Cybersecurity for Medical Devices
MDACS · ISO 14971 · IMDRF cybersecurity guidance
Why Cybersecurity Matters
Medical devices that are networked, connected to other systems, or incorporate software face cybersecurity risks that could affect patient safety — including:
- Unauthorised access or manipulation of device functionality
- Data breaches affecting patient privacy
- Malware affecting device operation
MDACS Cybersecurity Approach
The MDD expects cybersecurity risks to be addressed within the risk management process (ISO 14971). Manufacturers should:
- Identify cybersecurity threats — threat actors and their potential motivations, known or predicted vulnerabilities in the device or its operating environment, and the clinical and operational impact if a threat were realised
- Implement security controls — authentication, encryption, network segmentation, update mechanisms
- Validate security measures — penetration testing, vulnerability scanning
- Plan post-market cybersecurity monitoring — processes for detecting and responding to new vulnerabilities
Relevant Standards and Guidance
| Standard/Guidance | Scope |
|---|---|
| IEC 81001-5-1 | Health software and health IT — cybersecurity |
| IMDRF N60 | Cybersecurity guidance |
| NIST Cybersecurity Framework | General cybersecurity framework |