The Role of Cybersecurity in Medical Devices Regulation: Future Considerations and Solutions

被引:3
|
作者
Ludvigsen, Kaspar Rosager [1 ]
机构
[1] Univ Edinburgh, Edinburgh, Scotland
来源
LAW TECHNOLOGY AND HUMANS | 2023年 / 5卷 / 02期
基金
英国科研创新办公室;
关键词
Medical devices; EU Law; cybersecurity; policy; technology regulation; EUROPEAN-UNION; UNITED-STATES; SYSTEMS; COMPLEX;
D O I
10.5204/lthj.3080
中图分类号
D9 [法律]; DF [法律];
学科分类号
0301 ;
摘要
The cybersecurity of medical devices is paramount in a world where everything is increasingly digitised. Attention to how this important defence against malicious actors is regulated must, therefore, also increase. This paper uncovers how the cybersecurity of medical devices is currently regulated and how it can be improved going forward. First, the paper compares the regulation of medical device cybersecurity in the European Union, the United States and the United Kingdom (UK)-differentiating between Great Britain and Northern Ireland as per the current state of the law in the UK. Second, the paper develops a model of how cybersecurity shapes three key areas in the ecosystem of medical devices. These areas are the medical device itself; the structure between the surrounding institutional systems (such as manufacturers and healthcare providers); and the security of the data, the surrounding institutional system and the medical device. Third, based on a comparative analysis and a view of the system from above, the paper puts forward four recommendations on what future regulation should contain to properly regulate the cybersecurity of medical devices: technology specificity, circumvention protection, genuine privacy and security by design. The paper recommends that these four principles be followed. Technology specificity because it guarantees legislation that understands the necessary technical aspects to promote security and safety. Circumvention protection because preventing manufacturers and others from circumventing these requirements decreases risks to the health and wellbeing of patients. Finally, genuine privacy and security by design should be followed to align cybersecurity and privacy with current and future technical capacities.
引用
收藏
页码:59 / 77
页数:19
相关论文
共 50 条
  • [21] REGULATION OF MEDICAL DEVICES
    不详
    FDA PAPERS, 1971, 5 (10): : 30 - &
  • [22] The regulation of medical devices
    Wilmshurst, Peter
    BRITISH MEDICAL JOURNAL, 2011, 342
  • [23] REGULATION OF MEDICAL DEVICES
    SPIVAK, JM
    ANNALS OF THE AMERICAN ACADEMY OF POLITICAL AND SOCIAL SCIENCE, 1972, 400 (MAR): : 82 - 94
  • [24] MEDICAL DEVICES AND THEIR REGULATION
    EDWARDS, CC
    MEDICAL RESEARCH ENGINEERING, 1970, 9 (05) : 3 - &
  • [25] THE REGULATION OF MEDICAL DEVICES
    BANTA, HD
    PREVENTIVE MEDICINE, 1990, 19 (06) : 693 - 699
  • [26] Cybersecurity Protection for PACS and Medical Imaging: Deployment Considerations and Practical
    Eichelberg, Marco
    Kleber, Klaus
    Kaemmerer, Marc
    ACADEMIC RADIOLOGY, 2021, 28 (12) : 1761 - 1774
  • [27] Benefits of Conformity Assessment for Cybersecurity Standards of Diabetes Devices and Other Medical Devices
    Shang, Trisha
    Zhang, Jennifer Y.
    Dawson, Joe
    Klonoff, David C.
    JOURNAL OF DIABETES SCIENCE AND TECHNOLOGY, 2021, 15 (04): : 727 - 732
  • [28] Survey: Cybersecurity Vulnerabilities, Attacks and Solutions in the Medical Domain
    Razaque, Abdul
    Amsaad, Fathi
    Khan, Meer Jaro
    Hariri, Salim
    Chen, Shujing
    Chen Siting
    Ji, Xingchen
    IEEE ACCESS, 2019, 7 : 168774 - 168797
  • [29] Cybersecurity vulnerabilities in medical devices: a complex environment and multifaceted problem
    Williams, Patricia A. H.
    Woodward, Andrew J.
    MEDICAL DEVICES-EVIDENCE AND RESEARCH, 2015, 8 (305-316): : 305 - 315
  • [30] Considerations on Electromagnetic Compatibility for Medical Devices
    Buzdugan, M. I.
    Buzdugan, T. I.
    Balan, H.
    INTERNATIONAL CONFERENCE ON ADVANCEMENTS OF MEDICINE AND HEALTH CARE THROUGH TECHNOLOGY, 2011, 36 : 94 - 99