Alhammad Aeshah, Yusof Maryati Mohd, Jambari Dian Indrayani
Faculty of Information Science and Technology, Universiti Kebangsaan Malaysia, Bangi, Malaysia.
J Eval Clin Pract. 2025 Feb;31(1):e14140. doi: 10.1111/jep.14140. Epub 2024 Sep 19.
RATIONALE, AIMS, AND OBJECTIVES: Medical device-integrated electronic medical records (MDI-EMR) pose significant challenges in ensuring effective usage, data security and patient safety. The complexities of MDI-EMR necessitate applying various security mechanisms to safeguard against cyber threats. Therefore, we evaluated cyber threats to MDI-EMR and the effectiveness of applied security controls using a proposed framework from sociotechnical and risk assessment perspectives.
We conducted a qualitative case study evaluation in a general hospital in Saudi Arabia using interviews, observation, and document analysis from the perspectives of major MDI-EMR stakeholders, including healthcare providers, IT professionals and cybersecurity specialists.
The results showed the interplay among physical, technical and administrative security controls that maintained a secure posture of MDI-EMR. The effectiveness of security controls is highly influenced by the staff's cybersecurity awareness and training. The perceived effectiveness of security controls varied among users, with some expressing satisfaction with the ease of use and reliability, while others highlighting challenges such as password complexity and access procedures. Understanding these diverse perspectives is crucial for tailoring security measures to meet the needs of different stakeholders effectively.
Collaboration among the key stakeholders is crucial for implementing security controls for MDI-EMR. Balancing security measures with usability concerns is essential, as highlighted by challenges in implementing technical controls. A comprehensive approach encompassing physical, technical and administrative controls, continuous education and awareness initiatives are significant to empower staff in recognising and mitigating cyber threats effectively to safeguard medical data and ensure the integrity of healthcare systems.
原理、目的和目标:集成医疗设备的电子病历(MDI-EMR)在确保有效使用、数据安全和患者安全方面面临重大挑战。MDI-EMR的复杂性需要应用各种安全机制来防范网络威胁。因此,我们从社会技术和风险评估的角度,使用一个提议的框架评估了对MDI-EMR的网络威胁以及应用的安全控制措施的有效性。
我们在沙特阿拉伯的一家综合医院进行了定性案例研究评估,从包括医疗保健提供者、IT专业人员和网络安全专家在内的MDI-EMR主要利益相关者的角度进行访谈、观察和文件分析。
结果显示了物理、技术和管理安全控制之间的相互作用,这些控制保持了MDI-EMR的安全态势。安全控制措施的有效性高度受员工网络安全意识和培训的影响。安全控制措施的感知有效性在用户之间存在差异,一些人对其易用性和可靠性表示满意,而另一些人则强调了诸如密码复杂性和访问程序等挑战。了解这些不同观点对于有效定制安全措施以满足不同利益相关者的需求至关重要。
关键利益相关者之间的合作对于实施MDI-EMR的安全控制至关重要。正如实施技术控制方面的挑战所强调的,在安全措施与可用性问题之间取得平衡至关重要。一种包括物理、技术和管理控制、持续教育及提高意识举措在内的综合方法对于使员工能够有效识别和减轻网络威胁以保护医疗数据并确保医疗系统的完整性具有重要意义。