Legal Liability for Cyber-Attacks on Connected Medical Device Networks
DOI:
https://doi.org/10.59022/iijcl.5Keywords:
Medical Device Cybersecurity, Product Liability, Healthcare Regulation, Patient Safety, Connected Devices, Cyber-Attack Liability, Regulatory ComplianceAbstract
Connected medical devices increasingly expose hospitals and patients to significant cybersecurity risks. Hackers can remotely access pacemakers, insulin pumps, and monitoring equipment directly. Current legal frameworks focus primarily on device safety rather than cybersecurity vulnerabilities. This research examines how legal liability should apply following cyber-attacks on networked medical devices. Manufacturers design devices prioritizing functionality while often neglecting robust cybersecurity protection measures. Hospitals similarly lack clear legal guidance regarding network security responsibilities and obligations. This study employs qualitative doctrinal analysis examining existing product liability and healthcare regulations. Findings reveal significant gaps between traditional liability frameworks and modern networked medical technology risks. This research proposes clearer liability standards addressing manufacturer and healthcare provider cybersecurity responsibilities. Such standards would strengthen patient protection while clarifying accountability across the healthcare technology chain. The study offers practical recommendations for regulators, manufacturers, and healthcare institutions. This framework addresses urgent gaps in patient safety and healthcare cybersecurity governance today.
References
Aldosari, B. (2025). Cybersecurity in healthcare: New threat to patient safety. Cureus, 17(5), e83614. https://doi.org/10.7759/cureus.83614
AllahRakha, N. (2025). Sustainable ICT infrastructure and green technologies in the Caribbean. Industrial Engineering and Management Journal, 3(1), 4–12. https://doi.org/10.47412/CLVD2784
AllahRakha, N. (2026). Legal analysis of the law of the Republic of Uzbekistan “On Payments and Payment System”. TSUL Legal Report, 5(1), 38–55. https://doi.org/10.51788/tsul.lr.5.1./WAJR6426
Conceição, F., Rocha, M., & Almeida, F. (2026). Security compliance as a catalyst for sustainable partnerships: A design science approach for SMEs. Journal of Cybersecurity and Privacy, 6(2), 53. https://doi.org/10.3390/jcp6020053
Djeffal, C. (2025). Law by design obligations: The future of regulating digital technologies in Europe? Computer Law & Security Review, 59, Article 106232. https://doi.org/10.1016/j.clsr.2025.106232
Evershine CPAs Firm. (2024). Taiwan medical devices registration. Evershine CPAs Firm. https://www.evershinecpa.com/
Freyer, O., Jahed, F., Ostermann, M., Rosenzweig, C., Werner, P., & Gilbert, S. (2024). Consideration of cybersecurity risks in the benefit-risk analysis of medical devices: Scoping review. Journal of Medical Internet Research, 26, e65528. https://doi.org/10.2196/65528
Gennari, F. (2025). (Product) liability in the Medical Internet of Things. What now? In F. Casarosa, F. Gennari, & A. Rossi (Eds.), Enabling and safeguarding personalized medicine (pp. 317–338). Springer Nature Switzerland. https://doi.org/10.1007/978-3-031-99709-9_16
Javaid, M., Haleem, A., Singh, R. P., & Suman, R. (2023). Towards insighting cybersecurity for healthcare domains: A comprehensive review of recent practices and trends. Cyber Security and Applications, 1, 100016. https://doi.org/10.1016/j.csa.2023.100016
Jubaidi, D., & Khoirunnisa, K. (2025). Legal perspectives on the risks of medical malpractice in the implementation of artificial intelligence and telemedicine technologies. ALADALAH: Jurnal Politik Sosial Hukum dan Humaniora, 3(4), 77–100. https://doi.org/10.59246/aladalah.v3i4.1647
Layode, O., Naiho, H. N. N., Adeleke, G. S., Udeh, E. O., & Labake, T. T. (2024). The role of cybersecurity in facilitating sustainable healthcare solutions: Overcoming challenges to protect sensitive data. International Medical Science Research Journal, 4(6), 668–693. https://doi.org/10.51594/imsrj.v4i6.1228
Ludvigsen, K. R. (2023). The role of cybersecurity in medical devices regulation: Future considerations and solutions. Law, Technology and Humans, 5(2), 59–77. https://doi.org/10.5204/lthj.3080
Ludvigsen, K. R. (2023). The role of cybersecurity in medical devices regulation: Future considerations and solutions. Law, Technology and Humans, 5(2), 59–77. https://doi.org/10.5204/lthj.3080
Ludvigsen, K. R. (2023). The role of cybersecurity in medical devices regulation: Future considerations and solutions. Law, Technology and Humans, 5(2), 59–77. https://doi.org/10.5204/lthj.3080
Martinez-Licona, F. M. (2026). AI in medical devices: Regulatory challenges and the path forward. Health and Technology, 16, 659–669. https://doi.org/10.1007/s12553-026-01077-8
McDermott, O., Foley, I., Antony, J., Sony, M., & Butler, M. (2022). The impact of Industry 4.0 on the medical device regulatory product life cycle compliance. Sustainability, 14(21), 14650. https://doi.org/10.3390/su142114650
Menon, V. (2026). Cybersecurity breaches in medical devices: Analyzing FDA safety communications in response to patient security concerns. Frontiers in Digital Health, 8, 1701551. https://doi.org/10.3389/fdgth.2026.1701551
Nacu, A. G., Constantin, D. A., & Rogozea, L. M. (2025). Ethical dilemmas and legal responsibilities in patient care: An analysis of hospital safety. Healthcare, 13(21), 2800. https://doi.org/10.3390/healthcare13212800
Nwani, S. (2025). Evaluating the impact of blockchain technology on supply chain transparency and traceability. Gulf Journal of Advance Business Research, 3(6), 1065–1093. https://doi.org/10.51594/gjabr.v3i6.149
Ostermann, M., Mathias, R., Jahed, F., Parker, M. B., Hudson, F. D., Harding, W. C., Gilbert, S., & Freyer, O. (2025). Cybersecurity requirements for medical devices in the EU and US: A comparison and gap analysis of the MDCG 2019-16 and FDA premarket cybersecurity guidance. Computational and Structural Biotechnology Journal, 28, 259–266. https://doi.org/10.1016/j.csbj.2025.07.024
Petrov, I., & Kumar, R. (2025). Disinformation and legal responsibility: Regulating digital speech without curtailing dissent. Interdisciplinary Studies in Society, Law, and Politics, 4(2), 303–314. https://doi.org/10.61838/kman.isslp.4.2.26
Qazi, A. (2025). Systemically important supply chains in crisis: Mapping disruptions and global ripple effects. Natural Hazards Research. Advance online publication. https://doi.org/10.1016/j.nhres.2025.09.003
Saleem, H. A. R., Bukhtiar, A., Zaheer, B., & Farooq, M. A. U. (2025). Challenges faced by the judiciary in implementing cybersecurity laws in Pakistan. The Critical Review of Social Sciences Studies, 3(1), 1052–1066. https://doi.org/10.59075/1wyx0v30
Schorr, M. (2024). How will the new Product Liability Directive (EU) 2024/2853 impact businesses? Keystone Law. https://www.keystonelaw.com/
Williams, P. A., & Woodward, A. J. (2015). Cybersecurity vulnerabilities in medical devices: A complex environment and multifaceted problem. Medical Devices: Evidence and Research, 8, 305–316. https://doi.org/10.2147/MDER.S50048
Downloads
Published
Issue
Section
License
Copyright (c) 2026 Amina Anam (Author)

This work is licensed under a Creative Commons Attribution 4.0 International License.


