MDCG 2019-16 Guidelines: Case Study-Based Assessment and Path Forward

Research output: Contribution to book/Conference proceedings/Anthology/Report › Conference contribution › Contributed › peer-review

Contributors

  • Christos Androutsos - , University of Ioannina (Author)
  • Steve Taylor - , University of Southampton (Author)
  • Karin Bernsmed - , SINTEF (Author)
  • Andrea Neverdal Skytterholm - , SINTEF (Author)
  • Gregory Epiphaniou - , University of Warwick (Author)
  • Nabil Moukafih - , University of Warwick (Author)
  • Theodoros N. Arvanitis - , University of Birmingham (Author)
  • Sotiris Messinis - , Institute of Communications and Computer Systems (Author)
  • Nikos Papadakis - , Space Hellas S.A. (Author)
  • Marco Fruscione - , EBIT S.R.L. (Author)
  • Andrés Castillo - , Hospital Infantil Universitario Nino Jesus de Madrid (Author)
  • Dusko Milojevic - , KU Leuven (Author)
  • Dimitrios S. Karas - , Ubitech Ltd. (Author)
  • Nikolaos Fotos - , Ubitech Ltd. (Author)
  • Max Ostermann - , Else Kröner Fresenius Center for Digital Health (Author)
  • Oscar Freyer - , Else Kröner Fresenius Center for Digital Health (Author)
  • Stephen Gilbert - , Else Kröner Fresenius Center for Digital Health (Author)
  • Vasilis Pezoulas - , University of Ioannina (Author)
  • Lambros Athanasiou - , University of Ioannina (Author)
  • George Gkois - , University of Ioannina (Author)
  • Dimitrios I. Fotiadis - , University of Ioannina, Foundation for Research and Technology-Hellas (Author)

Abstract

The Medical Device Coordination Group (MDCG) 2019-16 guidelines provide a structured framework for cybersecurity in Connected Medical Devices (CMDs) throughout their lifecycle, offering guidance on how to fulfil all the relevant essential requirements outlined in Annex I of both the Medical Device Regulation (MDR) and the In Vitro Diagnostic Medical Devices Regulation (IVDR). This paper evaluates the practical applicability and limitations of these guidelines based on feedback from six Horizon Europe (HEU) projects. Each project employed case studies reflecting diverse CMD environments and operational contexts to assess the guidelines’ relevance and effectiveness in real-words scenarios. The paper identifies gaps in the practical application of the guidelines and explores their impact on different stages of the CMD lifecycle, from design and development to deployment and post-market activities. Based on these findings, the paper proposes targeted recommendations aimed at enhancing the usability and effectiveness of the MDCG 2019-16 guidelines. The insights contribute to the ongoing evolution of cybersecurity practices in medical technology, ensuring the guidelines are better aligned with the needs of CMD stakeholders, including manufacturers, integrators, and operators, while supporting the development of more resilient and secure medical devices.

Details

Original languageEnglish
Title of host publicationCybersecurity
EditorsIsabel Praça, Simona Bernardi, Pedro R.M. Inácio
PublisherSpringer Science and Business Media B.V.
Pages338-355
Number of pages18
ISBN (electronic)978-3-031-94855-8
ISBN (print)978-3-031-94854-1
Publication statusPublished - 2025
Peer-reviewedYes

Publication series

SeriesCommunications in Computer and Information Science
Volume2500 CCIS
ISSN1865-0929

Conference

Title9th European Interdisciplinary Cybersecurity Conference
Abbreviated titleEICC 2025
Conference number9
Duration18 - 19 June 2025
Website
LocationCentraleSupélec
CityRennes
CountryFrance

External IDs

ORCID /0000-0002-1997-1689/work/188439470
ORCID /0000-0003-3323-2492/work/188439491
ORCID /0009-0004-7808-2701/work/188439624

Keywords

Keywords

  • Cybersecurity, Medical Device Coordination Group, Medical Devices