{"id":7754,"date":"2026-08-29T11:36:08","date_gmt":"2026-08-29T09:36:08","guid":{"rendered":"https:\/\/mediconomics.com\/glossar\/cybersecurity-for-medical-devices\/"},"modified":"2026-08-29T11:36:08","modified_gmt":"2026-08-29T09:36:08","slug":"cybersecurity-for-medical-devices","status":"publish","type":"glossary","link":"https:\/\/mediconomics.com\/en\/glossar\/cybersecurity-for-medical-devices\/","title":{"rendered":"Cybersecurity for Medical Devices"},"content":{"rendered":"<p>Cybersecurity for medical devices refers to the full set of measures used to protect a product against unauthorized access, manipulation, and failure as a result of attacks, so that its safety and performance are maintained. Regulation (EU) 2017\/745 does not explicitly mention the term, but it embeds the requirements in several points of Annex I. Point 17.2 requires that software be developed in accordance with the principles of risk management, including information security; point 17.4 obliges manufacturers to define minimum requirements for hardware, IT network characteristics, and IT security measures, including protection against unauthorized access. MDCG 2019-16 Revision 1 specifies these requirements in more detail.  <\/p>\n<h2>Legal basis in Annex I<\/h2>\n<p>The relevant requirements are spread across Annex I. Point 3 requires a risk management system that also captures security-relevant threats. Point 14.2(d) concerns the interaction between software and the IT environment, and point 18.8 addresses protection against unauthorized access for products with an energy source. For information provided, point 23.4(ab) requires that the instructions for use specify the minimum requirements for hardware, IT network characteristics, and IT security measures, and point 23.1(g) requires residual risks to be stated. Cybersecurity is therefore part of the general safety and performance requirements and must be substantiated in the technical documentation in accordance with Annexes II and III.   <\/p>\n<h2>Security risk management and MDCG 2019-16<\/h2>\n<p>The guidance distinguishes between the classic safety risk and the security risk. In the case of an attack, the probability of occurrence cannot be estimated in a statistical sense; instead, the exploitability of a vulnerability and the impact on patients are assessed. Both perspectives must be brought together, because a security measure can create a patient risk and vice versa. MDCG 2019-16 describes eight practices: security management; defining security requirements such as authentication, authorization, encryption, and auditing; secure design; secure implementation; verification and validation of security functions; handling security-relevant incidents; managing security updates; and security guidance for users. The guidance cites IEC 81001-5-1, IEC 62443-4-1, IEC 62304, and ISO 14971 as reference standards.    <\/p>\n<h2>Operating environment and operator responsibility<\/h2>\n<p>A medical device is operated in an IT environment that the manufacturer does not control. Responsibility is therefore shared: the manufacturer defines the minimum requirements for the network, hardware, and safeguards and documents them in the instructions for use; the operator implements them and is responsible for network segmentation, access control, and system maintenance. However, MDCG 2019-16 makes it clear that requirements for the operating environment must not, in principle, replace product-side security controls. A layered approach is recommended, referred to in English as defence in depth, combining multiple independent layers of protection. Operators are also subject to additional national information security requirements.    <\/p>\n<h2>Vulnerability and patch management<\/h2>\n<p>After placing on the market, cybersecurity is an ongoing task. This requires a process for receiving and assessing vulnerability reports, a maintained inventory of the software components used including versions, and a process that provides security updates in a timely manner and safeguards them with regression testing before release. The results feed into post-market surveillance under Articles 83 to 86. If a vulnerability or its exploitation leads to a serious incident or requires a field safety corrective action, the reporting obligations under Article 87 apply. Material changes to the security architecture may also trigger a renewed assessment by the notified body.   <\/p>\n<h2>Distinction from NIS2, the Cyber Resilience Act, and data protection<\/h2>\n<p>Three regulatory areas are regularly confused. Directive (EU) 2022\/2555, known as NIS2, is aimed at entities and their risk management, not products; in the healthcare sector it covers, among others, medical device manufacturers that are classified as critical in a public health emergency. Regulation (EU) 2024\/2847 on horizontal cybersecurity requirements for products with digital elements, known as the Cyber Resilience Act, explicitly excludes products that fall under Regulation (EU) 2017\/745; for medical devices, the MDR remains the relevant framework. Data protection, finally, is a separate requirement: Article 62(4)(h) of Regulation (EU) 2017\/745 requires the protection of personal data for clinical investigations, irrespective of the product\u2019s technical safeguards.   <\/p>\n<h2>Relevance for clinical trials<\/h2>\n<p>In clinical investigations, cybersecurity has an impact at two levels. At product level, the security measures of the investigational device must be specified and verified before the study starts and described in the documentation under Annex XV, because an exploitable vulnerability constitutes a patient risk. It must also be clarified which network and hardware prerequisites each investigational site must meet and how updates will be handled during the study; a security patch is a product change and must be assessed within the study\u2019s change management.  <\/p>\n<p>At data level, requirements apply to the integrity and confidentiality of study data, for example for electronic case report forms, remote reading of device data, or patient-facing applications. Access concepts, pseudonymization, audit trails, and reporting pathways must be defined before the first data collection. Full-service CROs such as Mediconomics support manufacturers in aligning security requirements with the protocol and site prerequisites, assessing updates during the study, establishing data-protection-compliant data collection processes, and providing medical writing for study and regulatory documentation.  <\/p>\n<h2>Frequently Asked Questions (FAQ)<\/h2>\n<p><strong>Which MDR provision explicitly requires cybersecurity?<\/strong><\/p>\n<p>Primarily Annex I points 17.2 and 17.4, supplemented by point 18.8 and the information obligation under point 23.4(ab). The term \u201ccybersecurity\u201d itself is not used in the text of the Regulation. <\/p>\n<p><strong>Does the Cyber Resilience Act apply to medical devices?<\/strong><\/p>\n<p>No. Regulation (EU) 2024\/2847 excludes products that fall under Regulation (EU) 2017\/745. The requirements of Annex I and the MDCG 2019-16 guidance remain decisive.  <\/p>\n<p><strong>May the manufacturer shift security measures to the operator?<\/strong><\/p>\n<p>Only as a supplement. Requirements for the operating environment are permissible and must be documented, but must not, in principle, replace product-side protective measures. <\/p>\n<h2>Regulatory References<\/h2>\n<ul>\n<li>Regulation (EU) 2017\/745, Annex I points 3, 14.2, 17.2, 17.4, 18.8 and 23.4<\/li>\n<li>Regulation (EU) 2017\/745, Articles 83 to 87 \u2013 Post-market surveillance and vigilance<\/li>\n<li>MDCG 2019-16 Rev. 1 \u2013 Guidance on Cybersecurity for medical devices<\/li>\n<li>Directive (EU) 2022\/2555 \u2013 NIS2, Annex I, Healthcare sector<\/li>\n<li>Regulation (EU) 2024\/2847 \u2013 Cyber Resilience Act with an exemption for medical devices<\/li>\n<\/ul>\n","protected":false},"excerpt":{"rendered":"<p>Cybersecurity for medical devices refers to the full set of measures used to protect a product against unauthorized access, manipulation, and failure as a result of attacks, so that its safety and performance are maintained. Regulation (EU) 2017\/745 does not explicitly mention the term, but it embeds the requirements in several points of Annex I. [&hellip;]<\/p>\n","protected":false},"author":10,"featured_media":0,"parent":0,"template":"","meta":{"_acf_changed":false,"site-sidebar-layout":"default","site-content-layout":"","ast-site-content-layout":"default","site-content-style":"default","site-sidebar-style":"default","ast-global-header-display":"","ast-banner-title-visibility":"","ast-main-header-display":"","ast-hfb-above-header-display":"","ast-hfb-below-header-display":"","ast-hfb-mobile-header-display":"","site-post-title":"","ast-breadcrumbs-content":"","ast-featured-img":"","footer-sml-layout":"","ast-disable-related-posts":"","theme-transparent-header-meta":"","adv-header-id-meta":"","stick-header-meta":"","header-above-stick-meta":"","header-main-stick-meta":"","header-below-stick-meta":"","astra-migrate-meta-layouts":"default","ast-page-background-enabled":"default","ast-page-background-meta":{"desktop":{"background-color":"","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"tablet":{"background-color":"","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"mobile":{"background-color":"","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""}},"ast-content-background-meta":{"desktop":{"background-color":"var(--ast-global-color-5)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"tablet":{"background-color":"var(--ast-global-color-5)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"mobile":{"background-color":"var(--ast-global-color-5)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""}},"footnotes":""},"glossary-cat":[24],"class_list":["post-7754","glossary","type-glossary","status-publish","hentry","glossary-cat-medizinprodukte-ivd"],"acf":[],"related_terms":"","external_url":"","internal_reference_id":"","_links":{"self":[{"href":"https:\/\/mediconomics.com\/en\/wp-json\/wp\/v2\/glossary\/7754","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/mediconomics.com\/en\/wp-json\/wp\/v2\/glossary"}],"about":[{"href":"https:\/\/mediconomics.com\/en\/wp-json\/wp\/v2\/types\/glossary"}],"author":[{"embeddable":true,"href":"https:\/\/mediconomics.com\/en\/wp-json\/wp\/v2\/users\/10"}],"version-history":[{"count":0,"href":"https:\/\/mediconomics.com\/en\/wp-json\/wp\/v2\/glossary\/7754\/revisions"}],"wp:attachment":[{"href":"https:\/\/mediconomics.com\/en\/wp-json\/wp\/v2\/media?parent=7754"}],"wp:term":[{"taxonomy":"glossary-cat","embeddable":true,"href":"https:\/\/mediconomics.com\/en\/wp-json\/wp\/v2\/glossary-cat?post=7754"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}