Cargando…
IT risk management for medical devices in hospital IT networks: a catalogue of measures and indicators
OBJECTIVES: Connecting medical devices to hospital IT networks can create threats that must be covered by IT risk management. In practice, implementing such risk management is not trivial because the IEC 80001-1, as the existing state-of-the-art, do not describe sufficiently concrete implementation...
Autores principales: | , |
---|---|
Formato: | Online Artículo Texto |
Lenguaje: | English |
Publicado: |
BMJ Publishing Group
2023
|
Materias: | |
Acceso en línea: | https://www.ncbi.nlm.nih.gov/pmc/articles/PMC9896181/ https://www.ncbi.nlm.nih.gov/pubmed/36724909 http://dx.doi.org/10.1136/bmjhci-2022-100639 |
_version_ | 1784882015054594048 |
---|---|
author | Richter, Stefan Ammenwerth, Elske |
author_facet | Richter, Stefan Ammenwerth, Elske |
author_sort | Richter, Stefan |
collection | PubMed |
description | OBJECTIVES: Connecting medical devices to hospital IT networks can create threats that must be covered by IT risk management. In practice, implementing such risk management is not trivial because the IEC 80001-1, as the existing state-of-the-art, do not describe sufficiently concrete implementation measures or evaluation indicators. The aim of the present work was to develop and evaluate a catalogue of measures and indicators to help hospitals implement and evaluate risk management in accordance with IEC 80001-1. METHODS: We conducted a Delphi study with 22 experts. In the first round, we performed interviews to identify implementation measures and evaluation indicators using qualitative content analysis. In the second round, a quantitative experts’ survey confirmed the results of the first survey round and identified relationships between the measures and indicators. Based on these results, we then developed a catalogue containing the identified measures and indicators. Finally, we performed a case study to verify the practicability of this catalogue. RESULTS: We developed and verified a catalogue of 49 measures and 18 indicators to help hospitals implement and evaluate risk management following IEC 80001-1. The case study confirmed the practicability of the catalogue. DISCUSSION: Compared with IEC 80001-1, our catalogue goes into further detail to offer hospitals a stepwise implementation and evaluation approach. However, the catalogue must be tested in further case studies and evaluated in terms of generalisation. CONCLUSIONS: The catalogue will enable hospitals to overcome recent difficulties in implementing and evaluating IT risk management for medical devices according to IEC 80001-1. |
format | Online Article Text |
id | pubmed-9896181 |
institution | National Center for Biotechnology Information |
language | English |
publishDate | 2023 |
publisher | BMJ Publishing Group |
record_format | MEDLINE/PubMed |
spelling | pubmed-98961812023-02-04 IT risk management for medical devices in hospital IT networks: a catalogue of measures and indicators Richter, Stefan Ammenwerth, Elske BMJ Health Care Inform Original Research OBJECTIVES: Connecting medical devices to hospital IT networks can create threats that must be covered by IT risk management. In practice, implementing such risk management is not trivial because the IEC 80001-1, as the existing state-of-the-art, do not describe sufficiently concrete implementation measures or evaluation indicators. The aim of the present work was to develop and evaluate a catalogue of measures and indicators to help hospitals implement and evaluate risk management in accordance with IEC 80001-1. METHODS: We conducted a Delphi study with 22 experts. In the first round, we performed interviews to identify implementation measures and evaluation indicators using qualitative content analysis. In the second round, a quantitative experts’ survey confirmed the results of the first survey round and identified relationships between the measures and indicators. Based on these results, we then developed a catalogue containing the identified measures and indicators. Finally, we performed a case study to verify the practicability of this catalogue. RESULTS: We developed and verified a catalogue of 49 measures and 18 indicators to help hospitals implement and evaluate risk management following IEC 80001-1. The case study confirmed the practicability of the catalogue. DISCUSSION: Compared with IEC 80001-1, our catalogue goes into further detail to offer hospitals a stepwise implementation and evaluation approach. However, the catalogue must be tested in further case studies and evaluated in terms of generalisation. CONCLUSIONS: The catalogue will enable hospitals to overcome recent difficulties in implementing and evaluating IT risk management for medical devices according to IEC 80001-1. BMJ Publishing Group 2023-01-30 /pmc/articles/PMC9896181/ /pubmed/36724909 http://dx.doi.org/10.1136/bmjhci-2022-100639 Text en © Author(s) (or their employer(s)) 2023. Re-use permitted under CC BY-NC. No commercial re-use. See rights and permissions. Published by BMJ. https://creativecommons.org/licenses/by-nc/4.0/This is an open access article distributed in accordance with the Creative Commons Attribution Non Commercial (CC BY-NC 4.0) license, which permits others to distribute, remix, adapt, build upon this work non-commercially, and license their derivative works on different terms, provided the original work is properly cited, appropriate credit is given, any changes made indicated, and the use is non-commercial. See: http://creativecommons.org/licenses/by-nc/4.0/ (https://creativecommons.org/licenses/by-nc/4.0/) . |
spellingShingle | Original Research Richter, Stefan Ammenwerth, Elske IT risk management for medical devices in hospital IT networks: a catalogue of measures and indicators |
title | IT risk management for medical devices in hospital IT networks: a catalogue of measures and indicators |
title_full | IT risk management for medical devices in hospital IT networks: a catalogue of measures and indicators |
title_fullStr | IT risk management for medical devices in hospital IT networks: a catalogue of measures and indicators |
title_full_unstemmed | IT risk management for medical devices in hospital IT networks: a catalogue of measures and indicators |
title_short | IT risk management for medical devices in hospital IT networks: a catalogue of measures and indicators |
title_sort | it risk management for medical devices in hospital it networks: a catalogue of measures and indicators |
topic | Original Research |
url | https://www.ncbi.nlm.nih.gov/pmc/articles/PMC9896181/ https://www.ncbi.nlm.nih.gov/pubmed/36724909 http://dx.doi.org/10.1136/bmjhci-2022-100639 |
work_keys_str_mv | AT richterstefan itriskmanagementformedicaldevicesinhospitalitnetworksacatalogueofmeasuresandindicators AT ammenwerthelske itriskmanagementformedicaldevicesinhospitalitnetworksacatalogueofmeasuresandindicators |