Cargando…

IT risk management for medical devices in hospital IT networks: a catalogue of measures and indicators

OBJECTIVES: Connecting medical devices to hospital IT networks can create threats that must be covered by IT risk management. In practice, implementing such risk management is not trivial because the IEC 80001-1, as the existing state-of-the-art, do not describe sufficiently concrete implementation...

Descripción completa

Detalles Bibliográficos
Autores principales: Richter, Stefan, Ammenwerth, Elske
Formato: Online Artículo Texto
Lenguaje:English
Publicado: BMJ Publishing Group 2023
Materias:
Acceso en línea:https://www.ncbi.nlm.nih.gov/pmc/articles/PMC9896181/
https://www.ncbi.nlm.nih.gov/pubmed/36724909
http://dx.doi.org/10.1136/bmjhci-2022-100639
_version_ 1784882015054594048
author Richter, Stefan
Ammenwerth, Elske
author_facet Richter, Stefan
Ammenwerth, Elske
author_sort Richter, Stefan
collection PubMed
description OBJECTIVES: Connecting medical devices to hospital IT networks can create threats that must be covered by IT risk management. In practice, implementing such risk management is not trivial because the IEC 80001-1, as the existing state-of-the-art, do not describe sufficiently concrete implementation measures or evaluation indicators. The aim of the present work was to develop and evaluate a catalogue of measures and indicators to help hospitals implement and evaluate risk management in accordance with IEC 80001-1. METHODS: We conducted a Delphi study with 22 experts. In the first round, we performed interviews to identify implementation measures and evaluation indicators using qualitative content analysis. In the second round, a quantitative experts’ survey confirmed the results of the first survey round and identified relationships between the measures and indicators. Based on these results, we then developed a catalogue containing the identified measures and indicators. Finally, we performed a case study to verify the practicability of this catalogue. RESULTS: We developed and verified a catalogue of 49 measures and 18 indicators to help hospitals implement and evaluate risk management following IEC 80001-1. The case study confirmed the practicability of the catalogue. DISCUSSION: Compared with IEC 80001-1, our catalogue goes into further detail to offer hospitals a stepwise implementation and evaluation approach. However, the catalogue must be tested in further case studies and evaluated in terms of generalisation. CONCLUSIONS: The catalogue will enable hospitals to overcome recent difficulties in implementing and evaluating IT risk management for medical devices according to IEC 80001-1.
format Online
Article
Text
id pubmed-9896181
institution National Center for Biotechnology Information
language English
publishDate 2023
publisher BMJ Publishing Group
record_format MEDLINE/PubMed
spelling pubmed-98961812023-02-04 IT risk management for medical devices in hospital IT networks: a catalogue of measures and indicators Richter, Stefan Ammenwerth, Elske BMJ Health Care Inform Original Research OBJECTIVES: Connecting medical devices to hospital IT networks can create threats that must be covered by IT risk management. In practice, implementing such risk management is not trivial because the IEC 80001-1, as the existing state-of-the-art, do not describe sufficiently concrete implementation measures or evaluation indicators. The aim of the present work was to develop and evaluate a catalogue of measures and indicators to help hospitals implement and evaluate risk management in accordance with IEC 80001-1. METHODS: We conducted a Delphi study with 22 experts. In the first round, we performed interviews to identify implementation measures and evaluation indicators using qualitative content analysis. In the second round, a quantitative experts’ survey confirmed the results of the first survey round and identified relationships between the measures and indicators. Based on these results, we then developed a catalogue containing the identified measures and indicators. Finally, we performed a case study to verify the practicability of this catalogue. RESULTS: We developed and verified a catalogue of 49 measures and 18 indicators to help hospitals implement and evaluate risk management following IEC 80001-1. The case study confirmed the practicability of the catalogue. DISCUSSION: Compared with IEC 80001-1, our catalogue goes into further detail to offer hospitals a stepwise implementation and evaluation approach. However, the catalogue must be tested in further case studies and evaluated in terms of generalisation. CONCLUSIONS: The catalogue will enable hospitals to overcome recent difficulties in implementing and evaluating IT risk management for medical devices according to IEC 80001-1. BMJ Publishing Group 2023-01-30 /pmc/articles/PMC9896181/ /pubmed/36724909 http://dx.doi.org/10.1136/bmjhci-2022-100639 Text en © Author(s) (or their employer(s)) 2023. Re-use permitted under CC BY-NC. No commercial re-use. See rights and permissions. Published by BMJ. https://creativecommons.org/licenses/by-nc/4.0/This is an open access article distributed in accordance with the Creative Commons Attribution Non Commercial (CC BY-NC 4.0) license, which permits others to distribute, remix, adapt, build upon this work non-commercially, and license their derivative works on different terms, provided the original work is properly cited, appropriate credit is given, any changes made indicated, and the use is non-commercial. See: http://creativecommons.org/licenses/by-nc/4.0/ (https://creativecommons.org/licenses/by-nc/4.0/) .
spellingShingle Original Research
Richter, Stefan
Ammenwerth, Elske
IT risk management for medical devices in hospital IT networks: a catalogue of measures and indicators
title IT risk management for medical devices in hospital IT networks: a catalogue of measures and indicators
title_full IT risk management for medical devices in hospital IT networks: a catalogue of measures and indicators
title_fullStr IT risk management for medical devices in hospital IT networks: a catalogue of measures and indicators
title_full_unstemmed IT risk management for medical devices in hospital IT networks: a catalogue of measures and indicators
title_short IT risk management for medical devices in hospital IT networks: a catalogue of measures and indicators
title_sort it risk management for medical devices in hospital it networks: a catalogue of measures and indicators
topic Original Research
url https://www.ncbi.nlm.nih.gov/pmc/articles/PMC9896181/
https://www.ncbi.nlm.nih.gov/pubmed/36724909
http://dx.doi.org/10.1136/bmjhci-2022-100639
work_keys_str_mv AT richterstefan itriskmanagementformedicaldevicesinhospitalitnetworksacatalogueofmeasuresandindicators
AT ammenwerthelske itriskmanagementformedicaldevicesinhospitalitnetworksacatalogueofmeasuresandindicators