<?xml version="1.0" encoding="UTF-8"?><!DOCTYPE article PUBLIC "-//NLM//DTD Journal Publishing DTD v2.0 20040830//EN" "journalpublishing.dtd"><article xmlns:mml="http://www.w3.org/1998/Math/MathML" xmlns:xlink="http://www.w3.org/1999/xlink" dtd-version="2.0" xml:lang="en" article-type="research-article"><front><journal-meta><journal-id journal-id-type="nlm-ta">JMIR Res Protoc</journal-id><journal-id journal-id-type="publisher-id">ResProt</journal-id><journal-id journal-id-type="index">5</journal-id><journal-title>JMIR Research Protocols</journal-title><abbrev-journal-title>JMIR Res Protoc</abbrev-journal-title><issn pub-type="epub">1929-0748</issn><publisher><publisher-name>JMIR Publications</publisher-name><publisher-loc>Toronto, Canada</publisher-loc></publisher></journal-meta><article-meta><article-id pub-id-type="publisher-id">v15i1e98934</article-id><article-id pub-id-type="doi">10.2196/98934</article-id><article-categories><subj-group subj-group-type="heading"><subject>Protocol</subject></subj-group></article-categories><title-group><article-title>CYMEDSEC Cybersecurity Performance in Remote Patient Monitoring Systems in a Live Hospital Setting: Protocol for an Observational Study</article-title></title-group><contrib-group><contrib contrib-type="author" corresp="yes"><name name-style="western"><surname>Falcone</surname><given-names>Michela</given-names></name><degrees>MSc</degrees><xref ref-type="aff" rid="aff1">1</xref></contrib><contrib contrib-type="author"><name name-style="western"><surname>Giuliani</surname><given-names>Francesco</given-names></name><degrees>MSc</degrees><xref ref-type="aff" rid="aff1">1</xref></contrib><contrib contrib-type="author"><name name-style="western"><surname>Gilbert</surname><given-names>Stephen</given-names></name><degrees>PhD</degrees><xref ref-type="aff" rid="aff2">2</xref></contrib><contrib contrib-type="author"><name name-style="western"><surname>Freyer</surname><given-names>Oscar</given-names></name><degrees>Dr Med</degrees><xref ref-type="aff" rid="aff2">2</xref></contrib><contrib contrib-type="author"><name name-style="western"><surname>Ricciardi</surname><given-names>Francesco</given-names></name><degrees>PhD</degrees><xref ref-type="aff" rid="aff1">1</xref></contrib></contrib-group><aff id="aff1"><institution>Innovation and Artificial Intelligence Unit, Fondazione IRCCS Casa Sollievo della Sofferenza</institution><addr-line>Viale Cappuccini</addr-line><addr-line>San Giovanni Rotondo</addr-line><addr-line>Apulia</addr-line><country>Italy</country></aff><aff id="aff2"><institution>Else Kr&#x00F6;ner Fresenius Center for Digital Health, Technische Universit&#x00E4;t Dresden</institution><addr-line>Dresden</addr-line><addr-line>Saxony</addr-line><country>Germany</country></aff><contrib-group><contrib contrib-type="editor"><name name-style="western"><surname>Sarvestan</surname><given-names>Javad</given-names></name></contrib></contrib-group><contrib-group><contrib contrib-type="reviewer"><name name-style="western"><surname>Ewoh</surname><given-names>Pius</given-names></name></contrib></contrib-group><author-notes><corresp>Correspondence to Michela Falcone, MSc, Innovation and Artificial Intelligence Unit, Fondazione IRCCS Casa Sollievo della Sofferenza, Viale Cappuccini, San Giovanni Rotondo, Apulia, 71013, Italy; <email>m.falcone@operapadrepio.it</email></corresp></author-notes><pub-date pub-type="collection"><year>2026</year></pub-date><pub-date pub-type="epub"><day>5</day><month>10</month><year>2026</year></pub-date><volume>15</volume><elocation-id>e98934</elocation-id><history><date date-type="received"><day>21</day><month>04</month><year>2026</year></date><date date-type="rev-recd"><day>27</day><month>07</month><year>2026</year></date><date date-type="accepted"><day>30</day><month>07</month><year>2026</year></date></history><copyright-statement>&#x00A9; Michela Falcone, Francesco Giuliani, Stephen Gilbert, Oscar Freyer, Francesco Ricciardi. Originally published in JMIR Research Protocols (<ext-link ext-link-type="uri" xlink:href="https://www.researchprotocols.org">https://www.researchprotocols.org</ext-link>), 5.10.2026. </copyright-statement><copyright-year>2026</copyright-year><license license-type="open-access" xlink:href="https://creativecommons.org/licenses/by/4.0/"><p>This is an open-access article distributed under the terms of the Creative Commons Attribution License (<ext-link ext-link-type="uri" xlink:href="https://creativecommons.org/licenses/by/4.0/">https://creativecommons.org/licenses/by/4.0/</ext-link>), which permits unrestricted use, distribution, and reproduction in any medium, provided the original work, first published in JMIR Research Protocols, is properly cited. The complete bibliographic information, a link to the original publication on <ext-link ext-link-type="uri" xlink:href="https://www.researchprotocols.org">https://www.researchprotocols.org</ext-link>, as well as this copyright and license information must be included.</p></license><self-uri xlink:type="simple" xlink:href="https://www.researchprotocols.org/2026/1/e98934"/><abstract><sec><title>Background</title><p>Remote patient monitoring (RPM) systems based on the Internet of Medical Things (IoMT) technologies are increasingly integrated into chronic disease management and telemedicine pathways. Despite their widespread adoption, cybersecurity performance, system resilience, and user behavior in real-world clinical environments remain underexplored. Existing evidence is fragmented, often limited to laboratory simulations or vendor-driven assessments, leaving a critical gap in understanding how cybersecurity risks across the full life cycle of RPM systems deployed in health care settings.</p></sec><sec><title>Objective</title><p>This study aims to systematically analyze the cybersecurity posture, system resilience, and user behavior across the full life cycle of IoMT-enabled RPM systems in a real-world hospital and home-care environment. The study aims to generate empirical evidence on how technical safeguards, operational workflows, and human factors influence cybersecurity risks during procurement, integration, deployment, routine use, and decommissioning of these platforms.</p></sec><sec sec-type="methods"><title>Methods</title><p>This observational study will analyze 2 independent RPM systems used for chronic disease monitoring in a real-world hospital setting. The assessment framework includes (1) system-log analytics to evaluate authentication events, device connectivity, update and patch management, and anomalous behaviors; (2) a controlled phishing simulation targeting health care professionals to assess susceptibility and response patterns; (3) an evaluation of update management processes and vendor-hospital interactions; (4) measurement of cybersecurity awareness and practices among patients and health care professionals using validated instruments; and (5) mapping of vulnerabilities across all life cycle phases, from procurement to decommissioning. Although the study includes cybersecurity training, preassessments/postassessments, and controlled phishing and update-management scenarios, these activities are part of the observational framework and are not designed as experimental interventions that have an impact on the clinical aspects of patient care. Quantitative data will be analyzed using descriptive and inferential statistics, while qualitative insights from operational workflows will be integrated to contextualize system performance. Ethical approval has been obtained from the institutional ethics committee.</p></sec><sec sec-type="results"><title>Results</title><p>The CYMEDSEC (enhanced cybersecurity for networked medical devices through optimization of guidelines, standards, risk management, and security by design) project received funding from the European Union&#x2019;s Horizon Europe program (grant 101094218) and started on November 1, 2024. Ethical approval was obtained on December 18, 2025, and institutional authorization on January 29, 2026. Patient enrollment is scheduled to begin on April 1, 2026. At the time of paper submission, no patients were recruited. Data analysis will begin after completion of patient involvement, with results expected before the project end date in October 2027.</p></sec><sec sec-type="conclusions"><title>Conclusions</title><p>This study will provide real-world evidence on the cybersecurity performance of IoMT-enabled RPM systems, capturing the interplay among technical safeguards, operational processes, and human factors. Findings are expected to support the development of security-by-design approaches, inform procurement and regulatory frameworks, and guide the safe integration of connected medical devices into routine care within the framework of the CYMEDSEC research project.</p></sec><sec sec-type="registered-report"><title>International Registered Report Identifier (IRRID)</title><p>PRR1-10.2196/98934</p></sec></abstract><kwd-group><kwd>Internet of Medical Things</kwd><kwd>remote patient monitoring</kwd><kwd>cybersecurity</kwd><kwd>cybersecurity-by-design</kwd><kwd>user behavior</kwd><kwd>connected medical devices</kwd></kwd-group></article-meta></front><body><sec id="s1" sec-type="intro"><title>Introduction</title><sec id="s1-1"><title>Background</title><p>Remote patient monitoring (RPM) systems, powered by Internet of Medical Things (IoMT) devices, have revolutionized health care by enabling continuous, real-time tracking of patient vital signs outside traditional clinical settings [<xref ref-type="bibr" rid="ref1">1</xref>-<xref ref-type="bibr" rid="ref4">4</xref>]. These systems integrate wearable sensors, smart devices, and cloud-based analytics to support chronic disease management, postdischarge care, and telemedicine, particularly amid rising demands from aging populations and pandemic events like COVID-19 [<xref ref-type="bibr" rid="ref5">5</xref>-<xref ref-type="bibr" rid="ref8">8</xref>]. Home-based RPM can improve clinical outcomes and quality of life and is associated with reductions in hospitalizations and readmissions, while also suggesting potential cost savings for health systems [<xref ref-type="bibr" rid="ref9">9</xref>-<xref ref-type="bibr" rid="ref11">11</xref>].</p><p>However, the proliferation of IoMT devices introduces significant cybersecurity vulnerabilities, exposing the patients to threats like ransomware, data breaches, and device hijacking [<xref ref-type="bibr" rid="ref12">12</xref>,<xref ref-type="bibr" rid="ref13">13</xref>]. Real-world incidents, such as WannaCry&#x2019;s disruption of the UK&#x2019;s National Health Service (NHS) systems, show how these vulnerabilities can affect downstream care delivery [<xref ref-type="bibr" rid="ref14">14</xref>-<xref ref-type="bibr" rid="ref17">17</xref>]. Human factors and organizational processes exacerbate these issues: health care professionals and patients frequently bypass security protocols due to usability barriers, while inconsistent patch management leaves devices vulnerable to long-term exploitation [<xref ref-type="bibr" rid="ref18">18</xref>-<xref ref-type="bibr" rid="ref23">23</xref>].</p><p>Despite regulatory efforts, including the European Union&#x2019;s medical device regulation and the National Institute of Standards and Technology (NIST) cybersecurity framework for IoMT, gaps persist in real-world implementation, particularly in life cycle management and user behavior [<xref ref-type="bibr" rid="ref24">24</xref>-<xref ref-type="bibr" rid="ref27">27</xref>]. This exploratory observational implementation study addresses these gaps by evaluating the cybersecurity performance, resilience, and human-factor dimensions of an RPM ecosystem integrating IoMT devices in a live hospital setting in the Apulia region of Italy. The assessment spans the full device lifecycle&#x2014;procurement, integration, deployment, routine use, and decommissioning&#x2014;to identify vulnerabilities, mitigation strategies, and operational challenges.</p></sec><sec id="s1-2"><title>Aims and Objectives</title><sec id="s1-2-1"><title>Aim</title><p>The aim of this exploratory observational implementation study is to evaluate the cybersecurity performance, resilience, and human-factor dimensions of an RPM ecosystem integrating IoMT devices within a real-world hospital setting. The study examines cybersecurity risks and mitigation strategies across the full life cycle of the RPM system, including procurement, integration, deployment, routine use, and decommissioning.</p></sec><sec id="s1-2-2"><title>Primary Objective</title><p>The objective is to conduct a comprehensive, life cycle&#x2013;based assessment of cybersecurity controls, vulnerabilities, critical issues, and operational performance in IoMT-enabled RPM systems deployed within a production clinical environment.</p></sec><sec id="s1-2-3"><title>Secondary Objectives</title><p>The secondary objectives of the study are as follows: (1) define cybersecurity best practices for each phase of the IoMT medical device life cycle (procurement, setup and integration, deployment, usage, and decommissioning) in a hospital environment; (2) assess the cybersecurity risks arising from common practices adopted by both patients and health care professionals; (3) reduce cybersecurity risks associated with the use of IoMT medical devices by delivering targeted training to end users and by measuring the impact of the training initiative; (4) capture real-world challenges related to device usability, security compliance, and perceived risks; (5) evaluate the effectiveness of current update and patch distribution mechanisms and identify opportunities to optimize update management; and (6) provide health care institutions, policymakers, and technology providers with a structured approach for secure device and system decommissioning.</p></sec><sec id="s1-2-4"><title>Exploratory Objectives</title><p>The exploratory objectives of the study are as follows: (1) explore associations between user behavioral patterns and cybersecurity risk exposure; and (2) identify implementation barriers affecting cybersecurity compliance in home-based RPM contexts.</p></sec></sec></sec><sec id="s2" sec-type="methods"><title>Methods</title><sec id="s2-1"><title>Design and Setting</title><p>This research activity is designed as a prospective, exploratory, observational study conducted within a real-world hospital setting as part of the European research project CYMEDSEC (enhanced cybersecurity for networked medical devices through optimization of guidelines, standards, risk management, and security by design) [<xref ref-type="bibr" rid="ref28">28</xref>]. The primary objective is to conduct a comprehensive, life cycle-based assessment of cybersecurity controls, vulnerabilities, critical issues, and operational performance in IoMT-enabled RPM systems deployed in a production clinical environment rather than to evaluate clinical efficacy or safety outcomes of the solution under investigation.</p><p>The study does not introduce therapeutic interventions or modifications of current clinical pathways as defined by validated state-of-the-art clinical protocols. Instead, it examines the cybersecurity implications of procurement, integration, deployment, routine use, and decommissioning of RPM platforms under standard operational conditions.</p><p>The exploratory design is justified by the emerging and rapidly evolving nature of cybersecurity threats in the health care context, together with the current lack of standardized real-world evidence for IoMT life cycle cybersecurity management. This approach also reflects the need to generate structured evidence capable of informing future regulatory and procurement frameworks. In addition, it supports the intention to validate and operationalize the cybersecurity framework developed within the CYMEDSEC project in both hospital and home-care environments.</p><p>The study comprises 3 complementary assessments. The first is a process assessment, examining cybersecurity aspects related to procurement, system integration, deployment, and decommissioning. The second is a technical assessment, which includes system-log analysis, update-management processes, and the evaluation of incident-detection capabilities. The third is a behavioral assessment, focusing on user awareness, susceptibility to phishing attempts, and the effectiveness of cybersecurity-training interventions.</p><p>The study follows a sequential flow that reflects the life cycle-based evaluation model of the IoMT-enabled RPM systems. Participant involvement will be part of the real-world deployment.</p><p><xref ref-type="table" rid="table1">Table 1</xref> reports the sequence of the phases that will be analyzed during the project pilot.</p><p>The flow chart in <xref ref-type="fig" rid="figure1">Figure 1</xref> provides an overview of the study phases 4 (real-world use) and 5 (decommissioning) where there will be a direct involvement of the patients and of their data.</p><table-wrap id="t1" position="float"><label>Table 1.</label><caption><p>Study flow<sup><xref ref-type="table-fn" rid="table1fn1">a</xref></sup>.</p></caption><table id="table1" frame="hsides" rules="groups"><thead><tr><td align="left" valign="bottom">(Phase) scenario</td><td align="left" valign="bottom">Description</td></tr></thead><tbody><tr><td align="left" valign="top">(1) Procurement</td><td align="left" valign="top">Evaluate the procurement phase of RPM<sup><xref ref-type="table-fn" rid="table1fn2">b</xref></sup> systems with particular attention to the definitions of the cybersecurity requirements and market analysis as defined by the relevant legislation. This evaluation will be focused on the following domains: governance and compliance, privacy and data protection, medical device and clinical safety, Internet of Medical Things and sensors and embedded, cloud and hosting, network and integration, identity and access management, application and API security, secure SDLC<sup><xref ref-type="table-fn" rid="table1fn3">c</xref></sup> and vulnerability management, supply chain and SBOM<sup><xref ref-type="table-fn" rid="table1fn4">d</xref></sup>, logging, monitoring and incident response, and continuity and resilience. Those areas cover the main aspects of cybersecurity for an RPM platform and lead to a comprehensive evaluation of the RPM system under procurement with respect to the most relevant standards and legislation for each domain.</td></tr><tr><td align="left" valign="top">(2) Setup and integration</td><td align="left" valign="top">The integration phase as well as the setup of the system is a crucial phase from the cybersecurity point of view. In the health care setting, integration between systems is mandatory to guarantee information exchange and interoperability. There are a number of cybersecurity norms that consider this to a degree, including ISO 80001-1:2021, HL7<sup><xref ref-type="table-fn" rid="table1fn5">e</xref></sup> security and privacy module, and Integrating the Healthcare Enterprise (IHE) IT security profiles. To our knowledge, there is no standard comprehensively defined complete setup/integration phase. We will carry out searches for new or updated norms relevant to this phase; we will follow all existing cybersecurity standards; and we will transfer information regarding gaps in norms to project output.</td></tr><tr><td align="left" valign="top">(3) Deployment</td><td align="left" valign="top">Medical personnel and patients need to be instructed on the cybersecurity risks associated with the use of RPM systems during the deployment phase. We will investigate what the vulnerabilities are and how the deployment phase could be conducted effectively to reduce the cybersecurity risks.</td></tr><tr><td align="left" valign="top">(4) Real-world use</td><td align="left" valign="top">The usage of the devices is the most critical phase since data are collected and exchanged while the system is functioning. An evaluation of the device usage in a realistic environment will be conducted by the designer/producer of the system. It will be mixed with questionnaires on the system usage by the end users with particular attention to the aspects related to the updates/patches installation.</td></tr><tr><td align="left" valign="top">(5) Decommissioning</td><td align="left" valign="top">The decommissioning phase is one of the most sensitive phases of the life cycle of the devices, since at the end of life, the devices can often be dismissed without any precaution regarding the stored sensitive user data (if any). For this reason, an analysis of the behavior of the users and operators at the end of the life of the devices is needed. This will lead to the definition of best practices and guidelines to manage this phase.</td></tr></tbody></table><table-wrap-foot><fn id="table1fn1"><p><sup>a</sup>The table outlines the 5 phases assessed in this real-world observational study&#x2013;procurement, setup and integration, deployment, real-world use, and decommissioning&#x2013;describing the cybersecurity objectives, operational activities, and risk-assessment procedures applied across the full life cycle of 2 Internet of Medical Things&#x2013;enabled systems.</p></fn><fn id="table1fn2"><p><sup>b</sup>RPM: remote patient monitoring.</p></fn><fn id="table1fn3"><p><sup>c</sup>SDLC: software development life cycle. </p></fn><fn id="table1fn4"><p><sup>d</sup>SBOM: software bill of materials. </p></fn><fn id="table1fn5"><p><sup>e</sup>HL7: Health Level Seven. </p></fn></table-wrap-foot></table-wrap><fig position="float" id="figure1"><label>Figure 1.</label><caption><p>Flowchart of patient inclusion in the real-world use and decommissioning phases. The figure illustrates the full participant pathway, including screening, eligibility verification, informed consent, baseline cybersecurity assessment (Human Aspects of Information Security Questionnaire [HAIS-Q]), cybersecurity training, device allocation, real-world usage scenarios (routine use, phishing simulation, update-management evaluation), and secure device decommissioning for adult patients with chronic conditions. RPM: remote patient monitoring.</p></caption><graphic alt-version="no" mimetype="image" position="float" xlink:type="simple" xlink:href="resprot_v15i1e98934_fig01.png"/></fig><p>Key activities include enrollment, baseline assessments, cybersecurity training, device allocation, real-world usage scenarios, and end-of-study procedures. Two independent IoMT-enabled RPM ecosystems will be tested in parallel, each representing a distinct technological infrastructure with its own data flows, interfaces, and operational characteristics. These ecosystems&#x2014;Medisant&#x00E9; devices integrated with the PARTICLE.CARE platform and the Umana T1 wearable integrated with the POHEMA (GPI) platform&#x2014;are not compared against each other, nor do they constitute study arms in a clinical sense. Rather, they function as separate environments through which the cybersecurity framework can be observed, validated, and stress-tested across heterogeneous technological contexts.</p><p><xref ref-type="fig" rid="figure2">Figure 2</xref> illustrates the study timeline. The overall duration of participation is 12 months for participants utilizing the Medisant&#x00E9; devices and the PARTICLE.CARE platform and 6 months for those using the Umana ecosystem in order to minimize participants&#x2019; burden.</p><fig position="float" id="figure2"><label>Figure 2.</label><caption><p>Study timeline in months. The timeline displays the temporal sequence and duration of all study activities, including recruitment and enrollment (months 0&#x2010;2), baseline assessment and cybersecurity training (month 1), the active real-world usage phase (lasting 6 or 12 months depending on the assigned remote patient monitoring configuration), the midstudy update-management scenario and the controlled phishing simulation (both scheduled during the active-use period), end-of-study assessments (final month of participation), device decommissioning (final month), and data analysis (last 2 months). IEC: independent ethical committee.</p></caption><graphic alt-version="no" mimetype="image" position="float" xlink:type="simple" xlink:href="resprot_v15i1e98934_fig02.png"/></fig><p>The study will be conducted at Fondazione Instituto di Ricovero e Cura a Carattere Scientico (IRCCS) Casa Sollievo della Sofferenza (CSS), a major research hospital located in Southern Italy with a mature digital infrastructure and a fully integrated hospital information system. CSS does not currently operate an RPM system, offering an opportunity to observe the full life cycle of IoMT-enabled RPM systems from procurement and integration to deployment, daily use, and decommissioning without legacy constraints.</p><p>Two RPM ecosystems will be deployed within the study. The first consists of Medisant&#x00E9; cellular-enabled devices&#x2014;including a blood glucose monitor, a blood pressure monitor, a body-composition scale, and a multiparameter gateway&#x2014;integrated with the PARTICLE.CARE platform. The second ecosystem is based on the Umana T1 wearable cardiac monitoring system, which will operate in conjunction with the GPI POHEMA platform.</p><p>Both platforms will be securely connected to the hospital&#x2019;s information system through standardized authenticated interfaces.</p><p>Patients will use the devices in their daily lives, while health care professionals will interact with the RPM dashboards within the hospital. This dual-user setting enables evaluation of both technical and behavioral cybersecurity dimensions, including system reliability, secure data flows, update and patch management, authentication practices, and susceptibility to phishing attempts.</p><p>The CSS environment is therefore well-suited to the study&#x2019;s objectives, providing a controlled and operational environment to assess cybersecurity performance, resilience, and human-factor implications across the entire life cycle of IoMT-based RPM systems.</p><p>Although the study includes structured activities such as cybersecurity training, preassessments/postassessments, and controlled real-world scenarios (phishing and update-management), these components are not intended as experimental interventions. Instead, they serve as standardized observational stimuli that allow the research team to evaluate natural user behavior, system performance, and life cycle processes under realistic operational conditions.</p></sec><sec id="s2-2"><title>Study Population and Sample Size</title><p>A total of 30 participants will be included. As this is an exploratory observational study, the sample size was selected pragmatically rather than through formal statistical power calculations.</p><p>The chosen sample is consistent with methodological literature on qualitative and implementation research, which indicates that thematic and code saturation is often achieved within samples of approximately 20 to 30 participants, depending on the heterogeneity of the study population and the complexity of the investigated phenomena [<xref ref-type="bibr" rid="ref29">29</xref>]. This sample size is therefore considered appropriate to identify recurring behavioral patterns, characterize user interactions, and explore cybersecurity practices.</p><p>Given the continuous nature of system-log data, the repeated-measures structure of the Human Aspects of Information Security Questionnaire (HAIS-Q) [<xref ref-type="bibr" rid="ref30">30</xref>] assessments, and the inclusion of all eligible participants within the recruitment window, the proposed sample size is expected to provide a sufficiently rich dataset to characterize both human factors and technical cybersecurity dimensions across the life cycle of the RPM ecosystem.</p><p>Participants will be recruited from adult patients receiving care at CSS and living with chronic conditions. The planned cohort reflects the typical distribution of patients managed in CSS outpatient clinics and will include 19 individuals with type 2 diabetes, 4 with hypertension, 2 with obesity without diabetes, and 5 with low-complexity cardiac disease.</p><p>This composition mirrors the characteristics of potential end-users of IoMT-enabled RPM technologies and enables the study to assess both technical and behavioral cybersecurity aspects during real-world device usage.</p><p>Eligible participants will be adults aged 25 to 70 years with a diagnosis of type 2 diabetes, hypertension, obesity, or moderate low-complexity heart disease. All participants must be able to provide informed consent, demonstrate a basic ability to use a smartphone or digital tools, and be available to use the RPM devices throughout the study. They must also be reachable for monitoring calls from CSS staff and be willing to complete questionnaires and participate in training sessions.</p><p>Participants will be excluded if they are unable to understand or provide informed consent, have a low life expectancy, or have cardiac implants or pacemakers. Individuals with any condition that could interfere with safe participation or compromise adherence to study procedures will also be excluded.</p><p>Recruitment will begin after ethics committee approval. Eligible patients will be identified during routine outpatient visits and approached by qualified clinical staff. After verifying eligibility, potential participants will receive detailed information about the study procedures and expectations.</p><p>Before enrollment, participants will receive a written information sheet describing the study&#x2019;s purpose, procedures, risks, benefits, and data protection measures. Adequate time will be provided to ask questions and consider participation. Written informed consent will be obtained prior to any study activity. Consent forms will be securely stored for 5 years at the CSS Innovation and Artificial Intelligence Unit.</p><p>Participants will be informed that the study will not influence their clinical care or therapeutic decisions in any way. They will also be notified that a phishing simulation will take place during the study; however, specific details about the simulation will not be disclosed at enrollment in order to avoid influencing natural behavioral responses. Participants will be reassured that no data entered during phishing attempts will be stored or retained. They will also be reminded that they may withdraw from the study at any time, without providing a reason and without any consequences for their ongoing clinical care.</p><p>Patient withdrawal may occur under several circumstances. These include a direct request by the participant, the loss of capacity to provide informed consent, or noncompliance with study procedures to an extent that compromises data integrity. Withdrawal may also be required if safety concerns emerge, if the participant experiences device intolerance, or if the investigator determines that continued participation is not in the participant&#x2019;s best interest.</p><p>Upon withdrawal, devices will be returned and end-of-study procedures completed as appropriate. Data collected up to the point of withdrawal may be retained for analysis unless the participant requests deletion in accordance with applicable data-protection regulations.</p><p>Clinical staff who will be involved in the study are part of the study population. The staff will consist of at least 3 physicians and at least 2 nurses/research experts who will be actively involved in enrollment. They will be informed that the study must not influence clinical care or therapeutic decisions and that a phishing simulation will occur during the study. They will sign an informed consent form to formally agree to the proposed conditions.</p></sec><sec id="s2-3"><title>Interventions</title><p>This study does not involve clinical or therapeutic interventions. Instead, it includes a set of structured, cybersecurity-focused activities designed to evaluate how patients and health care professionals interact with IoMT-enabled RPM systems under real-world conditions. These activities encompass cybersecurity training, predefined usage scenarios, a controlled phishing simulation, and an update-management scenario. Together, they allow us to assess both technical system behavior and human-factor vulnerabilities across the full life cycle of the RPM ecosystem.</p><p>All participants attend an initial cybersecurity training session delivered by qualified CSS staff immediately after enrollment and completion of the baseline assessment. The session provides practical guidance on secure device use, appropriate authentication practices, recognition of phishing attempts, and general cybersecurity hygiene.</p><p>Training is delivered once, and attendance is recorded. Its effectiveness is evaluated by changes in behavioral indicators observed during the usage phase and by HAIS-Q scores at the end of the study.</p><p>Following training, participants enter the real-world usage phase, during which they employ the assigned RPM devices (Medisant&#x00E9; or Umana) in their daily lives. This phase enables continuous observation of system reliability, data-transmission integrity, update and patch-management processes, and user interaction patterns. The duration of this phase differs depending on the technology: 12 months for Medisant&#x00E9; devices integrated with the PARTICLE.CARE platform and 6 months for the Umana T1 system integrated with the GPI POHEMA platform. Adherence is monitored through system logs, device-usage statistics, and completeness of transmitted data.</p><p>During the usage period, participants are exposed to a controlled phishing simulation designed to assess susceptibility to social-engineering attacks. To avoid influencing behavior, participants are informed before signing the informed consent that a phishing simulation will take place at some point during the study, but the timing and specific nature of the simulation are not disclosed. This limited disclosure is part of the informed consent process but minimizes anticipatory behavioral adjustments and ensures that the scenario functions as an observational stimulus rather than an interventional component. Participants will receive a phishing email that will imitate the institutional emails of the project but will be received from a different web domain and with phishing characteristics in the email format. Participant training should allow them to recognize the attempt and manage it correctly. The open-source platform &#x201C;Gophish (Jordan Wright)&#x201D; will be used to conduct the assessment and will be operated on servers under our direct control to avoid data leaks. No data entered during the phishing attempts, if any, is stored. Participant responses&#x2014;such as whether they interact with the phishing message&#x2014;are used as behavioral indicators of cybersecurity awareness. After the phishing attempt, participants will be contacted to tell them that they have been part of a phishing initiative and what their response is. According to the level of success of the phishing attempt for each participant, specific training will be conducted to reduce the participant&#x2019;s exposure.</p><p>A dedicated update-management scenario is also implemented to evaluate how devices and platforms handle firmware updates, software patches, and potential connectivity interruptions. This scenario is scheduled during the midusage phase for the platforms and is overseen by CSS technical staff in collaboration with the device manufacturers. System logs are used to document update events, detect anomalies, and assess the resilience of the update process.</p><p>Across all interventions, adherence and exposure are monitored through attendance records, system-generated data, timestamps of scenario interactions, and end-of-study questionnaires. This ensures that each participant has been exposed to all planned components of the study and enables the evaluation of both the technical and behavioral cybersecurity dimensions.</p></sec><sec id="s2-4"><title>Outcomes and Measurements</title><p>The study evaluates processes, behavioral and technical dimensions of cybersecurity within an IoMT-enabled RPM ecosystem. The outcomes are defined to evaluate cybersecurity procedures in system procurement, integration, deployment, use, and decommissioning and to capture changes in user cybersecurity posture, the performance and resilience of the technological infrastructure, and user behavior under controlled attack scenarios. Measurements are collected through validated questionnaires, automated system logs, structured simulations, and end-of-study assessments.</p><p>The study has a composite primary outcome composed of four aspects. First, the evaluation of the current cybersecurity procedures, best practices, and risk assessments in procurement, integration, deployment, use, and decommissioning of IoMT systems. This will result in the publication of cybersecurity guidelines that could be used to inform standards and regulations for the real implementation of IoMT in hospitals. All aspects will be evaluated, taking into consideration current standards and regulations.</p><p>Second, the assessment of changes in cybersecurity posture among patients and health care professionals, together with indicators of the cybersecurity performance of the RPM ecosystem during real-world use. Cybersecurity posture is measured using the HAIS-Q, administered at enrollment and at the end of the study. This instrument captures knowledge, attitudes, and behaviors across multiple cybersecurity domains, allowing the study to quantify the impact of the initial training and prolonged exposure to the RPM system.</p><p>Third, analysis of the technical performance of the RPM ecosystem. Throughout the usage phase, the Medisant&#x00E9; devices, the PARTICLE.CARE platform, the Umana T1 system, and the GPI POHEMA platform generate continuous logs documenting data-transmission integrity, connectivity stability, encryption status, certificate validity, and system uptime. These data allow us to characterize system reliability, identify anomalies, and evaluate the robustness of the technological infrastructure under real-world conditions.</p><p>Fourth, evaluation of user susceptibility to social-engineering attacks. A controlled phishing simulation is conducted once, during the usage phase, to observe whether participants interact with the phishing attempt. No personal data entered during the attempt is stored, and the outcome is limited to behavioral indicators such as clicking, reporting, or ignoring the message.</p><p>Secondary outcomes explore additional aspects of system behavior and user interaction. One area of interest is the performance of update and patch-management processes. A dedicated scenario conducted midstudy evaluates how devices and platforms handle firmware updates, software patches, and potential connectivity interruptions. Update events and anomalies are documented through system logs and technical monitoring.</p><p>Authentication and access-control behaviors are also monitored. Platform logs capture authentication attempts, unauthorized access events, and patterns that may indicate weak or inconsistent security practices. These data are collected continuously during the usage phase and provide insight into user adherence to secure authentication procedures.</p><p>User experience and perceived usability are assessed at the end of the study through structured questionnaires. These measures capture perceptions of ease of use, perceived security, and satisfaction with training and device interaction, complementing the technical indicators with subjective user perspectives.</p><p>Finally, the study evaluates end-of-life security during the device decommissioning phase. CSS staff verify that data-erasure procedures are correctly executed and that devices are returned and processed in accordance with secure disposal practices.</p><p>In addition to the defined outcomes, the study collects supplementary data such as demographic characteristics, device-usage frequency, connectivity patterns, incident logs, training attendance, and adherence indicators. These data support the interpretation of outcomes and contribute to a comprehensive understanding of system performance and user behavior.</p><p><xref ref-type="table" rid="table2">Table 2</xref> summarizes study outcomes, measurement tools, and timing.</p><table-wrap id="t2" position="float"><label>Table 2.</label><caption><p>Summary of the study outcomes<sup><xref ref-type="table-fn" rid="table2fn1">a</xref></sup>.</p></caption><table id="table2" frame="hsides" rules="groups"><thead><tr><td align="left" valign="bottom">Outcome</td><td align="left" valign="bottom">What is measured</td><td align="left" valign="bottom">How it is measured</td><td align="left" valign="bottom">When it is measured</td></tr></thead><tbody><tr><td align="left" valign="top">Cybersecurity processes evaluation</td><td align="left" valign="top">Cybersecurity processes compliance during the device life cycle</td><td align="left" valign="top">Compliance with respect to current regulations and standards</td><td align="left" valign="top">Baseline and end-of-study</td></tr><tr><td align="left" valign="top">Cybersecurity posture (primary)</td><td align="left" valign="top">Knowledge, attitudes, and behaviors</td><td align="left" valign="top">HAIS-Q<sup><xref ref-type="table-fn" rid="table2fn2">b</xref></sup> questionnaire</td><td align="left" valign="top">Baseline and end-of-study</td></tr><tr><td align="left" valign="top">System cybersecurity performance (primary)</td><td align="left" valign="top">Reliability, integrity, availability, and anomalies</td><td align="left" valign="top">Automated system logs</td><td align="left" valign="top">Continuous during usage phase</td></tr><tr><td align="left" valign="top">Phishing susceptibility (primary)</td><td align="left" valign="top">User interaction with phishing attempt</td><td align="left" valign="top">Controlled phishing simulation</td><td align="left" valign="top">Once, midstudy</td></tr><tr><td align="left" valign="top">Update/patch performance (secondary)</td><td align="left" valign="top">Update success and failure, anomalies</td><td align="left" valign="top">System logs, technical monitoring</td><td align="left" valign="top">Once, midstudy</td></tr><tr><td align="left" valign="top">Authentication behaviors (secondary)</td><td align="left" valign="top">Login attempts and unauthorized access</td><td align="left" valign="top">Platform logs</td><td align="left" valign="top">Continuous</td></tr><tr><td align="left" valign="top">User experience (secondary)</td><td align="left" valign="top">Perceived usability</td><td align="left" valign="top">End-of-study questionnaire (UEQ<sup><xref ref-type="table-fn" rid="table2fn3">c</xref></sup>)</td><td align="left" valign="top">End-of-study</td></tr><tr><td align="left" valign="top">Decommissioning security (secondary)</td><td align="left" valign="top">Data erasure and device return</td><td align="left" valign="top">Technical verification</td><td align="left" valign="top">Final month</td></tr></tbody></table><table-wrap-foot><fn id="table2fn1"><p><sup>a</sup>The table summarizes all study outcomes, including life cycle&#x2013;based evaluation of cybersecurity procedures, changes in cybersecurity posture (HAIS-Q), technical performance of the remote patient monitoring  ecosystem (data-transmission integrity, connectivity stability, and continuity of secure operations), susceptibility to phishing attacks, update-management performance, authentication behavior, and system-level robustness.</p></fn><fn id="table2fn2"><p><sup>b</sup>HAIS-Q: Human Aspects of Information Security Questionnaire.</p></fn><fn id="table2fn3"><p><sup>c</sup>UEQ: User Experience Questionnaire.</p></fn></table-wrap-foot></table-wrap><p>This study does not involve clinical or therapeutic interventions and does not expose participants to additional clinical risks. For this reason, no adverse clinical events are expected or monitored. Technical incidents or anomalies related to medical devices or platform performance are captured through system logs and are considered part of the cybersecurity performance outcomes rather than adverse events.</p><p>All data are collected and managed in accordance with the study&#x2019;s data management plan and General Data Protection Regulation (GDPR) [<xref ref-type="bibr" rid="ref31">31</xref>] requirements. System and platform logs are stored on secure institutional servers with restricted access, while personal data are pseudonymized prior to analysis. Consent forms are archived for 5 years at the CSS Innovation and Artificial Intelligence Unit. At the end of the study, anonymized datasets will be made available in a public repository in line with the FAIR (findable, accessible, interoperable, and reusable) principles and applicable regulations.</p><p><xref ref-type="table" rid="table3">Table 3</xref> presents the key performance indicators that will be measured during the pilot. The indicators are grouped into 3 families related to &#x201C;Cybersecurity Effectiveness and Technical Performance of the RPM platforms,&#x201D; &#x201C;Human attitudes, cybersecurity culture and behavior,&#x201D; and &#x201C;System Usage.&#x201D; Those 3 macrocategories are detailed into specific key performance indicators reported in the table, which are related to each specific scenario.</p><table-wrap id="t3" position="float"><label>Table 3.</label><caption><p>Key performance indicators (KPIs)<sup><xref ref-type="table-fn" rid="table3fn1">a</xref></sup>.</p></caption><table id="table3" frame="hsides" rules="groups"><thead><tr><td align="left" valign="bottom" colspan="2">KPIs</td><td align="left" valign="bottom">Metrics</td><td align="left" valign="bottom">Target value</td><td align="left" valign="bottom">Tool</td><td align="left" valign="bottom">Scenario</td></tr></thead><tbody><tr><td align="left" valign="top" colspan="6"><bold>Cybersecurity effectiveness and technical performance of the RPM platforms</bold></td></tr><tr><td align="left" valign="top" colspan="6"><named-content content-type="indent">&#x00A0;&#x00A0;&#x00A0;&#x00A0;</named-content><bold>KPI 1: detection of cybersecurity events</bold></td></tr><tr><td align="left" valign="top" colspan="2"><named-content content-type="indent">&#x00A0;&#x00A0;&#x00A0;&#x00A0;</named-content><named-content content-type="indent">&#x00A0;&#x00A0;&#x00A0;&#x00A0;</named-content>KPI 1.1: number of detected security incidents</td><td align="left" valign="top">Number of events per pilot duration</td><td align="left" valign="top">&#x003E;0</td><td align="left" valign="top">Security logs</td><td align="left" valign="top">4</td></tr><tr><td align="left" valign="top" colspan="2"><named-content content-type="indent">&#x00A0;&#x00A0;&#x00A0;&#x00A0;</named-content><named-content content-type="indent">&#x00A0;&#x00A0;&#x00A0;&#x00A0;</named-content>KPI 1.2: number of detected unauthorized access attempts to the RPM system</td><td align="left" valign="top">Number of events per pilot duration</td><td align="left" valign="top">&#x003E;0</td><td align="left" valign="top">Security logs</td><td align="left" valign="top">4</td></tr><tr><td align="left" valign="top" colspan="6"><named-content content-type="indent">&#x00A0;&#x00A0;&#x00A0;&#x00A0;</named-content><bold>KPI 2: data confidentiality, integrity, and availability</bold></td></tr><tr><td align="left" valign="top" colspan="2"><named-content content-type="indent">&#x00A0;&#x00A0;&#x00A0;&#x00A0;</named-content><named-content content-type="indent">&#x00A0;&#x00A0;&#x00A0;&#x00A0;</named-content>KPI 2.1: percentage of time in which a valid digital certificate (over TLS 1.3<sup><xref ref-type="table-fn" rid="table3fn2">b</xref></sup>) is used</td><td align="left" valign="top">%</td><td align="left" valign="top">100</td><td align="left" valign="top">Verification tool</td><td align="left" valign="top">4</td></tr><tr><td align="left" valign="top" colspan="2"><named-content content-type="indent">&#x00A0;&#x00A0;&#x00A0;&#x00A0;</named-content><named-content content-type="indent">&#x00A0;&#x00A0;&#x00A0;&#x00A0;</named-content>KPI 2.2: number of data corruption events due to file system or database failure</td><td align="left" valign="top">Number of events per week</td><td align="left" valign="top">0</td><td align="left" valign="top">System logs</td><td align="left" valign="top">4</td></tr><tr><td align="left" valign="top" colspan="2"><named-content content-type="indent">&#x00A0;&#x00A0;&#x00A0;&#x00A0;</named-content><named-content content-type="indent">&#x00A0;&#x00A0;&#x00A0;&#x00A0;</named-content>KPI 2.3: time of network failures halting access to data</td><td align="left" valign="top">Number of minutes per week</td><td align="left" valign="top">&#x003C;5</td><td align="left" valign="top">System logs</td><td align="left" valign="top">4</td></tr><tr><td align="left" valign="top" colspan="2"><named-content content-type="indent">&#x00A0;&#x00A0;&#x00A0;&#x00A0;</named-content><named-content content-type="indent">&#x00A0;&#x00A0;&#x00A0;&#x00A0;</named-content>KPI 2.4: volume of residual data at the end of the pilot</td><td align="left" valign="top">MB</td><td align="left" valign="top">0</td><td align="left" valign="top">Database logs</td><td align="left" valign="top">5</td></tr><tr><td align="left" valign="top" colspan="6"><named-content content-type="indent">&#x00A0;&#x00A0;&#x00A0;&#x00A0;</named-content><bold>KPI 3: system reliability, availability, and maintainability</bold></td></tr><tr><td align="left" valign="top" colspan="2"><named-content content-type="indent">&#x00A0;&#x00A0;&#x00A0;&#x00A0;</named-content><named-content content-type="indent">&#x00A0;&#x00A0;&#x00A0;&#x00A0;</named-content>KPI 3.1: percentage of system uptime</td><td align="left" valign="top">%</td><td align="left" valign="top">&#x003E;99</td><td align="left" valign="top">System logs</td><td align="left" valign="top">4</td></tr><tr><td align="left" valign="top" colspan="2"><named-content content-type="indent">&#x00A0;&#x00A0;&#x00A0;&#x00A0;</named-content><named-content content-type="indent">&#x00A0;&#x00A0;&#x00A0;&#x00A0;</named-content>KPI 3.2: percentage of network uptime</td><td align="left" valign="top">%</td><td align="left" valign="top">&#x003E;95</td><td align="left" valign="top">System logs</td><td align="left" valign="top">4</td></tr><tr><td align="left" valign="top" colspan="2"><named-content content-type="indent">&#x00A0;&#x00A0;&#x00A0;&#x00A0;</named-content><named-content content-type="indent">&#x00A0;&#x00A0;&#x00A0;&#x00A0;</named-content>KPI 3.3: average downtime during the integration phase</td><td align="left" valign="top">Minutes</td><td align="left" valign="top">&#x003C;5</td><td align="left" valign="top">System logs</td><td align="left" valign="top">2</td></tr><tr><td align="left" valign="top" colspan="2"><named-content content-type="indent">&#x00A0;&#x00A0;&#x00A0;&#x00A0;</named-content><named-content content-type="indent">&#x00A0;&#x00A0;&#x00A0;&#x00A0;</named-content>KPI 3.4: number of integration vulnerabilities detected during setup testing</td><td align="left" valign="top">Absolute number</td><td align="left" valign="top">&#x003C;2</td><td align="left" valign="top">Analysis of the integration</td><td align="left" valign="top">2</td></tr><tr><td align="left" valign="top" colspan="6"><named-content content-type="indent">&#x00A0;&#x00A0;&#x00A0;&#x00A0;</named-content><bold>KPI 4: procurement compliance</bold></td></tr><tr><td align="left" valign="top" colspan="2"><named-content content-type="indent">&#x00A0;&#x00A0;&#x00A0;&#x00A0;</named-content><named-content content-type="indent">&#x00A0;&#x00A0;&#x00A0;&#x00A0;</named-content>KPI 4.1: number of noncompliances or gaps identified during procurement review</td><td align="left" valign="top">Absolute number</td><td align="left" valign="top">&#x003C;2</td><td align="left" valign="top">Procurement simulation</td><td align="left" valign="top">1</td></tr><tr><td align="left" valign="top" colspan="6"><bold>Human attitudes, cybersecurity culture, and behavior</bold></td></tr><tr><td align="left" valign="top" colspan="6"><named-content content-type="indent">&#x00A0;&#x00A0;&#x00A0;&#x00A0;</named-content><bold>KPI 5: measured knowledge, attitudes, and behaviors</bold></td></tr><tr><td align="left" valign="top" colspan="2"><named-content content-type="indent">&#x00A0;&#x00A0;&#x00A0;&#x00A0;</named-content><named-content content-type="indent">&#x00A0;&#x00A0;&#x00A0;&#x00A0;</named-content>KPI 5.1: knowledge of cybersecurity practices</td><td align="left" valign="top">Likert scale (1-5)</td><td align="left" valign="top">&#x003E;4</td><td align="left" valign="top">Validated questionnaire</td><td align="left" valign="top">4</td></tr><tr><td align="left" valign="top" colspan="2"><named-content content-type="indent">&#x00A0;&#x00A0;&#x00A0;&#x00A0;</named-content><named-content content-type="indent">&#x00A0;&#x00A0;&#x00A0;&#x00A0;</named-content>KPI 5.2: attitude toward cybersecurity practices</td><td align="left" valign="top">Likert scale (1-5)</td><td align="left" valign="top">&#x003E;4</td><td align="left" valign="top">Validated questionnaire</td><td align="left" valign="top">4</td></tr><tr><td align="left" valign="top" colspan="2"><named-content content-type="indent">&#x00A0;&#x00A0;&#x00A0;&#x00A0;</named-content><named-content content-type="indent">&#x00A0;&#x00A0;&#x00A0;&#x00A0;</named-content>KPI 5.3: cybersecurity-aware behavior</td><td align="left" valign="top">Likert scale (1-5)</td><td align="left" valign="top">&#x003E;4</td><td align="left" valign="top">Validated questionnaire</td><td align="left" valign="top">4</td></tr><tr><td align="left" valign="top" colspan="6"><named-content content-type="indent">&#x00A0;&#x00A0;&#x00A0;&#x00A0;</named-content><bold>KPI 6: live usage cybersecurity awareness and behavior</bold></td></tr><tr><td align="left" valign="top" colspan="2"><named-content content-type="indent">&#x00A0;&#x00A0;&#x00A0;&#x00A0;</named-content><named-content content-type="indent">&#x00A0;&#x00A0;&#x00A0;&#x00A0;</named-content>KPI 6.1: percentage of staff and patients completing cybersecurity training</td><td align="left" valign="top">%</td><td align="left" valign="top">&#x003E;90</td><td align="left" valign="top">Training registries</td><td align="left" valign="top">3</td></tr><tr><td align="left" valign="top" colspan="2"><named-content content-type="indent">&#x00A0;&#x00A0;&#x00A0;&#x00A0;</named-content><named-content content-type="indent">&#x00A0;&#x00A0;&#x00A0;&#x00A0;</named-content>KPI 6.2: percentage of users who click the phishing link in the message</td><td align="left" valign="top">%</td><td align="left" valign="top">&#x003C;20</td><td align="left" valign="top">System logs</td><td align="left" valign="top">4</td></tr><tr><td align="left" valign="top" colspan="2"><named-content content-type="indent">&#x00A0;&#x00A0;&#x00A0;&#x00A0;</named-content><named-content content-type="indent">&#x00A0;&#x00A0;&#x00A0;&#x00A0;</named-content>KPI 6.3: percentage of users who release username and password</td><td align="left" valign="top">%</td><td align="left" valign="top">&#x003C;10</td><td align="left" valign="top">System logs</td><td align="left" valign="top">4</td></tr><tr><td align="left" valign="top" colspan="2"><named-content content-type="indent">&#x00A0;&#x00A0;&#x00A0;&#x00A0;</named-content><named-content content-type="indent">&#x00A0;&#x00A0;&#x00A0;&#x00A0;</named-content>KPI 6.4: percentage of users who release their credit card number</td><td align="left" valign="top">%</td><td align="left" valign="top">&#x003C;5</td><td align="left" valign="top">System logs</td><td align="left" valign="top">4</td></tr><tr><td align="left" valign="top" colspan="2"><named-content content-type="indent">&#x00A0;&#x00A0;&#x00A0;&#x00A0;</named-content><named-content content-type="indent">&#x00A0;&#x00A0;&#x00A0;&#x00A0;</named-content>KPI 6.5: percentage of users who complete the update</td><td align="left" valign="top">%</td><td align="left" valign="top">&#x003E;50</td><td align="left" valign="top">System logs</td><td align="left" valign="top">4</td></tr><tr><td align="left" valign="top" colspan="6"><bold>System usage</bold></td></tr><tr><td align="left" valign="top" colspan="6"><named-content content-type="indent">&#x00A0;&#x00A0;&#x00A0;&#x00A0;</named-content><bold>KPI 7: system usage</bold></td></tr><tr><td align="left" valign="top" colspan="2"><named-content content-type="indent">&#x00A0;&#x00A0;&#x00A0;&#x00A0;</named-content><named-content content-type="indent">&#x00A0;&#x00A0;&#x00A0;&#x00A0;</named-content>KPI 7.1: number of logins in the web app per week</td><td align="left" valign="top">Number of events per week</td><td align="left" valign="top">&#x003E;4</td><td align="left" valign="top">System logs</td><td align="left" valign="top">4</td></tr><tr><td align="left" valign="top" colspan="2"><named-content content-type="indent">&#x00A0;&#x00A0;&#x00A0;&#x00A0;</named-content><named-content content-type="indent">&#x00A0;&#x00A0;&#x00A0;&#x00A0;</named-content>KPI 7.2: number of explicit logouts from the web app per week</td><td align="left" valign="top">Number of events per week</td><td align="left" valign="top">&#x003E;0</td><td align="left" valign="top">System logs</td><td align="left" valign="top">4</td></tr></tbody></table><table-wrap-foot><fn id="table3fn1"><p><sup>a</sup>The table lists quantitative and qualitative KPIs derived from system-log analytics, authentication events, update-management processes, phishing-simulation responses, Human Aspects of Information Security Questionnaire (HAIS-Q) scores, and operational workflow observations, providing a structured framework for assessing cybersecurity across the full life cycle of Internet of Medical Things&#x2013;enabled remote patient monitoring (RPM) systems.</p></fn><fn id="table3fn2"><p><sup>b</sup>TLS1.3: Transport Layer Security.</p></fn></table-wrap-foot></table-wrap></sec><sec id="s2-5"><title>Patient and Public Involvement Statement</title><p>Neither patients nor members of the public were involved in the design, conduct, reporting, or dissemination planning of this study. The study procedures, objectives, and data collection methods were defined by the research team based on the project requirements and technical specifications. Study findings will be disseminated through publications in peer-reviewed journals, and participants will be informed of the study results upon completion.</p></sec><sec id="s2-6"><title>Ethical Considerations</title><p>The study was reviewed and approved by the Territorial Ethics Committee of the Azienda Ospedaliero-Universitaria &#x201C;Policlinico Riuniti&#x201D; of Foggia (Comitato Etico Area 1). Approval was granted on December 18, 2025, with decision 208/CE/2025, as documented in the official deliberation issued by the committee. The study was subsequently authorized by the general director of Fondazione CSS on January 29, 2026, following verification by the internal legal, contractual, and privacy office.</p><p>Participation in the study is entirely voluntary. All participants receive detailed written information about the study objectives, procedures, risks, data protection measures, and their rights, as described in the approved patient information sheet and consent form (dated November 27, 2025) and the health care professional consent form (dated November 27, 2025). Written informed consent is obtained prior to any study activity. Participants may withdraw at any time without providing a reason and without any impact on their clinical care or professional responsibilities.</p><p>Data processing is conducted in accordance with the GDPR and institutional policies. Personal identifiers are pseudonymized by authorized staff at CSS, and only coded data are transmitted to project partners within the European Union. Identifiable data are stored securely within the institution and are not shared with external parties beyond those explicitly authorized in the study documentation. Participants are informed of their rights regarding access, rectification, restriction, objection, and withdrawal of consent, as detailed in the privacy sections of the approved consent forms.</p><p>The study does not involve clinical interventions and does not modify therapeutic pathways. Device measurements are not used for clinical decision-making, and participants are explicitly instructed not to alter their therapy based on device readings. No adverse clinical events are expected.</p><p>The outcomes of this research will be disseminated through publication in peer-reviewed journals. Participants will be informed of the study results upon completion.</p></sec><sec id="s2-7"><title>Data Analysis</title><p>Data analysis will focus on characterizing user behaviors, system-level cybersecurity performance, and changes in cybersecurity posture across the study period. Given the exploratory nature of the study and the absence of predefined hypotheses or intervention groups, analyses will be primarily descriptive, supported by structure comparisons of prestudy and poststudy measures where appropriate.</p><p>All participants who complete at least one study activity&#x2014;such as the baseline HAIS-Q assessment, device onboarding, or initial system-log generation&#x2014;will be included in the analysis. Participants who complete both baseline and end-of-study HAIS-Q questionnaires will contribute to the evaluation of changes in cybersecurity posture, while all individuals generating system logs during the usage phase will be included in the technical analyses of authentication behaviors, connectivity patterns, update events, and system anomalies.</p><p>Descriptive statistics will be used to summarize questionnaire scores, behavioral indicators, and system-level performance metrics. Continuous variables will be described using means, SD, medians, and IQRs, while categorical variables will be summarized using counts and percentages. These summaries will provide an overview of cybersecurity posture at baseline and at the end of the study, patterns of authentication and device usage, responses to the phishing simulation, and the performance of the update and patch-management processes.</p><p>Changes in cybersecurity posture will be examined by comparing baseline and end-of-study HAIS-Q scores within participants. Given the small sample size and the exploratory objectives, no inferential statistical tests are planned; instead, the analysis will focus on describing the direction and magnitude of observed changes. System-log data will be analyzed through time-based aggregation and event-level summaries to identify patterns in connectivity stability, transmission integrity, authentication attempts, and update-related events. Outcomes of the phishing simulation will be categorized (eg, clicked, ignored, and reported) and described in relation to participants&#x2019; baseline cybersecurity profiles to explore potential behavioral patterns.</p><p>Because the study is not designed to test hypotheses or estimate causal effects, no formal covariate adjustment or multivariable modeling will be performed. However, exploratory stratifications may be used to examine whether patterns differ across age groups, chronic condition categories, baseline HAIS-Q levels, or device types. These analyses will be descriptive only and will not be interpreted as inferential comparisons.</p><p>Missing data are expected primarily from incomplete questionnaires, intermittent device usage, or participant withdrawal. Missing values will not be replaced or estimated. All analyses will be conducted using the data actually available for each variable, and the number of participants contributing to each analysis will be explicitly reported. Patterns of missingness&#x2014;such as dropout timing or prolonged device inactivity&#x2014;will be described, as they may provide meaningful information for interpreting user behavior or technical performance.</p><p>Subgroup explorations may be conducted to examine potential differences in cybersecurity behaviors or system-level performance across clinical conditions or demographic characteristics. These analyses will be purely descriptive and will serve to generate insights rather than to support statistical inference.</p><p>Overall, the analytical approach is designed to provide a comprehensive and nuanced understanding of both human-factor and technical cybersecurity dimensions within the RPM ecosystem, while remaining aligned with the exploratory aims and methodological constraints of the study.</p></sec></sec><sec id="s3" sec-type="results"><title>Results</title><p>The CYMEDSEC project received funding from the European Union&#x2019;s Horizon Europe research and innovation program under grant agreement 101094218. The project started on November 1, 2024. Patient enrollment will start on April 1, 2026. At the time of paper submission, no patients had been recruited. Data analysis will start at the end of the patient involvement, and the pilot results will be published prior to the end of the research project, which is scheduled to conclude in October 2027.</p></sec><sec id="s4" sec-type="discussion"><title>Discussion</title><sec id="s4-1"><title>Principal Findings</title><p>The future of disease management passes through care at home. RPM systems based on IoMT technologies will be increasingly integrated into this new approach to care for patients. Home-based health care can improve clinical outcomes and potentially reduce costs [<xref ref-type="bibr" rid="ref9">9</xref>-<xref ref-type="bibr" rid="ref11">11</xref>]. The use of IoMT devices introduces cybersecurity incidents in the budget of the risks associated with the care [<xref ref-type="bibr" rid="ref12">12</xref>,<xref ref-type="bibr" rid="ref13">13</xref>]. Regulations in the area of cybersecurity and medical devices have gaps in life cycle management and user behavior [<xref ref-type="bibr" rid="ref24">24</xref>-<xref ref-type="bibr" rid="ref27">27</xref>]. This study would examine cybersecurity risks and mitigation strategies across the full life cycle of an RPM system deployed in a production clinical environment. To our knowledge, there are no previous similar works in this area.</p><p>The expected results of the CYMEDSEC study include the identification of behavioral patterns that may increase or mitigate exposure to cyber risk during the lifetime of connected medical devices used for RPM. Particular attention will be given to the processes related to the procurement, deployment, and decommissioning of such a system in a real hospital context. The analysis of the interactions of patients and clinicians with these platforms will be particularly relevant for understanding how users interpret and respond to security-related cues, including those introduced through phishing simulations and update-management scenarios.</p><p>The study is also expected to provide a clearer picture of how patients and health care professionals perceive cybersecurity in the context of remote monitoring, and how these perceptions influence their engagement with connected medical devices. Such evidence is essential for informing security-by-design approaches that reflect real user needs and constraints and for strengthening operational guidelines that support safer device usage across the entire life cycle of IoMT technologies, as per the objectives of the CYMEDSEC project.</p><p>By grounding its observations in a real hospital environment, as well as in routine clinical workflows and home-based use, the study is positioned to generate empirical insights that can support more informed decision-making around the deployment and management of connected medical devices. The findings may help interested stakeholders to better anticipate cybersecurity challenges, refine training strategies, and adapt operational processes to emerging risks.</p><p>The pilot activities results will constitute a valuable source of information for the creation of guidelines and recommendations for hospitals, manufacturers, and regulators. In particular, we hope to make an important contribution toward addressing the regulatory gaps identified within the project.</p><p>This study has several limitations that should be considered when interpreting its findings. Although the broader CYMEDSEC project involves multiple partners, the present protocol refers exclusively to the pilot conducted at a single clinical site. Consequently, the evidence generated will reflect the characteristics of this specific regional and institutional context&#x2014;including organizational workflows, digital infrastructure, and patient population&#x2014;which may limit the generalizability of the results to other settings.</p><p>The sample size is intentionally limited and aligned with the exploratory nature of the study. While sufficient for identifying behavioral patterns and system-level issues, it does not support inferential statistical analyses or robust subgroup comparisons. The study population includes adults with selected chronic conditions who receive care at a single institution and possess a minimum level of digital literacy. This may introduce selection bias and restrict applicability to populations with lower technological proficiency, different sociodemographic characteristics, or more complex clinical profiles. The limited number of health care professionals involved may further constrain generalizability.</p><p>The observational design imposes additional constraints. Because the study does not intervene in clinical pathways or device configurations, it may not capture the full spectrum of cybersecurity vulnerabilities that could emerge in more heterogeneous or dynamic environments. Participants&#x2019; awareness of being observed may influence behavior, including responses to the phishing simulation, potentially reducing validity.</p><p>Data collection relies on system logs and self-reported questionnaires, each with intrinsic limitations. System logs may not capture all relevant cybersecurity events, particularly those occurring outside the monitored ecosystem or not recorded by the devices and platforms under study. Self-reported measures may be affected by recall bias or social desirability, thereby influencing the accuracy of behavioral assessments.</p><p>Despite those limitations, as a point of strength, the study is expected to generate valuable empirical insights into the cybersecurity postures of patients and health care professionals, as well as the performance and resilience of IoMT-enabled remote monitoring systems in real-world use.</p><p>The results of the study will be published as part of the dissemination and communication activities of the CYMEDSEC project. These include publication in peer-reviewed papers and dissemination of the results at sector-specific conferences.</p></sec><sec id="s4-2"><title>Conclusions</title><p>To our knowledge, this study will provide one of the first integrated, real-world examinations of cybersecurity practices, vulnerabilities, and user behaviors associated with RPM technologies integrated into a production hospital environment and deployed in home-based settings. By combining process and behavioral assessments, system-level telemetry, and structured observations of patient and clinical interactions with IoMT-enabled devices, the study is designed to generate a multidimensional understanding of how cybersecurity risks emerge, evolve, and can be mitigated across the life cycle of connected medical technologies and how these insights may influence future standards and regulatory frameworks.</p><p>The importance of this work stems from the accelerating adoption of connected medical devices in care processes and the parallel increase in cyber threats targeting health care infrastructure. Despite the growing reliance on remote monitoring systems, empirical evidence describing how end-users engage with these technologies&#x2014;and how their behaviors intersect with system-level vulnerabilities&#x2014;remains limited. By addressing this gap, the study will produce results that will inform the CYMEDSEC project in relation to the development of more effective security-by-design approaches, strengthen operational guidelines, and support the creation of training strategies grounded in real user needs and behaviors.</p><p>The findings are expected to highlight practical areas where the cybersecurity of IoMT-enabled RPM can be enhanced, identify behavioral patterns that influence exposure to cyber risk, and reveal system-level factors that either support or hinder secure device usage. Ultimately, the study is anticipated to contribute actionable insights for health care organizations, technology developers, and policymakers seeking to build safer, more resilient remote monitoring ecosystems. As digital health technologies continue to expand, the evidence generated by this research would help shape future standards and best practices aimed at protecting both patients and health care infrastructure.</p></sec></sec></body><back><ack><p>AI-assisted tools were used in the preparation of this manuscript. Specifically, Microsoft Copilot and Google Gemini were used for English language checking only. All scientific content, conclusions, and intellectual contributions are solely the work of the authors. The authors take full responsibility for the accuracy and integrity of the manuscript.</p></ack><notes><sec><title>Funding</title><p>The CYMEDSEC project has received funding from the European Union&#x2019;s Horizon Europe research and innovation program under grant agreement 101094218.</p></sec></notes><fn-group><fn fn-type="con"><p>MF wrote the manuscript. FR designed the planning activities, contributed to writing the paper, and is the local principal investigator of the study. FG reviewed the paper. OF and SG reviewed the paper and are in charge of the overall direction of the CYMEDSEC project.</p></fn><fn fn-type="conflict"><p>FR, MF, and FG declare no nonfinancial interests and no competing financial interests. OF has a leadership role and holds stock in WhalesDontFly GmbH, has had consulting relationships with Prova Health Ltd, and has a subcontractual consulting relationship with the Saudi Food and Drug Administration (FDA). SG is an advisory group member of the Ernst &#x0026; Young&#x2013;coordinated &#x201C;Study on Regulatory Governance and Innovation in the field of Medical Devices&#x201D; conducted on behalf of the Directorate-General for Health and Food Safety of the European Commission. SG has or has had consulting relationships with Una Health GmbH, Lindus Health Ltd, Flo Ltd, Thymia Ltd, FORUM Institut f&#x00FC;r Management GmbH, High-Tech Gr&#x00FC;nderfonds Management GmbH, Saudi FDA, and Ada Health GmbH and holds share options in Ada Health GmbH.</p></fn></fn-group><glossary><title>Abbreviations</title><def-list><def-item><term id="abb1">CSS</term><def><p>Casa Sollievo della Sofferenza</p></def></def-item><def-item><term id="abb2">CYMEDSEC</term><def><p>enhanced cybersecurity for networked medical devices through optimization of guidelines, standards, risk management, and security by design</p></def></def-item><def-item><term id="abb3">FAIR</term><def><p>findable, accessible, interoperable, and reusable</p></def></def-item><def-item><term id="abb4">GDPR </term><def><p>General Data Protection Regulation</p></def></def-item><def-item><term id="abb5">HAIS-Q</term><def><p>Human Aspects of Information Security Questionnaire</p></def></def-item><def-item><term id="abb6">IoMT</term><def><p>Internet of Medical Things</p></def></def-item><def-item><term id="abb7">NHS </term><def><p>National Health Service</p></def></def-item><def-item><term id="abb8">NIST</term><def><p>National Institute of Standards and Technology</p></def></def-item><def-item><term id="abb9">RPM</term><def><p>remote patient monitoring</p></def></def-item></def-list></glossary><ref-list><title>References</title><ref id="ref1"><label>1</label><nlm-citation citation-type="journal"><person-group person-group-type="author"><name name-style="western"><surname>Patel</surname><given-names>R</given-names> </name><name name-style="western"><surname>Thornton-Swan</surname><given-names>TD</given-names> </name><name name-style="western"><surname>Armitage</surname><given-names>LC</given-names> </name><etal/></person-group><article-title>Remote vital sign monitoring in admission avoidance hospital at home: a systematic review</article-title><source>J Am Med Dir Assoc</source><year>2024</year><month>08</month><volume>25</volume><issue>8</issue><fpage>105080</fpage><pub-id pub-id-type="doi">10.1016/j.jamda.2024.105080</pub-id><pub-id pub-id-type="medline">38908399</pub-id></nlm-citation></ref><ref id="ref2"><label>2</label><nlm-citation citation-type="journal"><person-group person-group-type="author"><name name-style="western"><surname>Kavitha</surname><given-names>VP</given-names> </name><name name-style="western"><surname>Theivanathan</surname><given-names>G</given-names> </name><name name-style="western"><surname>Magesh</surname><given-names>V</given-names> </name><name name-style="western"><surname>Jayandhi</surname><given-names>G</given-names> </name></person-group><article-title>A comprehensive survey of IoT applications in remote patient monitoring, chronic disease management, and smart healthcare infrastructure</article-title><source>Proc 3rd Int Conf Sentim Anal Deep Learn</source><year>2024</year><fpage>689</fpage><lpage>696</lpage><pub-id pub-id-type="doi">10.1109/ICSADL61749.2024.00120</pub-id></nlm-citation></ref><ref id="ref3"><label>3</label><nlm-citation citation-type="journal"><person-group person-group-type="author"><name name-style="western"><surname>Holtz</surname><given-names>BE</given-names> </name><name name-style="western"><surname>Urban</surname><given-names>FA</given-names> </name><name name-style="western"><surname>Oesterle</surname><given-names>J</given-names> </name><name name-style="western"><surname>Blake</surname><given-names>R</given-names> </name><name name-style="western"><surname>Henry</surname><given-names>A</given-names> </name></person-group><article-title>The promise of remote patient monitoring</article-title><source>Telemed J E Health</source><year>2024</year><month>12</month><volume>30</volume><issue>12</issue><fpage>2776</fpage><lpage>2781</lpage><pub-id pub-id-type="doi">10.1089/tmj.2024.0521</pub-id><pub-id pub-id-type="medline">39535888</pub-id></nlm-citation></ref><ref id="ref4"><label>4</label><nlm-citation citation-type="journal"><person-group person-group-type="author"><name name-style="western"><surname>Vegesna</surname><given-names>A</given-names> </name><name name-style="western"><surname>Tran</surname><given-names>M</given-names> </name><name name-style="western"><surname>Angelaccio</surname><given-names>M</given-names> </name><name name-style="western"><surname>Arcona</surname><given-names>S</given-names> </name></person-group><article-title>Remote patient monitoring via non-invasive digital technologies: a systematic review</article-title><source>Telemed J E Health</source><year>2017</year><month>01</month><volume>23</volume><issue>1</issue><fpage>3</fpage><lpage>17</lpage><pub-id pub-id-type="doi">10.1089/tmj.2016.0051</pub-id><pub-id pub-id-type="medline">27116181</pub-id></nlm-citation></ref><ref id="ref5"><label>5</label><nlm-citation citation-type="journal"><person-group person-group-type="author"><name name-style="western"><surname>Riazul Islam</surname><given-names>SM</given-names> </name><name name-style="western"><surname>Humaun Kabir</surname><given-names>M</given-names> </name><name name-style="western"><surname>Hossain</surname><given-names>M</given-names> </name></person-group><article-title>The Internet of Things for health care: a comprehensive survey</article-title><source>IEEE Access</source><year>2015</year><volume>3</volume><fpage>678</fpage><lpage>708</lpage><pub-id pub-id-type="doi">10.1109/ACCESS.2015.2437951</pub-id></nlm-citation></ref><ref id="ref6"><label>6</label><nlm-citation citation-type="journal"><person-group person-group-type="author"><name name-style="western"><surname>Talpur</surname><given-names>MSH</given-names> </name><name name-style="western"><surname>Abro</surname><given-names>AA</given-names> </name><name name-style="western"><surname>Ebrahim</surname><given-names>M</given-names> </name><etal/></person-group><article-title>Illuminating healthcare management: a comprehensive review of IoT-enabled chronic disease monitoring</article-title><source>IEEE Access</source><year>2024</year><volume>12</volume><fpage>48189</fpage><lpage>48209</lpage><pub-id pub-id-type="doi">10.1109/ACCESS.2024.3382011</pub-id></nlm-citation></ref><ref id="ref7"><label>7</label><nlm-citation citation-type="journal"><person-group person-group-type="author"><name name-style="western"><surname>Omboni</surname><given-names>S</given-names> </name><name name-style="western"><surname>Campolo</surname><given-names>L</given-names> </name><name name-style="western"><surname>Panzeri</surname><given-names>E</given-names> </name></person-group><article-title>Telehealth in chronic disease management and the role of the internet-of-medical-things: the Tholomeus&#x00AE; experience</article-title><source>Expert Rev Med Devices</source><year>2020</year><month>07</month><volume>17</volume><issue>7</issue><fpage>659</fpage><lpage>670</lpage><pub-id pub-id-type="doi">10.1080/17434440.2020.1782734</pub-id><pub-id pub-id-type="medline">32536214</pub-id></nlm-citation></ref><ref id="ref8"><label>8</label><nlm-citation citation-type="journal"><person-group person-group-type="author"><name name-style="western"><surname>Hidayat</surname><given-names>DR</given-names> </name><name name-style="western"><surname>Herwanto</surname><given-names>ES</given-names> </name><name name-style="western"><surname>Nirmala</surname><given-names>ODN</given-names> </name></person-group><article-title>The role of telemedicine in chronic disease management: a literature review</article-title><source>Int J Sci Adv</source><year>2024</year><volume>5</volume><issue>4</issue><fpage>789</fpage><lpage>791</lpage><pub-id pub-id-type="doi">10.51542/ijscia.v5i4.21</pub-id></nlm-citation></ref><ref id="ref9"><label>9</label><nlm-citation citation-type="journal"><person-group person-group-type="author"><name name-style="western"><surname>Tan</surname><given-names>SY</given-names> </name><name name-style="western"><surname>Sumner</surname><given-names>J</given-names> </name><name name-style="western"><surname>Wang</surname><given-names>Y</given-names> </name><name name-style="western"><surname>Wenjun Yip</surname><given-names>A</given-names> </name></person-group><article-title>A systematic review of the impacts of remote patient monitoring (RPM) interventions on safety, adherence, quality-of-life and cost-related outcomes</article-title><source>NPJ Digit Med</source><year>2024</year><month>07</month><day>18</day><volume>7</volume><issue>1</issue><fpage>192</fpage><pub-id pub-id-type="doi">10.1038/s41746-024-01182-w</pub-id><pub-id pub-id-type="medline">39025937</pub-id></nlm-citation></ref><ref id="ref10"><label>10</label><nlm-citation citation-type="journal"><person-group person-group-type="author"><name name-style="western"><surname>Smedslund</surname><given-names>G</given-names> </name><name name-style="western"><surname>&#x00D8;ster&#x00E5;s</surname><given-names>N</given-names> </name><name name-style="western"><surname>Hestevik</surname><given-names>CH</given-names> </name></person-group><article-title>Effects of remote patient monitoring on health care utilization in patients with noncommunicable diseases: systematic review and meta-analysis</article-title><source>JMIR mHealth uHealth</source><year>2025</year><month>10</month><day>1</day><volume>13</volume><fpage>e68464</fpage><pub-id pub-id-type="doi">10.2196/68464</pub-id><pub-id pub-id-type="medline">41032865</pub-id></nlm-citation></ref><ref id="ref11"><label>11</label><nlm-citation citation-type="journal"><person-group person-group-type="author"><name name-style="western"><surname>Serrano</surname><given-names>LP</given-names> </name><name name-style="western"><surname>Maita</surname><given-names>KC</given-names> </name><name name-style="western"><surname>Avila</surname><given-names>FR</given-names> </name><etal/></person-group><article-title>Benefits and challenges of remote patient monitoring as perceived by health care practitioners: a systematic review</article-title><source>Perm J</source><year>2023</year><month>12</month><day>15</day><volume>27</volume><issue>4</issue><fpage>100</fpage><lpage>111</lpage><pub-id pub-id-type="doi">10.7812/TPP/23.022</pub-id><pub-id pub-id-type="medline">37735970</pub-id></nlm-citation></ref><ref id="ref12"><label>12</label><nlm-citation citation-type="journal"><person-group person-group-type="author"><name name-style="western"><surname>Cruz-Gavilanez</surname><given-names>N</given-names> </name><name name-style="western"><surname>Martinez-Santander</surname><given-names>C</given-names> </name><name name-style="western"><surname>Galm&#x00E9;s</surname><given-names>S</given-names> </name></person-group><article-title>IoMT device security: systematic review of threats, vulnerabilities, attacks and mitigation strategies</article-title><source>IEEE 9th Ecuador Tech Chapters Meet (ETCM)</source><year>2025</year><fpage>1</fpage><lpage>6</lpage><pub-id pub-id-type="doi">10.1109/ETCM67548.2025.11304419</pub-id></nlm-citation></ref><ref id="ref13"><label>13</label><nlm-citation citation-type="journal"><person-group person-group-type="author"><name name-style="western"><surname>Paes</surname><given-names>TMB</given-names> </name><name name-style="western"><surname>Begot</surname><given-names>FNI</given-names> </name><name name-style="western"><surname>Menezes</surname><given-names>CKY</given-names> </name><name name-style="western"><surname>Mendon&#x00E7;a</surname><given-names>EDS</given-names> </name></person-group><article-title>A systematic review of cybersecurity attacks on medical devices</article-title><source>J Interdiscip Debates</source><year>2026</year><volume>7</volume><issue>1</issue><fpage>104</fpage><lpage>122</lpage><pub-id pub-id-type="doi">10.51249/jid.v7i01.2921</pub-id></nlm-citation></ref><ref id="ref14"><label>14</label><nlm-citation citation-type="journal"><person-group person-group-type="author"><name name-style="western"><surname>Coventry</surname><given-names>L</given-names> </name><name name-style="western"><surname>Branley</surname><given-names>D</given-names> </name></person-group><article-title>Cybersecurity in healthcare: a narrative review of trends, threats and ways forward</article-title><source>Maturitas</source><year>2018</year><month>07</month><volume>113</volume><fpage>48</fpage><lpage>52</lpage><pub-id pub-id-type="doi">10.1016/j.maturitas.2018.04.008</pub-id><pub-id pub-id-type="medline">29903648</pub-id></nlm-citation></ref><ref id="ref15"><label>15</label><nlm-citation citation-type="report"><article-title>Postmarket management of cybersecurity in medical devices: guidance for industry and food and drug administration staff</article-title><year>2016</year><access-date>2026-09-11</access-date><publisher-name>US Food and Drug Administration</publisher-name><comment><ext-link ext-link-type="uri" xlink:href="https://www.fda.gov/media/95862/download">https://www.fda.gov/media/95862/download</ext-link></comment></nlm-citation></ref><ref id="ref16"><label>16</label><nlm-citation citation-type="journal"><person-group person-group-type="author"><name name-style="western"><surname>Umesh</surname><given-names>U</given-names> </name><name name-style="western"><surname>Kumar</surname><given-names>S</given-names> </name><name name-style="western"><surname>Dutta</surname><given-names>K</given-names> </name><name name-style="western"><surname>Kumari</surname><given-names>A</given-names> </name></person-group><article-title>Securing internet of medical things: exploring vulnerabilities and attack vectors</article-title><source>8th Int Conf Parallel Distrib Grid Comput (PDGC)</source><year>2024</year><fpage>678</fpage><lpage>684</lpage><pub-id pub-id-type="doi">10.1109/PDGC64653.2024.10984079</pub-id></nlm-citation></ref><ref id="ref17"><label>17</label><nlm-citation citation-type="journal"><person-group person-group-type="author"><name name-style="western"><surname>Khatiwada</surname><given-names>P</given-names> </name><name name-style="western"><surname>Yang</surname><given-names>B</given-names> </name></person-group><article-title>An overview on security and privacy of data in IoMT devices: performance metrics, merits, demerits, and challenges</article-title><source>Stud Health Technol Inform</source><year>2022</year><month>11</month><day>3</day><volume>299</volume><fpage>126</fpage><lpage>136</lpage><pub-id pub-id-type="doi">10.3233/SHTI220970</pub-id><pub-id pub-id-type="medline">36325853</pub-id></nlm-citation></ref><ref id="ref18"><label>18</label><nlm-citation citation-type="journal"><person-group person-group-type="author"><name name-style="western"><surname>Nifakos</surname><given-names>S</given-names> </name><name name-style="western"><surname>Chandramouli</surname><given-names>K</given-names> </name><name name-style="western"><surname>Nikolaou</surname><given-names>CK</given-names> </name><etal/></person-group><article-title>Influence of human factors on cyber security within healthcare organisations: a systematic review</article-title><source>Sensors (Basel)</source><year>2021</year><month>07</month><day>28</day><volume>21</volume><issue>15</issue><fpage>5119</fpage><pub-id pub-id-type="doi">10.3390/s21155119</pub-id><pub-id pub-id-type="medline">34372354</pub-id></nlm-citation></ref><ref id="ref19"><label>19</label><nlm-citation citation-type="journal"><person-group person-group-type="author"><name name-style="western"><surname>Erukayenure</surname><given-names>O</given-names> </name><name name-style="western"><surname>Bashir</surname><given-names>HA</given-names> </name><name name-style="western"><surname>Adekunbi</surname><given-names>A</given-names> </name><name name-style="western"><surname>Abere</surname><given-names>SE</given-names> </name><name name-style="western"><surname>Okpan</surname><given-names>O</given-names> </name><name name-style="western"><surname>Giwa</surname><given-names>AA</given-names> </name></person-group><article-title>Human factor vulnerabilities in healthcare cybersecurity: mitigating insider threats in medical facilities</article-title><source>Int J Sci Res Arch</source><year>2025</year><volume>17</volume><issue>1</issue><fpage>024</fpage><lpage>031</lpage><pub-id pub-id-type="doi">10.30574/ijsra.2025.17.1.2734</pub-id></nlm-citation></ref><ref id="ref20"><label>20</label><nlm-citation citation-type="journal"><person-group person-group-type="author"><name name-style="western"><surname>Koppel</surname><given-names>R</given-names> </name><name name-style="western"><surname>Smith</surname><given-names>S</given-names> </name><name name-style="western"><surname>Blythe</surname><given-names>J</given-names> </name><name name-style="western"><surname>Kothari</surname><given-names>V</given-names> </name></person-group><article-title>Workarounds to computer access in healthcare organizations: you want my password or a dead patient?</article-title><source>Stud Health Technol Inform</source><year>2015</year><volume>208</volume><fpage>215</fpage><lpage>220</lpage><pub-id pub-id-type="doi">10.3233/978-1-61499-488-6-215</pub-id><pub-id pub-id-type="medline">25676976</pub-id></nlm-citation></ref><ref id="ref21"><label>21</label><nlm-citation citation-type="journal"><person-group person-group-type="author"><name name-style="western"><surname>Grimes</surname><given-names>SL</given-names> </name><name name-style="western"><surname>Wirth</surname><given-names>A</given-names> </name></person-group><article-title>The case for medical device cybersecurity hygiene practices for frontline personnel</article-title><source>Biomed Instrum Technol</source><year>2021</year><month>07</month><day>1</day><volume>55</volume><issue>3</issue><fpage>96</fpage><lpage>99</lpage><pub-id pub-id-type="doi">10.2345/0899-8205-55.3.96</pub-id><pub-id pub-id-type="medline">34284497</pub-id></nlm-citation></ref><ref id="ref22"><label>22</label><nlm-citation citation-type="journal"><person-group person-group-type="author"><name name-style="western"><surname>Hassidim</surname><given-names>A</given-names> </name><name name-style="western"><surname>Korach</surname><given-names>T</given-names> </name><name name-style="western"><surname>Shreberk-Hassidim</surname><given-names>R</given-names> </name><etal/></person-group><article-title>Prevalence of sharing access credentials in electronic medical records</article-title><source>Healthc Inform Res</source><year>2017</year><month>07</month><volume>23</volume><issue>3</issue><fpage>176</fpage><lpage>182</lpage><pub-id pub-id-type="doi">10.4258/hir.2017.23.3.176</pub-id><pub-id pub-id-type="medline">28875052</pub-id></nlm-citation></ref><ref id="ref23"><label>23</label><nlm-citation citation-type="journal"><person-group person-group-type="author"><name name-style="western"><surname>Dart</surname><given-names>M</given-names> </name><name name-style="western"><surname>Ahmed</surname><given-names>M</given-names> </name></person-group><article-title>Evaluating staff attitudes, intentions, and behaviors related to cyber security in large Australian health care environments: mixed methods study</article-title><source>JMIR Hum Factors</source><year>2023</year><month>10</month><day>4</day><volume>10</volume><fpage>e48220</fpage><pub-id pub-id-type="doi">10.2196/48220</pub-id><pub-id pub-id-type="medline">37792450</pub-id></nlm-citation></ref><ref id="ref24"><label>24</label><nlm-citation citation-type="report"><article-title>Regulation (EU) 2017/745 of the European Parliament and of the Council of 5 April 2017 on medical devices, amending Directive 2001/83/EC, Regulation (EC) No 178/2002 and Regulation (EC) No 1223/2009 and repealing Council Directives 90/385/EEC and 93/42/EEC</article-title><year>2017</year><access-date>2026-09-11</access-date><publisher-name>European Union</publisher-name><comment><ext-link ext-link-type="uri" xlink:href="https://eur-lex.europa.eu/eli/reg/2017/745/oj/eng">https://eur-lex.europa.eu/eli/reg/2017/745/oj/eng</ext-link></comment></nlm-citation></ref><ref id="ref25"><label>25</label><nlm-citation citation-type="report"><article-title>Digital investigation techniques: a NIST scientific foundation review</article-title><year>2022</year><access-date>2026-09-11</access-date><publisher-name>National Institute of Standards and Technology (NIST)</publisher-name><comment><ext-link ext-link-type="uri" xlink:href="https://nvlpubs.nist.gov/nistpubs/ir/2022/NIST.IR.8354.pdf">https://nvlpubs.nist.gov/nistpubs/ir/2022/NIST.IR.8354.pdf</ext-link></comment></nlm-citation></ref><ref id="ref26"><label>26</label><nlm-citation citation-type="journal"><person-group person-group-type="author"><name name-style="western"><surname>Hireche</surname><given-names>R</given-names> </name><name name-style="western"><surname>Mansouri</surname><given-names>H</given-names> </name><name name-style="western"><surname>Pathan</surname><given-names>ASK</given-names> </name></person-group><article-title>Security and privacy management in internet of medical things (IoMT): a synthesis</article-title><source>J Cybersecur Priv</source><year>2022</year><volume>2</volume><issue>3</issue><fpage>640</fpage><lpage>661</lpage><pub-id pub-id-type="doi">10.3390/jcp2030033</pub-id></nlm-citation></ref><ref id="ref27"><label>27</label><nlm-citation citation-type="journal"><person-group person-group-type="author"><name name-style="western"><surname>Nolan</surname><given-names>N</given-names> </name><name name-style="western"><surname>McDermott</surname><given-names>O</given-names> </name></person-group><article-title>An investigation of the current status quo of ISO 14971 risk management challenges in the medical device industry</article-title><source>Int J Qual Reliab Manag</source><year>2026</year><month>04</month><day>7</day><volume>43</volume><issue>5</issue><fpage>1439</fpage><lpage>1463</lpage><pub-id pub-id-type="doi">10.1108/IJQRM-01-2025-0039</pub-id></nlm-citation></ref><ref id="ref28"><label>28</label><nlm-citation citation-type="web"><source>CYMEDSEC</source><access-date>2026-03-23</access-date><comment><ext-link ext-link-type="uri" xlink:href="https://cymedsec.eu/">https://cymedsec.eu/</ext-link></comment></nlm-citation></ref><ref id="ref29"><label>29</label><nlm-citation citation-type="journal"><person-group person-group-type="author"><name name-style="western"><surname>Saunders</surname><given-names>B</given-names> </name><name name-style="western"><surname>Sim</surname><given-names>J</given-names> </name><name name-style="western"><surname>Kingstone</surname><given-names>T</given-names> </name><etal/></person-group><article-title>Saturation in qualitative research: exploring its conceptualization and operationalization</article-title><source>Qual Quant</source><year>2018</year><volume>52</volume><issue>4</issue><fpage>1893</fpage><lpage>1907</lpage><pub-id pub-id-type="doi">10.1007/s11135-017-0574-8</pub-id><pub-id pub-id-type="medline">29937585</pub-id></nlm-citation></ref><ref id="ref30"><label>30</label><nlm-citation citation-type="journal"><person-group person-group-type="author"><name name-style="western"><surname>Parsons</surname><given-names>K</given-names> </name><name name-style="western"><surname>Calic</surname><given-names>D</given-names> </name><name name-style="western"><surname>Pattinson</surname><given-names>M</given-names> </name><name name-style="western"><surname>Butavicius</surname><given-names>M</given-names> </name><name name-style="western"><surname>McCormac</surname><given-names>A</given-names> </name><name name-style="western"><surname>Zwaans</surname><given-names>T</given-names> </name></person-group><article-title>The Human Aspects of Information Security Questionnaire (HAIS-Q): two further validation studies</article-title><source>Comput Secur</source><year>2017</year><month>05</month><volume>66</volume><fpage>40</fpage><lpage>51</lpage><pub-id pub-id-type="doi">10.1016/j.cose.2017.01.004</pub-id></nlm-citation></ref><ref id="ref31"><label>31</label><nlm-citation citation-type="report"><article-title>Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation)</article-title><year>2016</year><month>05</month><day>4</day><access-date>2026-09-11</access-date><publisher-name>European Union</publisher-name><comment><ext-link ext-link-type="uri" xlink:href="https://eur-lex.europa.eu/eli/reg/2016/679/oj/eng">https://eur-lex.europa.eu/eli/reg/2016/679/oj/eng</ext-link></comment></nlm-citation></ref></ref-list></back></article>