Integrated Healthcare IT Risk Management in a Hospital Setting: A Case Study of ISO 31000 and NIST SP 800-30 Implementation at Murni Teguh Tuban Bali Hospital

Authors

  • Leo Denny Hartanto Universitas Bina Nusantara
  • Benfano Soewito Universitas Bina Nusantara

DOI:

https://doi.org/10.59261/jequi.v8i3.387

Keywords:

Cybersecurity, Hospital Information System, Information Technology Risk Management, ISO 31000, NIST SP 800-30

Abstract

Background: Digital transformation in the healthcare sector has significantly increased the use of systems such as Hospital Information Systems (HIS), Electronic Medical Records (EMR), and technology infrastructure. This reliance increases risks of operational disruptions, cyber threats, and data breaches.

Objective: This study aims to develop an integrated IT risk management framework that combines ISO 31000 and NIST SP 800-30, and to examine how this integration supports regulatory compliance and hospital accreditation requirements.

Methods: A case study was carried out at Murni Teguh Tuban Hospital in Bali, Indonesia. Data were collected through interviews with seven informants from management and the IT unit, questionnaires, and direct observations. Risks were scored using a likelihood × impact matrix validated through source triangulation.

Results: ISO 31000 was applied as the governance framework while NIST SP 800-30 guided the technical assessment at every stage. The results show that three key assets are categorized as having very high-risk levels, namely systems (20), external services and vendors (16), and hardware (15). In terms of threats, operational risks are the most significant (20). The evaluation also highlights several gaps, including the absence of Multi-Factor Authentication (MFA), lack of regular IT audits, and insufficient security monitoring. To address these issues, mitigation strategies focus on strengthening access controls, performing regular updates, and implementing a Disaster Recovery Plan (DRP).

Conclusion: The combining of ISO 31000 and NIST SP 800-30 offers a more balanced approach, helping improve security, system resilience, and service continuity.

Downloads

Download data is not yet available.

References

Abraham, C., Chatterjee, D., & Sims, R. R. (2019). Muddling through cybersecurity: Insights from the US healthcare industry. Business Horizons, 62(4), 539–548.

Ariyanti, N., Agushybana, F., & Widodo, A. P. (2023). The Benefits of Electronic Medical Records Reviewed from Economic, Clinical, and Clinical Information Benefits in Hospitals. Jurnal Kesehatan Komunitas, 9(1), 190–197. https://doi.org/10.25311/keskom.vol9.iss1.1420

Artamevia, A., Eka, E., Suci, & Dhamanti, I. (2024). Cyber Security Dalam Sistem Informasi Rumah Sakit Indonesia: Kajian Literatur. Journal Of Social Science Research, 4, 17410–17421.

Artie, H. Z., Hilman, M., & Yazid, S. (2025). Penilaian Risiko Keamanan Informasi Pusat Data pada Instansi XYZ. Jurnal Informatika Ekonomi Bisnis, 7(2), 270–276. https://doi.org/10.37034/infeb.v7i2.1160

Aven, T. (2016). Risk assessment and risk management: Review of recent advances on their foundation. European Journal of Operational Research, 253(1), 1–13. https://doi.org/10.1016/j.ejor.2015.12.023

Basri, W. S., & Ayu, A. L. (2024). Risk Management in Information Systems: Applying ISO 31000:2018 and ISO/IEC 27001:2022 Controls at PMI’s Central Clinic. International Journal for Applied Information Management, 4(1), 1–13. https://doi.org/10.47738/ijaim.v4i1.70

Baz, A., Ahmed, R., Khan, S. A., & Kumar, S. (2023). Security Risk Assessment Framework for the Healthcare Industry 5.0. Sustainability, 15(23), 16519. https://doi.org/10.3390/su152316519

Bhardwaj, M., Juneja, Y., & Sidana, N. (2026). Cybersecurity in Healthcare: Risks, Vulnerabilities, and Ethical Imperatives. In Organ Trafficking Prevention in the Healthcare Sector: Examining the Co-Creation of Cybersecurity Value (pp. 1–34). IGI Global Scientific Publishing.

BSSN. (2024). Lanskap Keamanan Siber Indonesia 2024. https://www.bssn.go.id/wp-content/uploads/2025/02/LANSKAP-KEAMANAN-SIBER-2024-1.pdf

Coventry, L., & Branley, D. (2018). Cybersecurity in healthcare: A narrative review of trends, threats and ways forward. Maturitas, 113, 48–52. https://doi.org/10.1016/j.maturitas.2018.04.008

Diahapsari, A., & Riadi, I. (2022). Analysis Risk Assessment on Hospital Management Information System using Octave Allegro Framework. International Journal of Computer Applications, 184(24), 27–34. https://doi.org/10.5120/ijca2022922286

Effendy, C. A., Paramarta, V., & Purwanda, E. (2024). Peran Teknologi Informasi, Pengelolaan Sumber Daya Manusia, Dan Sistem Infoemasi Rumah Sakit Dalam Meningkatkan Kinerja Rumah Sakit (Kajian Literatur). Jurnal Review Pendidikan Dan Pengajaran, 7(4), 13479–13489. https://doi.org/https://doi.org/10.31004/jrpp.v7i4.34703

Ghafur, S., Kristensen, S., Honeyford, K., Martin, G., Darzi, A., & Aylin, P. (2019). A retrospective impact analysis of the WannaCry cyberattack on the NHS. Npj Digital Medicine, 2(1), 98. https://doi.org/10.1038/s41746-019-0161-6

Hermawan, I., Hanggara, B. T., & Perdanakusuma, A. R. (2025). Manajemen Risiko Sistem Informasi Menggunakan Metode NIST SP 800-30 Studi Kasus Pada Dinas Komunikasi dan Informatika Kabupaten Sidoarjo (Vol. 9, Number 6). https://j-ptiik.ub.ac.id/index.php/j-ptiik/article/view/14982

Indonesia, P. (2022). Undang-undang (UU) Nomor 27 Tahun 2022 tentang Pelindungan Data Pribadi. https://doi.org/https://peraturan.bpk.go.id/Details/229798/uu-no-27-tahun-2022

Indonesia, P. (2023). Undang-undang (UU) Nomor 17 Tahun 2023 tentang Kesehatan. https://doi.org/https://peraturan.bpk.go.id/details/258028/uu-no-17-tahun-2023

ISO. (2018). Risk management-Guidelines International Standart ISO 31000:2018. https://www.iso.org/standard/65694.html

Jalali, M. S., & Kaiser, J. P. (2018). Cybersecurity in Hospitals: A Systematic, Organizational Perspective. Journal of Medical Internet Research, 20(5), e10059. https://doi.org/10.2196/10059

Kemenkes RI. (2024). KMK No. 1596 Tahun 2024 tentang Standar Akreditasi Rumah Sakit.

Kruse, C. S., Dolezel, D., & Shanmugam, R. (2026). Cybersecurity in Healthcare: A Systematic Review and Narrative Analysis. In Applied Clinical Informatics, 17 (2), 315–328. Georg Thieme Verlag. https://doi.org/10.1055/a-2865-4206

Kruse, C. S., Frederick, B., Jacobson, T., & Monticone, D. K. (2017). Cybersecurity in healthcare: A systematic review of modern threats and trends. Technology and Health Care, 25(1), 1–10. https://doi.org/10.3233/THC-161263

NIST. (2012). Guide for Conducting Risk Assessments (NIST SP 800-30 Rev. 1). https://doi.org/10.6028/NIST.SP.800-30r1

Permadi, D. (2021). Kominfo: Data Pribadi WNI yang Bocor Identik Data BPJS Kesehatan. https://news.detik.com/berita/d-5577462/kominfo-data-pribadi-wni-yang-bocor-identik-data-bpjs-kesehatan

Pohan, R. (2025). Adaptasi Manajemen Risiko Pada Sistem Pendidikan Pascapandemi. Jurnal Media Akademik (JMA), 3(12).

Putra, A. P., & Soewito, B. (2023). Integrated methodology for information security risk management using ISO 27005:2018 and NIST SP 800-30 for insurance sector. In IJACSA) International Journal of Advanced Computer Science and Applications, 14 (4).

Quicho, R., Evans, L., Chopp Hinckley, C., & Beth Curran, M. (2024). Joint Commission International Mission Development Team for the 8th Edition. https://www.jointcommissioninternational.org.

Rahmawati, D. (2022). BSSN Temukan 1,6 Miliar Serangan Siber Sepanjang 2021, Mayoritas Malware. https://news.detik.com/berita/d-5972491/bssn-temukan-1-6-miliar-serangan-siber-sepanjang-2021-mayoritas-malware

Rahmi, T. A., & Ikhwani, M. (2025). Analisis Manajemen Risiko Pada Sistem Informasi Manajemen Rumah Sakit(SIMRS) Dengan ISO 31000 dan NIST 800-30 DI RSUD H. Ok Arya Zulkarnain. JATI (Jurnal Mahasiswa Teknik Informatika), 9(5), 8207–8215. https://doi.org/10.36040/jati.v9i5.15069

Rajput, K., Darzi, A., & Ghafur, S. (2025). Overlooked and under-reported: the impact of cyberattacks on primary care in the UK National Health Service. The Lancet Digital Health, 7(7).

Salama, R., Altrjman, C., & Al-Turjman, F. (2024). Healthcare cybersecurity challenges: a look at current and future trends. Computational Intelligence and Blockchain in Complex Systems, 97–111.

Utomo, D. K., Santosa, I., & Nutrisha, W. A. (2022). Perancangan Manajemen Informasi Berdasarkan Standar Nasional Akreditasi Rumah Sakit (SNARS) dan Joint Commission International (JCI) Pada Rumah Sakit Gigi Dan Mulut (RSGM) Maranatha. Jurnal Ilmiah Penelitian Dan Pembelajaran Informatika (JIPI), 07(4), 1045–1057. https://doi.org/https://doi.org/10.29100/jipi.v7i4.3193

Vantissha, D., Azizah, A. H., & Arifin, S. (2022). Assessing Hospital Management Information Systems Success Using Human Organization and Technology Fit Model. Applied Information System and Management (AISM), 5(1), 37–44. https://doi.org/10.15408/aism.v5i1.24738

Wahdah, F., & Soewito, B. (2022). manajemen resiko aplikasi keuangan pada perusahaan abc melalui kombinasi NIST SP 800-30, COBIT, PMBOK, dan ISO 31000. JIKO (Jurnal Informatika Dan Komputer), 5(2), 78–83. https://doi.org/10.33387/jiko.v5i2.4369

World Health Organization. (2025). Global strategy on digital health 2020-2027. http://apps.who.int/bookorders.

Downloads

Published

2026-08-13