Jump to the main content block
院內搜尋

Smart Hospital

-Smart Hospital-

1

The vision of a smart hospital is not merely about introducing new technologies, but more importantly, about how to continuously elevate medical quality and accessibility through innovative methods. NCKU Hospital ranked 140th globally in the "World's Best Smart Hospitals 2026" voted by Newsweek in the United States, and has entered the list for two consecutive years, clearly demonstrating that the Hospital's smart healthcare achievements have received high international recognition. In the future, the Hospital will continue to exert its innovative spirit, deepen cross-disciplinary collaboration, and ensure that smart healthcare is not only an international pride but also integrated into the daily medical care of every patient, achieving the true value and vision of smart healthcare.

World's Best Smart Hospital

In response to the increasingly complex medical demands and the rapid development of smart technology, NCKU Hospital continuously leverages digital transformation to elevate medical quality, operational efficiency, and service resilience. Through the introduction of digital tools and the reshaping of medical workflows, NCKU Hospital not only enhances clinical decision-making efficiency and service quality, but also strengthens patient safety, continuity of care, and the protection of human subjects' rights, demonstrating a concrete practice of technology-driven medical innovation and quality advancement.

Digital Transformation

Medical Information Workflow Optimization

NCKU Hospital continuously pursues "elevating medical efficiency, strengthening patient safety, and optimizing the service experience" as its goals to promote medical information workflow optimization. Through electronic medical records (EMR), the Clinical Advanced Record Database (CARD), smart healthcare systems, and cross-system data linking, the Hospital integrates key information across outpatient, emergency, inpatient, laboratory tests and examinations, medical imaging, and physiological monitoring. This enables the medical team to master comprehensive patient data in real time, reducing repetitive typing, manual compilation, and information gaps, thereby elevating the efficiency of clinical judgment and care decision-making.

Meanwhile, through the standardization of information workflows and real-time data utilization, the Hospital strengthens communication and care transitions across different departments and interprofessional teams, making medical services smoother—from data collection, diagnostic judgment, and examination scheduling to subsequent follow-ups. Relevant information can also further support clinical research, quality improvement, and smart applications, promoting the gradual transition of medical services from experience-oriented to data-assisted decision-making.

2

Achievements in Information System Digital Transformation

Through the continuous promotion of digital transformation in medical and administrative operations, the Hospital leverages electronic medical records, cross-system information integration, and workflow optimization as foundations to gradually construct a safe, highly efficient, and real-time smart healthcare environment, enabling the medical team to utilize real-time and accurate data as the basis for clinical judgment and care decision-making.

Meanwhile, by reducing paper documents and minimizing manual entry as well as repetitive tasks, the Hospital elevates administrative efficiency and internal management performance while lowering the risk of operational errors. Under the dual-track parallel implementation of institutional regulations and information technology, the Hospital continuously strengthens regulatory compliance, data governance, and information security management, laying a solid foundation for smart healthcare development and the hospital's sustainable operations. The concrete implementation achievements are as follows:

3      4

5

6

  • Healthcare Information Security

Information Security Certifications

Since 2016, the Hospital has passed ISO 27001 information security certification and completed the ISO 27001:2022 transition certification in 2024, with the certificate validity extending until December 7, 2027. To ensure the continuous and effective operation of the information security system, recertification is conducted every three years, and surveillance audits are accepted annually, continuously reviewing potential risks and strengthening protective measures.

To elevate the application benefits of medical data, the Hospital utilizes the Quanta QOCA aim low-code platform to integrate physiological data collected by Quanta IoT devices (QOCA apc, QOCA abc) and links it with CARD platform data. Through the integration and bridging of information and communication data streams, the Hospital rapidly builds models and conducts inference analysis, achieving more efficient, real-time, and clinically valuable data applications. By participating in smart healthcare-related exhibitions and exchanges, the Hospital actively demonstrates innovative achievements, absorbs international experience in information and communication streaming architecture, and continuously strengthens its information integration capabilities and international competitiveness.

7

Cybersecurity Joint Defense Mechanism

As a critical infrastructure in the medical field, NCKU Hospital has been designated by the National Security Office of the Executive Yuan as an A-level agency in information and communication security responsibility. The Hospital has established an information security governance system, formulated relevant operational standards, and annually retained professional consultants to guide the refinement and implementation of its information security maintenance plan. Execution progress is periodically reported in the Executive Yuan's management and evaluation system to ensure that information security management meets both regulatory requirements and medical operational needs.

To strengthen cybersecurity joint defense and real-time monitoring capabilities, the Hospital has joined the Health Information Sharing and Analysis Center (H-ISAC) for the healthcare sector to share cybersecurity intelligence with peer institutions and enhance staff cybersecurity awareness through internal communications. The Hospital has also commissioned a top-rated cybersecurity firm to establish a Security Operations Center (SOC) to monitor the Hospital’s cybersecurity status in real time and simultaneously transmit incident information to the Ministry of Health and Welfare’s H-SOC platform and the National Security Operations Center (N-SOC) platform, elevating the efficiency of cybersecurity incident detection, notification, and prevention.

8

9

10

Furthermore, the Hospital coordinates with competent authorities annually to conduct cybersecurity incident reporting and response drills, refining its capabilities in incident notification, disposal, recovery, and business continuity. In 2025, the Hospital participated in the Cyber Offensive and Defensive Exercise (CODE) organized by the Ministry of Digital Affairs, forming a joint defense alliance with other medical centers. Through real-world offensive and defensive simulations, intelligence sharing, and joint defense collaboration, the Hospital elevated its response resilience against emerging cybersecurity threats, continuously safeguarding the stable operation of medical services and the security of patient data.

11

12

Cybersecurity Protection and Governance

With the acceleration of smart healthcare and hospital digital transformation, NCKU Hospital regards cybersecurity governance as a critical cornerstone for safeguarding patient privacy and operational resilience. Through systematic education and training, rigorous decision-making mechanisms, and highly efficient technical defense, the Hospital is dedicated to constructing a secure and trustworthy digital medical environment.

In terms of elevating personnel protection awareness, the Hospital conducts more than 4 hospital-wide cybersecurity awareness courses annually, with contents focusing primarily on personal cybersecurity protection and social engineering prevention. To ensure learning effectiveness, participants must pass assessments to obtain credits, achieving a training compliance rate as high as 94% in 2025.

Regarding governance and management mechanisms, the Hospital adopts multi-tiered committee operations to implement risk control, regularly convening Cybersecurity Working Group and Information Authorization Group meetings every quarter. All resolutions are submitted quarterly to the Information Management Committee for review and deliberation. For major cybersecurity incidents, separate reports and explanations are presented to the Crisis Management Committee to ensure the timeliness and precision of decision-making.

On the technical defense front, the Hospital has deeply deployed Endpoint Detection and Response (EDR) mechanisms and integrated them into the Security Operations Center (SOC) threat monitoring and notification platform, establishing 24/7 monitoring and abnormal behavior analysis capabilities. Through relevant protective mechanisms, the Hospital successfully detected and blocked anomalous access behavior from a vendor in 2026, effectively preventing the escalation of potential risks. The relevant incident process, investigation results, and improvement measures have all been reported to the Crisis Management Committee for case review, demonstrating the Hospital's management mechanisms for transparent governance and continuous improvement regarding cybersecurity incidents.

The Hospital also continuously promotes cybersecurity awareness education and social engineering defense drills to reduce operational risks caused by human factors. In the 2025 social engineering drills organized by the Ministry of Education, a total of 200 participants were randomly selected for testing. Only 1 person opened the drill email, resulting in an opening rate of 0.5%, which did not exceed the target threshold. During the drill period, zero individuals clicked on malicious links or opened attachments, with both the link click rate and attachment opening rate remaining at 0%. This demonstrates that the Hospital's colleagues have developed excellent recognition capabilities and high cybersecurity vigilance against social engineering attacks.

 

 
Login Success