Background: Digital transformation in the healthcare sector has significantly increased the use of systems such as Hospital Information Systems (HIS), Electronic Medical Records (EMR), and technology infrastructure. This reliance increases risks of operational disruptions, cyber threats, and data breaches. Objective: This study aims to develop an integrated IT risk management framework that combines ISO 31000 and NIST SP 800-30, and to examine how this integration supports regulatory compliance and hospital accreditation requirements. Methods: A case study was carried out at Murni Teguh Tuban Hospital in Bali, Indonesia. Data were collected through interviews with seven informants from management and the IT unit, questionnaires, and direct observations. Risks were scored using a likelihood × impact matrix validated through source triangulation. Results: ISO 31000 was applied as the governance framework while NIST SP 800-30 guided the technical assessment at every stage. The results show that three key assets are categorized as having very high-risk levels, namely systems (20), external services and vendors (16), and hardware (15). In terms of threats, operational risks are the most significant (20). The evaluation also highlights several gaps, including the absence of Multi-Factor Authentication (MFA), lack of regular IT audits, and insufficient security monitoring. To address these issues, mitigation strategies focus on strengthening access controls, performing regular updates, and implementing a Disaster Recovery Plan (DRP). Conclusion: The combining of ISO 31000 and NIST SP 800-30 offers a more balanced approach, helping improve security, system resilience, and service continuity.
Copyrights © 2026