Purpose: Digital transformation in hospitals improves service efficiency but simultaneously increases cybersecurity risks, particularly in Electronic Medical Record (EMR) systems containing sensitive patient data. This study aims to evaluate the level of cybersecurity maturity in hospital digital services using the IKAS Plus framework developed by the National Cyber and Crypto Agency. Methodology: The study employed a quantitative descriptive design with a case study approach conducted in one government hospital. Data were collected through interviews, observations, and document reviews, and cybersecurity maturity was assessed using the IKAS Plus framework. Results: The assessment revealed that the hospital's cybersecurity maturity level is at Level 2 (Repetitive), with an actual score of 2.17 against a target score of 2.51. Among the domains, the Protection domain achieved the highest score (2.41), whereas the Identification domain recorded the lowest score (1.65), indicating weaknesses in governance and risk management.Applications/Originality/Value: The findings highlight the urgent need for improving procedural consistency, strengthening governance structures, and enhancing human resource awareness regarding cybersecurity within the healthcare sector. This study contributes practical insights for hospitals seeking to evaluate and strengthen their cybersecurity maturity using a nationally recognized framework.
Copyrights © 2025