의료기관 종별 전자의무기록 정보보안 실태와 보안 관리 인식 제고의 차이

The Differences in Information Security Status and Security Management Awareness of Electronic Medical Records by Medical Institution Type

초록

Background: This study assesses information security levels, including institutional and technical vulnerabilities, and proposes policy improvements for healthcare institutions. Electronic medical records (EMRs) are legally protected under the Medical Service Act, and tertiary hospitals follow additional government regulations. However, general hospitals lack comprehensive oversight, highlighting the need for research on enhancing their information security management. Methods: Data from the “Healthcare Institution Information Security Survey” conducted by the Ministry of Health and Welfare (Nov. 2023–Jan. 2024) were analyzed. Among the 219 sampled institutions, 158 responded (37 tertiary, 118 general, and 3 hospitals), yielding a 72.10% response rate. The data were anonymized, cleaned, and analyzed. Information security status was treated as a categorical dependent variable, whereas the need for centralized management was binary. The independent variables included security personnel, equipment, practices, awareness, backup/recovery measures, and incident prevention, assessed via multiple-response survey methods. Results: The survey showed that 59.5% of general hospitals lacked dedicated security personnel, and only 57% of institutions conducted incident monitoring. Approximately 70% of EMRs were Internet-connected; however, technical protections, such as IPS and NAC, were limited. Key gaps included uneven staffing, insufficient personnel relative to system needs, inadequate security equipment, the absence of size-differentiated policies, and low monitoring levels reflecting the perceived necessity level and costs. Conclusion: The policy recommendations include establishing differentiated management standards by hospital size and type, expanding incident notifications and responses, ensuring sufficient budgets and personnel for security management, enforcing administrative sanctions for noncompliance, and integrating mandatory monitoring into accreditation. This study highlights the importance of legal and financial support for general hospitals and clarifies the direction for future EMR security policies to ensure sustainable information security across healthcare institutions.

키워드

Electronic health recordsComputer securityHospital information systemsRadiology information systems
제목
의료기관 종별 전자의무기록 정보보안 실태와 보안 관리 인식 제고의 차이
제목 (타언어)
The Differences in Information Security Status and Security Management Awareness of Electronic Medical Records by Medical Institution Type
저자
Shin Bum SunYu Hyun JiSeo Hwa Jeong
DOI
10.52937/hira.26.6.1.e1
발행일
2026-05
유형
Y
저널명
HIRA Research
6
1
페이지
102 ~ 116