IT risk management for medical devices in hospital IT networks: a catalogue of measures and indicators

Author:

Richter StefanORCID,Ammenwerth ElskeORCID

Abstract

ObjectivesConnecting medical devices to hospital IT networks can create threats that must be covered by IT risk management. In practice, implementing such risk management is not trivial because the IEC 80001-1, as the existing state-of-the-art, do not describe sufficiently concrete implementation measures or evaluation indicators. The aim of the present work was to develop and evaluate a catalogue of measures and indicators to help hospitals implement and evaluate risk management in accordance with IEC 80001-1.MethodsWe conducted a Delphi study with 22 experts. In the first round, we performed interviews to identify implementation measures and evaluation indicators using qualitative content analysis. In the second round, a quantitative experts’ survey confirmed the results of the first survey round and identified relationships between the measures and indicators. Based on these results, we then developed a catalogue containing the identified measures and indicators. Finally, we performed a case study to verify the practicability of this catalogue.ResultsWe developed and verified a catalogue of 49 measures and 18 indicators to help hospitals implement and evaluate risk management following IEC 80001-1. The case study confirmed the practicability of the catalogue.DiscussionCompared with IEC 80001-1, our catalogue goes into further detail to offer hospitals a stepwise implementation and evaluation approach. However, the catalogue must be tested in further case studies and evaluated in terms of generalisation.ConclusionsThe catalogue will enable hospitals to overcome recent difficulties in implementing and evaluating IT risk management for medical devices according to IEC 80001-1.

Funder

TÜV AUSTRIA GmbH

Publisher

BMJ

Subject

Health Information Management,Health Informatics,Computer Science Applications

Reference22 articles.

1. Implications of electronic health record downtime: an analysis of patient safety event reports;Larsen;J Am Med Inform Assoc,2018

2. Ahlbrandt J , Röhrig R , Dehm J . Risikomanagement für medizinische Netzwerke in der Intensiv-und Notfallmedizin. Gemeinsames Positionspapier zur Norm IEC 80001-1. In: GMS Medizinische Informatik, Biometrie und Epidemiologie, 9, 2013.

3. Cybersecurity in healthcare: A systematic review of modern threats and trends

4. Magrabi F , Ong MS , Coiera E . Health IT for patient safety and improving the safety of health IT. In: Evidence-based health informatics: promoting safety and efficiency through scientific methods and ethical policy, 2016.

5. Ahlbrandt J , Röhrig R . Safety first! managing risks for a daisy chain of medical devices connected to the IT-network-first experiences applying IEC 80001-1. In: Studies in health technology and informatics, 2013.

Cited by 2 articles. 订阅此论文施引文献 订阅此论文施引文献,注册后可以免费订阅5篇论文的施引文献,订阅后可以查看论文全部施引文献

同舟云学术

1.学者识别学者识别

2.学术分析学术分析

3.人才评估人才评估

"同舟云学术"是以全球学者为主线,采集、加工和组织学术论文而形成的新型学术文献查询和分析系统,可以对全球学者进行文献检索和人才价值评估。用户可以通过关注某些学科领域的顶尖人物而持续追踪该领域的学科进展和研究前沿。经过近期的数据扩容,当前同舟云学术共收录了国内外主流学术期刊6万余种,收集的期刊论文及会议论文总量共计约1.5亿篇,并以每天添加12000余篇中外论文的速度递增。我们也可以为用户提供个性化、定制化的学者数据。欢迎来电咨询!咨询电话:010-8811{复制后删除}0370

www.globalauthorid.com

TOP

Copyright © 2019-2024 北京同舟云网络信息技术有限公司
京公网安备11010802033243号  京ICP备18003416号-3