CEN/CLC/WS CYMEDSEC
Continuous security and privacy monitoring processes for the connected remote care medical device ecosystem

This workshop focuses on the continuous monitoring and testing of the data processing governance and privacy of connected medical devices for remote care and their supporting ecosystem components. It aims to focus on the support of information security management of all related components participating in data processing and privacy-related governance with respect to remote care connected medical devices in coherent way, leaving out of its scope issues related to operational or clinical assurance. The framework described in this workshop aims to address issues in: - Remote care medical device hardware: both embedded and peripheral devices connected to healthcare networks. - Remote care medical device software: including software incorporated into remote care medical devices (as per IEC 62304) and external applications that interface with such devices. - Intermediary components, such as data transfer hubs, gateways, and edge/fog computing nodes. - Associated services include cloud-based solutions, remote maintenance, and health IT systems integrating connected devices. - Artificial Intelligence (AI) and Machine Learning (ML) models, including their development, deployment, monitoring, and mitigation of bias or adversarial manipulation. Remote care is medical and health support delivered outside of traditional clinics using digital tools (including AI-enabled tools), which enable patients and doctors connect through video calls, phone check-ins, apps, and wearable medical devices to track vital signs, manage chronic illnesses, and provide treatment without an in-person visit. The workshop will: - Specify best practices for DevSecOps integration into connected medical device lifecycle management. - Describe MLOps processes tailored to AI/ML-driven medical device applications. - Provide guidelines for data processing governance and privacy monitoring processes operating continuously throughout the device and ecosystem lifecycle. - Allow for the definitions of testing and validation methodologies for connected environments, including interoperability, threat resilience, and data protection compliance. The following are within the scope of this CWA: - All classes of remote care connected medical devices, regardless of form factor or intended medical purpose. This includes medical device consumer wearables and applications which include in their intended purpose the sharing of information between doctor and patient, that may be used to influence care. - Cybersecurity and privacy processes spanning design, manufacturing, deployment, operation, and decommissioning. - Integration with relevant standards (e.g., ISO 13485, ISO 14971, IEC 62304, IEC 80001-1, ISO 81001-1, IEEE 2621, NIST SP 800-53). - Continuous vulnerability assessment, risk management, incident response, and regulatory reporting processes. The following are explicitly excluded from the scope of this CWA: - Medical devices not providing remote care (e.g., purely in health care institution medical devices), non-connected medical devices with no digital communication capabilities. - General healthcare IT systems not directly interacting with remote care connected medical devices. - Implementation of national or regional legal requirements (though such requirements may be referenced for alignment). - Definition of safety requirements for connected medical devices. - Clinical efficacy and safety or functional safety evaluation of medical devices not directly linked to security and privacy , as the focus of this CWA is security and privacy, not clinical performance. - Consumer health and wellness devices (e.g., fitness trackers), unless they form part of a regulated medical device ecosystem. This workshop will not - replace or modify regulatory or normative safety compliance, - provide safety assurance for connected medical devices

National mirror committee of CEN/CLC/WS CYMEDSEC

Committee ID Name
NA 176-02-01 AA Horizontal working group of section 2