Cybersecurity of AI medical devices: risks, legislation, and challenges

03/06/2023
by   Elisabetta Biasin, et al.
0

Medical devices and artificial intelligence systems rapidly transform healthcare provisions. At the same time, due to their nature, AI in or as medical devices might get exposed to cyberattacks, leading to patient safety and security risks. This book chapter is divided into three parts. The first part starts by setting the scene where we explain the role of cybersecurity in healthcare. Then, we briefly define what we refer to when we talk about AI that is considered a medical device by itself or supports one. To illustrate the risks such medical devices pose, we provide three examples: the poisoning of datasets, social engineering, and data or source code extraction. In the second part, the paper provides an overview of the European Union's regulatory framework relevant for ensuring the cybersecurity of AI as or in medical devices (MDR, NIS Directive, Cybersecurity Act, GDPR, the AI Act proposal and the NIS 2 Directive proposal). Finally, the third part of the paper examines possible challenges stemming from the EU regulatory framework. In particular, we look toward the challenges deriving from the two legislative proposals and their interaction with the existing legislation concerning AI medical devices' cybersecurity. They are structured as answers to the following questions: (1) how will the AI Act interact with the MDR regarding the cybersecurity and safety requirements?; (2) how should we interpret incident notification requirements from the NIS 2 Directive proposal and MDR?; and (3) what are the consequences of the evolving term of critical infrastructures? [This is a draft chapter. The final version will be available in Research Handbook on Health, AI and the Law edited by Barry Solaiman I. Glenn Cohen, forthcoming 2023, Edward Elgar Publishing Ltd]

READ FULL TEXT

page 1

page 2

page 3

page 4

research
07/26/2023

Acceptable risks in Europe's proposed AI Act: Reasonableness and other principles for deciding how much risk management is enough

This paper critically evaluates the European Commission's proposed AI Ac...
research
09/19/2023

Functional requirements to mitigate the Risk of Harm to Patients from Artificial Intelligence in Healthcare

The Directorate General for Parliamentary Research Services of the Europ...
research
11/25/2022

The European AI Liability Directives – Critique of a Half-Hearted Approach and Lessons for the Future

The optimal liability framework for AI systems remains an unsolved probl...
research
03/20/2022

Synergy between 6G and AI: Open Future Horizons and Impending Security Risks

This paper investigates the synergy between 6G and AI. It argues that th...
research
04/24/2023

The Design and Implementation of a National AI Platform for Public Healthcare in Italy: Implications for Semantics and Interoperability

The Italian National Health Service is adopting Artificial Intelligence ...
research
06/22/2022

AI Challenges for Society and Ethics

Artificial intelligence is already being applied in and impacting many i...
research
05/26/2022

The Opportunity to Regulate Cybersecurity in the EU (and the World): Recommendations for the Cybersecurity Resilience Act

Safety is becoming cybersecurity under most circumstances. This should b...

Please sign up or login with your details

Forgot password? Click here to reset