Integrated Healthcare IT Risk Management in a Hospital Setting: A Case Study of ISO 31000 and NIST SP 800-30 Implementation at Murni Teguh Tuban Bali Hospital
DOI:
https://doi.org/10.59261/jequi.v8i3.387Keywords:
Cybersecurity, Hospital Information System, Information Technology Risk Management, ISO 31000, NIST SP 800-30Abstract
Background: Digital transformation in the healthcare sector has significantly increased the use of systems such as Hospital Information Systems (HIS), Electronic Medical Records (EMR), and technology infrastructure. This reliance increases risks of operational disruptions, cyber threats, and data breaches.
Objective: This study aims to develop an integrated IT risk management framework that combines ISO 31000 and NIST SP 800-30, and to examine how this integration supports regulatory compliance and hospital accreditation requirements.
Methods: A case study was carried out at Murni Teguh Tuban Hospital in Bali, Indonesia. Data were collected through interviews with seven informants from management and the IT unit, questionnaires, and direct observations. Risks were scored using a likelihood × impact matrix validated through source triangulation.
Results: ISO 31000 was applied as the governance framework while NIST SP 800-30 guided the technical assessment at every stage. The results show that three key assets are categorized as having very high-risk levels, namely systems (20), external services and vendors (16), and hardware (15). In terms of threats, operational risks are the most significant (20). The evaluation also highlights several gaps, including the absence of Multi-Factor Authentication (MFA), lack of regular IT audits, and insufficient security monitoring. To address these issues, mitigation strategies focus on strengthening access controls, performing regular updates, and implementing a Disaster Recovery Plan (DRP).
Conclusion: The combining of ISO 31000 and NIST SP 800-30 offers a more balanced approach, helping improve security, system resilience, and service continuity.
Downloads
References
Abraham, C., Chatterjee, D., & Sims, R. R. (2019). Muddling through cybersecurity: Insights from the US healthcare industry. Business Horizons, 62(4), 539–548.
Ariyanti, N., Agushybana, F., & Widodo, A. P. (2023). The Benefits of Electronic Medical Records Reviewed from Economic, Clinical, and Clinical Information Benefits in Hospitals. Jurnal Kesehatan Komunitas, 9(1), 190–197. https://doi.org/10.25311/keskom.vol9.iss1.1420
Artamevia, A., Eka, E., Suci, & Dhamanti, I. (2024). Cyber Security Dalam Sistem Informasi Rumah Sakit Indonesia: Kajian Literatur. Journal Of Social Science Research, 4, 17410–17421.
Artie, H. Z., Hilman, M., & Yazid, S. (2025). Penilaian Risiko Keamanan Informasi Pusat Data pada Instansi XYZ. Jurnal Informatika Ekonomi Bisnis, 7(2), 270–276. https://doi.org/10.37034/infeb.v7i2.1160
Aven, T. (2016). Risk assessment and risk management: Review of recent advances on their foundation. European Journal of Operational Research, 253(1), 1–13. https://doi.org/10.1016/j.ejor.2015.12.023
Basri, W. S., & Ayu, A. L. (2024). Risk Management in Information Systems: Applying ISO 31000:2018 and ISO/IEC 27001:2022 Controls at PMI’s Central Clinic. International Journal for Applied Information Management, 4(1), 1–13. https://doi.org/10.47738/ijaim.v4i1.70
Baz, A., Ahmed, R., Khan, S. A., & Kumar, S. (2023). Security Risk Assessment Framework for the Healthcare Industry 5.0. Sustainability, 15(23), 16519. https://doi.org/10.3390/su152316519
Bhardwaj, M., Juneja, Y., & Sidana, N. (2026). Cybersecurity in Healthcare: Risks, Vulnerabilities, and Ethical Imperatives. In Organ Trafficking Prevention in the Healthcare Sector: Examining the Co-Creation of Cybersecurity Value (pp. 1–34). IGI Global Scientific Publishing.
BSSN. (2024). Lanskap Keamanan Siber Indonesia 2024. https://www.bssn.go.id/wp-content/uploads/2025/02/LANSKAP-KEAMANAN-SIBER-2024-1.pdf
Coventry, L., & Branley, D. (2018). Cybersecurity in healthcare: A narrative review of trends, threats and ways forward. Maturitas, 113, 48–52. https://doi.org/10.1016/j.maturitas.2018.04.008
Diahapsari, A., & Riadi, I. (2022). Analysis Risk Assessment on Hospital Management Information System using Octave Allegro Framework. International Journal of Computer Applications, 184(24), 27–34. https://doi.org/10.5120/ijca2022922286
Effendy, C. A., Paramarta, V., & Purwanda, E. (2024). Peran Teknologi Informasi, Pengelolaan Sumber Daya Manusia, Dan Sistem Infoemasi Rumah Sakit Dalam Meningkatkan Kinerja Rumah Sakit (Kajian Literatur). Jurnal Review Pendidikan Dan Pengajaran, 7(4), 13479–13489. https://doi.org/https://doi.org/10.31004/jrpp.v7i4.34703
Ghafur, S., Kristensen, S., Honeyford, K., Martin, G., Darzi, A., & Aylin, P. (2019). A retrospective impact analysis of the WannaCry cyberattack on the NHS. Npj Digital Medicine, 2(1), 98. https://doi.org/10.1038/s41746-019-0161-6
Hermawan, I., Hanggara, B. T., & Perdanakusuma, A. R. (2025). Manajemen Risiko Sistem Informasi Menggunakan Metode NIST SP 800-30 Studi Kasus Pada Dinas Komunikasi dan Informatika Kabupaten Sidoarjo (Vol. 9, Number 6). https://j-ptiik.ub.ac.id/index.php/j-ptiik/article/view/14982
Indonesia, P. (2022). Undang-undang (UU) Nomor 27 Tahun 2022 tentang Pelindungan Data Pribadi. https://doi.org/https://peraturan.bpk.go.id/Details/229798/uu-no-27-tahun-2022
Indonesia, P. (2023). Undang-undang (UU) Nomor 17 Tahun 2023 tentang Kesehatan. https://doi.org/https://peraturan.bpk.go.id/details/258028/uu-no-17-tahun-2023
ISO. (2018). Risk management-Guidelines International Standart ISO 31000:2018. https://www.iso.org/standard/65694.html
Jalali, M. S., & Kaiser, J. P. (2018). Cybersecurity in Hospitals: A Systematic, Organizational Perspective. Journal of Medical Internet Research, 20(5), e10059. https://doi.org/10.2196/10059
Kemenkes RI. (2024). KMK No. 1596 Tahun 2024 tentang Standar Akreditasi Rumah Sakit.
Kruse, C. S., Dolezel, D., & Shanmugam, R. (2026). Cybersecurity in Healthcare: A Systematic Review and Narrative Analysis. In Applied Clinical Informatics, 17 (2), 315–328. Georg Thieme Verlag. https://doi.org/10.1055/a-2865-4206
Kruse, C. S., Frederick, B., Jacobson, T., & Monticone, D. K. (2017). Cybersecurity in healthcare: A systematic review of modern threats and trends. Technology and Health Care, 25(1), 1–10. https://doi.org/10.3233/THC-161263
NIST. (2012). Guide for Conducting Risk Assessments (NIST SP 800-30 Rev. 1). https://doi.org/10.6028/NIST.SP.800-30r1
Permadi, D. (2021). Kominfo: Data Pribadi WNI yang Bocor Identik Data BPJS Kesehatan. https://news.detik.com/berita/d-5577462/kominfo-data-pribadi-wni-yang-bocor-identik-data-bpjs-kesehatan
Pohan, R. (2025). Adaptasi Manajemen Risiko Pada Sistem Pendidikan Pascapandemi. Jurnal Media Akademik (JMA), 3(12).
Putra, A. P., & Soewito, B. (2023). Integrated methodology for information security risk management using ISO 27005:2018 and NIST SP 800-30 for insurance sector. In IJACSA) International Journal of Advanced Computer Science and Applications, 14 (4).
Quicho, R., Evans, L., Chopp Hinckley, C., & Beth Curran, M. (2024). Joint Commission International Mission Development Team for the 8th Edition. https://www.jointcommissioninternational.org.
Rahmawati, D. (2022). BSSN Temukan 1,6 Miliar Serangan Siber Sepanjang 2021, Mayoritas Malware. https://news.detik.com/berita/d-5972491/bssn-temukan-1-6-miliar-serangan-siber-sepanjang-2021-mayoritas-malware
Rahmi, T. A., & Ikhwani, M. (2025). Analisis Manajemen Risiko Pada Sistem Informasi Manajemen Rumah Sakit(SIMRS) Dengan ISO 31000 dan NIST 800-30 DI RSUD H. Ok Arya Zulkarnain. JATI (Jurnal Mahasiswa Teknik Informatika), 9(5), 8207–8215. https://doi.org/10.36040/jati.v9i5.15069
Rajput, K., Darzi, A., & Ghafur, S. (2025). Overlooked and under-reported: the impact of cyberattacks on primary care in the UK National Health Service. The Lancet Digital Health, 7(7).
Salama, R., Altrjman, C., & Al-Turjman, F. (2024). Healthcare cybersecurity challenges: a look at current and future trends. Computational Intelligence and Blockchain in Complex Systems, 97–111.
Utomo, D. K., Santosa, I., & Nutrisha, W. A. (2022). Perancangan Manajemen Informasi Berdasarkan Standar Nasional Akreditasi Rumah Sakit (SNARS) dan Joint Commission International (JCI) Pada Rumah Sakit Gigi Dan Mulut (RSGM) Maranatha. Jurnal Ilmiah Penelitian Dan Pembelajaran Informatika (JIPI), 07(4), 1045–1057. https://doi.org/https://doi.org/10.29100/jipi.v7i4.3193
Vantissha, D., Azizah, A. H., & Arifin, S. (2022). Assessing Hospital Management Information Systems Success Using Human Organization and Technology Fit Model. Applied Information System and Management (AISM), 5(1), 37–44. https://doi.org/10.15408/aism.v5i1.24738
Wahdah, F., & Soewito, B. (2022). manajemen resiko aplikasi keuangan pada perusahaan abc melalui kombinasi NIST SP 800-30, COBIT, PMBOK, dan ISO 31000. JIKO (Jurnal Informatika Dan Komputer), 5(2), 78–83. https://doi.org/10.33387/jiko.v5i2.4369
World Health Organization. (2025). Global strategy on digital health 2020-2027. http://apps.who.int/bookorders.
Downloads
Published
Issue
Section
License
Copyright (c) 2026 Leo Denny Hartanto, Benfano Soewito

This work is licensed under a Creative Commons Attribution-ShareAlike 4.0 International License.
Authors who publish with this journal agree to the following terms:
- Authors retain copyright and grant the journal right of first publication with the work simultaneously licensed under a Creative Commons Attribution-ShareAlike 4.0 International (CC-BY-SA). that allows others to share the work with an acknowledgement of the work's authorship and initial publication in this journal.
- Authors are able to enter into separate, additional contractual arrangements for the non-exclusive distribution of the journal's published version of the work (e.g., post it to an institutional repository or publish it in a book), with an acknowledgement of its initial publication in this journal.
- Authors are permitted and encouraged to post their work online (e.g., in institutional repositories or on their website) prior to and during the submission process, as it can lead to productive exchanges, as well as earlier and greater citation of published work.




