Jurnal Ilmiah Sistem Informasi
Vol. 4 No. 3 (2025): November: Jurnal Ilmiah Sistem Informasi

Enhancing Information Security and Risk Governance in Hospital Electronic Medical Record Systems

Mahfazza, Evva Choirotul (Unknown)
Amrozi, Yusuf (Unknown)
Amin, Faris Muslihul (Unknown)



Article Info

Publish Date
30 Nov 2025

Abstract

This study aims to analyse risk management in hospital medical records information systems using the ISO 31000:2018 framework. Electronic medical records play a critical role in storing and managing sensitive patient data, requiring a structured risk management approach to identify, evaluate, and control potential threats. The research method used was a descriptive qualitative approach, using observation and interviews with information technology staff and medical records managers. The results revealed 11 key risks, divided into three categories: high, medium, and low. High risks were primarily related to the lack of system protection against cyber threats. This study concluded that implementing ISO 31000:2018 can help hospitals develop more effective risk mitigation strategies, thereby supporting the security, integrity, and availability of patient data.

Copyrights © 2025






Journal Info

Abbrev

JUISI

Publisher

Subject

Computer Science & IT

Description

Sistem Pendukung Keputusan (DSS), Sistem Informasi Geografi (GIS), Perusahaan Skala Sistem Informasi (ERP, EAI, CRM, SCM), E-Commerce, E-Government, Sistem Informasi dari Rumah Sakit, Sistem Informasi Perbankan, Sistem Informasi Industri, Pengambilan Informasi, Keamanan Sistem Informasi, Sistem ...