SlideShare a Scribd company logo
CYBERSECURITY 
FOR 
MEDICAL DEVICES 
MD Project event 
9 december 2014 
Erik Vollebregt 
www.axonadvocaten.nl
Agenda: 
1. Introduction 
2. FDA approach to cybersecurity measures 
3. Current EU Medical Devices law 
4. Future EU Medical Devices law 
5. General EU security regulations and standards
Setting the scene 
• Homeland pacemaker hack; 
• FDA Guidelines on Premarket Submissions for Management of Cubersecurity in 
Medical Devices; 
• Proposals for MDR and IVDR; 
• EU Directive 95/46/EC on personal data protection; 
• EU Commission`s Green Paper on mHealth;
FDA approach to cybersecurity measures 
Based on US National Institute of 
Standards and Technology (NIST) 
cybersecurity framework: 
• identification of assets, threats and 
vulnerabilities; 
• assessment of the impact of 
threats and vulnerabilities on 
device 
• functionality and end users / 
patients; 
• assessment of the likelihood of a 
threat and of a vulnerability being 
exploited; 
• determination of risk levels and 
suitable mitigation strategies; 
• assessment of residual risk and 
risk acceptance criteria;
Are we doing anything in the EU? 
Biggest EVAH! About public utilities 
and communications infrastructure 
What are the medical 
devices companies and 
healthcare institutions 
doing?
EN 62304 § 5.2.2 Software 
requirements content re security 
Typical cybersecurity points, 
but only with respect to 
standalone software
Future EU Medical Devices law 
• nothing specifically new in the field of cybersecurity; 
• MDR Proposal, Annex I, point 14 does not addresses cybersecurity specificallu: 
• point 14.2 repeats point 12.1a of the MDD, which will remain linked to EN 62304 so 
future cybersecurity – for the moment – is more of the same 
• Any cybersecurity measure will need to come from harmonised standard
Future EU Medical Devices law 
• Delegated acts or common technical specifications are a good way to 
amend the general safety and performance requirements with cyber 
security requirements, as foreseen by the new regulations. 
• However, this option for delegated acts is proposed to be removed in the 
EU Parliament`s 1st reading of 2 April 2014.
General EU security regulations and 
standards 
• IEC 80001 – Application of risk management for IT-networks 
incorporating medical devices 
• Plays important role in Swedish competent authority 
Läkemedelsverket in 2009 in the first version of their guidance 
“Proposal for guidelines regarding classification of software based 
information systems used in health care”. 
• This is not a harmonised standard under the medical devices 
directives, because it is directed at clinical institutions and not to 
medical device manufacturers.
Draft NIS Directive 
Article 14 provides for market operator 
• security requirements and 
• incident notification duty 
ERGO: all (medical)devices 
that run software, that 
interconnect and process / 
transmit data
NIS Directive 
Duty to implement 
measures 
Notification duty 
Public disclosure 
of incidents 
Delegated acts
General EU security regulations and 
standards: data protection 
• Protection against e.g. alteration and unauthorized access have 
everything to do with cybersecurity, as these impact directly on safety 
and performance of the device. 
• Non harmonization of the Data Protection Directive is a big problem 
because it leads to the situation of member states taking different views 
on security terms requirements. 
• Dutch NCA refers to ISO 27000 family as informal harmonised standard 
• Dutch sause ISO 27002 mandatory standard in Dutch healthcare 
market (NEN 7510)
Personal data currently in the EU 
• Everybody agrees the current EU system 
is 
• Fragmented 
• Outdated 
• Unclear 
• But, it’s still a good system that has 
produced a lot of good practices, among 
others Article 29 WP opinions on security 
related subjects, e.g. WP 223 on IoT:
General EU security regulations and 
standards 
• Currently authorities mainly approach cybersecurity issues via Data Protection 
Directive, which features a secutiry regime in Article 17(1):
Privacy by design obligations for 
medical devices 
• WP 223: Controller has responsibility for security of IoT devices 
• Parties purchasing OEM devices and solutions will want privacy by 
design compliance warranties
Privacy by design obligations for 
medical devices 
WP 223 on end of life devices and remote monitoring / measuring devices
Data protection: security case 
study 
CASE 
STUDY
Developments? 
• Unfortunately, we did not have yet a European version of the Homeland 
pacemaker hack that gets politicians moving – attention is at 
manageable safety issues in well understood implantables 
• EU Commission seems reluctant to update anything substantive in the 
medical devices guidance while medical device regulations are still in 
works. 
• DG Enterprise might be able to make a difference in cybersecurity for 
medical devices.
Background
THANKS FOR YOUR ATTENTION 
Erik Vollebregt 
Axon Lawyers 
Piet Heinkade 183 
1019 HC Amsterdam 
T +31 88 650 6500 
F +31 88 650 6555 
M +31 6 47 180 683 
E erik.vollebregt@axonlawyers.com 
@meddevlegal 
B http://medicaldeviceslegal.com 
READ MY BLOG: 
http://medicaldeviceslegal.com 
www.axonlawyers.com

More Related Content

PPTX
EU MDR
PPTX
Iso13485 ppt
PPTX
Medical Devices Regulation (MDR) 2017/745 - Identification, traceability
PDF
The European Medical Device Regulations - analysis of the final text
 
PPTX
ISO Standard 13485
PPTX
Cybersecurity in Medical Devices
PPTX
Breakout Session: Cybersecurity in Medical Devices
PDF
IEC 62304 Action List
EU MDR
Iso13485 ppt
Medical Devices Regulation (MDR) 2017/745 - Identification, traceability
The European Medical Device Regulations - analysis of the final text
 
ISO Standard 13485
Cybersecurity in Medical Devices
Breakout Session: Cybersecurity in Medical Devices
IEC 62304 Action List

What's hot (20)

PDF
Understanding IEC 62304
PPTX
Medical Devices Regulation (MDR) 2017/745 - Clinical investigations
PPTX
CE marking and CE certification
PPTX
International Medical Device Regulators Forum
PPTX
Regulatory requirements for CE CERTIFICATION of Medical Devices in European U...
PPTX
IDE Application Process and Best Practices
PPTX
Good distribution practices for API's
PDF
IEC 62304: SDLC Conformance and Management
PPTX
THE FDA and Medical Device Cybersecurity Guidance
PDF
Medical Device Regulations
PPTX
FDA regulation for medical devices
PDF
Presentation: Software as a Medical Device: Regulatory insights and Q & A
PPT
CE Certification.ppt
PPTX
Iso 13485:2016
PDF
Usability Validation Testing of Medical Devices and Software
PPTX
Regulation of software as medical devices
PPTX
ISO 13485.pptx
PPTX
medical device regulatory approval in USA
PPTX
Medical devices
PPTX
ISO 13485: Quality Management System for Medical Device
Understanding IEC 62304
Medical Devices Regulation (MDR) 2017/745 - Clinical investigations
CE marking and CE certification
International Medical Device Regulators Forum
Regulatory requirements for CE CERTIFICATION of Medical Devices in European U...
IDE Application Process and Best Practices
Good distribution practices for API's
IEC 62304: SDLC Conformance and Management
THE FDA and Medical Device Cybersecurity Guidance
Medical Device Regulations
FDA regulation for medical devices
Presentation: Software as a Medical Device: Regulatory insights and Q & A
CE Certification.ppt
Iso 13485:2016
Usability Validation Testing of Medical Devices and Software
Regulation of software as medical devices
ISO 13485.pptx
medical device regulatory approval in USA
Medical devices
ISO 13485: Quality Management System for Medical Device
Ad

Similar to Cybersecurity for medical devices in the EU (20)

PPTX
MMA roadshow m health summit europe
PPTX
Mma roadshow mHealth in the EU
PPTX
EU cybersecurity requirements under current and future medical devices regula...
PDF
Software and Smartphone Applications By E. Vollebregt - Axon Lawers (Qserve C...
PPTX
E health, mhealth and apps
PPTX
Andy-Bridden-IoMT-Canterburyv1.pptx
PPT
eHealth and mhealth presentation
PPT
ehealthandmhealthpresentation-130310142714-phpapp01.ppt
DOCX
EU MDR Annex I Simplified
PDF
Steps to Compliance with the European Medical Device Regulations
PPTX
regulatoryapprovalprocessformdineu-150120223330-conversion-gate02.pptx
PDF
Health apps regulation and quality control case studies and session 2 present...
PDF
Health apps regulation and quality control case studies and session 2 present...
PPTX
[Wroclaw #6] Medical device security
PDF
Cybersécurité des dispositifs médicaux
PPTX
Recent and future developments in UDI for medical devices in the EU
PDF
Legal-landscape-struggles-to-keep-pace-with-the-rise-of-Telemedicine
PPTX
Presentation: Conformity assessment evidence
PPTX
EU data protection issues in IoT
PDF
EU General Data Protection: Implications for Smart Metering
MMA roadshow m health summit europe
Mma roadshow mHealth in the EU
EU cybersecurity requirements under current and future medical devices regula...
Software and Smartphone Applications By E. Vollebregt - Axon Lawers (Qserve C...
E health, mhealth and apps
Andy-Bridden-IoMT-Canterburyv1.pptx
eHealth and mhealth presentation
ehealthandmhealthpresentation-130310142714-phpapp01.ppt
EU MDR Annex I Simplified
Steps to Compliance with the European Medical Device Regulations
regulatoryapprovalprocessformdineu-150120223330-conversion-gate02.pptx
Health apps regulation and quality control case studies and session 2 present...
Health apps regulation and quality control case studies and session 2 present...
[Wroclaw #6] Medical device security
Cybersécurité des dispositifs médicaux
Recent and future developments in UDI for medical devices in the EU
Legal-landscape-struggles-to-keep-pace-with-the-rise-of-Telemedicine
Presentation: Conformity assessment evidence
EU data protection issues in IoT
EU General Data Protection: Implications for Smart Metering
Ad

More from Erik Vollebregt (20)

PPTX
Economic operators and the exits
PPTX
Q1 medical device packaging conference 10 november 2020
PPTX
Easy medical devices podcast self tests ivdr
PPTX
Your legal relationship with your notified body
PPTX
Point of-care, biosensors & mobile diagnostics europe 2019
PPTX
HOW TO WORK WITH EMERGENCY RULES RELATING TO COVID 19?
PPTX
M&A and medical devices presentation
PPTX
MDR and class I medical devices presentation
PPTX
Q1 MDR and IVDR PRRC presentation
PPTX
Legal aspects of the new EU Medical Devices Regulation - known and unknowns
PPTX
Advamed Med Tech 2019 countdown presentation
PPTX
Managing New Requirement for Economic Operator Regime
PPTX
Legal and regulatory developments in precision medicine and diagnostic devices
PPTX
Q1 Medical Devices Regulation - practical consequences for manufacturers
PPTX
Economic operators under the MDR and IVDR
PPTX
GDPR and eHealth for the pharma industry (VFenR presentation)
PPTX
VZI jaarcongres: de MDR en IVDR - de impact in de medische techniek
PPTX
NEN symposium on Medical Devices and IVD Regulation
PPTX
Advamed EU MDR and IVDR panel presentation
PPTX
Use of left over samples under the IVDR and GDPR
Economic operators and the exits
Q1 medical device packaging conference 10 november 2020
Easy medical devices podcast self tests ivdr
Your legal relationship with your notified body
Point of-care, biosensors & mobile diagnostics europe 2019
HOW TO WORK WITH EMERGENCY RULES RELATING TO COVID 19?
M&A and medical devices presentation
MDR and class I medical devices presentation
Q1 MDR and IVDR PRRC presentation
Legal aspects of the new EU Medical Devices Regulation - known and unknowns
Advamed Med Tech 2019 countdown presentation
Managing New Requirement for Economic Operator Regime
Legal and regulatory developments in precision medicine and diagnostic devices
Q1 Medical Devices Regulation - practical consequences for manufacturers
Economic operators under the MDR and IVDR
GDPR and eHealth for the pharma industry (VFenR presentation)
VZI jaarcongres: de MDR en IVDR - de impact in de medische techniek
NEN symposium on Medical Devices and IVD Regulation
Advamed EU MDR and IVDR panel presentation
Use of left over samples under the IVDR and GDPR

Recently uploaded (20)

PDF
Khadir.pdf Acacia catechu drug Ayurvedic medicine
PPTX
surgery guide for USMLE step 2-part 1.pptx
PPT
1b - INTRODUCTION TO EPIDEMIOLOGY (comm med).ppt
PDF
Therapeutic Potential of Citrus Flavonoids in Metabolic Inflammation and Ins...
PPT
Breast Cancer management for medicsl student.ppt
PDF
Medical Evidence in the Criminal Justice Delivery System in.pdf
PPTX
Pathophysiology And Clinical Features Of Peripheral Nervous System .pptx
PPTX
Electromyography (EMG) in Physiotherapy: Principles, Procedure & Clinical App...
PPT
genitourinary-cancers_1.ppt Nursing care of clients with GU cancer
PPTX
Slider: TOC sampling methods for cleaning validation
PPTX
Uterus anatomy embryology, and clinical aspects
PPTX
post stroke aphasia rehabilitation physician
PPTX
ca esophagus molecula biology detailaed molecular biology of tumors of esophagus
PPTX
Important Obstetric Emergency that must be recognised
PPTX
Acid Base Disorders educational power point.pptx
PPTX
15.MENINGITIS AND ENCEPHALITIS-elias.pptx
PPTX
JUVENILE NASOPHARYNGEAL ANGIOFIBROMA.pptx
PPT
ASRH Presentation for students and teachers 2770633.ppt
PPTX
Imaging of parasitic D. Case Discussions.pptx
PPT
OPIOID ANALGESICS AND THEIR IMPLICATIONS
Khadir.pdf Acacia catechu drug Ayurvedic medicine
surgery guide for USMLE step 2-part 1.pptx
1b - INTRODUCTION TO EPIDEMIOLOGY (comm med).ppt
Therapeutic Potential of Citrus Flavonoids in Metabolic Inflammation and Ins...
Breast Cancer management for medicsl student.ppt
Medical Evidence in the Criminal Justice Delivery System in.pdf
Pathophysiology And Clinical Features Of Peripheral Nervous System .pptx
Electromyography (EMG) in Physiotherapy: Principles, Procedure & Clinical App...
genitourinary-cancers_1.ppt Nursing care of clients with GU cancer
Slider: TOC sampling methods for cleaning validation
Uterus anatomy embryology, and clinical aspects
post stroke aphasia rehabilitation physician
ca esophagus molecula biology detailaed molecular biology of tumors of esophagus
Important Obstetric Emergency that must be recognised
Acid Base Disorders educational power point.pptx
15.MENINGITIS AND ENCEPHALITIS-elias.pptx
JUVENILE NASOPHARYNGEAL ANGIOFIBROMA.pptx
ASRH Presentation for students and teachers 2770633.ppt
Imaging of parasitic D. Case Discussions.pptx
OPIOID ANALGESICS AND THEIR IMPLICATIONS

Cybersecurity for medical devices in the EU

  • 1. CYBERSECURITY FOR MEDICAL DEVICES MD Project event 9 december 2014 Erik Vollebregt www.axonadvocaten.nl
  • 2. Agenda: 1. Introduction 2. FDA approach to cybersecurity measures 3. Current EU Medical Devices law 4. Future EU Medical Devices law 5. General EU security regulations and standards
  • 3. Setting the scene • Homeland pacemaker hack; • FDA Guidelines on Premarket Submissions for Management of Cubersecurity in Medical Devices; • Proposals for MDR and IVDR; • EU Directive 95/46/EC on personal data protection; • EU Commission`s Green Paper on mHealth;
  • 4. FDA approach to cybersecurity measures Based on US National Institute of Standards and Technology (NIST) cybersecurity framework: • identification of assets, threats and vulnerabilities; • assessment of the impact of threats and vulnerabilities on device • functionality and end users / patients; • assessment of the likelihood of a threat and of a vulnerability being exploited; • determination of risk levels and suitable mitigation strategies; • assessment of residual risk and risk acceptance criteria;
  • 5. Are we doing anything in the EU? Biggest EVAH! About public utilities and communications infrastructure What are the medical devices companies and healthcare institutions doing?
  • 6. EN 62304 § 5.2.2 Software requirements content re security Typical cybersecurity points, but only with respect to standalone software
  • 7. Future EU Medical Devices law • nothing specifically new in the field of cybersecurity; • MDR Proposal, Annex I, point 14 does not addresses cybersecurity specificallu: • point 14.2 repeats point 12.1a of the MDD, which will remain linked to EN 62304 so future cybersecurity – for the moment – is more of the same • Any cybersecurity measure will need to come from harmonised standard
  • 8. Future EU Medical Devices law • Delegated acts or common technical specifications are a good way to amend the general safety and performance requirements with cyber security requirements, as foreseen by the new regulations. • However, this option for delegated acts is proposed to be removed in the EU Parliament`s 1st reading of 2 April 2014.
  • 9. General EU security regulations and standards • IEC 80001 – Application of risk management for IT-networks incorporating medical devices • Plays important role in Swedish competent authority Läkemedelsverket in 2009 in the first version of their guidance “Proposal for guidelines regarding classification of software based information systems used in health care”. • This is not a harmonised standard under the medical devices directives, because it is directed at clinical institutions and not to medical device manufacturers.
  • 10. Draft NIS Directive Article 14 provides for market operator • security requirements and • incident notification duty ERGO: all (medical)devices that run software, that interconnect and process / transmit data
  • 11. NIS Directive Duty to implement measures Notification duty Public disclosure of incidents Delegated acts
  • 12. General EU security regulations and standards: data protection • Protection against e.g. alteration and unauthorized access have everything to do with cybersecurity, as these impact directly on safety and performance of the device. • Non harmonization of the Data Protection Directive is a big problem because it leads to the situation of member states taking different views on security terms requirements. • Dutch NCA refers to ISO 27000 family as informal harmonised standard • Dutch sause ISO 27002 mandatory standard in Dutch healthcare market (NEN 7510)
  • 13. Personal data currently in the EU • Everybody agrees the current EU system is • Fragmented • Outdated • Unclear • But, it’s still a good system that has produced a lot of good practices, among others Article 29 WP opinions on security related subjects, e.g. WP 223 on IoT:
  • 14. General EU security regulations and standards • Currently authorities mainly approach cybersecurity issues via Data Protection Directive, which features a secutiry regime in Article 17(1):
  • 15. Privacy by design obligations for medical devices • WP 223: Controller has responsibility for security of IoT devices • Parties purchasing OEM devices and solutions will want privacy by design compliance warranties
  • 16. Privacy by design obligations for medical devices WP 223 on end of life devices and remote monitoring / measuring devices
  • 17. Data protection: security case study CASE STUDY
  • 18. Developments? • Unfortunately, we did not have yet a European version of the Homeland pacemaker hack that gets politicians moving – attention is at manageable safety issues in well understood implantables • EU Commission seems reluctant to update anything substantive in the medical devices guidance while medical device regulations are still in works. • DG Enterprise might be able to make a difference in cybersecurity for medical devices.
  • 20. THANKS FOR YOUR ATTENTION Erik Vollebregt Axon Lawyers Piet Heinkade 183 1019 HC Amsterdam T +31 88 650 6500 F +31 88 650 6555 M +31 6 47 180 683 E erik.vollebregt@axonlawyers.com @meddevlegal B http://medicaldeviceslegal.com READ MY BLOG: http://medicaldeviceslegal.com www.axonlawyers.com