Evidence map›Paper›PMID 39718821›Full record

ArticleJournal of medical Internet research2024

Consideration of Cybersecurity Risks in the Benefit-Risk Analysis of Medical Devices: Scoping Review.

Oscar Freyer, Fatemeh Jahed, Max Ostermann, Christian Rosenzweig, Pascal Werner, Stephen Gilbert

Abstract readScoping Review
In one paragraph

Article in Journal of medical Internet research, 2024. The graph could read no effect estimate from its abstract, so it casts no vote on the map. Cited by 8 papers.

0numbers the graph read from it
0cells of the map it votes in
8citing papers in PubMed
–field-weighted citation impact
1 · What the graph read from it

What it found

Each row is one number read from the abstract, on the scale the paper reported it, with its interval. Left of the dashed line favours the treatment, right favours the comparator. Under each row is the sentence it came from. New to these charts? A ten-minute tutorial.

The abstract states no effect estimate the extractor could read, or names no intervention and outcome on the map, so this paper lights no cell and moves no belief. It is still indexed, cited and linked below.

2 · The registry

The trial behind it

Trials whose registry record cites this paper, or whose number appears in the abstract. A trial that started after this paper was published is citing it as background, not reporting it.

Neither the registry nor the abstract names a trial number. If this is a trial report, that itself is worth knowing.

3 · Its place in the literature

Who cites it

8 citing papers in PubMed.

  1. Review
  2. Article
  3. Review
  4. Review
  5. Article
  6. Article
  7. Article
  8. Article
4 · The record

Corrections and comments

PubMed lists nothing against this paper. Absence here is not a guarantee, only a check that was made.

5 · Who and what money

Authors and funding

6 authors.

Oscar FreyerElse Kröner Fresenius Center for Digital Health, Dresden University of Technology, Dresden, Germany.ORCID 0000-0003-3323-2492
Fatemeh JahedElse Kröner Fresenius Center for Digital Health, Dresden University of Technology, Dresden, Germany.ORCID 0009-0003-0858-002X
Max OstermannElse Kröner Fresenius Center for Digital Health, Dresden University of Technology, Dresden, Germany.ORCID 0009-0004-7808-2701
Christian RosenzweigJohner Institute, Konstanz, Germany.ORCID 0009-0006-3839-3366
Pascal WernerRegulatory.me, Mebane, NC, United States.ORCID 0009-0002-0264-7855
Stephen GilbertElse Kröner Fresenius Center for Digital Health, Dresden University of Technology, Dresden, Germany.ORCID 0000-0002-1997-1689

Funding

No grant is acknowledged in the PubMed record.

6 · The paper itself

Abstract

backgroundThe integration of connected medical devices (MDs) into health care brings benefits but also introduces new, often challenging-to-assess risks related to cybersecurity, which have the potential to harm patients. Current regulations in the European Union and the United States mandate the consideration of these risks in the benefit-risk analysis (BRA) required for MD approval. This important step in the approval process weighs all the defined benefits of a device with its anticipated risks to ensure that the product provides a positive argument for use. However, there is limited guidance on how cybersecurity risks should be systematically evaluated and incorporated into the BRA.

objectiveThis scoping review aimed to identify current legal frameworks, guidelines, and standards in the United States, Canada, South Korea, Singapore, Australia, the United Kingdom, and the European Union on how cybersecurity risks should be considered in the BRA of MDs.

methodsThis scoping review followed the PRISMA-ScR (Preferred Reporting Items for Systematic Reviews and Meta-Analyses extension for Scoping Reviews) framework. A systematic literature search of 10 databases was conducted in two phases on July 3, 2024 and September 30, 2024, including the guidance databases of the Food and Drug Administration, the Medical Device Coordination Group, and other International Medical Device Regulators Forum members; the International Medical Device Regulators Forum database; PubMed; and Scopus. Search terms included "cybersecurity," "security," "benefit/risk," "benefit-risk," and "risk-benefit." Additional references were identified via citation searching and expert interviews. Inclusion criteria were met if a document was a guideline or standard in force that provided guidance on the BRA or cybersecurity risks of MDs. Documents were excluded when they were not relevant to MDs, they were limited to a subclass of devices, they were about in vitro diagnostic MDs or investigational devices, and the content of the source was insufficient to undertake a scientific analysis. Data were extracted and analyzed using MAXQDA 2022, and the findings were narratively summarized and visualized in figures and tables.

resultsThe search identified 150 documents, with 34 (22.7%) meeting the inclusion criteria. These 34 documents included 4 (12%) regulations, 5 (15%) standards, 6 (18%) technical reports, and 19 (56%) guidance documents. While cybersecurity risks were acknowledged in most documents, detailed methods for their integration into the BRA were lacking. Some standards and guidelines provided examples of how to consider cybersecurity risks in the BRA, but a comprehensive and standardized approach was lacking.

conclusionsThis review highlights a substantial gap between the recognition of cybersecurity risks in MDs and the guidance on their incorporation into the BRA. Standardized frameworks are needed to provide clear methods for evaluating cybersecurity risks and their impact on the safety and security of MDs.

Indexed as

Computer SecurityEquipment and SuppliesCanadaEuropean UnionHumansRisk AssessmentUnited Statesbenefit-risk analysisconnected medical devicescybersecuritypatient safetyregulationrisk managementvulnerability assessment

Identifiers

PMID39718821
PMCPMC11707448

What OpenQuestion holds

Textmetadata
LicenceCC BY
Read underepoch 390

Registered trials

None linked

Read under generation 80e0d062 · epoch 390. Bibliography from PubMed, PubMed Central and OpenAlex; grants from NIH RePORTER; trial links from ClinicalTrials.gov; estimates, votes and beliefs from the OpenQuestion graph.