{
  "abstract": "Background and Importance With the rising frequency of cyberattacks targeting the healthcare sector in France, the medical device (MD) network whether connected or reliant on computerised processes for management, maintenance, and traceability represents a particularly vulnerable target. Such attacks may compromise patient safety and the continuity of care. Despite increasing awareness, the level of preparedness among healthcare institutions (HIs) remains inadequately documented.Aim and Objectives This study aimed to assess the organisational and technical measures implemented by healthcare institutions to prevent, detect, and respond to the risks and impacts of a cyberattack on the MD network.Material and Methods A 3 month audit was conducted using an online questionnaire distributed to public and private hospital pharmacies. The survey was developed based on existing regulatory frameworks and shared experience feedback to evaluate preparedness practices for cyberattacks involving medical devices. Responses were analysed using descriptive quantitative and qualitative methods to identify trends, practice gaps, and common limitations.Results Among the 31 responding institutions, one had previously experienced a cyberattack. Data related to medical devices were mainly stored on secure internal servers (57%), while a minority were kept on USB drives and personal computers. Access control was primarily based on password authentication (84%), although in 3% of cases, data remained freely accessible to pharmacy staff. Cyberattack procedures have been formalised in 54% of HIs, under development in 27%, and absent in 19%. Among those with a procedure, only 18% had tested it. Major areas for improvement included limited staff training and difficulties in performing regular data backups. In practice, 52% of pharmacists reported having a defined Business Continuity and Recovery Plan (BCRP). Logistically, 80% of hospital pharmacies declared having sufficient stock levels; however, visibility regarding non-stocked medical devices and consumables remained limited. Key strengths included the implementation of ‘crash boxes’, effective territorial cooperation, and regular data backups. Reported limitations involved insufficient IT (information technology) department support, irregular training, limited financial resources, and understaffing.Conclusion and Relevance This audit reveals varied cybersecurity preparedness for medical devices. Formal procedures exist in some institutions but are poorly implemented. Harmonisation at national and European levels, along with routine integration and staff training, is essential to protect patient safety.Conflict of Interest No conflict of interest",
  "authors": [
    {
      "affiliations": [
        "Centre Hospitalier Victor Dupouy, Pharmacy Department, Argenteuil, France"
      ],
      "name": "E Choulet"
    },
    {
      "affiliations": [
        "Centre Hospitalier Victor Dupouy, Pharmacy Department, Argenteuil, France"
      ],
      "name": "AM Belliard"
    },
    {
      "affiliations": [
        "Centre Hospitalier Victor Dupouy, Pharmacy Department, Argenteuil, France"
      ],
      "name": "N Belkaid"
    },
    {
      "affiliations": [
        "Centre Hospitalier Victor Dupouy, Pharmacy Department, Argenteuil, France"
      ],
      "name": "E Cauchetier"
    },
    {
      "affiliations": [
        "Centre Hospitalier Victor Dupouy, Pharmacy Department, Argenteuil, France"
      ],
      "name": "JL Pons"
    }
  ],
  "title": "2SPD-022 Cybersecurity risks in the medical device network: are French hospitals prepared?",
  "uid": "a097ec38-ebb9-536c-8899-9604aff79d5a"
}
