The implementation of Electronic Medical Record (EMR) faces challenges regarding patient information privacy, making it essential to assess the maturity level of its security. This study aimed to conduct an EMR security assessment to evaluate current conditions against those expected to meet the ISO 27002:2022 standard. This qualitative research employed a case study design. Data were analyzed using the System Security Engineering–Capability Maturity Model (SSE-CMM) method and gap analysis. The assessment revealed that the current EMR security level is at the initial/ad hoc stage (level 1), with an average score of 1.06 and a gap of 1.94 from the target defined process level (level 3). Thus, EMR security remains in its early stages, necessitating improvements in formally documented policies and security procedures, which have yet to be implemented.
Copyrights © 2025