The rapid advancement of medical technology brings increasing cybersecurity challenges. As medical devices and drug-device combination products integrate with wireless networks and cloud systems, they become prime targets for cyberattacks. A single breach can endanger patient safety, disrupt healthcare operations, and expose sensitive medical data.
Regulatory bodies provide cybersecurity guidelines, but compliance alone does not ensure protection. Developers must embed security throughout the product lifecycle by conducting risk assessments, implementing encryption, enforcing access controls, and continuously monitoring vulnerabilities.
Addressing these evolving threats requires collaboration between companies, healthcare providers, and cybersecurity experts. As cyberattacks grow more sophisticated, the industry is adopting and constantly refining security frameworks to safeguard medical technology, the question remains: in a world of ever-evolving threats, can we ever be truly secure?
Cybersecurity in Healthcare Products
Dragan Jovic is a military telecommunication engineer with expertise in military telecommunications, cybersecurity, and operational planning who transitioned to the Medical Device field.
He is currently employed as the Director of Quality and IT at a Danish medical device manufacturer, while also working as a regulatory consultant. With 9+ years of regulatory experience, he specialises in CE Marking, Software as a Medical Device, Risk Management, and Post-Market Surveillance. He has worked on cybersecurity in medical devices, ensuring compliance with ISO/IEC 27001 and Medical Device Regulation (MDR) cybersecurity requirements.
As a lead auditor (ISO 13485, ISO/IEC 27001), MDSAP auditor, and technical documentation assessor, he supports certification processes. He has extensive experience in health informatics, AI-driven medical solutions, and telecom-based telehealth systems.
Dragan lectures at the Serbian Institute for Standardisation, speaks at EMWA conferences, and has worked globally, including direct client projects in Denmark. His expertise includes FDA pre-market submissions (510k), software development (IEC 62304), and cybersecurity risk management.
