When technical risk-reducing measures for healthcare-related issues cannot be implemented immediately, the organization should apply temporary administrative controls to limit exposure until permanent solutions are in place.
Risk assessments should be supported by appropriate expertise and involve healthcare representatives where relevant, and shall explicitly consider the potential consequences for patients and the provision of healthcare.
To ensure proper handling and oversight:
- Risk assessors must have a clear escalation path to management or the board
- Results of the assessment and planned follow-up actions shall be communicated to leadership at the appropriate level
These steps ensure that risks are addressed effectively and remain visible to decision-makers.