Skip to main content :::
Taichung Armed Forces General Hospital Sustainable Development SCROLL DOWN

Performance Management

:::

2.4 Risk Management

To ensure the continuity of medical services, patient safety, and sustainable organizational development, our hospital has established a comprehensive risk management system addressing areas such as climate change, medical disputes, information security, personal data protection, and emergency disaster response. This system is integrated into the hospital’s governance framework and coordinated by the Sustainability Development Committee, which oversees risk identification, assessment, monitoring, and improvement processes. Through cross-departmental collaboration and regular review mechanisms, we continuously enhance the organization’s operational resilience and risk governance capabilities.

Our hospital’s risk management adheres to the principles of prevention first, systematic management, and continuous improvement. Risk management is integrated into daily operational decision-making, fostering a risk governance culture led by senior management to ensure that all potential risks are identified early, effectively controlled, and appropriately addressed.

Climate Risk Identification

In response to the global challenge of climate change, our hospital will adopt the TCFD (Task Force on Climate-related Financial Disclosures) framework to develop a systematic climate risk management system. Climate change considerations will be integrated into our overall risk management processes to strengthen the resilience of medical services and promote sustainable development.

The climate-related risks identified by our hospital include the following:

1. Physical Risks

Extreme heat, heavy rainfall, typhoons, and other severe weather events may cause:

2. Transition Risks

Including:

3. Healthcare Industry-Specific Risks

Including:

Our hospital employs a dual-axis risk matrix for risk assessment, evaluating risks based on the “likelihood of occurrence” and the “degree of impact.” The resulting risk levels are used to prioritize management actions and serve as the foundation for resource allocation and decision-making.

The assessment results are presented in the figure below:

Impact Level
(Impact or Consequence)
Low Risk
(Score 1)
Medium Risk
(Score 2)
High Risk
(Score 3)
Extreme Threats (Score 4) Level 3 Level 3 Level 4
◆ Fire
Impact on Personal Safety (Score 3) Level 2 Level 3
◆ High-pressure oxygen gas leakage
◆ Natural disasters
◆ Medical violence
Level 3
Impacting Multiple Units (Score 2) Level 2
◆ Electromechanical and water/electric facility failures
◆ Information crisis
Level 2 Level 3
◆ Nosocomial infection clusters
◆ Medical disputes
Impact on a Few Units (Score 1) Level 1
◆ News Media Incident
◆ Nursing Staff and Nurse-to-Patient Ratio
Level 2 Level 2
Event Occurrence Probability Low Risk
(Score 1)
Medium Risk
(Score 2)
High Risk
(Score 3)

Note: Level 4 represents the highest risk level and requires immediate response measures. Each risk item is regularly reviewed and updated by the Sustainable Development Committee.

Facing the increasing frequency of extreme climate events and the potential impacts of climate change on the healthcare system, our hospital continuously strengthens its climate adaptation capabilities and integrates related risks into the overall risk management framework to ensure uninterrupted medical services and patient safety.

Regarding infrastructure resilience, our hospital continuously enhances its backup power systems to ensure that emergency rooms, intensive care units, operating rooms, and critical medical equipment can maintain normal operations during power outages or natural disasters. Additionally, to address the risks posed by increased energy loads and reduced equipment performance caused by extreme heat, we consistently improve the efficiency of air conditioning and cooling systems to maintain a suitable medical environment and ensure stable equipment operation across the campus.

In terms of disaster prevention and resource management, our hospital has implemented flood prevention facilities and drainage improvement measures to reduce the risk of campus flooding caused by heavy rainfall and typhoons. We have also established a water resource backup system to ensure that medical operations and patient care can be maintained during water supply disruptions. Additionally, in response to natural disasters and extreme weather events, we continuously optimize disaster response plans and regularly conduct drills and emergency response training to enhance the capabilities of each unit and improve disaster recovery efficiency.

Regarding the continuous management of medical services, our hospital has established high-temperature response procedures that include preventive measures for patient care, employee health management, and equipment operation under extreme heat conditions. These measures aim to minimize the impact of extreme temperatures on medical quality and occupational safety. Additionally, to mitigate the risk of supply chain disruptions caused by global climate change, our hospital has implemented a secure inventory system for critical drugs and medical devices and developed a diversified supplier management strategy to enhance the stability of medical supplies and improve risk diversification.

Furthermore, our hospital incorporates climate-related risks into medical quality management, infection control, occupational safety and health, and operational management systems. Through cross-departmental coordination and regular review mechanisms, we continuously monitor risk changes and the implementation of improvement measures, thereby enhancing overall risk governance effectiveness and organizational resilience.

In the future, our hospital will continue to adhere to climate risk management and sustainable development principles by strengthening infrastructure resilience, maintaining continuous medical service operations, and enhancing supply chain risk management. These efforts aim to improve our capacity to adapt to the impacts of climate change, ensuring the provision of safe, stable, and high-quality medical services amid various environmental challenges.

Enhance information security governance capabilities

With the rapid advancement of digital healthcare, information systems have become the core infrastructure for medical service operations. Information security management not only safeguards patient privacy but also directly impacts the continuity of medical services and the resilience of organizational operations. Taichung Armed Forces General Hospital integrates information security into its overall governance framework and risk management processes. The information management unit centrally oversees the promotion of information security policies, risk assessments, monitoring, and incident response. Through institutionalized management mechanisms and continuous improvement, we have established an information security protection system that combines prevention, monitoring, response, and recovery capabilities to ensure the stable operation of medical information systems and the security of patient data.

To enhance information security governance capabilities, our hospital integrates information security resources within the military medical system and incorporates the Security Operations Center (SOC) established by the Military Medical Bureau. This center operates a 24/7 continuous monitoring, threat detection, and incident response mechanism. Utilizing a centralized monitoring platform, it analyzes abnormal behaviors, suspicious connections, and potential attack risks in real time. This approach effectively strengthens the protection of medical information systems, network equipment, and critical infrastructure, minimizes the impact of information security incidents on medical services, and ensures uninterrupted patient care.

Our hospital is classified as a Level B agency under the Digital Development Department of the Executive Yuan’s “Information and Communication Security Management Act.” In compliance with regulatory requirements, we have established a comprehensive information security management system and regularly undergo third-party inspections and verifications. Every two years, we participate in a cybersecurity health check led by the Ministry of National Defense’s Communications Office, with a health check team composed of information security management experts from the Information and Communication Electronic Military. Additionally, as required, we conduct penetration testing biennially and perform annual host vulnerability scans to continuously assess the security and potential risks of our information systems. The related cybersecurity verification operations for 2024 to 2025 have been completed in accordance with regulations and comply with information and communication security legal requirements.

Beyond meeting regulatory inspection requirements, our hospital regularly conducts emergency response drills for information systems to enhance system stability and disaster response capabilities. Monthly cybersecurity and system anomaly simulation drills cover scenarios such as system crashes, hacker intrusions, equipment failures, natural disasters, and network attacks that could impact medical services. Comprehensive standard operating procedures (SOPs) have been established. Through continuous drills and a review and improvement process, we strengthen staff response capabilities to information security incidents, improve system disaster recovery efficiency, and enhance overall operational resilience.

Our hospital’s information security regulatory compliance status:

Item Cycle Execution Time Executing Unit
Cybersecurity Health Check Every two years April 15–26, 2024 Ministry of National Defense
Penetration Testing Every two years 2025.11.17 Thomas Software Consulting Limited Company
Vulnerability Scanning Annually 2025.9.12 CHT Security
Emergency Drill Monthly Second Week Information and Communications Management

To continuously enhance the maturity of our information security management, our hospital completed the ISO 27001 Information Security Management System third-party certification in 2025. The certification was issued by Alpha International Co., Ltd., and is valid from August 6, 2025, to August 5, 2028. The scope of this certification includes management aspects such as the formulation of information security policies, risk assessment procedures, design of control measures, internal audit mechanisms, and continuous improvement processes. This certification demonstrates that our hospital’s information security management system fully complies with international standards.

Through the implementation of the ISO 27001 management system, our hospital has established a systematic, traceable, and continuously improving information security management framework. This framework comprehensively strengthens the security protection capabilities of the Hospital Information System (HIS), Picture Archiving and Communication System (PACS), and Electronic Medical Record (EMR) system, enhancing the reliability and operational resilience of our digital healthcare infrastructure. As a result, medical services maintain high security and stable operation within a digital environment.

Regarding patient data governance and personal data protection, our hospital adheres to the Personal Data Protection Act and relevant medical ethics regulations to establish a comprehensive management system covering the entire data lifecycle. This system includes measures such as data minimization during collection, restrictions on usage purposes, access permission controls, encrypted storage, data retention policies, and secure destruction procedures to ensure that patient privacy and personal data security are fully protected.

In addition, our hospital continuously enhances staff awareness of compliance and information security literacy through institutionalized hierarchical access management, information system account controls, and regular education and training programs. In 2025, we conducted ongoing information security and personal data protection training sessions, achieving a participation rate exceeding 90%. This effectively reduced information security risks caused by human error and further strengthened the overall organizational information security culture.

As of 2025, our hospital has not experienced any major patient data breaches nor been involved in significant legal disputes or lawsuits related to personal data protection. This demonstrates that our hospital’s information security governance and privacy protection systems have achieved stable and mature management effectiveness. Additionally, our hospital continues to strengthen emergency response capabilities through monthly disaster and cybersecurity scenario drills to minimize incident impact, reduce damage, and ensure that medical services can quickly resume normal operations under abnormal conditions.

The 2025 SOC information security monitoring statistics indicate that a total of 596 security incidents were monitored throughout the year, including 5 high-risk incidents, 490 medium-risk incidents, and 101 low-risk incidents. All incidents were promptly detected, analyzed, and addressed through the SOC monitoring system. There were no incidents resulting in patient data leakage, medical service interruptions, or affected individuals during the year, demonstrating that our hospital’s information security protection mechanisms have strong monitoring effectiveness and risk control capabilities.

2025 National Army Taichung General Hospital Information Security Monitoring (SOC) Notification Statistics Table

Interval Monitoring Level Connection Count Number of People Affected or Incidents
High Medium Low Total
January 2025 0 57 5 62 0
February 2025 0 63 5 68 0
March 2025 0 55 6 61 0
April 2025 0 48 11 59 0
May 2025 0 53 11 64 0
June 2025 5 30 11 46 0
July 2025 0 24 15 39 0
August 2025 0 41 11 52 0
September 2025 0 16 4 20 0
October 2025 0 21 12 33 0
November 2025 0 13 5 18 0
December 2025 0 69 5 74 0
Total 5 490 101 596 0

Looking ahead, our institute will continue to deepen information security governance and enhance digital resilience. We plan to implement the “Zero Trust Architecture” and “Endpoint Detection and Response (EDR)” systems by 2026 to further strengthen identity authentication management, abnormal behavior monitoring, and endpoint device protection capabilities. Simultaneously, we will continue conducting social engineering drills and phishing email tests to improve all staff members’ ability to recognize information security threats and increase their awareness of incident reporting. Additionally, our institute will keep refining digital governance mechanisms and the quality of sustainable information disclosure, thereby strengthening governance transparency, risk management effectiveness, and organizational resilience. Our goal is to steadily progress toward becoming a smart medical institution with international compatibility, a high level of information security protection, and sustainable competitiveness.

view:15updated date:2026-08-22Back

You are about to leave this website. Continue?