IT risk management for medical devices in hospital IT networks: a catalogue of measures and indicators

被引:3
作者
Richter, Stefan [1 ]
Ammenwerth, Elske [1 ]
机构
[1] UMIT TIROL Private Univ Hlth Sci & Hlth Technol, Inst Med Informat, Hall In Tirol, Austria
关键词
Medical Informatics; BMJ Health Informatics; Health Information Management; PATIENT SAFETY; HEALTH-CARE; CYBERSECURITY;
D O I
10.1136/bmjhci-2022-100639
中图分类号
R19 [保健组织与事业(卫生事业管理)];
学科分类号
摘要
ObjectivesConnecting medical devices to hospital IT networks can create threats that must be covered by IT risk management. In practice, implementing such risk management is not trivial because the IEC 80001-1, as the existing state-of-the-art, do not describe sufficiently concrete implementation measures or evaluation indicators. The aim of the present work was to develop and evaluate a catalogue of measures and indicators to help hospitals implement and evaluate risk management in accordance with IEC 80001-1.MethodsWe conducted a Delphi study with 22 experts. In the first round, we performed interviews to identify implementation measures and evaluation indicators using qualitative content analysis. In the second round, a quantitative experts' survey confirmed the results of the first survey round and identified relationships between the measures and indicators. Based on these results, we then developed a catalogue containing the identified measures and indicators. Finally, we performed a case study to verify the practicability of this catalogue.ResultsWe developed and verified a catalogue of 49 measures and 18 indicators to help hospitals implement and evaluate risk management following IEC 80001-1. The case study confirmed the practicability of the catalogue.DiscussionCompared with IEC 80001-1, our catalogue goes into further detail to offer hospitals a stepwise implementation and evaluation approach. However, the catalogue must be tested in further case studies and evaluated in terms of generalisation.ConclusionsThe catalogue will enable hospitals to overcome recent difficulties in implementing and evaluating IT risk management for medical devices according to IEC 80001-1.
引用
收藏
页数:9
相关论文
共 50 条
[31]   KEY ASPECTS TO IMPLEMENT A MEDICAL DEVICES SURVEILLANCE PLAN IN HEALTH CARE INSTITUTIONS AND BRIEF OVERVIEW OF THIS PROCESS ENHANCEMENT THROUGH RISK MANAGEMENT [J].
Alvarez, Alessa I. ;
Roldan, Sebastian .
2013 PAN AMERICAN HEALTH CARE EXCHANGES (PAHCE), 2013,
[32]   Objective Measures of Adoption of Patient Lift and Transfer Devices to Reduce Nursing Staff Injuries in the Hospital Setting [J].
Schoenfisch, Ashley L. ;
Pompeii, Lisa A. ;
Myers, Douglas J. ;
James, Tamara ;
Yeung, Yeu-Li ;
Fricklas, Ethan ;
Pentico, Marissa ;
Lipscomb, Hester J. .
AMERICAN JOURNAL OF INDUSTRIAL MEDICINE, 2011, 54 (12) :935-945
[33]   Approval of High-Risk Medical Devices in the US: Implications for Clinical Cardiology [J].
Benjamin N. Rome ;
Daniel B. Kramer ;
Aaron S. Kesselheim .
Current Cardiology Reports, 2014, 16
[34]   Approval of High-Risk Medical Devices in the US: Implications for Clinical Cardiology [J].
Rome, Benjamin N. ;
Kramer, Daniel B. ;
Kesselheim, Aaron S. .
CURRENT CARDIOLOGY REPORTS, 2014, 16 (06)
[35]   EXPLORING MEDICAL DEVICES: THE USE OF RISK ASSESSMENT TOOLS AND THEIR LINK WITH TRAINING IN HOSPITALS [J].
Porte, Petra J. ;
Verweij, Lisanne M. ;
de Bruijne, Martine C. ;
van der Vleuten, Cees P. M. ;
Wagner, Cordula .
INTERNATIONAL JOURNAL OF TECHNOLOGY ASSESSMENT IN HEALTH CARE, 2018, 34 (02) :218-223
[36]   Choosing Protection: User Investments in Security Measures for Cyber Risk Management [J].
Ben Yaakov, Yoav ;
Wang, Xinrun ;
Meyer, Joachim ;
An, Bo .
DECISION AND GAME THEORY FOR SECURITY, 2019, 11836 :33-44
[37]   Implementation of a comprehensive clinical risk management system in a university hospital [J].
Buchberger, Wolfgang ;
Schmied, Marten ;
Schomaker, Michael ;
del Rio, Anca ;
Siebert, Uwe .
ZEITSCHRIFT FUR EVIDENZ FORTBILDUNG UND QUALITAET IM GESUNDHEITSWESEN, 2024, 328 :18-25
[38]   Care bundles: the holy grail of infectious risk management in hospital? [J].
Marwick, Charis ;
Davey, Peter .
CURRENT OPINION IN INFECTIOUS DISEASES, 2009, 22 (04) :364-369
[39]   Developing performance indicators for clinical governance in dimensions of risk management and clinical effectiveness [J].
Azami-Aghdash, Saber ;
Tabrizi, Jafar Sadegh ;
Sadeghi-Bazargani, Homayoun ;
Hajebrahimi, Sakineh ;
Naghavi-Behzad, Mohammad .
INTERNATIONAL JOURNAL FOR QUALITY IN HEALTH CARE, 2015, 27 (02) :110-116
[40]   Utilisation of hospital information systems for medical research in Saudi Arabia: A mixed-method exploration of the views of healthcare and IT professionals involved in hospital database management systems [J].
Samra, Halima ;
Li, Alice ;
Soh, Ben ;
Al Zain, Mohammed .
HEALTH INFORMATION MANAGEMENT JOURNAL, 2020, 49 (2-3) :117-126