Cargando…

Development of an enterprise risk inventory for healthcare

BACKGROUND: The first phase of an enterprise risk management (ERM) program is the identification of risks. Accurate identification is essential to a proactive and effective ERM function. The authors identified a lack of such risk identification in the literature and in practical cases when interview...

Descripción completa

Detalles Bibliográficos
Autores principales: Etges, Ana Paula Beck da Silva, Grenon, Veronique, Lu, Ming, Cardoso, Ricardo Bertoglio, de Souza, Joana Siqueira, Kliemann Neto, Francisco José, Felix, Elaine Aparecida
Formato: Online Artículo Texto
Lenguaje:English
Publicado: BioMed Central 2018
Materias:
Acceso en línea:https://www.ncbi.nlm.nih.gov/pmc/articles/PMC6057062/
https://www.ncbi.nlm.nih.gov/pubmed/30041651
http://dx.doi.org/10.1186/s12913-018-3400-7
_version_ 1783341449988800512
author Etges, Ana Paula Beck da Silva
Grenon, Veronique
Lu, Ming
Cardoso, Ricardo Bertoglio
de Souza, Joana Siqueira
Kliemann Neto, Francisco José
Felix, Elaine Aparecida
author_facet Etges, Ana Paula Beck da Silva
Grenon, Veronique
Lu, Ming
Cardoso, Ricardo Bertoglio
de Souza, Joana Siqueira
Kliemann Neto, Francisco José
Felix, Elaine Aparecida
author_sort Etges, Ana Paula Beck da Silva
collection PubMed
description BACKGROUND: The first phase of an enterprise risk management (ERM) program is the identification of risks. Accurate identification is essential to a proactive and effective ERM function. The authors identified a lack of such risk identification in the literature and in practical cases when interviewing the chief risk officers from healthcare organizations. A risk inventory specific to healthcare organizations that includes detailed risk scenarios and risk impacts currently does not exist. Thus, the objective of this research is to develop an enterprise risk inventory for healthcare organizations to create a common understanding of how each type of risk impacts a healthcare organization. METHOD: ERM guidelines and data from 15 interviews with chief risk officers were analyzed to create the risk inventory. The identified risks were confirmed through a survey of risk managers from a range of global healthcare organizations during the ASHRM conference in 2017. Descriptive statistics were developed and cluster analysis was performed using the survey results. RESULTS: The risk inventory includes 28 risks and their specific risk scenarios. Cyberattack was ranked as the principal risk by the participants, followed by sentinel events and risks associated with human capital management (organizational culture, use of electronic medical records and physician wellness). The data analysis showed that the specific characteristics of the survey participants, such as the length of time working in risk management, the size of the organization, and the presence of a school of medicine, do not impact an individual’s opinion of the importance of the risks identified. A personal background in risk management (clinical or enterprise) was a characteristic that showed a small difference in the perceived importance of the risks from the proposed risk inventory. CONCLUSIONS: In addition to defining specific risk scenarios, the enterprise risk inventory presented in this research can contribute to guiding the risk identification phase of an ERM program and thereby support the development of a risk culture. Patient data security in hospitals that operate with high levels of technology is fundamental to delivering high quality and safe care to patients. At the top of the risk ranking, the identification of cyberattacks reflects the importance that healthcare risk managers place on this risk by allocating time and other resources. Exploring opportunities to improve cyber risk management and evaluating the benefits of using the risk inventory at the beginning of the risk identification phase in an ERM program are suggestions for future studies. ELECTRONIC SUPPLEMENTARY MATERIAL: The online version of this article (10.1186/s12913-018-3400-7) contains supplementary material, which is available to authorized users.
format Online
Article
Text
id pubmed-6057062
institution National Center for Biotechnology Information
language English
publishDate 2018
publisher BioMed Central
record_format MEDLINE/PubMed
spelling pubmed-60570622018-07-30 Development of an enterprise risk inventory for healthcare Etges, Ana Paula Beck da Silva Grenon, Veronique Lu, Ming Cardoso, Ricardo Bertoglio de Souza, Joana Siqueira Kliemann Neto, Francisco José Felix, Elaine Aparecida BMC Health Serv Res Research Article BACKGROUND: The first phase of an enterprise risk management (ERM) program is the identification of risks. Accurate identification is essential to a proactive and effective ERM function. The authors identified a lack of such risk identification in the literature and in practical cases when interviewing the chief risk officers from healthcare organizations. A risk inventory specific to healthcare organizations that includes detailed risk scenarios and risk impacts currently does not exist. Thus, the objective of this research is to develop an enterprise risk inventory for healthcare organizations to create a common understanding of how each type of risk impacts a healthcare organization. METHOD: ERM guidelines and data from 15 interviews with chief risk officers were analyzed to create the risk inventory. The identified risks were confirmed through a survey of risk managers from a range of global healthcare organizations during the ASHRM conference in 2017. Descriptive statistics were developed and cluster analysis was performed using the survey results. RESULTS: The risk inventory includes 28 risks and their specific risk scenarios. Cyberattack was ranked as the principal risk by the participants, followed by sentinel events and risks associated with human capital management (organizational culture, use of electronic medical records and physician wellness). The data analysis showed that the specific characteristics of the survey participants, such as the length of time working in risk management, the size of the organization, and the presence of a school of medicine, do not impact an individual’s opinion of the importance of the risks identified. A personal background in risk management (clinical or enterprise) was a characteristic that showed a small difference in the perceived importance of the risks from the proposed risk inventory. CONCLUSIONS: In addition to defining specific risk scenarios, the enterprise risk inventory presented in this research can contribute to guiding the risk identification phase of an ERM program and thereby support the development of a risk culture. Patient data security in hospitals that operate with high levels of technology is fundamental to delivering high quality and safe care to patients. At the top of the risk ranking, the identification of cyberattacks reflects the importance that healthcare risk managers place on this risk by allocating time and other resources. Exploring opportunities to improve cyber risk management and evaluating the benefits of using the risk inventory at the beginning of the risk identification phase in an ERM program are suggestions for future studies. ELECTRONIC SUPPLEMENTARY MATERIAL: The online version of this article (10.1186/s12913-018-3400-7) contains supplementary material, which is available to authorized users. BioMed Central 2018-07-24 /pmc/articles/PMC6057062/ /pubmed/30041651 http://dx.doi.org/10.1186/s12913-018-3400-7 Text en © The Author(s). 2018 Open AccessThis article is distributed under the terms of the Creative Commons Attribution 4.0 International License (http://creativecommons.org/licenses/by/4.0/), which permits unrestricted use, distribution, and reproduction in any medium, provided you give appropriate credit to the original author(s) and the source, provide a link to the Creative Commons license, and indicate if changes were made. The Creative Commons Public Domain Dedication waiver (http://creativecommons.org/publicdomain/zero/1.0/) applies to the data made available in this article, unless otherwise stated.
spellingShingle Research Article
Etges, Ana Paula Beck da Silva
Grenon, Veronique
Lu, Ming
Cardoso, Ricardo Bertoglio
de Souza, Joana Siqueira
Kliemann Neto, Francisco José
Felix, Elaine Aparecida
Development of an enterprise risk inventory for healthcare
title Development of an enterprise risk inventory for healthcare
title_full Development of an enterprise risk inventory for healthcare
title_fullStr Development of an enterprise risk inventory for healthcare
title_full_unstemmed Development of an enterprise risk inventory for healthcare
title_short Development of an enterprise risk inventory for healthcare
title_sort development of an enterprise risk inventory for healthcare
topic Research Article
url https://www.ncbi.nlm.nih.gov/pmc/articles/PMC6057062/
https://www.ncbi.nlm.nih.gov/pubmed/30041651
http://dx.doi.org/10.1186/s12913-018-3400-7
work_keys_str_mv AT etgesanapaulabeckdasilva developmentofanenterpriseriskinventoryforhealthcare
AT grenonveronique developmentofanenterpriseriskinventoryforhealthcare
AT luming developmentofanenterpriseriskinventoryforhealthcare
AT cardosoricardobertoglio developmentofanenterpriseriskinventoryforhealthcare
AT desouzajoanasiqueira developmentofanenterpriseriskinventoryforhealthcare
AT kliemannnetofranciscojose developmentofanenterpriseriskinventoryforhealthcare
AT felixelaineaparecida developmentofanenterpriseriskinventoryforhealthcare