Legal Requirements towards Enhancing the Security of Medical Devices

被引:0
|
作者
Yeng, Prosper K. [1 ]
Wulthusen, Stephen D. [1 ,2 ]
Yang, Bian [1 ]
机构
[1] NTNU, Dept Informat Secur & Commun Technol, Gjovik, Norway
[2] Royal Holloway Univ London, Sch Math & Informat Secur, Egham, Surrey, England
关键词
Information security; medical device; legal requirement; healthcare; privacy; REGULATIONS; PACEMAKERS;
D O I
10.14569/IJACSA.2020.0111181
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
Over 25 million Americans are dependent on medical devices. However, the patients who need these devices only have two choices, thus the choice between using an insecure critical-life-functioning devices or the choice to live without the support of a medical device with the consequences of the threats presented by the disease. This study therefore conducted a stateof-the-art on security requirements, concerning medical devices in the US and EU. Food, Drugs and Cosmetic Act, HIPAA, Medical Device Regulations of EU and GDPR were some of the identified regulations for controlling the security of these devices. Statutory laws such as computer Fraud and abuse Act (CFAA), Anti-Tempering Act, Panel Code as well as Battery and Trespass to Chattel in the civil law, were also identified. In analyzing the security requirements, there are less motivations on criminal charges against cyber criminals in addressing the security issues. Because it is often challenging to identify the culprits in medical device hacks. It is also difficult to hold device manufactures on negligence of duty especially after the device has been approved or if the harm on patient was as a result of a cyber attacker. Suggestions have been provided to improve upon the regulations so that both the regulatory bodies and MDM can improve upon their security conscious care.
引用
收藏
页码:666 / 675
页数:10
相关论文
共 50 条
  • [2] LEGAL REQUIREMENTS CONCERNING MEDICAL DEVICES IN GERMANY.
    Schorn, Gert
    Journal of Medical Engineering & Technology, 1984, 10 (01) : 25 - 29
  • [3] Security of implantable medical devices: limits, requirements, and proposals
    Ellouze, Nourhene
    Allouche, Mohamed
    Ben Ahmed, Habib
    Rekhis, Slim
    Boudriga, Noureddine
    SECURITY AND COMMUNICATION NETWORKS, 2014, 7 (12) : 2475 - 2491
  • [4] Legal requirements for computer security: Electronic medical records and data interchange
    Waller, AA
    Darrah, JM
    BEHAVIORAL HEALTHCARE TOMORROW, 1996, 5 (01): : 45 - 47
  • [5] Towards an International Security Case Framework for Networked Medical Devices
    Finnegan, Anita
    McCaffery, Fergal
    COMPUTER SAFETY, RELIABILITY, AND SECURITY, SAFECOMP 2015, 2015, 9337 : 197 - 209
  • [6] Towards security in medical telematics - Legal and technical aspects - Concluding remarks
    Barber, B
    TOWARDS SECURITY IN MEDICAL TELEMATICS: LEGAL AND TECHNICAL ASPECTS, 1996, 27 : 246 - 247
  • [7] LABELING REQUIREMENTS FOR MEDICAL DEVICES
    DAVIS, JB
    FOOD DRUG COSMETIC LAW JOURNAL, 1972, 27 (10): : 608 - 616
  • [8] Medical Devices in Legal Metrology
    Badnjevic, Almir
    Gurbeta, Lejla
    Boskovic, Dusanka
    Dzemic, Zijad
    2015 4TH MEDITERRANEAN CONFERENCE ON EMBEDDED COMPUTING (MECO), 2015, : 365 - 367
  • [9] LEGAL METROLOGY: MEDICAL DEVICES
    Bosnjakovic, Alen
    Dzemic, Zijad
    PROCEEDINGS OF THE INTERNATIONAL CONFERENCE ON MEDICAL AND BIOLOGICAL ENGINEERING 2017 (CMBEBIH 2017), 2017, 62 : 583 - 588
  • [10] THE LEGAL REQUIREMENTS OF MEDICAL-PRACTICE
    SCOTT, J
    WESTERN JOURNAL OF MEDICINE, 1983, 139 (02): : 229 - 229