---
title: Why MD Cybersecurity is so important
description: Understand the reasons why nowadays Cybersecurity has become a main concern for all Medical Devices producers.
image: https://blog.pqegroup.com/hubfs/Cybersecurity-for-Medical-Devices-risks-and-vulnerabilities.jpg
---

[![Logo PQE Group - azzurro - 2024](https://blog.pqegroup.com/hs-fs/hubfs/Logo%20PQE%20Group%20-%20azzurro%20-%202024.png?width=2000&height=721&name=Logo%20PQE%20Group%20-%20azzurro%20-%202024.png "Logo PQE Group - azzurro - 2024")](https://www2.pqegroup.com)

- [Home](https://www2.pqegroup.com/)
- [Industry](https://www2.pqegroup.com/industry/) 
    - [Pharma & API](https://www2.pqegroup.com/pharma-api/)
    - [Medical Device](https://www2.pqegroup.com/medical-device/)
    - [Biotech](https://www2.pqegroup.com/biotech/)
    - [Startup](https://www2.pqegroup.com/startup/)
    - [Veterinary](https://www2.pqegroup.com/veterinary/)
- [Services](https://www2.pqegroup.com/services/) 
    - [Data Integrity](https://www2.pqegroup.com/data-integrity/)
    - [Digital Governance](https://www2.pqegroup.com/digital-governance/)
    - [Engineering](https://www2.pqegroup.com/engineering/)
    - [Commissioning, Qualification and Validation (CQV)](https://www2.pqegroup.com/commissioning-qualification-validation/)
    - [Quality Compliance](https://www2.pqegroup.com/quality-compliance/)
    - [Laboratory Excellence](https://www2.pqegroup.com/laboratory-excellence/)
    - [Regulatory Affairs](https://www2.pqegroup.com/regulatory-affairs/)
    - [Audits](https://www2.pqegroup.com/audits/)
    - [Training](https://www2.pqegroup.com/training/)
    - [Clinical Research](https://www2.pqegroup.com/clinical-research-services/)
    - [Pharmacovigilance](https://www2.pqegroup.com/pharmacovigilance/)
- About 
    - [About Us](https://www2.pqegroup.com/about/)
    - [ESG](https://www2.pqegroup.com/about/csr/)
    - [Women in STEM](https://www2.pqegroup.com/about/women-in-stem/)
- Resources 
    - [News & Press](https://www2.pqegroup.com/news/)
    - [Webinars](https://www2.pqegroup.com/webinars/)
    - [Blog](https://blog.pqegroup.com/)
- [Careers](https://www2.pqegroup.com/careers/)
- [Contact Us](https://www2.pqegroup.com/contact-us/)

![Danilo Maruccia](https://blog.pqegroup.com/hubfs/Danilo-Maruccia.jpg)

Danilo Maruccia

Executive Consultant & Business Partner @PQE Group

# **Why MD Cybersecurity is so important**

[Medical Device](https://blog.pqegroup.com/tag/medical-device)

## **The hidden risks of a disruptive innovation**

It’s well renowned that latest technological innovations radically changed our lives at all levels, to the point to be considered “disruptive”: they changed the way we communicate, the way we access information, how we buy and use products and services, how we move and definitely live. In this context, the Medical field not only makes no exception, but it also has be considered among the most investing industries, with the development of ICT innovations that may revert the ‘status-quo’, such as new methods and technologies both capable to enhance the treatments and health care capabilities available today, and make possible to treatments for health conditions that due to many reasons weren’t treatable just a few years ago.

Anyways, this kind of game-changing innovations doesn’t come for free: along with innovation, a lot of new potential vulnerabilities putting at risk medical device’s functionalities and also patients’ health have stepped into the scene.

 

**Connected Medical Devices: treating the most complex diseases with ICT and cloud potential**

Among the entire medical field, Medical Devices development plays a major role in innovation, with devices used to treat human diseases like diabetes, heart diseases, neurological diseases and many others, tracing new paths and exploring new horizons in human (and not only) health care.

According to E.U. definition\[1\], “medical device’ means any “instrument, apparatus, appliance, software, material or other article, whether used alone or in combination, including the software intended by its manufacturer to be used specifically for diagnostic and/or therapeutic purposes and necessary for its proper application, intended by the manufacturer to be used for human beings:

- diagnosis, prevention, monitoring, treatment or alleviation of disease,
- diagnosis, monitoring, treatment, alleviation of or compensation for an injury or handicap,
- investigation, replacement or modification of the anatomy or of a physiological process,
- control of conception,

and which does not achieve its principal intended action in or on the human body by pharmacological, immunological or metabolic means, but which may be assisted in its function by such means;”

One of the top innovations today consists in the “Connected Medical Devices”, which use the connectivity and infrastructure of the internet, plus the most advanced software and hardware technologies and the IoT computing power to improve their health care capabilities by analysing and understanding the patient’s needs and adapt monitoring, diagnosis and treatments in real time.

Let’s think about all the types three types of software related to Medical Devices: not only the software used to manage production of Medical Devices, but also the Software integrated into a Medical Device (“Software in a Medical Device”), and the software which is meant to be a Medical Device by itself (“Software as a Medical Device (SaMD)”: cfr. definition by International Medical Device Regulators Forum (IMDRF)\[2\]) while used for medical purposes without being integrated in any other medical device.

 

## **Vulnerabilities with serious consequences on health and life**

Like every other connected devices we commonly use, there’s always the possibility for them to suffer cyber attacks and possible vulnerabilities to Unauthorized Access. Let’s think about the Medjack (I,II, and III) crisis, that demonstrated how network-connected hospital medical devices such as Heart Monitors, CT and MRI machines, and PAC systems may be attacked and their functionalities hijacked or compromised\[3\] without notice trough a backdoor, using their vulnerabilities to spread the ‘infection’ through the entire local healthcare system.

Therefore, all Medical Devices producers should be aware that a vulnerability in their devices could be exploited and that it could have consequences that just a few years ago weren’t even imaginable, putting at stake the patients’ lives:  
for example, an Insulin Pump, an MD that works maintaining the correct insulin levels in a patient with Type 2 Diabetes, could be wirelessly connected to a server which communicates to a smartphone application where he/she, or a physician, could keep track on insuline levels changes in his/her body.

That wireless connection could be exploited by a ransomware, to hijack both software and hardware control of the insulin pump for ransom. It’s clear that this kind of attacks may have a direct impact not only on the patient’s health condition, but could put at risk his/her life as well in case the insulin pump should suddenly stop or change its functioning: absolutely not an abstract scenario, as already in 2012 a renowned McAfee’s professional hacker declared \[4\] the possibility to hijack several Medtronic Heart monitors overriding their basic functionalities like the vibration alerts and other features.

Another vulnerable category consists in the Implantable Medical Devices (IMD)\[5\], such as neurological stimulators, used to treat diseases like Parkinson via-deep brain stimulation: since they have more complex and powerful computational capabilities, and deep interaction with the patient’s brain, a vulnerability in their software could seriously undermine the patient’s health.

 

## **Authorities raising regulatory awareness and requirements on MD Cybersecurity**

It makes therefore sense to think that nowadays the Cybersecurity has to be considered a must for all connected medical devices: such intrusions and vulnerabilities may imply strong negative impacts such as diagnostic and/or therapeutics errors, impacts on clinical operations, and even a violation of C.I.A. Agreement, and even put at risk both patient’s data, health and life.

For this reason, the most important Regulatory Authorities such as FDA (Post Market Management of Cybersecurity in Medical Devices), and European Commission ([MDR 2017/745](https://www.pqegroup.com/blog/2021/03/eu-mdr-2017-745-new-cybersecurity-requirements-for-networked-md-producers//) and IVDR 2017/746) have already updated their definitions and requirements to define a ‘Safe Medical Device’, not just by itself but also regarding its components and interactions with other devices and tools, to assure its safety on the short, medium and long term at all levels, including their cybersecurity.

 

### **References**

\[1\][Regulation (EU) 2017/745-746](https://eur-lex.europa.eu/legal-content/en/TXT/?uri=CELEX%3A32017R0745)  
\[2\][IMDRF Definitions (Software as Medical Device)](http://www.imdrf.org/docs/imdrf/final/technical/imdrf-tech-131209-samd-key-definitions-140901.pdf)  
\[3\][Article about MedJack 3 Malware attacks by Data Privacy Security Insider](https://www.dataprivacyandsecurityinsider.com/2017/03/medical-device-malware-medjack-3-poses-threat-to-hospitals/)  
\[4\][Article about Medtronic MD vulnerabilities by Bloomberg.com](https://www.bloomberg.com/news/articles/2012-02-29/mcafee-hacker-says-medtronic-insulin-pumps-vulnerable-to-attack)  
\[5\][“Security and privacy issues in implantable medical devices: A comprehensive survey.”(Camara, Peris-Lopez , Tapiador.) – Abstract.](https://www.ncbi.nlm.nih.gov/pubmed/25917056)

![Cybersecurity-for-Medical-Devices-risks-and-vulnerabilities](https://blog.pqegroup.com/hubfs/Cybersecurity-for-Medical-Devices-risks-and-vulnerabilities.jpg)

## Want to know more? Watch the video by D.Maruccia for more insights.

PQE Group developed a specific **holistic Approach to verify and assure that our client’s have the highest level of cyber security, analysing and solving any possible vulnerabilities, preventing future observations and violations**: If you want to know more about MD Cybersecurity, get more deepening knowledge about how most important Regulatory Authorities regulated this important topic, and how PQE Group can support MD companies minimizing the risk of vulnerabilities that may lead to heavy unexpected costs, [download our FREE Medical Devices Cybersecurity Guide about major local regulations address Cybersecurity (FDA, EMA, Canada, and more)](https://focus.pqegroup.com/en/medical-devices-cybersecurity).

[Connect with us](https://www2.pqegroup.com/contact-us/)

#### More on this topic

[Medical Device ![Why Your Software as a Medical Device (SaMD) Development Should Take a Quality by Design Approach ](https://blog.pqegroup.com/hubfs/BANNER-Why%20Your%20Software%20as%20a%20Medical%20Device%20(SaMD)%20Development%20Should%20Take%20a%20Quality%20by%20Design%20Approach%20_1_1_1.jpg)](https://blog.pqegroup.com/medical-device/why-your-software-as-a-medical-device-samd-development-should-take-a-quality-by-design-approach)

 15 Sep 2025

## [Why Your Software as a Medical Device (SaMD) Development Should Take a Quality by Design Approach  Learn why Software as a Medical Device development needs a Quality by Design approach to ensure safety, compliance, and patient trust](https://blog.pqegroup.com/medical-device/why-your-software-as-a-medical-device-samd-development-should-take-a-quality-by-design-approach)

[Medical Device ![Italian Guidelines on Safety and Performance of Veterinary Devices](https://blog.pqegroup.com/hubfs/Devices%20for%20Veterinary%20Use_Site%20Banner_1-1.jpg)](https://blog.pqegroup.com/medical-device-compliance/italian-guidelines-on-safety-and-performance-of-veterinary-devices)

 25 Jul 2024

## [Italian Guidelines on Safety and Performance of Veterinary Devices Discover the Italian Guidelines on Safety and Performance of Veterinary Devices, outlining key requirements for manufacturers to ensure efficacy](https://blog.pqegroup.com/medical-device-compliance/italian-guidelines-on-safety-and-performance-of-veterinary-devices)

[Medical Device ![AI application in the Medical Device Field](https://blog.pqegroup.com/hubfs/AI%20Medical%20Device%20Field_Site%20Banner.jpg)](https://blog.pqegroup.com/medical-device-compliance/ai-application-in-the-medical-device-field)

 18 Jun 2024

## [AI application in the Medical Device Field Explore the transformative impact of Artificial Intelligence in the medical device field, from disease detection to personalized treatment recommendations.](https://blog.pqegroup.com/medical-device-compliance/ai-application-in-the-medical-device-field)

![new PQE logo white tagline](https://blog.pqegroup.com/hubfs/new%20PQE%20logo%20white%20tagline.png)

ISO 9001 Certified compliance services provider since 1998.

 

![Logo ISO 9001](https://blog.pqegroup.com/hs-fs/hubfs/Logo%20ISO%209001.png?width=125&name=Logo%20ISO%209001.png)

 

- Discover PQE 
    - [Work with PQE](https://www2.pqegroup.com/careers/)
    - [Locations](https://www2.pqegroup.com/contact-us/#locations)
    - [About](https://www2.pqegroup.com/about/)
    - [Blog](https://blog.pqegroup.com/)

- Useful Links 
    - [Privacy Notice](https://www2.pqegroup.com/privacy-notice/)
    - [Cookie Policy](https://www2.pqegroup.com/cookie-policy/)
    - [Model of Organization](https://www2.pqegroup.com/model-of-organization/)
    - [Ethical Code](https://www2.pqegroup.com/ethical-code/)

English

CHANGE LANGUAGE

Copyright **2024** | Proudly powered by **PQE Group Creative Team**

[LinkedIn](https://www.linkedin.com/company/pqe-group) [![twitter](https://blog.pqegroup.com/hubfs/twitter-w.png) Twitter](https://twitter.com/PQEGroup) [Facebook](https://www.facebook.com/PQEGroup/) [Instagram](https://www.instagram.com/lifeatpqe) [YouTube](https://www.youtube.com/c/PQEGroup) [Xing](https://www.xing.com/pages/pqegroup)