> For the complete documentation index, see [llms.txt](https://mediam.gitbook.io/mediam/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://mediam.gitbook.io/mediam/specification/market-study/market-characteristics.md).

# Market characteristics

Healthcare meets cybersecurity

## **Characteristics of the market (medical devices)**

From a European perspective, it's important to realize that the "medical device" market is organized around many smaller players, and big US players.

* 20.000 vendors worldwide, 80% SME (including 1.100 in France)
* 90% of the volumes are generated by 30 vendors
  * France : Essilor, Biomérieux
  * Germany : Siemens, B Braun, Fresenius, Paul Hartmann, Roche Diagnostic, Alcon
  * US : 19 vendors out of 30

Medical devices are classified according to their impact on patient safety:

* Class I: non-invasive (stay outside the human body) or non-surgical invasive devices temporary. Example: compresses, crutches or infusers.&#x20;
* Class IIa: non-invasive devices in contact with blood, body fluids, organs or skin injured or non-surgical invasive short-term use. Example: contact lenses or gloves sterile surgical procedures.&#x20;
* Class IIb: non-invasive devices in contact with damaged skin in the event of destruction of the dermis or devices surgical invasives intended for long use. Example: blood bags, staples, a generator of dialysis or a contraceptive device.&#x20;
* Class III: invasive surgical devices, made from tissue of animal origin, incorporating a substance active or implantable device. Example: vascular prostheses, heart valve.

The certification process is configured accordingly:

```
Class I: no control, self-certification by the manufacturer.
Class IIa: production control.
Class IIb: production control and quality assurance monitoring.
Class III: design and manufacturing control, logistics monitoring, quality assurance and validation by
clinical tests
```

It's harder to assess the specificities of the "connected medical devices". We can observe that electrical equipement manufacturers are also developing in that area (ex: Philips). BSI has recently published the results from its [ecare study](https://www.bsi.bund.de/SharedDocs/Downloads/DE/BSI/DigitaleGesellschaft/eCare_Abschlussbericht_EN.pdf;jsessionid=7D3A65B7BF62A51DB477F28025BDC6C3.1_cid501?__blob=publicationFile\&v=2).&#x20;

From field interviews, we could gather a few additional metrics :&#x20;

* a radiologist deals with 50000 images / day, automation is a requirement
* an average of 10-15 sensors per connected bed

![What do we mean by connected medical device ?](https://3178453543-files.gitbook.io/~/files/v0/b/gitbook-legacy-files/o/assets%2F-MRtPf74KcFoj7U-KiQV%2F-MS3Qv2xUlotH91-7xKo%2F-MS3UIuGDJzg-28fC_Y5%2Fimage.png?alt=media\&token=e09fd1db-822e-43b1-b720-46918331928a)

Therefore cybersecurity becomes a big concern for medical organizations. Attacks have already occured and even led to catastrophic [consequences ](https://www.theverge.com/2020/9/17/21443851/death-ransomware-attack-hospital-germany-cybersecurity#:~:text=A%20woman%20in%20Germany%20died,a%20cyberattack%20on%20a%20hospital.\&text=The%20cyberattack%20was%20not%20intended,the%20German%20news%20outlet%20RTL.)for patients.

## **Personas**

### Healthcare organisations

In healthcare organisations, there are 2 main jobs that are directly involved into the security of connected medical devices:&#x20;

* "Chief information security officer - CISO" (in charge of cyber security)
* networking specialist may define network segmentations to mitigate some of the risks (especially for older devices that can't be removed or upgraded)
* biomedical engineer (in charge of medical devices) - example in France [afib](https://afib.asso.fr/)&#x20;

Often we've seen silo-ed approach between traditional information systems (IT) and connected devices (IoT).&#x20;

### Vendors

Vendors need to address both product innovation and cybersecurity. In implementing a program to manage cybersecurity risks, manufacturers should, among other things, have a way to monitor and detect cybersecurity vulnerabilities in their devices; establish a process for working with researchers and other stakeholders to get information about potential vulnerabilities ("coordinated vulnerability disclosure policy"); and deploy mitigations (e.g., software patches) to address issues early, before they can be exploited and cause harm.

This may involve many different job functions:

* a CISO may coordinate the efforts
* the product manager should have a minimal understanding of how to deal with the cybersecurity of devices that will be deployed
* hardware and software technical teams need to design with cybersecurity in mind (and have time for that)

&#x20;
