Research Article Open Access

Risk Assessment of Healthcare Information Systems in Indonesian Regional Government Hospitals Using ISO 27001:2022

Deo Alif Alfitrah1 and Nilo Leegowo2
  • 1 Information Systems Management Department, BINUS Graduate Program, Master of Information Systems Management, Bina Nusantara University, Jakarta 11480, Indonesia
  • 2 Information Systems Management Department, BINUS Graduate Program, Master of Information Systems Management, Bina Nusantara University, Jakarta 11480, Indonesia

Abstract

The growing number of cyber-attacks targeting the healthcare sector, particularly Indonesian regional government hospitals, reflects the absence of a structured information security management system. Issues such as shared account usage, lack of staff security training, and undocumented incident reporting present serious risks to patient data. This study aims to assess the current state of information security in a government hospital using the ISO/IEC 27001:2022 standard and to propose mitigation measures based on Annex A controls. The assessment was conducted using the ISO 27001 framework and methodology. A qualitative case study approach was adopted, with data collected through semi-structured interviews, direct observations, and document analysis. The evaluation followed the Plan Do Check Act (PDCA) cycle and ISO 27005 risk assessment matrix, scoring each risk based on likelihood and impact. The results show that out of eight identified risk categories, four were classified as high namely, access management, information security policy, security awareness training, and system backup management while the rest were categorized as medium. A gap analysis indicated that many of these risks were not supported by effective controls. Recommendations include policy updates, regular training, formalized incident reporting, and annual security audits. These findings highlight the urgent need for systematic ISMS implementation to improve cybersecurity resilience and safeguard patient information in public healthcare institutions.

Journal of Computer Science
Volume 22 No. 3, 2026, 778-786

DOI: https://doi.org/10.3844/jcssp.2026.778.786

Submitted On: 2 June 2025 Published On: 13 March 2026

How to Cite: Alfitrah, D. A. & Leegowo, N. (2026). Risk Assessment of Healthcare Information Systems in Indonesian Regional Government Hospitals Using ISO 27001:2022. Journal of Computer Science, 22(3), 778-786. https://doi.org/10.3844/jcssp.2026.778.786

  • 56 Views
  • 11 Downloads
  • 0 Citations

Download

Keywords

  • Information Security
  • Risk Assessment
  • Regional Government Hospital
  • Healthcare IS
  • ISO/IEC 27001