Related Experiment Videos
Regulatory Approaches to Cybersecurity Risk Management for AI-Enabled Medical Device Software in Korea, the United
Saera Jung1,2, Kihong Son1,3
1Department of Artificial Intelligence, University of Science and Technology (UST), 217 Gajeong-ro, Yuseong District, Daejeon, Republic of Korea, 82 10-8633-1544.
Background:
Software-based and AI-enabled medical devices are increasingly networked and updatable, expanding the attack surface and making cybersecurity governance intersect with quality management and postmarket oversight. Regulated device risk management nevertheless remains primarily oriented toward patient-safety harms under ISO 14971 frameworks, which may not fully capture cybersecurity risks affecting data integrity, system resilience, or service continuity.
Objective:
This study aimed to compare how Korea's Ministry of Food and Drug Safety (MFDS), the US Food and Drug Administration (FDA), and the European Union/Medical Device Coordination Group (EU/MDCG) define and operationalize cybersecurity for medical device software across premarket review and postmarket surveillance, and to identify informatics-relevant gaps between safety vigilance and vulnerability-focused cybersecurity practice.
Methods:
We conducted a qualitative comparative document analysis of 10 jurisdiction-specific regulatory and guidance documents (MFDS: n=2, FDA: n=4, and EU/MDCG: n=4), supplemented by cross-sectoral instruments and peer-reviewed literature. Using a common analytic framework informed by functional comparative legal analysis, we mapped (1) conceptual scope (definitions and life cycle boundaries), (2) premarket operationalization (required artifacts and evidence such as threat modeling, software bills of materials, and vulnerability management plans), and (3) postmarket operationalization (monitoring, reporting, and update governance).
Results:
Of the 10 documents analyzed (MFDS: n=2, FDA: n=4, and EU/MDCG: n=4), all 3 jurisdictions converged on protecting confidentiality, integrity, and availability of data and device functions but embedded these expectations in different regulatory architectures. MFDS emphasized documentation completeness aligned with ISO 14971 risk management; the FDA framed cybersecurity as quality-system and design-control activities spanning the total product life cycle, including statutory requirements for "cyber devices" under Federal Food, Drug, and Cosmetic Act section 524B; and the European Union treated cybersecurity as an extension of safety under the Medical Device Regulation (MDR) and In Vitro Diagnostic Regulation (IVDR), interpreted through MDCG guidance, with additional cross-sector obligations from the Network and Information Security 2 (NIS2) Directive and the General Data Protection Regulation (GDPR). A common limitation was that vigilance pathways were largely triggered by patient-harm thresholds, whereas vulnerabilities and near-miss security events were often managed through parallel information-security processes. Mapping to ISO 13485 Clauses 7.3 and 8 indicated that integration of cybersecurity controls into existing quality management system (QMS) processes is feasible but not consistently mandated.
Conclusions:
Across the 3 jurisdictions examined in this study, regulatory approaches to medical device cybersecurity show definitional alignment but operational fragmentation at the interface between patient-safety vigilance and vulnerability-centric cybersecurity practice. Within the limits of this document-based analysis, the findings suggest that integrating cybersecurity as an interoperable process within the QMS-linking vulnerability monitoring, incident response, and software update controls to corrective and preventive action (CAPA) and change control-and expanding postmarket surveillance to incorporate vulnerability and performance signals could support more trustworthy deployment of regulated AI-enabled medical software.
Related Concept Videos
Issues And Trends In Healthcare Delivery System
Cost Containment
Payment for healthcare services has historically promoted adoption of costly and often unnecessary or inefficient...
Ethical Standards I
The Code of Ethics provisions outline the nurse's duty to the patient, the healthcare team, the profession, and society. The Code's fundamental principles include advocacy,...