3.8 Article

IT risk management for medical devices in hospital IT networks: a catalogue of measures and indicators

期刊

BMJ HEALTH & CARE INFORMATICS
卷 30, 期 1, 页码 -

出版社

BMJ PUBLISHING GROUP
DOI: 10.1136/bmjhci-2022-100639

关键词

Medical Informatics; BMJ Health Informatics; Health Information Management

向作者/读者索取更多资源

This study aims to develop and evaluate a catalogue of measures and indicators to assist hospitals in implementing and evaluating risk management for medical devices according to IEC 80001-1. Through a Delphi study, a catalogue consisting of 49 measures and 18 indicators was developed and its practicability was verified through a case study. This catalogue will help hospitals overcome difficulties in implementing and evaluating IT risk management for medical devices according to IEC 80001-1.
ObjectivesConnecting medical devices to hospital IT networks can create threats that must be covered by IT risk management. In practice, implementing such risk management is not trivial because the IEC 80001-1, as the existing state-of-the-art, do not describe sufficiently concrete implementation measures or evaluation indicators. The aim of the present work was to develop and evaluate a catalogue of measures and indicators to help hospitals implement and evaluate risk management in accordance with IEC 80001-1.MethodsWe conducted a Delphi study with 22 experts. In the first round, we performed interviews to identify implementation measures and evaluation indicators using qualitative content analysis. In the second round, a quantitative experts' survey confirmed the results of the first survey round and identified relationships between the measures and indicators. Based on these results, we then developed a catalogue containing the identified measures and indicators. Finally, we performed a case study to verify the practicability of this catalogue.ResultsWe developed and verified a catalogue of 49 measures and 18 indicators to help hospitals implement and evaluate risk management following IEC 80001-1. The case study confirmed the practicability of the catalogue.DiscussionCompared with IEC 80001-1, our catalogue goes into further detail to offer hospitals a stepwise implementation and evaluation approach. However, the catalogue must be tested in further case studies and evaluated in terms of generalisation.ConclusionsThe catalogue will enable hospitals to overcome recent difficulties in implementing and evaluating IT risk management for medical devices according to IEC 80001-1.

作者

我是这篇论文的作者
点击您的名字以认领此论文并将其添加到您的个人资料中。

评论

主要评分

3.8
评分不足

次要评分

新颖性
-
重要性
-
科学严谨性
-
评价这篇论文

推荐

暂无数据
暂无数据