Cybersecurity 2026

UK Law and Practice Contributed by: William Long, Francesca Blythe, Eleanor Dodding and Matthias Bruynseraede, Sidley Austin LLP

must use if they have access to NHS patient data and systems. This includes an incident reporting tool that incorporates the notification requirements of the UK GDPR and the NIS Regulations. There is also a GDPR-focused document entitled “Respond to an NHS Cyber-Alert”, which explains the intersection between medicine, personal data, and cybersecurity and sets operational expectations for NHS organi - sations to acknowledge and remediate cyber alerts within specified timeframes. At an EU level (albeit highly persuasive, rather than legally binding, from a UK perspective), the Medi - cal Device Co-Ordination Group published updated guidance in June 2020 on cybersecurity for medical devices, which is intended to assist medical device manufacturers in meeting the cybersecurity require - ments in the EU’s Medical Devices Regulation and the In Vitro Diagnostic Regulation. According to the updated guidance, manufacturers must consider safety and cybersecurity throughout the life cycle of a product – that is, they must integrate security “by design”. This concept closely aligns with the privacy- by-design requirement under the UK GDPR. Manu - facturers must also perform increased post-market surveillance and vigilance. Such post-market surveil - lance should address the following: • operation of the device in the intended environ - ment; • sharing and dissemination of cybersecurity infor - mation and knowledge of cybersecurity vulnerabili - ties and threats across multiple sectors; • vulnerability remediation; and • incident response.

The MHRA clearly states in its Roadmap that the regu - lations will move the UK towards greater alignment of the cybersecurity requirements for medical devices with the approach taken by the EU and other interna - tional regulators. Lastly, it is worth noting that, rather than taking a separate approach to any AI-enabled product, the UK’s approach to regulating cybersecurity risks aris - ing from AI is sector-specific. In the healthcare space, the MHRA has announced in its Policy Paper “Impact of AI on the regulation of medical products” of April 2024 that it will follow a principles-based approach to avoid constraining innovation, including guidance on cybersecurity for AI, expected to be published in 2026.

455 CHAMBERS.COM

Powered by