SOUTH KOREA Law and Practice Contributed by: Hwan Kyoung Ko, Tae Joo Kim, Jaeyoung Chang and Ji Hoon Kim, Lee & Ko
Medical Device Cybersecurity Guidelines The Ministry of Food and Drug Safety (MFDS) has established and operates the “Guidelines for Cyber - security Approval and Review of Medical Devices”, which set out minimum security requirements and the scope of materials to be submitted in connection with the approval and review of medical devices to address cybersecurity threats. These guidelines present stand - ards for security risk management, the implementa - tion of security functions and post-market security management for network-connected medical devices, including software as a medical device (SaMD).
AI Operators. These mandatory obligations heavily intersect with cybersecurity, encompassing the strict security assurance of AI systems and guaranteeing the integrity of AI training data. Regulation Under PIPA Where an AI system processes personal information, PIPA’s security safeguard obligations (Article 29) apply in the same manner. The PIPC has provided guidance on security safeguards for personal information pro - cessing in AI development and use through materials such as the “Guidelines on Personal Information Pro - cessing for the Development and Use of Generative AI”. Those guidelines distinguish between “model devel - opers” and “model users”, and present items each should follow, dividing them into mandatory require - ments and voluntary responsibilities. 6.3 Cybersecurity in the Healthcare Sector Overlap of the Medical Service Act and PIPA Health information constitutes sensitive information under PIPA (Article 23 (1)), and accordingly it is sub - ject to enhanced regulation; as a result, heightened standards also apply to security safeguards (Articles 23 (2) and 29 of PIPA). Separately, where healthcare professionals or medical institutions create and store medical records and similar documentation as elec - tronic medical records (EMRs), they must maintain the facilities and equipment necessary to manage and preserve such records securely (Article 23 of the Medi - cal Service Act). The Ministry of Health and Welfare (MOHW) issues and administers a public notice titled “Standards for Facilities and Equipment Necessary for the Management and Preservation of Electronic Medical Records”, which sets standards for security measures such as retention of EMR access logs, as well as standards for EMR system facilities and equip - ment. In addition, with respect to the use of healthcare data, the PIPC and the MOHW jointly established and operate the “Healthcare Data Guidelines”.
318 CHAMBERS.COM
Powered by FlippingBook