Alan ParkinsonUK medical device cybersecurity: where the rules stand (and don't)
The UK Medical Devices Regulations 2002 contain no explicit cybersecurity requirements. The word doesn't appear once. Yet new postmarket surveillance rules now require reporting security incidents within 15 days and treating security patches as Field Safety Corrective Actions. Where UK medical device cybersecurity stands in 2026, and where it doesn't.