Strengthening the MDCG Guidance on Cybersecurity for Medical Devices: A Legal Approach
摘要
The increasing digitisation of healthcare, including the integration of connected medical devices (MDs) into healthcare systems, and the growing number of cyber threats necessitate robust cybersecurity measures for MDs to ensure patient safety, data integrity, and system functionality. The MDCG guidance on cybersecurity for MDs plays a pivotal role in aligning industrial regulatory compliance with technical standards across the EU. However, the current guidance lacks currency and consistency with the rapidly evolving EU legal framework, including data protection regulations, cybersecurity regulations, and the AI Act. Adopting a legal approach, this paper identifies the relevant significant shortcomings, examines the implications of legislative developments, and provides targeted recommendations to align the guidance with current cybersecurity frameworks. The analysis highlights the urgency of strengthening the guidance and argues that the strengthened guidance would better support stakeholders, particularly manufacturers, in safeguarding MD cybersecurity through enhancing legal clarity and practical applicability.