IEC 81001-5-1Health Software Cybersecurity
IEC 81001-5-1 specifies the cybersecurity activities that belong in the health software development lifecycle. Published in 2021, it maps onto the IEC 62304 process structure and adds the security work — threat modelling, secure design and coding, verification, and vulnerability handling after release — that 62304 itself does not cover.
- Full title
- Health software and health IT systems safety, effectiveness and security — Part 5-1: Security — Activities in the product life cycle
- Edition
- IEC 81001-5-1:2021
- Issued by
- International Electrotechnical Commission
- Applies
- Recognised internationally; the practical route to MDR Annex I cybersecurity requirements
In practice
In the EU this is the standard that gives practical shape to the cybersecurity requirements in MDR Annex I, which are otherwise stated too generally to build against. MDCG 2019-16 is the accompanying guidance.
Its most useful contribution to a small team is the insistence that vulnerability handling is a lifecycle obligation. A device shipped with a clean scan and no route to deliver a patch eighteen months later does not meet the intent. In practice that means a software bill of materials you actually regenerate, a monitored disclosure channel, and a validated update path designed before launch rather than improvised during an incident.