With the acceleration of hospital informatization and the rise of smart healthcare, medical equipment has become increasingly networked and interoperable, making equipment-generated data a core asset for clinical decision-making and hospital operations1. These data may include personally identifiable information, device operational logs, and diagnostic outputs such as physiological parameters, imaging objects, and treatment records, which are closely linked to patient privacy and care quality2. Security incidents involving such data can directly affect patient safety and trust in clinical services3.
Despite growing attention, multiple challenges persist. In Internet of Medical Things (IoMT) environments, external intrusions and unauthorized insider disclosures remain dominant breach patterns4. Data integrity can be fragile where devices lack robust validation mechanisms, leaving records vulnerable to tampering that may mislead diagnosis and treatment5. Heterogeneous vendor ecosystems and inconsistent security standards complicate secure data exchange across devices and systems6. Legacy equipment often operates beyond safe maintenance windows and cannot receive timely security patches7. Human factors, including limited security awareness and operational lapses, further elevate organizational vulnerability8. Default credentials, unencrypted communications, and weak access control increase the attack surface9. Hospitals may also prioritize functionality over security and lack dedicated governance and quality control systems10. Insufficient cybersecurity investment can further constrain the implementation of systematic safeguards11. Environmental constraints, including electromagnetic interference and 24/7 availability requirements, can limit the feasibility of security interventions in practice12. Uneven policy enforcement, third-party oversight gaps, insider misconduct, and external attacks may compound the threat landscape13.
Prior work proposes regulatory frameworks and technical defenses. Since 2014, the U.S. Food and Drug Administration has treated cybersecurity as a condition for medical-equipment approval, catalyzing security-by-design practices14. Methodological advances include multi-criteria evaluation using the Analytic Hierarchy Process-Technique for Order Preference by Similarity to an Ideal Solution (AHP-TOPSIS) for device and data risk15. Attack-probability-based management models have also been developed, building on the Fennigkoh-Smith approach16. Federated learning with blockchain has been explored to enable secure remote data sharing17. Lightweight cloud-edge security architectures have been proposed to improve confidentiality and computational efficiency in connected healthcare18. Optimized classifiers have further been used to enhance detection performance under resource constraints19. Blockchain-backed maintenance records can strengthen transparency and integrity for imaging devices20. Organizational programs combining policy, continuous education, and awareness training can strengthen threat identification and mitigation21. Such programs are most effective when embedded in routine governance and accountability mechanisms rather than implemented as one-time initiatives22.
However, many existing approaches are either technology-centered (e.g., intrusion detection, cryptography, blockchain-enabled exchange) or compliance-centered (e.g., regulatory checklists), and therefore provide limited operational guidance for hospital teams on how to (i) assign cross-department ownership at the level of concrete governance tasks, (ii) anchor maturity judgments to auditable evidence artifacts, and (iii) connect assessment outputs to a repeatable corrective-action cycle23. M-ATSSPD addresses this operational gap by offering a protocolized governance workflow with three practical advantages over common alternatives. First, instead of treating controls as an unstructured list, it operationalizes a task-by-task accountability structure by assigning ownership at the cell level of a lifecycle-by-domain matrix. Second, rather than relying on opinion-based maturity judgments, it requires each score to be justified by auditable evidence artifacts (e.g., policies, logs, configurations, incident tickets), thereby improving traceability and reproducibility. Third, it translates assessment results into an action-and-verification loop (score, prioritize, remediate, verify, and rescore), enabling governance improvement to be tracked over time rather than asserted as a one-off compliance outcome.
Grounded-theory analysis of semi-structured interviews with stakeholders across tertiary public hospitals synthesized 360 reference points into 149 initial concepts, 39 categories, 27 main categories, and 7 core categories. In line with the National Health Commission of the People's Republic of China's emphasis on strengthening hospital safety and quality management and monitoring24, the protocol adopts an SQ (I-SPORT) safety and quality matrix logic as the organizing scaffold for structuring cross-lifecycle governance and evidence-backed improvement25. On this basis, the M-ATSSPD protocol constructs a 6 × 6 matrix by coupling six data-lifecycle stages (Acquisition, Transmission, Storage, Sharing, Processing, and Disposal) with six governance domains (Organization & Personnel, Metadata, Compliance & Policies, Monitoring & Audit, Incident Response, and Technical Tooling). The protocol specifies an evidence-mapped scoring scheme with explicit 0-3 anchors, heat-map visualization for cell-level prioritization, and ownership/documentation rules to support cross-department coordination and iterative reassessment in public-hospital settings.
The protocol is intended for hospitals operating networked medical equipment and multi-vendor data flows, where relevant stakeholders and evidence artifacts can be accessed for scoring. Settings with limited artifact availability, highly outsourced data pathways, vendor-controlled data pathways, or governance responsibilities dispersed across external entities may require adapting evidence requirements and ownership assignments, and such constraints should be documented explicitly to preserve the interpretability of maturity scores.