Open-access A comprehensive maturity model for Health 5.0: integrating technology, digital governance, and information security in hospital environments

Abstract

Paper aims  This paper aims to develop a maturity model for assessing Health 5.0 maturity across five key hospital sectors: Triage, Outpatient Clinic, Diagnosis, Surgery, and Hospitalization, while also evaluating transversal governance and information security capabilities.

Originality  The study is original because it treats digital maturity as a systemic and conditional configuration rather than as a simple accumulation of technologies. Existing maturity models for hospital environments predominantly rely on additive aggregation logics, treating governance and security as parallel dimensions rather than enabling constraints. The proposed model addresses this gap by adopting a non-compensatory scoring logic that structurally limits technological maturity when governance and security capabilities are insufficient, a contribution that is both conceptually novel and practically relevant for high-risk settings.

Research method  The study follows a design-oriented research approach grounded in the Design Science Research (DSR) paradigm, focused on the conceptualization, structuring, and formalization of a maturity model. The model includes guiding axes, a structured assessment instrument with an evidence-based scoring rubric, and an explicit non-compensatory scoring mechanism. An illustrative hospital application demonstrates operational feasibility and analytical behavior.

Main findings  The results indicate that the model captures heterogeneous maturity profiles across hospital sectors and reveals structural vulnerabilities not identified through additive assessment approaches.

Implications for theory and practice  The study advances maturity model research by incorporating risk sensitivity into assessment and provides a diagnostic tool to support hospital managers in prioritizing interventions and aligning digital transformation with governance and security capabilities.

Keywords:
Sociotechnical systems; Organizational resilience; Systemic risk; Organizational diagnostics; Non-compensatory logic

1. Introduction

The rapid integration of digital technologies, including artificial intelligence (AI), automation, and interconnected devices, is transforming healthcare, improving efficiency and patient outcomes (Chi et al., 2023). However, this shift increases concerns about system reliability, security, and interoperability (International Organization for Standardization, 2013). Hospitals are complex sociotechnical systems where technology, organization, and governance are deeply linked (Lima et al., 2026).

The systemic nature of these risks is illustrated by a scenario increasingly documented in the cybersecurity literature: a ransomware attack that simultaneously encrypts electronic health records, disables intensive care monitoring systems, and blocks access to medication management platforms, forcing a hospital to revert to paper-based procedures during critical care operations (Farhadighalati et al., 2023). Such cascading failures, where a single security breach propagates across interconnected digital systems, demonstrate that technological sophistication without equivalent governance and security capabilities does not reduce institutional risk. Recent incidents affecting major healthcare providers globally underscore that the question is no longer whether hospitals will be targeted, but whether their governance and resilience capabilities are mature enough to contain the impact (Wazid et al., 2024).

Health 5.0 has emerged as an extension of earlier digital health and Industry 4.0-oriented approaches, emphasizing not only technological sophistication but also human-centricity, resilience, ethical responsibility, and institutional trust (Raja Santhi & Muthuswamy, 2023). This paradigm prioritizes digital solutions that are structured, explainable, and safely embedded in organizational processes (Zhang et al., 2023). In hospital environments, failures can directly affect patient safety and operational continuity, making these considerations particularly critical.

Assessing Health 5.0 maturity remains challenging. Existing approaches often focus on technological adoption or isolated functional domains, such as electronic health records or telemedicine, and rely on additive aggregation logics (Becker et al., 2009; Khan et al., 2023). These approaches assume compensability between dimensions, potentially overestimating institutional readiness (International Organization for Standardization, 2013). High levels of technological deployment alone do not ensure preparedness to manage risks such as data protection, cybersecurity, regulatory compliance, and operational continuity (Wazid et al., 2024). Technological expansion can introduce governance and security vulnerabilities, undermining benefits (Farhadighalati et al., 2023), and misalignment between capability and institutional capacity can have severe consequences (Schmeelk et al., 2022).

Maturity models provide analytical tools to diagnose stages of organizational development, support benchmarking, and guide improvements (Pöppelbuß & Röglinger, 2011). However, few explicitly integrate risk sensitivity and institutional constraints, with governance and security often treated as secondary indicators rather than as enabling conditions (Aven, 2016). In Health 5.0, technological innovation must be accompanied by strong institutional capabilities, including governance, security practices, and organizational learning (Argote & Miron-Spektor, 2011; Venkatesh et al., 2012). Without these foundations, digital initiatives may increase systemic risk rather than improve performance.

To address this gap, this paper aims to develop a maturity model for assessing Health 5.0 maturity across five key hospital sectors: Triage, Outpatient Clinic, Diagnosis, Surgery, and Hospitalization, while also evaluating transversal governance and information security capabilities.The model integrates sectoral technological maturity across key hospital sectors with digital governance and information security, treating the latter as conditioning, not compensable, elements (Leveson, 2011). Using a design-oriented research approach, the model incorporates critical success factors and vulnerabilities identified through literature (Gomathi et al., 2023), operationalized in an assessment instrument with non-compensatory aggregation logic. An illustrative application demonstrates the model's feasibility and analytical behavior without focusing on empirical generalization (Pöppelbuß & Röglinger, 2011).

The originality of this study lies in three interconnected contributions that address limitations identified in existing Health 5.0 maturity assessments. First, the proposed model conceptualizes digital maturity in hospital environments as a conditional and systemic configuration rather than solely as the accumulation of technological capabilities. Second, it operationalizes this perspective through a transparent non-compensatory scoring mechanism based on explicit mathematical equations and a multiplier matrix, enhancing replicability and risk sensitivity. Third, digital governance and information security are incorporated as enabling constraints that directly influence the maturity level achievable by a hospital, rather than being treated as supplementary assessment dimensions. Together, these conceptual, methodological, and instrumental contributions provide a novel evaluative framework for assessing Health 5.0 maturity in high-risk healthcare environments.

To guide model development and discussion, the study addresses the following research questions: (Q1) How can a structured, replicable assessment framework capture the conditional relationship between technological adoption and institutional governance and security in hospital environments? (Q2) To what extent does technological adoption depend on digital governance and information security capabilities? (Q3) How do compensatory versus non-compensatory assessment logics influence maturity classification in high-risk organizational contexts? (Q4) What methodological and diagnostic contributions does a non-compensatory maturity model offer over conventional additive approaches when applied to Health 5.0 assessment in hospitals?

The article is structured as follows. Section 2 presents the literature review on Health 5.0 adoption and information security. Section 3 describes the methodology for model construction, including critical success factors, analytical axes, assessment instruments, and non-compensatory scoring logic. Section 4 presents results, including maturity levels, questionnaires, and illustrative application. Section 5 presents theoretical and practical implications, as well as limitations and future research directions. Section 6 concludes, summarizing contributions. The subsequent section reviews the evolution from Industry 4.0 to Industry 5.0, establishing the theoretical basis for Health 5.0 and grounding the proposed maturity model in a conceptual framework.

2. Literature review

The transition from Industry 4.0 to Industry 5.0 reflects a shift from a purely technology-driven paradigm toward a human-centric, collaborative, and sustainable model (Raja Santhi & Muthuswamy, 2023). Industry 5.0 emphasizes integration between intelligent systems and human decision-making, aiming to enhance adaptability, resilience, and sustainability in complex organizational environments (Yadav et al., 2023). Core technologies include artificial intelligence (AI), robotics, cyber-physical systems, Internet of Things (IoT) devices, and advanced data analytics, enabling automation, predictive capabilities, and real-time monitoring (Becker et al., 2009). Techniques such as predictive analytics, edge computing, and machine learning facilitate adaptive responses, while blockchain and distributed architectures improve traceability, transparency, and trust in digital ecosystems (Pöppelbuß & Röglinger, 2011). Industry 5.0 thus provides a foundation for systemic digital transformation, which is directly applied in healthcare contexts.

Rosas Quintero and Namuche Maldonado (2024) map the competencies engineers need for this transition, explicitly including cybersecurity skills alongside adaptability and interdisciplinary problem-solving, linking professional readiness for digital transformation to information security.

2.1. Health 5.0

Health 5.0 applies Industry 5.0 principles to hospital environments, integrating technological adoption with human-centric processes, operational resilience, and patient-focused care (Chi et al., 2023). Advanced digital tools are applied across core hospital areas:

  • Triage: AI-assisted decision support systems and predictive analytics optimize patient prioritization and resource allocation (Gomathi et al., 2023);

  • Outpatient Clinic: IoT-enabled wearable devices and telemedicine platforms allow remote monitoring and early intervention (Sujith et al., 2022);

  • Diagnosis: Machine learning and AI-driven imaging analysis enhance diagnostic accuracy and reduce errors (Yadav et al., 2023);

  • Surgery: Robotics and augmented reality assist minimally invasive procedures, improving precision and reducing intraoperative risk (Chi et al., 2023);

  • Hospitalization: Smart resource management and predictive monitoring optimize bed allocation, staffing, and patient safety (Raja Santhi & Muthuswamy, 2023).

In addition, interoperability and data integration are critical for effective Health 5.0 adoption. Schmeelk et al. (2022) highlight that electronic health records require blockchain-based interoperability frameworks to enable secure, consistent, and auditable data exchange across hospital departments. Verma et al. (2023) further demonstrate that blockchain applications in healthcare, when combined with Industry 5.0 technologies, support transparency, data integrity, and cross-system collaboration, facilitating safer and more efficient adoption of digital tools.

Despite these technological advances, adoption is limited by infrastructure, interoperability issues, staff training, and process integration challenges (Khan et al., 2023; Sujith et al., 2022). These findings emphasize that technological adoption alone is insufficient, and systemic institutional support is necessary to realize the full potential of Health 5.0. The integration of blockchain and interoperable architectures underscores the relevance of transversal governance and data security in this context.

2.2. Information security

Governance practices include formalized procedures, risk management, compliance, and continuity planning to ensure the reliable operation of hospital systems (Aven, 2016). Information security is especially critical due to the sensitivity of patient data and the interconnectivity of medical devices. Studies emphasize that technological advancement cannot compensate for deficiencies in governance or security (Becker et al., 2009). Cybersecurity strategies, including intrusion detection, encryption, and secure edge computing, are essential to protect hospital systems from breaches and operational failures (Farhadighalati et al., 2023).

Blockchain-based solutions, as shown by Schmeelk et al. (2022) and Verma et al. (2023), offer secure and interoperable electronic health records, while also requiring regulatory alignment and institutional readiness for effective implementation. Interoperability challenges remain critical due to heterogeneous information systems, legacy software, and varying departmental practices (Zhang et al., 2023). Any comprehensive maturity assessment must integrate both technological adoption and transversal governance and security dimensions, ensuring a realistic and risk-sensitive evaluation of hospital readiness (Leveson, 2011).

2.3. Existing maturity models for hospital environments

To situate the proposed model in relation to existing literature, this section presents a comparative overview of maturity models applied to hospital and healthcare digital transformation contexts. Although several models have been developed to assess organizational maturity in health settings, few explicitly integrate governance and security as enabling constraints rather than independent dimensions.

The Healthcare Information and Management Systems Society Electronic Medical Record Adoption Model (HIMSS EMRAM) is among the most widely adopted frameworks for assessing digital maturity in hospitals. It defines eight stages of electronic medical record adoption, from stage 0 (no ancillary department systems installed) to stage 7 (complete electronic medical record with data analytics). While the EMRAM provides a widely benchmarked reference framework, its focus on electronic health record adoption means that governance, cybersecurity, and risk management capabilities are not systematically integrated into the scoring logic. High adoption of digital systems does not preclude institutional vulnerability if governance structures are absent or weak.

Brazilian production engineering research has also examined hospital operations with an operational rather than governance-security focus. Borges et al. (2020) applied discrete-event simulation to lean practices in a public hospital supply chain, and Gayer et al. (2020) used a Design Science Research based model, structured around route, rhythm, and routine, to diagnose hospital logistics flow. Both confirm the relevance of Design Science Research for hospital-focused artifacts, the methodological choice shared by the present study, while leaving governance and security outside the diagnostic logic.

The Capability Maturity Model Integration (CMMI) and its derivatives have been applied in hospital information technology contexts to assess process maturity. The CMMI defines five maturity levels, Initial, Managed, Defined, Quantitatively Managed, and Optimizing, that reflect the degree to which organizational processes are standardized, measured, and continuously improved (Becker et al., 2009). While useful for process benchmarking, the CMMI does not address the specific technological and governance dimensions of Health 5.0, nor does it incorporate risk-sensitive non-compensatory aggregation logic.

In the broader maturity model literature, compensatory aggregation remains the predominant approach: scores across dimensions are averaged or summed, potentially allowing high performance in one area to offset weaknesses in another (Pöppelbuß & Röglinger, 2011). This logic is particularly problematic in health contexts, where governance or security deficits can produce cascading systemic failures regardless of the level of technological sophistication (Leveson, 2011).

A similar reliance on compensatory logic appears outside the health domain. Santos et al. (2022) applied the Analytic Hierarchy Process to a product lifecycle management diagnostic, and Neira Sacaski et al. (2025) quantified digital maturity in real estate agencies through structural equation modeling; in both cases the resulting score remained an aggregate, with no dimension treated as a non-compensable constraint on the others.

Table 1 summarizes the key characteristics and limitations of selected existing frameworks in relation to the proposed model.

Table 1
Comparison of selected maturity frameworks with the proposed model.

The proposed model differentiates itself from these frameworks through three features: (1) the explicit treatment of governance and information security as non-compensable conditions for technological maturity; (2) the use of a structured mathematical scoring mechanism with a multiplier matrix; and (3) the integration of sectoral and transversal dimensions in a unified evaluative framework designed for the Health 5.0 paradigm.

3. Methodology

This study adopts a design-oriented research approach grounded in the Design Science Research (DSR) paradigm, which emphasizes the systematic development, formalization, and evaluation of artifacts, such as models, frameworks, and instruments, that address practical problems in their organizational and technological contexts (Gregor & Hevner, 2013). The DSR paradigm was selected because it provides methodological foundations that are appropriate for the construction of prescriptive artifacts, such as maturity models, that go beyond hypothesis testing and aim at the generation of design knowledge applicable across contexts (Dresch et al., 2015).

Rather than focusing on statistical validation or causal inference, the methodological emphasis is placed on the rigorous construction of an evaluative artifact grounded in theory, responsive to contextual challenges, and suitable for practical application in high-risk and highly regulated settings such as healthcare. In this study, the primary scientific outcome is the maturity model itself, understood as a structured and formalized artifact.

The methodological process was structured as a sequential and iterative workflow comprising six main stages, each designed to ensure coherence between the conceptual foundations of the model, the analytical choices made during its construction, and the final structure of the assessment instrument. This workflow is summarized in Figure 1, which illustrates the methodological stages adopted in the study.

Figure 1
Methodological fluxogram.

The process illustrated in Figure 1 comprised six stages:

Stage 1

Literature Review and Identification of Critical Success Factors: The first stage consisted of a targeted review of the academic literature on Health 5.0, digital maturity models, information security in hospital environments, and sociotechnical systems. Articles were selected based on relevance to the research questions, recurrence of key concepts across sources, and publication in peer-reviewed journals or indexed conference proceedings. Priority was given to studies published in the last decade, with particular attention to those addressing technological vulnerabilities, governance failures, and risk-sensitive assessment in digital health contexts.

From this review, recurring technological patterns and institutional vulnerabilities were identified and synthesized. These patterns informed the definition of critical success factors — including AI integration, IoT adoption, data governance, information security, regulatory compliance, and continuity planning — that were treated as central inputs to the design of the maturity model.

Stage 2

Structuring the Analytical Axes: Building on the critical success factors identified in Stage 1, the second stage focused on structuring the analytical axes of the maturity model. Two interdependent axes were defined: (1) sectoral technological maturity, capturing the extent to which Health 5.0 technologies and practices are incorporated in key hospital sectors; and (2) transversal digital governance and security maturity, capturing institutional capabilities related to data protection, operational continuity, regulatory compliance, and risk management. The transversal axis was explicitly designed as a conditioning element, not as an independent or compensable dimension.

Stage 3

Development of Assessment Instruments: The third stage consisted of developing the measurement instruments that operationalize the two analytical axes. For sectoral technological maturity, five core hospital sectors were defined: Triage, Outpatient Clinic, Diagnosis, Surgery, and Hospitalization. Both instruments use a five-point Likert scale ranging from 1 (Initial) to 5 (Optimized), with each level explicitly defined and theoretically grounded.

To address the inherent subjectivity of perception-based Likert scales — a recognized methodological concern in self-reported organizational assessments — the assessment instrument includes an evidence-based scoring rubric presented in Table 2. This rubric operationalizes each maturity level in terms of observable, documentable organizational evidence, reducing interpretive variability across evaluators and contexts. The rubric is particularly important for the governance and security dimension, where the risk of optimistic self-assessment is highest.

Table 2
Evidence-based scoring rubric for governance and security items.

Evaluators applying a score of 5 (Optimized) to any governance or security item should be able to present supporting documentation such as audit reports, compliance certificates, incident logs, or records of periodic security testing. Scores assigned without corresponding documentary evidence should be flagged for triangulation with additional respondents or external verification.

Stage 4

Formalization of the Non-Compensatory Scoring Logic: The fourth stage consisted of formalizing the scoring logic that relates technological maturity to governance and security maturity through a non-compensatory mechanism. This involved defining the mathematical equations for sectoral and overall score computation, the discretization rules, and the multiplier matrix. The logic is detailed in Section 4.3 of this paper.

The multiplier values adopted in the matrix were heuristically defined by the authors based on the theoretical assumption that digital governance and information security function as enabling constraints for the sustainable consolidation of Health 5.0 technologies. The values were intentionally designed to progressively penalize situations in which technological maturity exceeds governance and security capabilities, reflecting the risk-sensitive orientation of the proposed model. Therefore, the matrix should be interpreted as an illustrative application of the model's underlying theoretical premises rather than as an empirically validated representation of real-world risk relationships.

Stage 5

Respondent Profile Block: A respondent profile block was incorporated into the assessment instrument to capture contextual variables, such as professional role, department, experience, and familiarity with digital technologies, that may influence score interpretation and the identification of perceptual asymmetries across organizational units.

Stage 6

Illustrative Application: The sixth stage consisted of an illustrative case study application conducted in a private hospital environment, following the guidelines for case study research described by Yin (2017). Yin's framework guided the methodological choices in this stage in the following ways: (a) the unit of analysis was defined as the hospital as an organizational entity assessed at a single point in time; (b) a structured research protocol was followed, comprising the assessment instrument, a data collection guide, and an explicit scoring procedure; (c) the chain of evidence was maintained by documenting the respondent profile, the individual item responses, and the intermediate calculations that produced the final maturity score; and (d) construct validity was addressed through the theoretical grounding of each item and maturity level, as described in Section 4.1.

The application served to test the operational feasibility of the proposed model and to observe the sensitivity of the non-compensatory scoring logic in a real institutional setting. It is not intended as an empirical generalization, but as a demonstrative use case that illustrates how the model generates diagnostic insights that compensatory approaches would not produce.

To support replication, the scoring procedure adopted in this study is fully operationalized through the equations and the multiplier matrix presented in Section 4.3. Future researchers seeking to replicate or extend this study may apply the same instrument and scoring logic to different hospital settings, using the respondent profile block to contextualize results and identify perceptual asymmetries across professional roles and organizational units.

4. Results: maturity model development

This section presents the results derived from the methodological workflow described in Section 3, namely the development of a maturity model for assessing Health 5.0 in hospital environments. In line with a design-oriented research approach, maturity models are understood as analytical instruments that represent progressive levels of organizational capability development, supporting diagnosis, benchmarking, and the prioritization of improvement initiatives in complex sociotechnical systems.

4.1. Defining maturity levels

The first step involved identifying and consolidating technologies, concepts, and organizational practices recurrently associated with Health 5.0, as well as the vulnerabilities reported alongside their implementation. The literature consistently highlights that the introduction of advanced digital technologies in healthcare is often accompanied by vulnerabilities in cybersecurity, data protection, interoperability, regulatory compliance, and service continuity. These recurring vulnerabilities reinforced the need to incorporate risk-sensitive elements into the maturity assessment.

Each level of the five-point scale is explicitly defined and justified based on prior literature on digital maturity, governance, risk management, and organizational learning, as presented in Table 3.

Table 3
Proposed maturity levels.

4.2. Structuring the analytical axes of the maturity model and questionnaires

Subsequently, the third step focused on structuring the analytical axes of the maturity model. Two interdependent axes were established. The first axis captures sectoral technological maturity, reflecting the extent to which Health 5.0 related technologies, processes, and practices are incorporated into critical hospital sectors. The second axis captures transversal digital governance and security maturity, encompassing organizational capabilities related to data protection, continuity, compliance, and risk management. This transversal axis was explicitly defined as a conditioning element of technological maturity, rather than as an independent or compensable dimension.

The fourth step consisted of developing the measurement instruments that operationalize these analytical axes. To assess sectoral technological maturity, the hospital environment was decomposed into five core sectors, presented in Table 4, representing key stages of the care flow: Triage, Outpatient Clinic, Diagnosis, Surgery, and Hospitalization. For each sector, a set of items was defined to capture technological, procedural, human, strategic, and integration dimensions associated with Health 5.0. Both the technology questionnaire and the digital governance and security questionnaire are evaluated using the Likert scale, ranging from (1) initial to (5) optimized.

Table 4
Technology Questionnaire.

In parallel, a transversal block of items was presented in Table 5 to assess digital governance and security maturity at the organizational level.

Table 5
Digital Governance and Security Questionnaire.

To strengthen the diagnostic character of the model and support segmented analyses, a block of respondent profile variables was incorporated into the assessment instrument. These variables capture the respondent’s role, department, length of experience, self-perceived familiarity with digital technologies, and main sources of information related to digitalization and security. Although these variables are not directly used in the computation of maturity scores, they enable the identification of perception asymmetries, communication gaps, and training needs across organizational units. The inclusion of the respondent profile questionnaire presented in Table 6 is justified by literature in the fields of organizational learning and technology adoption.

Table 6
Respondent Questionnaire.

4.3. Developing the non-compensatory scoring logic

The fifth step consisted of a central element of the model, which is the built-in scoring logic, which relates the scoring of maturity of technology (a) to the scoring of maturity of digital governance and security (s) through non-compensatory mul. pliers μa,s This rule ensures that insufficient levels of security directly penalize global maturity, even in contexts of high technological adoption.

The adoption of this logic aims to avoid distorted evaluations, in which technological advances can mask critical weaknesses in governance and information security. In the context of digital health, highly technologized but vulnerable systems pose significant risks to service continuity, data integrity, and patient safety. Thus, digital security is treated as a critical success factor for the sustainable consolidation of technologies associated with Health 5.0.

To ensure transparency and replicability, the scoring logic of the maturity model is formalized below through a set of equations that explicitly define the aggregation rules and the non-compensatory relationship between technological maturity and digital governance and security:

Let xij denote the response to item j in sector i, measured on a 1 to 5 scale, with i ∈ {1,…,5} representing Triage, Outpatient Clinic, Diagnosis, Surgery, and Hospitalization. Sector means are computed as:

x _ i = 1 n i ∑ j = 1 n i x i j (1)

The overall technology means is:

x _ = 1 5 ∑ i = 1 5 x _ i (2)

To preserve a conservative diagnostic interpretation and avoid marginal overestimation, the technology score is defined by a floor discretization:

a = x _ (3)

For the governance and security block, let yk denote the response to item k (on the same 1 to 5 scale). The means of governance and security is:

y _ = 1 m ∑ k = 1 m y k (4)

The security score is likewise discretized by floor:

s = y _ (5)

The model then applies a predefined non-compensatory multiplier μa,s, obtained from the multiplier matrix, presented in Table 7, to adjust the technology score as a function of governance and security maturity.

Table 7
Multiplier Matrix.

The final maturity score is computed as:

z = a ⋅ μ a , s (6)

This rule operates on the assumption that governance and security are enabling constraints: when digital governance and security lag technological adoption, μa,s≼1 penalizes maturity; when governance and security are aligned or exceed the technological baseline in controlled ways, μa,s≥1 prevents underestimation while preserving conservatism. The repeated use of floor rounding reinforces that progression between discrete maturity levels occurs only when practices are consolidated rather than when mean values marginally exceed thresholds.

This approach is consistent with contemporary risk management and complex sociotechnical systems literature, which emphasizes that deficiencies in critical dimensions should not be offset by superior performance in other areas, due to the potential for cascading failures and systemic vulnerability. In addition, widely adopted information security frameworks emphasize the foundational importance of governance and data protection as prerequisites for building trusted digital systems. The scoring structure of the model, therefore, reflects the strategic objectives of the evaluated domain and follows consolidated recommendations for the development of transparent and context-aligned maturity models.

5. Illustrated application of the maturity model

To illustrate the operational feasibility and analytical behavior of the proposed maturity model, the sixth step was conducted as an empirical application in a private hospital environment. This application is not intended to provide an in-depth characterization of the organization nor to support empirical generalization. Instead, it serves as a demonstrative use case, showing how the model can be applied in practice and what types of insights it can generate when assessing Health 5.0 maturity in a real institutional setting.

Data was collected using the structured assessment instrument defined in the model, encompassing the respondent profile block, the sectoral technology questionnaire, and the transversal digital governance and security questionnaire. The application followed strictly the scoring logic formalized in the previous section, ensuring full consistency between the conceptual design of the model and its empirical operationalization. The diagnosis of institutional maturity was carried out based on the answers provided by a key informant, with experience at the hospital coordination level, two years of experience in the institution, and a degree of familiarity classified as advanced with digital technologies. The respondent indicated formal training as the main source of knowledge about digitization processes and information security.

5.1. Results

The assessment results for sectoral technological maturity are presented in Table 8, organized by hospital sector and evaluated dimensions. The results reveal a heterogeneous maturity profile across sectors, illustrating the model’s ability to capture differentiated stages of digital consolidation within the same organization. While some sectors exhibit advanced incorporation of Health 5.0-related technologies and practices, others remain at initial or intermediate levels, particularly in early stages of the care flow. This heterogeneity highlights the importance of sector-level diagnostics, as aggregate indicators alone would conceal such structural asymmetries.

Table 8
Results of the Technology Questionnaire.

The results of the digital governance and security assessment are presented in Table 9. All evaluated items reached advanced maturity levels, indicating a consolidated institutional capacity in this transversal dimension. From the perspective of the proposed model, this result is analytically relevant because governance and security are treated as conditioning factors rather than parallel dimensions. The high maturity observed in this block suggests the presence of institutional capabilities that may support digitalization, mitigating risks associated with interoperability, data protection, system availability, and regulatory compliance.

Table 9
Results of the Digital Governance and Security Questionnaire.

To make the analytical implications of the proposed non-compensatory scoring logic explicit, the results were deliberately contrasted with an alternative compensatory aggregation logic. By presenting both logics side by side, the model allows the discrepancy between additive and non-compensatory evaluations to be directly observed and interpreted. Based on the sectoral technology scores and the digital governance and security score, the final institutional maturity level was computed using the non-compensatory aggregation rules defined in Section 4, while the compensatory results were derived using conventional additive logic for comparison purposes.

The intermediate calculations and outcomes are summarized in Table 10, which consolidates sectoral averages, the overall technology score, the governance and security score, the applied multiplier, and the resulting maturity level under both logics.

Table 10
Final scores and comparison of institutional maturity.

5.2. Results analysis

The assessment of sectoral maturity scores reveals important differences across hospital areas, highlighting both strengths and gaps in the adoption of Health 5.0 technologies and practices. Triage remains at initial maturity in wearable sensors, IoT integration, and predictive AI, while outpatient clinics, surgery, and hospitalization exhibit higher maturity scores, reflecting more advanced incorporation of digital tools and associated organizational practices. This heterogeneous maturity profile is consistent with previous Health 5.0 studies that report uneven patterns of digital transformation across healthcare functions, often associated with differences in technological complexity, infrastructure requirements, and workforce preparedness (Gomathi et al., 2023; Khan et al., 2023). These findings reinforce the importance of sector-level diagnostics, as institution-wide averages may obscure critical differences in readiness and capability development.

The contrast between compensatory and non-compensatory scoring demonstrates the sensitivity of the proposed model to structural deficiencies. Under compensatory logic, the institution is classified as Advanced (4); under non-compensatory logic, the classification is Intermediate (3). This one-level difference reflects the floor discretization applied to the overall technology mean (3.72 → 3), highlighting the conservative nature of the model's scoring approach. This conservatism is intentional and theoretically grounded, ensuring that progression to higher maturity levels occurs only when practices are consolidated across sectors rather than marginally exceeding predefined thresholds. Similar concerns have been raised in the maturity model literature, where additive aggregation mechanisms may overestimate organizational capabilities by allowing strengths in some dimensions to compensate for weaknesses in others (Becker et al., 2009; Pöppelbuß & Röglinger, 2011).

From a broader sociotechnical perspective, these findings support the argument that institutional readiness in healthcare should not be inferred solely from aggregate indicators of technological adoption. High-risk organizational environments require assessment approaches that are sensitive to structural vulnerabilities and interdependencies among organizational capabilities. In this regard, the literature on complex systems emphasizes that deficiencies in critical dimensions may compromise overall system performance despite strong results in other areas (Aven, 2016; Leveson, 2011). The comparison between compensatory and non-compensatory scoring, therefore serves not only as a methodological demonstration but also as a substantive finding that reinforces the relevance of risk-sensitive maturity assessment in Health 5.0 contexts.

5.3. Theoretical and practical implications

5.3.1. Theoretical implications

This study advances the theoretical understanding of digital maturity in healthcare by conceptualizing it as a conditional and systemic configuration rather than a cumulative measurement. The formal integration of governance and security as enabling constraints challenges the additive and compensatory approaches that dominate the maturity model literature. The non-compensatory scoring logic, implemented through explicit mathematical equations and a multiplier matrix, provides a transparent and replicable mechanism for operationalizing theoretical assumptions about institutional systemic fragility.

The study also contributes to the intersection of Health 5.0 research and design science by demonstrating that evaluative artifacts can carry substantial theoretical content — not only in the dimensions they measure but in the logic through which they aggregate information. By making the aggregation logic an explicit theoretical choice, the model opens a line of inquiry for researchers interested in how assessment design shapes organizational diagnosis.

Furthermore, the comparative analysis of compensatory and non-compensatory scoring logics contributes empirical grounding to theoretical arguments about measurement validity in high-risk contexts: the same set of responses can yield substantially different maturity classifications depending on the aggregation logic, which has implications for how researchers and practitioners interpret and use assessment results.

5.3.2. Practical implications

From a practical perspective, the model delivers diagnostic insights that aggregate scores cannot provide. The separation between sectoral technological maturity and transversal governance and security capabilities allows hospital managers to identify structural asymmetries and prioritize interventions accordingly. The illustrative application demonstrated that triage and diagnosis sectors require focused investment in digital infrastructure and training, while outpatient clinics, surgery, and hospitalization benefit from sustaining and refining existing practices.

The model also functions as a planning and audit instrument: it can support hospital administrators in ensuring that investments in AI, IoT, and other Health 5.0 technologies are systematically accompanied by governance and security capabilities. Healthcare regulators may use it as a structured diagnostic framework for institutional accreditation or readiness assessments.

For practitioners implementing the model, it is recommended that assessments involve multiple respondents representing different organizational roles, clinical staff, IT management, hospital administration, to reduce perceptual bias. In addition, self-reported scores for governance and security items should be validated against documentary evidence such as audit reports, compliance certifications, and incident records. This triangulation approach strengthens the validity of the maturity assessment and reduces the risk of optimistic overestimation that single-respondent instruments are susceptible to.

5.4. Limitations and future research directions

Despite its contributions, this study presents limitations that should be considered when interpreting its findings and applying the model in practice.

First, the illustrative application was conducted in a single private hospital, which restricts comparative generalization across institutional types, ownership models, and technological contexts. The findings cannot be generalized to public hospitals, university hospitals, or institutions operating in different regulatory environments without further validation.

Second, the assessment relied on a single key informant with two years of institutional experience and a managerial coordination role. Single-respondent assessments are inherently susceptible to optimistic bias, as evidenced by the uniform 'Optimized' ratings across all governance and security items (Table 9). This pattern suggests potential overestimation of maturity in the transversal dimension, and future applications must mitigate this risk through triangulation: multiple respondents (clinical, IT, administrative), documentary evidence (audits, compliance reports, incident logs), and, where possible, external validation.

Although the multiplier matrix was theoretically justified and operationalized in this study, its parameters have not yet undergone empirical calibration or expert validation across multiple institutional contexts. The validity of these weights as representations of real risk relationships remains an open empirical question.

Fourth, the dynamic nature of Health 5.0 technologies and evolving regulatory frameworks (such as the LGPD in Brazil and GDPR in Europe) necessitates periodic updating of the model to maintain its relevance and applicability as the technological and institutional landscape evolves.

Future research may expand the application of the model to multiple healthcare institutions, including public, private, and university hospitals at different levels of technological development, to enable comparative benchmarking and empirical validation of the scoring logic and multiplier matrix. Longitudinal studies could monitor digital transformation trajectories over time, transforming the model into a strategic planning and monitoring instrument. Expert validation through Delphi panels or structured stakeholder consultations would strengthen the multiplier matrix and the maturity level definitions. Additionally, assessment protocols involving multiple respondents per institution, representing clinical staff, IT management, and hospital administration (360-degree evaluations), would leverage respondent profiles to analyze perception asymmetries and identify training needs across organizational units. Such extensions would substantially enhance both the theoretical validity and practical reliability of the model.

6. Conclusion

This study proposed and developed a maturity model for assessing Health 5.0 maturity across five key hospital sectors: Triage, Outpatient Clinic, Diagnosis, Surgery, and Hospitalization, while also evaluating transversal governance and information security capabilities.. By repositioning the maturity model itself as the primary scientific outcome, the research focused on the systematic construction of an evaluative artifact that is grounded in design science theory, sensitive to institutional risk, and applicable to complex healthcare settings.

The proposed model demonstrates that institutional digital maturity can be systematically assessed by evaluating both sectoral technological adoption and transversal governance and security capabilities (Q1). The findings show that technological adoption is structurally dependent on governance and security: deficiencies in these transversal dimensions directly constrain the overall maturity level achievable (Q2). The comparison of scoring logics illustrates that assessment methodology substantially influences classification, with non-compensatory logic preventing artificially inflated scores and exposing critical gaps (Q3). Finally, the model generates targeted diagnostic insights that reveal sector-specific asymmetries and actionable opportunities for improvement (Q4).

From a theoretical standpoint, the study contributes to maturity model literature by formalizing a conditional and systemic conceptualization of digital maturity and by demonstrating how aggregation logic functions as a theoretical choice with substantive consequences. From a practical perspective, the model delivers a diagnostic tool that hospital managers and regulators can use to prioritize investments, identify governance gaps, and support risk-aware digital transformation strategies.

Data availability

Research data is available in the body of the article.

  • How to cite this article:
    Luna, R. N. B., Lima, I. A. S., Alcantara, B. A., Samed, M. (2026). A comprehensive maturity model for Health 5.0: integrating technology, digital governance, and information security in hospital environments. Production, 36, e20260051. https://doi.org/10.14488/1980-5411.20260051.
  • Financial Support
    This research was funded by the Araucária Foundation through the NAPI PITS project. The Araucária Foundation did not participate in the data collection, analysis, or interpretation, nor in the writing of the manuscript.
  • Ethical Statement
    Not applicable.

References

  • Argote, L., & Miron-Spektor, E. (2011). Organizational learning: from experience to knowledge. Organization Science, 22(5), 1123-1137. https://doi.org/10.1287/orsc.1100.0621
    » https://doi.org/10.1287/orsc.1100.0621
  • Aven, T. (2016). Risk assessment and risk management: review of recent advances on their foundation. European Journal of Operational Research, 253(1), 1-13. https://doi.org/10.1016/j.ejor.2015.12.023
    » https://doi.org/10.1016/j.ejor.2015.12.023
  • Becker, J., Knackstedt, R., & Pöppelbuß, J. (2009). Developing maturity models for IT management. Business & Information Systems Engineering, 1(3), 213-222. https://doi.org/10.1007/s12599-009-0044-5
    » https://doi.org/10.1007/s12599-009-0044-5
  • Borges, G. A., Tortorella, G. L., Martínez, F., & Thurer, M. (2020). Simulation-based analysis of lean practices implementation on the supply chain of a public hospital. Production, 30, e20190131. https://doi.org/10.1590/0103-6513.20190131
    » https://doi.org/10.1590/0103-6513.20190131
  • Chi, H. R., de Fátima Domingues, M., Zhu, H., Li, C., Kojima, K., & Radwan, A. (2023). Healthcare 5.0: in the perspective of consumer Internet-of-Things-based fog/cloud computing. IEEE Transactions on Consumer Electronics, 69(4), 745-755. https://doi.org/10.1109/TCE.2023.3293993
    » https://doi.org/10.1109/TCE.2023.3293993
  • Dresch, A., Lacerda, D. P., & Antunes, J. A. V. (2015). A method for science and technology advancement. In A. Dresch, D. P. Lacerda & J. A. V. Antunes (Eds.), Design science research: a method for science and technology advancement (pp. 67-102). Cham: Springer. https://doi.org/10.1007/978-3-319-07374-3_4
    » https://doi.org/10.1007/978-3-319-07374-3_4
  • Farhadighalati, N., Farhady Ghalaty, N., Nikghadam-Hojjati, S., Marchetti, E., & Barata, J. (2023). Safe-health: a secure framework for advancing edge-based health 5.0. In Proceedings of the 2023 IEEE 9th World Forum on Internet of Things (WF-IoT) (pp. 1-6). New York: IEEE. https://doi.org/10.1109/WF-IoT58464.2023.10539418
    » https://doi.org/10.1109/WF-IoT58464.2023.10539418
  • Gayer, B., Marcon, E., Bueno, W. P., Wachs, P., Saurin, T. A., & Ghinato, P. (2020). Analysis of hospital flow management: the 3 R’s approach. Production, 30, e20200033. https://doi.org/10.1590/0103-6513.20200033
    » https://doi.org/10.1590/0103-6513.20200033
  • Gomathi, L., Mishra, A. K., & Tyagi, A. K. (2023). Industry 5.0 for Healthcare 5.0: opportunities, challenges and future research possibilities. In 2023 7th International Conference on Trends in Electronics and Informatics (ICOEI) (pp. 204-213). New York: IEEE. https://doi.org/10.1109/ICOEI56765.2023.10125660
    » https://doi.org/10.1109/ICOEI56765.2023.10125660
  • Gregor, S., & Hevner, A. R. (2013). Positioning and presenting design science research for maximum impact. Management Information Systems Quarterly, 37(2), 337-355. https://doi.org/10.25300/MISQ/2013/37.2.01
    » https://doi.org/10.25300/MISQ/2013/37.2.01
  • International Organization for Standardization – ISO. (2013) ISO 27001: information security management systems: requirements. Geneva: ISO; 2013.
  • Khan, T. A., Fatima, A., Shahzad, T., Atta-Ur-Rahman, Alissa, K., Ghazal, T. M., Al-Sakhnini, M. M., Abbas, S., Khan, M. A., & Ahmed, A. (2023). Secure IoMT for disease prediction empowered with transfer learning in healthcare 5.0, the concept and case study. IEEE Access : Practical Innovations, Open Solutions, 11, 39418-39430. https://doi.org/10.1109/ACCESS.2023.3266156
    » https://doi.org/10.1109/ACCESS.2023.3266156
  • Leveson, N. (2011). Engineering a safer world: systems thinking applied to safety. Cambridge: MIT Press.
  • Lima, I. A. S., Alcantara, B. A., Gomes, H. C., & Samed, M. M. A. (2026). Healthcare supply chain resilience during the COVID-19 pandemic: PPE procurement challenges and strategies. Gestão & Produção, 33, e1325. https://doi.org/10.1590/1806-9649-2025v33e1325
    » https://doi.org/10.1590/1806-9649-2025v33e1325
  • Neira Sacaski, D. R., Graciano, P., Cerna Risco, K., Campos Llerena, J. P., Cafruni Gularte, A., & Lermen, F. H. (2025). The impact of digitalization on real estate agencies: the case of Peru. Production, 35, e20240146. https://doi.org/10.1590/0103-6513.20240146
    » https://doi.org/10.1590/0103-6513.20240146
  • Pöppelbuß, J., & Röglinger, M. (2011). What makes a useful maturity model? A framework of general design principles for maturity models and its demonstration in business process management. In Proceedings of the European Conference on Information Systems (ECIS). Atlanta: Association for Information Systems.
  • Raja Santhi, A., & Muthuswamy, P. (2023). Industry 5.0 or industry 4.0S? Introduction to industry 4.0 and a peek into the prospective industry 5.0 technologies. International Journal on Interactive Design and Manufacturing, 17(2), 947-979. https://doi.org/10.1007/s12008-023-01217-8 PMid:40478102.
    » https://doi.org/10.1007/s12008-023-01217-8
  • Rosas Quintero, W., & Namuche Maldonado, J. E. (2024). Competencies of the engineer in industry 4.0 context: a systematic literature review. Production, 34, e20230051. https://doi.org/10.1590/0103-6513.20230051
    » https://doi.org/10.1590/0103-6513.20230051
  • Santos, K. C. P., Loures, E. F. R., Canciglieri Junior, O., & Micosky, A. L. (2022). Diagnostic assessment of product lifecycle management based on Industry 4.0 requirements. Production, 32, e20210082. https://doi.org/10.1590/0103-6513.20210082
    » https://doi.org/10.1590/0103-6513.20210082
  • Schmeelk, S., Kanabar, M., Peterson, K., & Pathak, J. (2022). Electronic health records and blockchain interoperability requirements: a scoping review. JAMIA Open, 5(3), ooac068. https://doi.org/10.1093/jamiaopen/ooac068 PMid:35911668.
    » https://doi.org/10.1093/jamiaopen/ooac068
  • Sujith, A. V. L. N., Sajja, G. S., Mahalakshmi, V., Nuhmani, S., & Prasanalakshmi, B. (2022). Systematic review of smart health monitoring using deep learning and Artificial intelligence. Neuroscience Informatics (Online), 2(3), 100028. https://doi.org/10.1016/j.neuri.2021.100028
    » https://doi.org/10.1016/j.neuri.2021.100028
  • Venkatesh, V., Thong, J. Y. L., & Xu, X. (2012). Consumer acceptance and use of information technology: extending the unified theory of acceptance and use of technology. Management Information Systems Quarterly, 36(1), 157-178. https://doi.org/10.2307/41410412
    » https://doi.org/10.2307/41410412
  • Verma, S. K. Nadeem, M., Verma, V., Sayeed, M. A., Agrawal, A., & Khan, R. A. (2023). Blockchain application in healthcare domain: industry 5.0 perspective. In Proceedings of the 2023 6th International Conference on Contemporary Computing and Informatics (IC3I) (pp. 208-215). New York: IEEE. https://doi.org/10.1109/IC3I59117.2023.10397614
    » https://doi.org/10.1109/IC3I59117.2023.10397614
  • Wazid, M., Singh, J., Das, A. K., & Rodrigues, J. J. P. C. (2024). An ensemble-based machine learning-envisioned intrusion detection in Industry 5.0-driven healthcare applications. IEEE Transactions on Consumer Electronics, 70(1), 1903-1912. https://doi.org/10.1109/TCE.2023.3318850
    » https://doi.org/10.1109/TCE.2023.3318850
  • Yadav, M., Vardhan, A., Chauhan, A. S., & Saini, S. (2023). A Study on Creation of Industry 5.0: New Innovations using big data through artificial intelligence, Internet of Things and next-origination technology policy. In Proceedings of the 2023 IEEE International Students’ Conference on Electrical, Electronics and Computer Science (SCEECS) (pp. 1-12). New York: IEEE. https://doi.org/10.1109/SCEECS57921.2023.10063069
    » https://doi.org/10.1109/SCEECS57921.2023.10063069
  • Yin, R. K. (2017). Case study research and applications: design and methods (6th ed.). Thousand Oaks: Sage Publication.
  • Zhang, H., Luo, J., Tu, Y., Wang, R., Wu, D., & Yang, J. (2023). Microservice deployment mechanism with diversified QoS requirements for smart health system in Industry 5.0. IEEE Transactions on Consumer Electronics, 69(4), 869-880. https://doi.org/10.1109/TCE.2023.3296534
    » https://doi.org/10.1109/TCE.2023.3296534

Edited by

  • Editor(s)
    Adriana Leiras
    Rodrigo Caiado

Publication Dates

  • Publication in this collection
    18 Sept 2026
  • Date of issue
    2026

History

  • Received
    14 Apr 2026
  • Accepted
    24 Aug 2026
Creative Common - by 4.0
This is an Open Access article distributed under the terms of the Creative Commons Attribution license (https://creativecommons.org/licenses/by/4.0/), which permits unrestricted use, distribution, and reproduction in any medium, provided the original work is properly cited.
location_on
Associação Brasileira de Engenharia de Produção CNPJ: 30.115.422/0001-73, Avenida Cassiano Ricardo, Nº 601, Residencial Aquarius, CEP: 12.246-870, http://portal.abepro.org.br/ - São José dos Campos - SP - Brazil
E-mail: production@editoracubo.com.br
rss_feed Stay informed of issues for this journal through your RSS reader
Go to top Report error