIDISCIPLINARY HEALTHCARE, 2024, 17 :2281-2301
[23]   The institutional work of hospital risk managers: democratizing and professionalizing risk management [J].
Labelle, Veronique ;
Rouleau, Linda .
JOURNAL OF RISK RESEARCH, 2017, 20 (08) :1053-1075
[24]   A forensics-by-design management framework for medical devices based on blockchain [J].
Malamas, Vaggelis ;
Dasaklis, Thomas K. ;
Kotzanikolaou, Panayiotis ;
Burmester, Mike ;
Katsikas, Sokratis .
2019 IEEE WORLD CONGRESS ON SERVICES (IEEE SERVICES 2019), 2019, :35-40
[25]   Improving risk management in the distribution of hospital diets by oral [J].
Lobato, Talita Ariane Amaro ;
da Silva, Thiago Oliveira ;
Correa, Laurena Santos Von-Grapp ;
Ainett, Waleria do Socorro de Oliveira ;
da Roza, Aghata Konrad .
NUTRICION CLINICA Y DIETETICA HOSPITALARIA, 2019, 39 (01) :141-145
[26]   Development of an effective risk management system in a teaching hospital [J].
Adibi H. ;
Khalesi N. ;
Ravaghi H. ;
Jafari M. ;
Jeddian A.R. .
Journal of Diabetes & Metabolic Disorders, 11 (1) :1-7
[27]   Consistency of performance indicators for cardiovascular risk management across procedures and panels [J].
van Lieshout, Jan ;
Nouwens, Elvira ;
Bouma, Margriet ;
Spreeuwenberg, Cor ;
Wensing, Michel .
QUALITY & SAFETY IN HEALTH CARE, 2010, 19 (05)
[28]   Customer experience management in medical tourism (case study: Iranian hospital's medical tourists) [J].
Dabaghi, Hamed ;
Tabataba'i-Nasab, Seyed Mohammad ;
Ardakani, Saeid Saieda .
JOURNAL OF ISLAMIC MARKETING, 2022, 13 (01) :198-226
[29]   Impact of Present-on-admission Indicators on Risk-adjusted Hospital Mortality Measurement [J].
Dalton, Jarrod E. ;
Glance, Laurent G. ;
Mascha, Edward J. ;
Ehrlinger, John ;
Chamoun, Nassib ;
Sessler, Daniel I. .
ANESTHESIOLOGY, 2013, 118 (06) :1298-1306
[30]   A Novel EMR Integrity Management Based on a Medical Blockchain Platform in Hospital [J].
Hang, Lei ;
Choi, Eunchang ;
Kim, Do-Hyeun .
ELECTRONICS, 2019, 8 (04)