Securing the Trial Device: Cybersecurity Obligations for Clinical DHTs
A networked device holding clinical data is a security artefact — and security is a data-integrity obligation, not optional hygiene.
A networked trial device holding clinical data is a security artifact, and its security is a data-integrity obligation the sponsor must evidence.
If the device or its data can be tampered with, the GCP record built on it is no longer trustworthy — a breach is a data-integrity finding before it is anything else. Map surfaces, controls and owners in the RIA before deployment, treat every patch and end-of-support event as a regulated change, and wire incident response to the reporting clocks.
Every layer of the trial device carries a security obligation; an endpoint passcode covers only the first
| Layer | Exposure | Key control |
|---|---|---|
| Device / OS | Lost, stolen, jailbroken or unpatched handsets, wearables, gateways | Encryption at rest, screen lock, remote wipe, enforced patch baseline |
| Application | Insecure storage, weak authentication, third-party SDKs | Secure SDLC (IEC 81001-5-1:2021), SBOM, vetted SDKs, strong authentication |
| Connectivity (eSIM / data plan) | Interception, rogue networks, remote-provisioning abuse | Transport encryption, trusted provisioning, traffic monitoring |
| Device management (MDM) | Fleet-wide configure-and-wipe platform — a high-value target | Hardened console, least privilege, MFA, audit logging (ISO/IEC 27001:2022) |
| Back-end / integrations | APIs and boundaries into EDC — integrity lost in transit | Authenticated APIs, integrity checks, network segmentation |
Four positions: security is a data-integrity requirement owned across the whole chain
MDR Annex I (ss.17.1–17.4) and FD&C Act s.524B write it into the device; the Cyber Resilience Act and RED into the non-device handset, wearable or gateway; the EMA guideline into the trial record.
ALCOA++ attributability, traceability and protection against alteration all depend on a tamper-resistant device. A weakness is a reason to doubt the GCP record — the sponsor's accountability.
"Never patch" leaves known vulnerabilities open; "patch freely" disturbs the validated state. Route every update through change control; end-of-support is itself a security trigger.
GDPR Art. 33 notification within 72 hours; CTR serious-breach reporting within 7 days (Art. 52); MDR vigilance (Arts 87–90) where a device is involved; Cyber Resilience Act reporting for a non-device product.
Questions to answer in the RIA before deployment
- 1Record the device as in-scope clinical infrastructure — medical device, cyber device, or non-device product under the Cyber Resilience Act.
- 2Encrypt on-device clinical data at rest, with screen lock and remote wipe enforced, and minimize local retention.
- 3Evidence a secure development lifecycle, an SBOM and a vulnerability-management plan for the app; inventory and vet third-party SDKs.
- 4Harden the MDM console — least privilege, MFA, audit logging — and qualify the vendor under QPP-12.
- 5Route every software and OS update through change control (QPP-07), with revalidation of affected functions.
- 6Plan end-of-support refresh and incident response mapped to the GDPR, CTR, vigilance and Cyber Resilience Act reporting clocks.
EU MDR Annex I ss.17.1–17.4 · MDCG 2019-16 Rev. 1 · FD&C Act s.524B · FDA Cybersecurity in Medical Devices (Feb 2026) · Cyber Resilience Act (EU) 2024/2847 · RED Delegated Regulation (EU) 2022/30 · NIS2 (EU) 2022/2555 · EMA/INS/GCP/112288/2023 · ICH E6(R3) · 21 CFR Part 11 · IEC 81001-5-1:2021 · ISO/IEC 27001:2022 · ISO 14971:2019 · IEC 62304
© qointa 2026 – Public – Uncontrolled when printed · Not legal advice; this summary does not classify any device.
sales@qointa.com · qointa.com
More from the library
Digital Health Technologies in Clinical Trials — A Regulatory Position-Paper Series
One device, several perimeters: a framework for assessing the regulatory impact of the technologies a trial relies on.
Read more →Who Is the Manufacturer? Economic-Operator Roles in DHT Supply Chains
How provisioning, importing, kitting and modifying a device assign manufacturer, importer and distributor duties — often by operation of law.
Read more →You Can Delegate the Work, Not the Accountability: Vendor Qualification and Oversight under ICH E6(R3)
The sponsor’s duty to qualify and oversee its DHT vendors — distinct from who holds the economic-operator role.
Read more →Talk to a specialist
Bring one device and one protocol — a wearable, a sensor, an app, anything. We will tell you which regulatory perimeters it opens and what it takes to close them.
Book a 15-minute call