Hospital is a health institution which is a health service center where sick people can be accommodated and treated properly. XYZ Hospital is part of the AHSA health service network, which in 1986 used the CLIPPER application for data storage. This study aims to carry out risk management of the Hospital Management Information System (SIMRS) at the XYZ Hospital. By conducting interviews and distributing questionnaires to Mirsa's department as IT manager at the hospital. In carrying out risk management, ISO 31000 is applied and adapted for all types of organizations by providing a structure and guidelines that apply generically to all operations related to risk management. The results of this study indicate that there are 2 high level risk levels, which are dangerous risks that must be dealt with as soon as possible, and 13 medium level risks which are risks that must be considered continuously, so that each risk must be treated with risk which is expected to be a reference in handling and maintenance of Information Systems in the future.