Analysis of Electronic Medical Record Security Risk Factors During the Implementation of a New Hospital Information System at Hospital X

Authors

  • Adinda Salsabila Departement of Medical Records and Health Information, Faculty of Health, Politeknik Piksi Ganesha, Indonesia
  • Irda Sari Departement of Medical Records and Health Information, Faculty of Health, Politeknik Piksi Ganesha, Indonesia

DOI:

https://doi.org/10.69930/jsi.v3i5.936

Keywords:

Electronic Medical Records; Information Security; Risk Factors; Hospital Information System; Cybersecurity

Abstract

The implementation of a new Hospital Management Information System (SIMRS) integrated with Electronic Medical Records (EMRs) can improve healthcare services, but it may also introduce risks to patient-data security. This study aimed to analyze EMR security risk factors during the implementation of a new SIMRS at Hospital X. A descriptive qualitative approach was used through interviews and direct observation involving five purposively selected informants: two registration officers, two SIMRS security officers, and one SIMRS information technology staff member. The findings identified risks related to availability, confidentiality, physical and environmental security, human factors, and cybersecurity. A system downtime lasting more than one hour occurred during feature addition, network devices experienced technical disruptions, and failure to log out created a risk of unauthorized account use. Existing controls included individual usernames and passwords, role-based access restrictions, restricted database access for the IT team, CCTV-supported physical protection, and a firewall. The 5M analysis further grouped the identified issues into Man, Method, Machine, Material, and Money. The study concludes that EMR security at Hospital X is supported by several existing controls, but residual risks remain and require continuous management. Periodic security evaluation, stronger user compliance and training, improved infrastructure reliability, clearer access-control procedures, and regular cybersecurity maintenance are recommended to protect the confidentiality, integrity, and availability of EMR data.

Downloads

Published

2026-09-22

How to Cite

Salsabila, A., & Sari, I. (2026). Analysis of Electronic Medical Record Security Risk Factors During the Implementation of a New Hospital Information System at Hospital X. Journal of Scientific Insights, 3(5), 632–641. https://doi.org/10.69930/jsi.v3i5.936