Cybersecurity of Connected Medical Devices: A Major Clinical Safety Issue

Picture of Maurice Bagot D'arc

Maurice Bagot D'arc

ENT surgeon, head and neck surgeon, specialized in ENT oncology, legal compensation for bodily injury, and pharmaceutical marketing, with over 30 years of experience in Medical Affairs serving the healthcare industries and 15 years of surgical practice.

Connected medical devices are now widely used in healthcare systems: infusion pumps, cardiac implants, imaging systems, clinical decision-support software, and remote monitoring platforms.

However, this digital transformation introduces a new type of risk: cybersecurity of connected medical devices.

Beyond IT concerns, vulnerabilities affecting the cybersecurity of medical devices can have direct consequences for patient safety. Health authorities are increasingly considering cybersecurity of medical devices as an integral component of medical device safety.

Cybersecurity of Connected Medical Devices: An Emerging Clinical Risk

The cybersecurity of connected medical devices encompasses all threats that may affect connected devices or medical software: unauthorized access, data manipulation, system disruption, or alteration of therapeutic functions.

According to the Digital Health Center of Excellence of the FDA, connected medical devices may be exposed to several types of cyberattacks that could compromise their functioning or the confidentiality of patient data.

https://www.fda.gov/medical-devices/digital-health-center-excellence/cybersecurity

Unlike a traditional IT system, a medical device may be directly involved in patient care. A cyberattack affecting the cybersecurity of medical devices could, for example:

  • modify the parameters of an infusion pump
  • interrupt a monitoring system
  • alter data used for medical decision-making

In such situations, the risk becomes a clinical safety risk, not merely an IT issue. Ensuring the cybersecurity of medical devices is therefore essential to maintaining safe healthcare delivery.

Cybersecurity Incidents Already Documented in Healthcare

Over the past few years, several alerts have shown that vulnerabilities affecting the cybersecurity of medical devices are not purely theoretical.

Some vulnerabilities have been identified in implantable devices or in connected hospital systems. These weaknesses could potentially allow malicious actors to interfere with the functioning of medical devices.

The FDA emphasizes that cybersecurity of connected medical devices must be managed throughout the entire lifecycle of a device, from design to post-market surveillance.

https://www.fda.gov/medical-devices/digital-health-center-excellence/cybersecurity-medical-devices

In Europe, regulatory authorities also stress the need to integrate cybersecurity of medical devices into post-market surveillance and materiovigilance systems.

Cybersecurity of Connected Medical Devices Integrated into Regulatory Requirements

In response to these challenges, regulatory authorities have progressively strengthened requirements related to the cybersecurity of connected medical devices.

The European Medical Device Regulation (MDR – Regulation (EU) 2017/745) now requires manufacturers to integrate cybersecurity considerations into risk management and clinical evaluation.

The European Commission highlights that manufacturers must address cybersecurity threats as early as the design stage of medical devices, following a “security by design” approach.

https://health.ec.europa.eu/system/files/2020-09/md_cybersecurity_en_0.pdf

This approach to cybersecurity of connected medical devices includes:

  • identifying potential vulnerabilities
  • implementing regular software updates
  • securing data exchanges
  • managing security patches

As a result, cybersecurity of medical devices is now considered part of a device’s safety and performance, alongside its clinical performance.

A Major Challenge for Healthcare Institutions

The cybersecurity of connected medical devices is not only the responsibility of manufacturers. Healthcare institutions also play a crucial role.

Hospitals now rely on complex networks linking medical devices, electronic health records, and IT infrastructures. This interconnected environment increases the number of potential entry points for cyberattacks targeting the cybersecurity of connected medical devices.

Several international reports highlight that healthcare organizations are among the sectors most frequently targeted by cyberattacks.

In this context, managing cybersecurity of connected medical devices requires close collaboration between:

  • medical device manufacturers
  • hospital biomedical engineering teams
  • cybersecurity and IT specialists
  • regulatory authorities

Cybersecurity of Connected Medical Devices: Toward a New Risk Culture

The digital transformation of healthcare offers considerable opportunities to improve diagnosis, patient monitoring, and healthcare system performance.

However, it also requires the integration of new types of risks.

The cybersecurity of medical devices is now emerging as a fundamental component of clinical safety. Addressing these risks requires a comprehensive approach combining secure design, post-market monitoring, and robust governance of digital risks.

As medical devices become increasingly connected and intelligent, ensuring the cybersecurity of medical devices will likely become a strategic priority for the entire healthcare ecosystem.

If you would like to receive regularly our articles, please subscribe here.

Other articles to consult

Participez au webinaire

Présentation de BluePharm Academy : Les modules de formation de BluePharm