Transatlantic Perspectives on AI-Based Medical Device Cybersecurity
Investigators:
Elisabetta Biasin & Erik Kamenjašević
Abstract:
Cybersecurity of medical devices has become a concrete concern for regulators and policymakers in the US and EU. Following the COVID-19 pandemic, there has been an increase in cyber-attacks on critical healthcare infrastructures and their IT systems, which have suffered service disruptions and put patients’ and other users’ health and safety at risk.
Recent studies and medical device manufacturers’ disclosures have shown the potential safety risks of these types of vulnerabilities, including those of AI-based medical devices. Those could include data poisoning, data exfiltration, or even social engineering (Biasin, Kamenjasevic, Ludvigsen, forthcoming).
The increase in cybersecurity risks for medical devices, exacerbated by the growing digitalization of healthcare services in the US and the EU, has led legislators and regulatory bodies to pay more attention to medical devices’ cybersecurity. Research by legal doctrine is critical to support policymakers in addressing their legal and regulatory challenges. In this view, this research addresses the legal and regulatory aspects of medical devices’ cybersecurity and adopts a comparative transatlantic perspective between the US and the EU. The regulation of medical devices in the EU has been historically inspired by the regulatory trends from the US, although with the different cultural, societal, and legal traditions that made them adapt to the specificities of the territory. Comparing the US and the EU legal landscapes concerning AI-based medical devices cybersecurity means appraising their different regulatory systems. Therefore, this research aims to answer the following research question: What are the main implications of different regulatory approaches toward AI-based medical devices cybersecurity in the US and EU?