ETRI-Knowledge Sharing Plaform

KOREAN
논문 검색
Type SCI
Year ~ Keyword

Detail

Journal Article Regulatory Approaches to Cybersecurity Risk Management for AI-Enabled Medical Device Software in Korea, the United States, and the European Union: Comparative Document Analysis
Cited - time in scopus Share share facebook twitter linkedin kakaostory
Authors
Saera Jung, Kihong Son
Issue Date
2026-07
Citation
JMIR Medical Informatics, v.14, pp.1-17
ISSN
2291-9694
Publisher
JMIR Publications Inc.
Language
English
Type
Journal Article
DOI
https://dx.doi.org/10.2196/94846
Abstract
Abstract Background Software-based and AI-enabled medical devices are increasingly networked and updatable, expanding the attack surface and making cybersecurity governance intersect with quality management and postmarket oversight. Regulated device risk management nevertheless remains primarily oriented toward patient-safety harms under ISO 14971 frameworks, which may not fully capture cybersecurity risks affecting data integrity, system resilience, or service continuity. Objective This study aimed to compare how Korea’s Ministry of Food and Drug Safety (MFDS), the US Food and Drug Administration (FDA), and the European Union/Medical Device Coordination Group (EU/MDCG) define and operationalize cybersecurity for medical device software across premarket review and postmarket surveillance, and to identify informatics-relevant gaps between safety vigilance and vulnerability-focused cybersecurity practice. Methods We conducted a qualitative comparative document analysis of 10 jurisdiction-specific regulatory and guidance documents (MFDS: n=2, FDA: n=4, and EU/MDCG: n=4), supplemented by cross-sectoral instruments and peer-reviewed literature. Using a common analytic framework informed by functional comparative legal analysis, we mapped (1) conceptual scope (definitions and life cycle boundaries), (2) premarket operationalization (required artifacts and evidence such as threat modeling, software bills of materials, and vulnerability management plans), and (3) postmarket operationalization (monitoring, reporting, and update governance). Results Of the 10 documents analyzed (MFDS: n=2, FDA: n=4, and EU/MDCG: n=4), all 3 jurisdictions converged on protecting confidentiality, integrity, and availability of data and device functions but embedded these expectations in different regulatory architectures. MFDS emphasized documentation completeness aligned with ISO 14971 risk management; the FDA framed cybersecurity as quality-system and design-control activities spanning the total product life cycle, including statutory requirements for “cyber devices” under Federal Food, Drug, and Cosmetic Act section 524B; and the European Union treated cybersecurity as an extension of safety under the Medical Device Regulation (MDR) and In Vitro Diagnostic Regulation (IVDR), interpreted through MDCG guidance, with additional cross-sector obligations from the Network and Information Security 2 (NIS2) Directive and the General Data Protection Regulation (GDPR). A common limitation was that vigilance pathways were largely triggered by patient-harm thresholds, whereas vulnerabilities and near-miss security events were often managed through parallel information-security processes. Mapping to ISO 13485 Clauses 7.3 and 8 indicated that integration of cybersecurity controls into existing quality management system (QMS) processes is feasible but not consistently mandated. Conclusions Across the 3 jurisdictions examined in this study, regulatory approaches to medical device cybersecurity show definitional alignment but operational fragmentation at the interface between patient-safety vigilance and vulnerability-centric cybersecurity practice. Within the limits of this document-based analysis, the findings suggest that integrating cybersecurity as an interoperable process within the QMS—linking vulnerability monitoring, incident response, and software update controls to corrective and preventive action (CAPA) and change control—and expanding postmarket surveillance to incorporate vulnerability and performance signals could support more trustworthy deployment of regulated AI-enabled medical software.
Keyword
cybersecurity, medical device software, software as a medical device, artificial intelligence, generative AI, risk management, ISO 14971, IEC 81001, AAMI TIR57, regulatory science, post-market surveillance
KSP Keywords
Attack Surface, Bills of materials, Change control, Data Integrity, Drug safety, European union, Food and Drug Administration(FDA), General Data Protection Regulation, ISO 14971, Information security, Legal analysis