Connected medical devices: securing the whole ecosystem
How dependencies, trust boundaries and compromised networks should shape threat modelling and penetration testing for connected medical devices.
Plans, methods, independence, acceptance criteria and objective evidence.
Articles
How dependencies, trust boundaries and compromised networks should shape threat modelling and penetration testing for connected medical devices.
How stale data, incorrect units, patient mismatches and misleading displays can produce plausible but wrong outputs—and how to detect and control these quiet failures.
Why successful medical software requires evidence for the complete clinical product and workflow—not only the performance of its algorithm.
A practical approach to shared software assurance evidence, with clear regulatory boundaries and a worked calibration-system example.
Why standards selection for an IVD must follow the complete system, its intended purpose and the consequences of an incorrect result.
Why a long standards list is not enough—and how intended purpose, harmonisation and product-specific evidence shape a defensible standards assessment.
A playful but serious reflection on AI as assistant, reviewer and decision-maker—and why fluent answers still need evidence, judgement and accountability.
AI changes the speed and economics of medical-device development, but it does not remove the need for product definition, objective evidence, competent review or manufacturer accountability.
Why outsourcing medical-device development increases the need for intelligent manufacturer oversight—and what must be controlled before an audit or submission exposes the gaps.
Why absence of commercial registration does not automatically prevent a digital health technology from being used in a clinical trial—and the questions sponsors should ask instead.
A practical interpretation of Essential Performance for electronically driven injection systems, and what engineers should specify, trace and verify.
How user needs, requirements, design outputs, risk controls, verification and validation form a coherent evidence chain.
A practical introduction to IEC 62304, software safety classification and the evidence created across development and maintenance.
A clear explanation of verification, validation and how both connect to user needs, design inputs and objective evidence.
A practical framework for distinguishing device functions, essential performance, safety-related requirements and supporting quality attributes.
What makes development evidence coherent, reviewable and defensible before an audit or submission.