An Ni’mah Wangon General Hospital has implemented a Hospital Management Information System (HMIS) as part of its commitment to creating an innovative and productive work system based on information technology. Issues identified during its use include data inconsistencies resulting from user error, system disruptions caused by server and network problems, limitations in supporting infrastructure such as electricity and data storage, and security threats in the form of viruses and misuse of access rights. This study aims to analyse the level of IT risk based on likelihood and impact through a qualitative approach using observation, interviews and documentation. The method used was ISO 31000:2018. The research findings identified 14 potential risks, comprising 3 high-level risks, 3 moderate-level risks and 8 low-level risks, of which the assignment of users who do not possess the appropriate competencies, errors in the SIMRS software, and virus attacks were identified as the top priorities for management due to their significant impact on hospital operations. Using the ISO 31000:2018 framework, this study concluded that systematic risk management is crucial in supporting the continuity of services. The proposed mitigation strategies include improving the reliability of the infrastructure, providing regular training for users, standardising data input procedures, and carrying out routine maintenance to ensure the security and optimisation of the SIMRS service at An Ni’mah Wangon General Hospital.
Copyrights © 2026