A subscription to JoVE is required to view this content. Sign in or start your free trial.

Method Article

Hospital Medical Equipment Data Security Governance: A Grounded Theory Informed Data Lifecycle and Governance Matrix Protocol

265 views

DOI:

10.3791/69835

April 3rd, 2026

In This Article

Summary

This protocol presents a grounded theory-informed matrix workflow mapping six data lifecycle stages to six governance domains to audit and improve hospital medical equipment data security. Based on evidence, artifacts, and 48 stakeholder interviews across 14 hospitals, it generates heat maps and prioritized actions for iterative governance improvement.

Abstract

This article describes a reproducible governance protocol for hospital medical equipment data security grounded in qualitative evidence. From August to October 2024, we conducted semi-structured interviews with 48 stakeholders across 14 tertiary public hospitals in S City. Transcripts were analyzed using grounded theory procedures (Strauss and Corbin: open, axial, and selective coding), yielding 360 reference points, 149 initial concepts, 39 categories, 27 main categories, and 7 core categories. Building on the National Health Commission of the People's Republic of China's safety and quality management agenda and adopting the SQ (I SPORT) matrix logic as an organizing scaffold, we developed a Medical equipment data security audit and tracking protocol based on grounded theory (M-ATSSPD). The protocol operationalizes a matrix that maps six data lifecycle stages (Acquisition, Transmission, Storage, Sharing, Processing, and Disposal) to six governance domains (Organization and Personnel, Metadata, Compliance and Policies, Monitoring and Audit, Incident Response, and Technical Tooling). It specifies scoring anchors (0-3), evidence mapping rules, and heat map visualization to identify high-risk cells, prioritize corrective actions, and support iterative improvement without vendor dependence. The protocol further defines cell-level ownership and documentation requirements to strengthen cross-departmental coordination, compliance readiness, and incident preparedness, and provides guidance for transferability across public hospital settings.

Introduction

With the acceleration of hospital informatization and the rise of smart healthcare, medical equipment has become increasingly networked and interoperable, making equipment-generated data a core asset for clinical decision-making and hospital operations1. These data may include personally identifiable information, device operational logs, and diagnostic outputs such as physiological parameters, imaging objects, and treatment records, which are closely linked to patient privacy and care quality2. Security incidents involving such data can directly affect patient safety and trust in clinical services3.

Despite growing attention, multiple challenges persist. In Internet of Medical Things (IoMT) environments, external intrusions and unauthorized insider disclosures remain dominant breach patterns4. Data integrity can be fragile where devices lack robust validation mechanisms, leaving records vulnerable to tampering that may mislead diagnosis and treatment5. Heterogeneous vendor ecosystems and inconsistent security standards complicate secure data exchange across devices and systems6. Legacy equipment often operates beyond safe maintenance windows and cannot receive timely security patches7. Human factors, including limited security awareness and operational lapses, further elevate organizational vulnerability8. Default credentials, unencrypted communications, and weak access control increase the attack surface9. Hospitals may also prioritize functionality over security and lack dedicated governance and quality control systems10. Insufficient cybersecurity investment can further constrain the implementation of systematic safeguards11. Environmental constraints, including electromagnetic interference and 24/7 availability requirements, can limit the feasibility of security interventions in practice12. Uneven policy enforcement, third-party oversight gaps, insider misconduct, and external attacks may compound the threat landscape13.

Prior work proposes regulatory frameworks and technical defenses. Since 2014, the U.S. Food and Drug Administration has treated cybersecurity as a condition for medical-equipment approval, catalyzing security-by-design practices14. Methodological advances include multi-criteria evaluation using the Analytic Hierarchy Process-Technique for Order Preference by Similarity to an Ideal Solution (AHP-TOPSIS) for device and data risk15. Attack-probability-based management models have also been developed, building on the Fennigkoh-Smith approach16. Federated learning with blockchain has been explored to enable secure remote data sharing17. Lightweight cloud-edge security architectures have been proposed to improve confidentiality and computational efficiency in connected healthcare18. Optimized classifiers have further been used to enhance detection performance under resource constraints19. Blockchain-backed maintenance records can strengthen transparency and integrity for imaging devices20. Organizational programs combining policy, continuous education, and awareness training can strengthen threat identification and mitigation21. Such programs are most effective when embedded in routine governance and accountability mechanisms rather than implemented as one-time initiatives22.

However, many existing approaches are either technology-centered (e.g., intrusion detection, cryptography, blockchain-enabled exchange) or compliance-centered (e.g., regulatory checklists), and therefore provide limited operational guidance for hospital teams on how to (i) assign cross-department ownership at the level of concrete governance tasks, (ii) anchor maturity judgments to auditable evidence artifacts, and (iii) connect assessment outputs to a repeatable corrective-action cycle23. M-ATSSPD addresses this operational gap by offering a protocolized governance workflow with three practical advantages over common alternatives. First, instead of treating controls as an unstructured list, it operationalizes a task-by-task accountability structure by assigning ownership at the cell level of a lifecycle-by-domain matrix. Second, rather than relying on opinion-based maturity judgments, it requires each score to be justified by auditable evidence artifacts (e.g., policies, logs, configurations, incident tickets), thereby improving traceability and reproducibility. Third, it translates assessment results into an action-and-verification loop (score, prioritize, remediate, verify, and rescore), enabling governance improvement to be tracked over time rather than asserted as a one-off compliance outcome.

Grounded-theory analysis of semi-structured interviews with stakeholders across tertiary public hospitals synthesized 360 reference points into 149 initial concepts, 39 categories, 27 main categories, and 7 core categories. In line with the National Health Commission of the People's Republic of China's emphasis on strengthening hospital safety and quality management and monitoring24, the protocol adopts an SQ (I-SPORT) safety and quality matrix logic as the organizing scaffold for structuring cross-lifecycle governance and evidence-backed improvement25. On this basis, the M-ATSSPD protocol constructs a 6 × 6 matrix by coupling six data-lifecycle stages (Acquisition, Transmission, Storage, Sharing, Processing, and Disposal) with six governance domains (Organization & Personnel, Metadata, Compliance & Policies, Monitoring & Audit, Incident Response, and Technical Tooling). The protocol specifies an evidence-mapped scoring scheme with explicit 0-3 anchors, heat-map visualization for cell-level prioritization, and ownership/documentation rules to support cross-department coordination and iterative reassessment in public-hospital settings.

The protocol is intended for hospitals operating networked medical equipment and multi-vendor data flows, where relevant stakeholders and evidence artifacts can be accessed for scoring. Settings with limited artifact availability, highly outsourced data pathways, vendor-controlled data pathways, or governance responsibilities dispersed across external entities may require adapting evidence requirements and ownership assignments, and such constraints should be documented explicitly to preserve the interpretability of maturity scores.

Access restricted. Please log in or start a trial to view this content.

Protocol

1. Ethical approval and informed consent procedures

  1. Obtain approval from an institutional review board before recruitment.
  2. Provide each participant with an information sheet describing study aims, recording procedures, confidentiality protections, and withdrawal rights, and obtain written informed consent before conducting any interview.
  3. Record interviews only after receiving explicit permission.
  4. Transcribe recordings verbatim and de-identify transcripts by removing names, phone numbers, and site-specific identifiers.
  5. Store audio files, transcripts, and consent forms in an access-controlled repository with role-based permissions.
  6. Do not collect patient-level clinical data, and conduct all procedures in accordance with the Declaration of Helsinki.

2. Preparation 1 - Scope, team, and evidence artifacts

  1. Define the assessment scope by listing included equipment classes, connected systems, and participating departments.
  2. Draw an equipment-to-system data flow overview showing data sources, transmission links, storage endpoints, processing nodes, sharing interfaces, and disposal routes.
  3. Assemble a cross-functional team including clinical engineering, IT or security, compliance or legal, procurement or tendering, and representative clinical units.
  4. Assign responsibilities using a Responsible, Accountable, Consulted, and Informed (RACI) table and record the owner for each governance domain and lifecycle stage.
  5. Create an evidence artifact register and define required artifact types A to I: A policies and standard operating procedures; B access control lists and role definitions; C configuration baselines and security settings snapshots; D audit logs and monitoring reports; E network diagrams and data flow documentation; F vendor contracts and service level agreements; G training records and awareness documentation; H incident tickets and post incident reports; I verification reports for corrective actions.
  6. Assign a unique ID to each artifact using a fixed format and record metadata. Use the format SITE YYYY ART ### for artifact IDs, and record artifact type, owner, creation date, last update date, and storage location for each ID.
  7. Reference Figure 1 to align collection steps with the overall workflow.

3. Preparation 2 - Sources of information

  1. Literature retrieval and screening
    1. Search a national academic literature database (see Table of Materials) and record the exact query string used; use the query ("medical equipment" OR "medical device") AND ("data security" OR "information security" OR "cybersecurity") AND ("hospital" OR "healthcare institution").
    2. Search an engineering/technology literature database (see Table of Materials) and record the exact query string used; use the query ("medical equipment" OR "medical device") AND ("data security" OR "cybersecurity" OR "information security") AND (hospital OR healthcare).
    3. Restrict the publication window to 2018-08-01 to 2024-08-01 and record the restriction in a search log.
    4. Specify language restrictions explicitly and record "none" if no restriction is applied.
    5. Include peer-reviewed journal articles and conference papers, and exclude editorials, news items, patents, and non-scholarly commentary.
    6. Export all retrieved records in a standard citation format and remove duplicates using reference-management software (see Table of Materials).
    7. Archive the search log, exported records, and the deduplication log in the audit repository.
    8. Screen titles and abstracts for relevance, then screen full texts using predefined inclusion criteria.
      1. Include studies that address hospital contexts, medical equipment or device data flows, and data-security governance, controls, or assessment approaches; exclude studies that do not address medical equipment or device data or do not provide actionable governance or control information.
    9. Perform screening independently by two reviewers and resolve disagreements by consensus discussion.
    10. Record inclusion decisions and reasons for exclusion in a screening table.
  2. Methodological quality assessment during dual-review screening
    1. Apply the Mixed Methods Appraisal Tool (MMAT) to mixed-methods studies and apply the Critical Appraisal Skills Programme (CASP) qualitative checklist to qualitative-only studies; archive completed appraisal forms as screening evidence.
    2. Define an inclusion threshold before appraisal and document the threshold rule as meeting all critical items and at least 70% of total items.
    3. Appraise each eligible full text independently by two reviewers, record item-level judgments, and resolve appraisal disagreements by consensus or third-reviewer adjudication; archive the final appraisal table.

4. Recruitment and data collection

  1. Recruit stakeholders from 14 tertiary Grade-A hospitals in S City during 2024-08 to 2024-10 and document inclusion criteria for each role group.
  2. Begin recruitment with 36 participants and expand recruitment until 48 participants are reached or until saturation criteria are met.
  3. Define target role composition and document achieved composition, including hospital administrators with governance responsibilities, clinical engineers responsible for device deployment and maintenance, information technology personnel responsible for systems and infrastructure, and cybersecurity or information-security personnel responsible for monitoring, audit, and incident response.
  4. Index each participant with a unique participant ID and store a participant metadata table separately from transcript content.

5. Literature content analysis

  1. Import included publications into qualitative analysis software (see Table of Materials) and create a project file with a predefined folder structure (e.g., separate folders for included studies, codebook, memos, and exports).
  2. Create an initial codebook aligned to the study aim and define each code using four required elements: a code definition, inclusion criteria, exclusion criteria, and an exemplar quote or excerpt26.
  3. Code each document line-by-line by assigning codes to text segments and write an analytic memo after coding each document.
  4. Export a codebook report, a coded-segments report, and a memo log using the software's export/report function, and archive exported files with version numbers.

6. Semi-structured interviews

  1. Draft a semi-structured interview guide and ensure coverage of governance roles, data-lifecycle practices, evidence artifacts, incident handling, and vendor constraints.
  2. Pilot the interview guide and revise ambiguous questions for clarity and coverage.
  3. Conduct each interview for 30-60 min and record audio with permission.
  4. Transcribe each interview verbatim within 72 h and de-identify sensitive information using standardized tags.
  5. Assign each transcript a unique transcript ID and record metadata, including role, department, interview date, and interviewer ID.
  6. Archive transcripts, field notes, and consent forms in the audit repository.

7. Grounded-theory coding (Strauss - Corbin)

  1. Declare the analytic orientation before coding and document it in a coding memo; conduct primarily inductive coding, and record any sensitizing concepts used as prompts, including whether a concept influenced code naming or category grouping27.
  2. Calibrate coders and document disagreement resolution by having two coders independently code the same initial subset of transcripts, comparing codes unit-by-unit, and resolving disagreements using a documented rule that specifies retain, merge, or split actions; record all decisions in a decision log and update the codebook version after each adjudication cycle.
  3. Perform open coding.
    1. Conduct line-by-line open coding and assign short labels to meaning units.
    2. Attach at least one coded excerpt and one memo entry to each emerging category.
  4. Perform axial coding.
    1. Group open codes into categories by specifying conditions, actions or interactions, and consequences.
    2. Define properties and dimensions for each category and record them in a category table.
    3. Generate a relationship diagram linking categories and archive the diagram.
  5. Perform selective coding.
    1. Identify a core category that integrates the category system.
    2. Write explicit relational statements linking subcategories to the core category.
    3. Compile an analytic trace package including coded excerpts, memos, diagrams, and the final version of the codebook.
  6. Apply constant comparison and define the stopping rule by comparing new transcripts with previously coded transcripts to refine codes and categories; stop adding new categories when two consecutive coding cycles produce no materially new codes and no changes to category properties or dimensions.
  7. Calculate inter-coder agreement.
    1. Export coder-by-coder coding comparison data for the calibration subset and format it as a binary agreement table by coding unit; define each coding unit as "agree = 1" when both coders assign the same code to the same unit and "disagree = 0" otherwise.
    2. Calculate Cohen's κ using statistical software (see Table of Materials), archive the script, software output, and the final agreement table in the audit repository, and calculate a 95% confidence interval for κ using a bootstrap procedure (e.g., 1,000 resamples of coding units); report κ with the unit of analysis, the number of coded units, and the confidence interval28.

8. Theoretical saturation test

  1. Sample nine senior directors for confirmatory interviews and record eligibility criteria, including directors from the Hospital Administration Office, Medical Engineering, and Information.
  2. Re-code saturation-test transcripts against the stabilized codebook.
  3. Judge saturation by the presence or absence of new codes or categories across all saturation-test transcripts.
  4. Extend sampling and refine theory only if novel concepts appear; otherwise confirm saturation.

9. Construct the SQ (M-ATSSPD) matrix

  1. Define six lifecycle stages as Acquisition, Transmission, Storage, Sharing, Processing, and Disposal.
  2. Define six governance domains and record an operational definition for each domain29.
  3. Map observable indicators and required evidence artifacts to each 6 × 6 cell.
  4. Anchor cell scoring at 0-3 and document maturity anchors in a scoring manual.
    1. Define score 0 as missing with no acceptable evidence.
    2. Define score 1 as partial with incomplete evidence or inconsistent execution.
    3. Define score 2 as adequate with complete evidence and routine execution.
    4. Define score 3 as optimized with complete evidence, continuous monitoring, and verified improvement.
  5. Weight indicators where regulation or risk impact warrants and record rationales in a weighting table.

10. Heat-map visualization and prioritization

  1. Aggregate indicator scores to a single cell score using a documented formula and record the formula in the matrix workbook.
  2. Implement cell-score aggregation as a weighted mean of indicator scores using spreadsheet software (see Table of Materials) and store the formula in the score sheet.
  3. Generate a red-yellow-green heat map using spreadsheet software (see Table of Materials) with conditional-formatting rules and record key settings.
    1. Set the threshold rule as red for scores from 0.0 to 1.0, yellow for scores greater than 1.0 and up to 2.0, and green for scores greater than 2.0 and up to 3.0; apply the same thresholds across all cells and disable per-row normalization to preserve absolute comparability.
    2. Record the exact conditional-formatting rule set by exporting the formatting configuration or by capturing a versioned screenshot and archiving it with the workbook.
  4. Assign an owner, a deadline, a verification metric, and a closure-evidence requirement to each prioritized cell and record decisions in an action register.
  5. Integrate the heat-map review into routine governance meetings and update the action register after each cycle.

11. Retrospective incident analysis and verification (Hospital S, 3-year window)

  1. Extract information-security incident records for the previous 3 years and assign a unique incident ID to each record.
  2. Code each incident against the matrix and record supporting evidence for each coded incident.
  3. Quantify incident distribution by lifecycle stage and governance domain, and compute 95% confidence intervals using a prespecified method in statistical software (see Table of Materials).
    1. Compute confidence intervals for proportions using the Wilson method and archive the script and outputs.
  4. Cross-check attributions using a layered Swiss-cheese analysis and classify contributing factors into operational, technical, and management layers.
  5. Initiate a cross-department quality control circle project and define QCC as Quality Control Circle at first use.
  6. Perform root-cause analysis on high-frequency vulnerabilities and standardize countermeasures for replication and scale-up.
  7. Measure pre- and post-verification using predefined metrics, a defined timeframe, and a prespecified statistical comparison method.
    1. Define the pre-period as the baseline quarter immediately before implementation, and define the post-period as the quarter immediately after implementation.
    2. Measure outcome metric A as incident rate per quarter and compare pre versus post using a two-proportion test.
    3. Measure outcome metric B as median time to revoke access after staff offboarding and compare pre versus post using the Mann-Whitney U test.
    4. Measure outcome metric C as patch compliance within 30 days and compare pre versus post using a two-proportion test.
    5. Record metric definitions, data sources, comparison results, and supporting artifacts in the action register.
  8. Collect stakeholder feedback on feasibility and usability during governance meetings and record protocol modifications triggered by feedback.

12. Translate matrix outputs into controls and priority rules

  1. Build a matrix-based control tool sheet covering all 6 × 6 cells and score baseline status with attached evidence artifacts.
  2. Compute priority using Priority = (3 − Cell Score) × Risk Weight × (1 + Incident Frequency), record the full formula in the control tool sheet, and lock the calculation cells to prevent accidental edits.
  3. Apply boundary rules to prevent misleading rankings in the priority list.
    1. Set Priority = 0 when Cell Score = 3 regardless of Risk Weight or Incident Frequency.
    2. Cap Incident Frequency at a maximum value of 3 when incident counts are highly skewed, and record the cap rule and rationale in the control tool sheet.
  4. Assign ownership to each prioritized cell and document execution authority.
    1. Assign a single owner when implementation falls within one department's authority and record the accountable role, deadline, and verification metric in the action register.
    2. Assign co-ownership only when remediation requires shared authority across departments and record a named escalation path, a decision deadline, and a conflict-resolution rule in the action register.
  5. Enforce access minimization and role-based rules for the Sharing stage and record the permission model used.
    1. Define permitted roles, permitted data elements, permitted destinations, and time-bounded access conditions in an access rule table.
    2. Attach evidence artifacts supporting enforcement (e.g., access-control lists, approval records, or audit logs) to the relevant Sharing-related cells and record the evidence artifact IDs in the action register.
  6. Formalize third-party agreements and lawful bases for data processing and document the compliance basis used.
    1. Record data-processing purposes, data categories, retention periods, and security obligations in third-party agreements.
    2. Attach signed agreements and compliance review records as evidence artifacts for relevant Sharing- and Processing-related cells and record the evidence artifact IDs in the action register.
  7. Deploy behavior analytics for anomalous access and record detection rules and escalation criteria.
    1. Define at least three detection rules (e.g., abnormal access volume, access outside duty hours, repeated export attempts) and record alert thresholds and review frequency.
    2. Define an escalation workflow including notification roles, response timelines, and required evidence for closure (e.g., ticket record, log excerpt), and record closure criteria in the action register.
  8. Apply DICOM de-identification for research or exchange workflows and define DICOM as Digital Imaging and Communications in Medicine at first use.
    1. Define de-identification fields and suppression rules in a de-identification checklist.
    2. Verify de-identification by sampling exported files and confirming that predefined identifiers are removed or replaced; archive verification outputs as evidence artifacts and record their IDs.
  9. Record de-identification rules, verification evidence, and release approvals for each exchange event.
    1. Assign a unique exchange-event ID, record requester role, purpose, dataset scope, and destination, and attach the approval record.
    2. Attach the verification record and the release log to the corresponding Sharing cell in the action register and record the exchange-event ID.

13. Documentation and versioning

  1. Archive transcripts, codebooks, matrices, heat maps, scripts, and action logs in a secure, access-controlled repository with role-based permissions.
  2. Version all artifacts and maintain audit trails for code changes, weighting updates, and score revisions.
  3. Schedule reassessment every 6-12 months or after significant system changes and report updates to governance committees.
  4. End the protocol by issuing a versioned M-ATSSPD assessment package including the final matrix, heat map, action register, verification records, the expert-elicitation table (if used), and the analytic trace package.

Access restricted. Please log in or start a trial to view this content.

Results

Guided by grounded theory, evidence from the screened literature and the interview corpus was synthesized to derive a model of factors influencing hospital medical-equipment data security. Three-level coding (open, axial, and selective) was performed, and the analytic workflow is summarized below30.

Open coding
Source texts were examined line by line, retaining verbatim phrasing to preserve meaning and context. Meaning units were coded into sub-node...

Access restricted. Please log in or start a trial to view this content.

Discussion

This protocol operationalizes hospital medical-equipment data-security governance as a traceable, evidence-based workflow linking grounded theory outputs to a 6 × 6 maturity matrix and an action-and-verification loop. The SQ (M-ATSSPD) matrix was derived by integrating interview and literature evidence into stable categories and translating them into lifecycle stages (Acquisition, Transmission, Storage, Sharing, Processing, and Disposal) and governance domains (Organization and Personnel, Metadata, Compliance and Po...

Access restricted. Please log in or start a trial to view this content.

Disclosures

The authors have no conflict of interest to disclose.

Acknowledgements

This work was supported by the 2024 Medical Engineering Research Project of the Institute of Hospital Management, National Health Commission of the People's Republic of China (2024MEB115), and the 2024 Health Economics and Management Research Project of Jiangsu Provincial Health Commission (CW202407).

Access restricted. Please log in or start a trial to view this content.

Materials

List of materials used in this article
NameCompanyCatalog NumberComments
Qualitative analysis software (MAXQDA 24)VERBI Software GmbH (Berlin, Germany)N/A (License-based; order/serial in invoice)Used for literature content analysis and coding; export codebook/coded segments/memos and archive with version numbers.
Statistical computing software (R v4.3.2)R Foundation for Statistical Computing (Vienna, Austria)N/A (Open-source)Used for Cohen’s κ, Wilson CI, and statistical comparisons; archive scripts and outputs.
R package “irr” (κ calculation)Comprehensive R Archive Network (CRAN)N/A (Open-source)Used for Cohen’s κ (e.g., kappa2); record package version used.
Spreadsheet software (Microsoft Excel / Microsoft 365 Excel)Microsoft Corporation (Redmond, WA, USA)N/A (License-based)Used for weighted scoring formulas and conditional-format heat map; archive workbook and rule settings.
Reference-management software (choose one: EndNote or Zotero)Clarivate (EndNote) / ZoteroN/A (License-based/Open-source)Used for exporting citations and deduplication; archive deduplication log.
China National Knowledge Infrastructure (CNKI)CNKI (Tsinghua Tongfang)N/A (Online subscription)Literature retrieval database; record exact query, filters, and export format in search log.
IEEE XploreIEEEN/A (Online subscription)Literature retrieval database; record exact query, filters, and export format in search log.
Mixed Methods Appraisal Tool (MMAT, 2018)MMAT authors (Hong et al.)N/AQuality appraisal tool for mixed-methods studies; archive completed appraisal table.
CASP Qualitative Checklist (latest version used)Critical Appraisal Skills Programme (CASP)N/AQuality appraisal checklist for qualitative-only studies; archive completed appraisal table.
Secure, access-controlled repository (encrypted storage)Institutional IT / compliant cloud / on-premN/AStore audio, transcripts, consent forms, scripts, matrices, heat maps, and audit trails with role-based permissions.
Audio recorder (digital recorder or smartphone)Any equivalentN/ARecord interviews with permission; model optional if a specific device was used.
Computer workstationAny equivalentN/AUsed for coding, scoring, analysis, and archiving.
Transcription tool/workflowAny equivalentN/AVerbatim transcription + de-identification; keep workflow secure.
De-identification tag templateSelf-preparedN/AStandard tags for removing identifiers in transcripts.
Participant information sheet + consent formSelf-preparedN/ARequired for informed consent and confidentiality protections.
Screening table templateSelf-preparedN/ARecord inclusion/exclusion decisions and reasons.
Evidence artifact registerSelf-preparedN/ARegister artifacts (A–I) with IDs =, owners, dates, and locations.
Matrix workbook template (6 × 6)Self-prepared (spreadsheet)N/AContains indicators, weights, formulas, cell scores, and documentation fields.
Heat-map rule set documentationSelf-prepared (export/screenshot)N/AStore conditional-format thresholds and absolute comparability settings.
Action register templateSelf-preparedN/ARecord prioritized cells, owners, deadlines, verification metrics, and closure evidence.
Coding decision log + versioned codebookSelf-prepared / exportedN/ARecord retain/merge/split decisions and codebook versioning after adjudication.
Analytic trace packageSelf-prepared / exportedN/ACoded excerpts, memos, diagrams enabling traceable grounded-theory transparency.

References

  1. Goldman, J. M., Weininger, S., Jaffe, M. B. Applying Medical Device Informatics to Enable Safe and Secure Interoperable Systems: Medical Device Interface Data Sheets. Anesth Analg. 131 (3), 969-976 (2020).
  2. Seh, A. H., et al. Healthcare Data Breaches: Insights and Implications. Healthcare (Basel). 8 (2), 133(2020).
  3. Aldosari, B. Cybersecurity in Healthcare: New Threat to Patient Safety. Cureus. 17 (5), e83614(2025).
  4. Shams, F. A., et al. Insights into Internet of Medical Things (IoMT): Data fusion, security issues and potential solutions. Information Fusion. 102, 102060(2024).
  5. Zarour, M., et al. Ensuring data integrity of healthcare information in the era of digital health. Healthcare Technology Letters. 8, 66-77 (2021).
  6. Williams, P. A., Woodward, A. J. Cybersecurity vulnerabilities in medical devices: a complex environment and multifaceted problem. Medical Devices (Auckland). 8, 305-316 (2015).
  7. Willing, M., et al. Analyzing medical device connectivity and its effect on cyber security in German hospitals. BMC Med Inform Decis Mak. 20 (1), 106(2020).
  8. Perneger, T. V. The Swiss cheese model of safety incidents: are there holes in the metaphor. BMC Health Services Research. 5 (1), 71(2005).
  9. Grimes, S. L., Wirth, A. The Case for Medical Device Cybersecurity Hygiene Practices for Frontline Personnel. Biomed Instrum Technol. 55 (3), 96-99 (2021).
  10. Richter, S., Ammenwerth, E. IT risk management for medical devices in hospital IT networks: a catalogue of measures and indicators. BMJ Health Care Inform. 30 (1), e100639(2023).
  11. Uwizeyemungu, S., Poba-Nzaou, P., Cantinotti, M. European Hospitals' Transition Toward Fully Electronic-Based Systems: Do Information Technology Security and Privacy Practices Follow. JMIR Med Inform. 7 (3), e13555(2019).
  12. Aboelmaged, M., Hashem, G. RFID application in patient and medical asset operations management: A technology, organizational and environmental (TOE) perspective into key enablers and impediments. Int J Med Inform. 112, 111-121 (2018).
  13. Daryanani, A. E., et al. Ensuring Medical Device Safety: The Role of Standards Organizations and Regulatory Bodies. J Med Syst. 49, 16(2025).
  14. Food and Drug Administration. Cybersecurity in Medical Devices: Quality System Considerations and Content of Premarket Submissions; Guidance for Industry and Food and Drug Administration Staff. Fed Regist. 88 (186), 66458-66460 (2023).
  15. Alzahrani, F. A., Ahmad, M., Ansari, M. T. J. Towards Design and Development of Security Assessment Framework for Internet of Medical Things. Appl Sci. 12, 8148(2022).
  16. Kim, D. W., Choi, J. Y., Han, K. H. Medical Device Safety Management Using Cybersecurity Risk Analysis. IEEE Access. 8, 115370-115382 (2020).
  17. Li, N., et al. A data sharing method for remote medical system based on federated distillation learning and consortium blockchain. Connect Sci. 35 (1), 1-18 (2023).
  18. Mehrtak, M., et al. Security challenges and solutions using healthcare cloud computing. J Med Life. 14 (4), 448-461 (2021).
  19. Balhareth, G., Ilyas, M. Optimized Intrusion Detection for IoMT Networks with Tree-Based Machine Learning and Filter-Based Feature Selection. Sensors (Basel). 24 (17), 5712(2024).
  20. Omar, I. A., Hasan, H. R., AlKhader, W., Jayaraman, R., Salah, K., Omar, M. Blockchain-based trusted accountability in the maintenance of medical imaging equipment. Expert Systems with Applications. 241, 122718(2024).
  21. Alhammad, A., Yusof, M. M., Jambari, D. I. Evaluating applied security controls for safeguarding medical device-integrated electronic medical records. J Eval Clin Pract. 30 (2), 256-265 (2024).
  22. Scally, G., Donaldson, L. J. Clinical governance and the drive for quality improvement in the new NHS in England. BMJ. 317 (7150), 61-65 (1998).
  23. He, Y., Aliyu, A., Evans, M., Luo, C. Health Care Cybersecurity Challenges and Solutions Under the Climate of COVID-19: Scoping Review. J Med Internet Res. 23 (4), e21747(2021).
  24. Zhang, Y., et al. Quantitative analysis of medical quality intelligent management policies in China: a PMC index model approach. Front Public Health. 13, 1716942(2025).
  25. Strauss, A., Corbin, J. Basics of Qualitative Research: Grounded Theory Procedures and Techniques. Sage. , Newbury Park, CA, US. (1990).
  26. Zhang, D., Liao, M., Liu, T. Implementation and Promotion of Quality Control Circle: A Starter for Quality Improvement in Chinese Hospitals. Risk Manag Healthc Policy. 13, 1215-1224 (2020).
  27. Hsieh, H. F., Shannon, S. E. Three approaches to qualitative content analysis. Qual Health Res. 15 (9), 1277-1288 (2005).
  28. McHugh, M. L. Interrater reliability: the kappa statistic. Biochem Med (Zagreb). 22 (3), 276-282 (2012).
  29. Donabedian, A. The quality of care: how can it be assessed. JAMA. 260 (12), 1743-1748 (1988).
  30. Chun Tie, Y., Birks, M., Francis, K. Grounded theory research: A design framework for novice researchers. SAGE Open Med. 7, 2050312118822927(2019).
  31. Foley, G., Timonen, V. Using Grounded Theory Method to Capture and Analyze Health Care Experiences. Health Serv Res. 50 (4), 1195-1210 (2015).
  32. Kendall, J. Axial coding and the grounded theory controversy. West J Nurs Res. 21 (6), 743-757 (1999).
  33. Runciman, W. B., Williamson, J. A., Deakin, A., Benveniste, K. A., Bannon, K., Hibbert, P. D. An integrated framework for safety, quality and risk management: an information and incident management system based on a universal patient safety classification. Qual Saf Health Care. 15 (Suppl 1), i82-i90 (2006).
  34. Reason, J. Human error: models and management. BMJ. 320 (7237), 768-770 (2000).
  35. Halligan, A., Donaldson, L. Implementing clinical governance: turning vision into reality. BMJ. 322 (7299), 1413-1417 (2001).
  36. Taylor, M. J., McNicholas, C., Nicolay, C., Darzi, A., Bell, D., Reed, J. E. Systematic review of the application of the plan-do-study-act method to improve quality in healthcare. BMJ Qual Saf. 23 (4), 290-298 (2014).
  37. Ostermann, M., et al. Cybersecurity requirements for medical devices in the EU and US - A comparison and gap analysis of the MDCG 2019-16 and FDA premarket cybersecurity guidance. Comput Struct Biotechnol J. 28, 259-266 (2025).

Access restricted. Please log in or start a trial to view this content.

Reprints and Permissions

Tags

Hospital Data SecurityData Audit ProtocolCompliance PoliciesIncident ResponseCross-Departmental Coordination