Suppr超能文献

欧盟和美国医疗设备的网络安全要求——MDCG 2019-16与美国食品药品监督管理局上市前网络安全指南的比较及差距分析

Cybersecurity requirements for medical devices in the EU and US - A comparison and gap analysis of the MDCG 2019-16 and FDA premarket cybersecurity guidance.

作者信息

Ostermann Max, Mathias Rebecca, Jahed Fatemeh, Parker Mitchell B, Hudson Florence D, Harding William C, Gilbert Stephen, Freyer Oscar

机构信息

Else Kröner Fresenius Center for Digital Health, TUD Dresden University of Technology, Dresden, Germany.

Information Security and Compliance, Indiana University Health, Indiana University Health University Hospital, Indianapolis, IN, USA.

出版信息

Comput Struct Biotechnol J. 2025 Jul 15;28:259-266. doi: 10.1016/j.csbj.2025.07.024. eCollection 2025.

Abstract

The increasing use of connected medical devices has led to substantial cybersecurity challenges, putting patient safety and the integrity of healthcare infrastructures at risk. This study examines regulatory guidance on medical device cybersecurity in the European Union (guidance document of Medical Device Coordination Group MDCG 2019-16 revision 1) and the United States (US Food and Drug Administration Guidance on Cybersecurity) and identifies their strengths and weaknesses. First, the study compares these documents with a baseline requirements framework derived from international standards and best practices, revealing gaps in the thematic areas of "Cryptography," "Authentication & Access Control," and "Source Code/Software Development." Second, the guidance documents were compared with real-world cybersecurity incidents, showing that the current guidance documents would help to mitigate the weaknesses of important vulnerability examples, while recommendations are missing in both guidance documents, but more so in MDCG 2019-16, for the most important weaknesses. In conclusion, both guidance documents are inadequately formulated in certain aspects, have an unclear scope, inconsistent levels of detail, and contain thematic gaps. These gaps could result in manufacturers failing to sufficiently address cybersecurity concerns in their products, thereby creating vulnerabilities. This study highlights the need for future guidance documents to be clearer in scope and to close existing gaps to ultimately allow safer medical devices.

摘要

联网医疗设备的使用日益增加,带来了重大的网络安全挑战,使患者安全和医疗保健基础设施的完整性面临风险。本研究审视了欧盟(医疗器械协调小组MDCG 2019 - 16修订版1的指导文件)和美国(美国食品药品监督管理局网络安全指南)关于医疗器械网络安全的监管指导,并确定了它们的优点和缺点。首先,该研究将这些文件与源自国际标准和最佳实践的基线要求框架进行比较,揭示了“加密”、“认证与访问控制”以及“源代码/软件开发”等主题领域存在的差距。其次,将指导文件与实际网络安全事件进行比较,结果表明当前的指导文件有助于减轻重要漏洞示例的弱点,不过两份指导文件都缺少针对最重要弱点的建议,MDCG 2019 - 16中更是如此。总之,两份指导文件在某些方面的制定都不够完善,范围不明确,细节程度不一致,且存在主题空白。这些空白可能导致制造商未能充分解决其产品中的网络安全问题,从而产生漏洞。本研究强调,未来的指导文件需要在范围上更加清晰,并填补现有空白,以最终实现医疗设备更安全。

https://cdn.ncbi.nlm.nih.gov/pmc/blobs/5e54/12301760/7cc37525af56/ga1.jpg

相似文献

2
Mapping the European landscape and specificity of ATMPs guidance.
Cytotherapy. 2025 Jun 20. doi: 10.1016/j.jcyt.2025.06.008.
3
4
Medical assistance in dying in Canada: A review of regulatory practice standards and guidance documents for physicians.
Palliat Care Soc Pract. 2025 Jun 24;19:26323524251338859. doi: 10.1177/26323524251338859. eCollection 2025.
5
The Black Book of Psychotropic Dosing and Monitoring.
Psychopharmacol Bull. 2024 Jul 8;54(3):8-59.
8
"In a State of Flow": A Qualitative Examination of Autistic Adults' Phenomenological Experiences of Task Immersion.
Autism Adulthood. 2024 Sep 16;6(3):362-373. doi: 10.1089/aut.2023.0032. eCollection 2024 Sep.
9
Neuraminidase inhibitors for preventing and treating influenza in healthy adults and children.
Cochrane Database Syst Rev. 2012 Jan 18;1:CD008965. doi: 10.1002/14651858.CD008965.pub3.

本文引用的文献

1
How secure are your health devices-stopping wearables becoming a personal and national security risk?
NPJ Digit Med. 2025 May 28;8(1):317. doi: 10.1038/s41746-025-01710-2.
2
Policing the Boundary Between Responsible and Irresponsible Placing on the Market of Large Language Model Health Applications.
Mayo Clin Proc Digit Health. 2025 Jan 21;3(1):100196. doi: 10.1016/j.mcpdig.2025.100196. eCollection 2025 Mar.
5
Cybersecurity vulnerability analysis of medical devices purchased by national health services.
Sci Rep. 2023 Nov 9;13(1):19509. doi: 10.1038/s41598-023-45927-1.
6
Security vulnerabilities in healthcare: an analysis of medical devices and software.
Med Biol Eng Comput. 2024 Jan;62(1):257-273. doi: 10.1007/s11517-023-02912-0. Epub 2023 Oct 4.
7
Trends in Ransomware Attacks on US Hospitals, Clinics, and Other Health Care Delivery Organizations, 2016-2021.
JAMA Health Forum. 2022 Dec 2;3(12):e224873. doi: 10.1001/jamahealthforum.2022.4873.
8
Analyzing medical device connectivity and its effect on cyber security in german hospitals.
BMC Med Inform Decis Mak. 2020 Sep 29;20(1):246. doi: 10.1186/s12911-020-01259-y.
9
Cybersecurity features of digital medical devices: an analysis of FDA product summaries.
BMJ Open. 2019 Jun 28;9(6):e025374. doi: 10.1136/bmjopen-2018-025374.
10
Cybersecurity vulnerabilities in medical devices: a complex environment and multifaceted problem.
Med Devices (Auckl). 2015 Jul 20;8:305-16. doi: 10.2147/MDER.S50048. eCollection 2015.

文献AI研究员

20分钟写一篇综述,助力文献阅读效率提升50倍。

立即体验

用中文搜PubMed

大模型驱动的PubMed中文搜索引擎

马上搜索

文档翻译

学术文献翻译模型,支持多种主流文档格式。

立即体验