Cybersecurity of Internet of Things in the health sector: Understanding the applicable legal framework

被引:0
|
作者
Casarosa, Federica [1 ]
机构
[1] Scuola Super Sant Anna, Pisa, Italy
关键词
Cybersecurity; Internet of things; Medical device; Health law; Data protection; Data breach; Incident response;
D O I
10.1016/j.clsr.2024.105982
中图分类号
D9 [法律]; DF [法律];
学科分类号
0301 ;
摘要
Although the digitalisation of healthcare is an ongoing process that dates back to more than two decades ago, it has gained more momentum with the COVID-19 pandemic. Recent developments in this sector include the adoption of wearable devices based on Internet of Things technology. The possibility of connecting devices that can work outside the physical boundaries of a hospital and follow patients at home, i.e. during their day-to-day life, has several obvious advantages. However, the digitalisation of the health sector through increased adoption of connected devices does not exclude vulnerabilities, particularly risks concerning the protection of patients' data and the security of networks and information systems. Connected devices can gather, process, and store personal patient health data. Failure to safeguard the integrity and security of these data may affect the patients' identity and finances and put their lives at risk. The presence of an IoT device in a healthcare setting may affect and reduce the level of network security of the overall system as it may provide an access point for an unlawful hacking attack. Although IoT technologies in the health sector are becoming increasingly pervasive, the European legal framework applicable to them is not clearly defined. This is extremely relevant in the case of cybersecurity, where the legal point of reference is the General Data Protection Regulation, addressing the measures and requirements applicable in case of data breaches, and the Medical Device Regulation, providing provisions focused on the security of data relevant to IoT defined as medical devices. The most recent interventions that address health data processing and cybersecurity are the proposed Cyber Resilience Act and the Health Data Space Regulation. The two acts provide measures and requirements applicable to IoT from two perspectives. Yet, they add complexities and some inconsistencies that may hamper the effectiveness of the overall cybersecurity framework.
引用
收藏
页数:12
相关论文
共 50 条
  • [1] Cybersecurity in the Internet of Things: Legal aspects
    Weber, Rolf H.
    Studer, Evelyne
    [J]. COMPUTER LAW & SECURITY REVIEW, 2016, 32 (05) : 715 - 728
  • [2] Adaptive Cybersecurity Framework for Healthcare Internet of Things
    Boudko, Svetlana
    Abie, Habtamu
    [J]. 2019 13TH INTERNATIONAL SYMPOSIUM ON MEDICAL INFORMATION AND COMMUNICATION TECHNOLOGY (ISMICT), 2019, : 210 - 215
  • [3] Toward a Cybersecurity Certification Framework for the Internet of Things
    Matheu, Sara N.
    Hernandez-Ramos, Jose L.
    Skarmeta, Antonio F.
    [J]. IEEE SECURITY & PRIVACY, 2019, 17 (03) : 66 - 76
  • [4] Medical Internet of Things and Legal Issues Regarding Cybersecurity
    Chou, Chien-Cheng
    [J]. IOT AS A SERVICE, IOTAAS 2017, 2018, 246 : 50 - 53
  • [5] A Proposed The Internet of Things (IoT) Framework for Health Sector in Indonesia
    Ariyanti, Sri
    Kautsarina
    [J]. 2018 IEEE REGION TEN SYMPOSIUM (TENSYMP), 2018, : 282 - 286
  • [6] An Ontology-Based Cybersecurity Framework for the Internet of Things
    Mozzaquatro, Bruno Augusti
    Agostinho, Carlos
    Goncalves, Diogo
    Martins, Joao
    Jardim-Goncalves, Ricardo
    [J]. SENSORS, 2018, 18 (09)
  • [7] CYBERSECURITY AND INTERNET OF THINGS
    Capek, Jan
    [J]. STRATEGIC MODELING IN MANAGEMENT, ECONOMY AND SOCIETY (IDIMT-2018), 2018, 47 : 343 - 349
  • [8] A Deep Learning-Based Framework for Strengthening Cybersecurity in Internet of Health Things (IoHT) Environments
    Algethami, Sarah A.
    Alshamrani, Sultan S.
    [J]. APPLIED SCIENCES-BASEL, 2024, 14 (11):
  • [9] The Internet of Things Cybersecurity Examination
    Prokofiey, Anton O.
    Smirnova, Yulia S.
    Silnov, Dmitry S.
    [J]. 2017 SIBERIAN SYMPOSIUM ON DATA SCIENCE AND ENGINEERING (SSDSE), 2017, : 44 - 48
  • [10] Cybersecurity in the Internet of Medical Things
    Thomasian, Nicole M.
    Adashi, Eli Y.
    [J]. HEALTH POLICY AND TECHNOLOGY, 2021, 10 (03)