Cybersecurity of medical devices: new challenges arising from the AI Act and NIS 2 Directive proposals

被引:0
作者
Elisabetta Biasin
Erik Kamenjašević
机构
[1] KU Leuven Centre for IT & IP Law,
来源
International Cybersecurity Law Review | 2022年 / 3卷 / 1期
关键词
Security; Healthcare; Critical infrastructure; Artificial intelligence; Network and information system security;
D O I
10.1365/s43439-022-00054-x
中图分类号
学科分类号
摘要
Cyberattacks on the IT infrastructure of hospitals, electronic health records or medical devices that have taken place during the COVID-19 pandemic reaffirmed how crucial it is to ensure cybersecurity in the healthcare sector. Medical devices are regulated in the European Union (EU) through vertical product-specific legislation, such as the Medical Device Regulation (MDR), among others. The MDR foresees safety requirements implying cybersecurity obligations for medical device manufacturers. In 2021, the EU legislator put forward the Network and Information Security System Directive reform (NIS 2) and the Artificial Intelligence Act (AIA) proposal, containing additional cybersecurity requirements applicable to medical devices. This article analyses how the new reforms interact with the existing legislation from a cybersecurity perspective. The research finds that parallel provision of analogous cybersecurity requirements (especially on notification requirements) could lead to regulatory overlapping, fragmentation, and uneven levels of protection of individuals in the EU internal market. In the “Recommendations and conclusions”, the article provides policy recommendations to the EU legislator to help mitigate these risks.
引用
收藏
页码:163 / 180
页数:17
相关论文
共 4 条
[1]  
Ducuing C(2021)Understanding the rule of prevalence in the NIS directive: C-ITS as a case study Comput Law Secur Rev 40 1-12
[2]  
Markopoulou D(2021)The Regulatory Framework for the Protection of Critical Infrastructures against Cyberthreats: Identifying Shortcomings and Addressing Future Challenges: The Case of the Health Sector in Particular Comput Law Secur Rev 41 1-12
[3]  
Papakonstantinou V(2000)Identifying, Understanding, and Analysing Critical Infrastructure Interdependencies IEEE Control Syst Mag 4 11-25
[4]  
Rinaldi SM(undefined)undefined undefined undefined undefined-undefined