Institute of Medical Informatics, UMIT TIROL - Private University for Health Sciences and Health Technology, Hall in Tirol, Austria
Institute of Medical Informatics, UMIT TIROL - Private University for Health Sciences and Health Technology, Hall in Tirol, Austria.
BMJ Health Care Inform. 2023 Jan;30(1). doi: 10.1136/bmjhci-2022-100639.
Connecting medical devices to hospital IT networks can create threats that must be covered by IT risk management. In practice, implementing such risk management is not trivial because the IEC 80001-1, as the existing state-of-the-art, do not describe sufficiently concrete implementation measures or evaluation indicators. The aim of the present work was to develop and evaluate a catalogue of measures and indicators to help hospitals implement and evaluate risk management in accordance with IEC 80001-1.
We conducted a Delphi study with 22 experts. In the first round, we performed interviews to identify implementation measures and evaluation indicators using qualitative content analysis. In the second round, a quantitative experts' survey confirmed the results of the first survey round and identified relationships between the measures and indicators. Based on these results, we then developed a catalogue containing the identified measures and indicators. Finally, we performed a case study to verify the practicability of this catalogue.
We developed and verified a catalogue of 49 measures and 18 indicators to help hospitals implement and evaluate risk management following IEC 80001-1. The case study confirmed the practicability of the catalogue.
Compared with IEC 80001-1, our catalogue goes into further detail to offer hospitals a stepwise implementation and evaluation approach. However, the catalogue must be tested in further case studies and evaluated in terms of generalisation.
The catalogue will enable hospitals to overcome recent difficulties in implementing and evaluating IT risk management for medical devices according to IEC 80001-1.
将医疗设备连接到医院 IT 网络可能会产生威胁,这些威胁必须由 IT 风险管理来覆盖。在实践中,实施这种风险管理并不简单,因为 IEC 80001-1 作为现有最先进的标准,没有充分描述具体的实施措施或评估指标。本研究的目的是开发和评估一套措施和指标,以帮助医院根据 IEC 80001-1 实施和评估风险管理。
我们进行了一项有 22 名专家参与的德尔菲研究。在第一轮中,我们通过定性内容分析进行访谈,以确定实施措施和评估指标。在第二轮中,进行了一项定量专家调查,以确认第一轮调查结果,并确定措施和指标之间的关系。基于这些结果,我们开发了一个包含已识别措施和指标的目录。最后,我们进行了案例研究,以验证该目录的实用性。
我们开发并验证了一个包含 49 项措施和 18 项指标的目录,以帮助医院根据 IEC 80001-1 实施和评估风险管理。案例研究证实了该目录的实用性。
与 IEC 80001-1 相比,我们的目录更详细,为医院提供了一种逐步实施和评估的方法。然而,该目录必须在进一步的案例研究中进行测试,并在推广方面进行评估。
该目录将使医院能够克服根据 IEC 80001-1 实施和评估医疗设备 IT 风险管理的当前困难。