CYMEDSEC Cybersecurity Performance in Remote Patient Monitoring Systems in a Live Hospital Setting: Protocol for an Observational Study
Abstract Background Remote patient monitoring (RPM) systems based on the Internet of Medical Things (IoMT) technologies are increasingly integrated into chronic disease management and telemedicine pathways. Despite their widespread adoption, cybersecurity performance, system resilience, and user behavior in real-world clinical environments remain underexplored. Existing evidence is fragmented, often limited to laboratory simulations or vendor-driven assessments, leaving a critical gap in understanding how cybersecurity risks across the full life cycle of RPM systems deployed in health care settings. Objective This study aims to systematically analyze the cybersecurity posture, system resilience, and user behavior across the full life cycle of IoMT-enabled RPM systems in a real-world hospital and home-care environment. The study aims to generate empirical evidence on how technical safeguards, operational workflows, and human factors influence cybersecurity risks during procurement, integration, deployment, routine use, and decommissioning of these platforms. Methods This observational study will analyze 2 independent RPM systems used for chronic disease monitoring in a real-world hospital setting. The assessment framework includes (1) system-log analytics to evaluate authentication events, device connectivity, update and patch management, and anomalous behaviors; (2) a controlled phishing simulation targeting health care professionals to assess susceptibility and response patterns; (3) an evaluation of update management processes and vendor-hospital interactions; (4) measurement of cybersecurity awareness and practices among patients and health care professionals using validated instruments; and (5) mapping of vulnerabilities across all life cycle phases, from procurement to decommissioning. Although the study includes cybersecurity training, preassessments/postassessments, and controlled phishing and update-management scenarios, these activities are part of the observational framework and are not designed as experimental interventions that have an impact on the clinical aspects of patient care. Quantitative data will be analyzed using descriptive and inferential statistics, while qualitative insights from operational workflows will be integrated to contextualize system performance. Ethical approval has been obtained from the institutional ethics committee. Results The CYMEDSEC (enhanced cybersecurity for networked medical devices through optimization of guidelines, standards, risk management, and security by design) project received funding from the European Union’s Horizon Europe program (grant 101094218) and started on November 1, 2024. Ethical approval was obtained on December 18, 2025, and institutional authorization on January 29, 2026. Patient enrollment is scheduled to begin on April 1, 2026. At the time of paper submission, no patients were recruited. Data analysis will begin after completion of patient involvement, with results expected before the project end date in October 2027. Conclusions This study will provide real-world evidence on the cybersecurity performance of IoMT-enabled RPM systems, capturing the interplay among technical safeguards, operational processes, and human factors. Findings are expected to support the development of security-by-design approaches, inform procurement and regulatory frameworks, and guide the safe integration of connected medical devices into routine care within the framework of the CYMEDSEC research project.
Authors
- Francesco Ricciardi (ORCID: https://orcid.org/0000-0003-0068-9912)
- Stephen Gilbert (ORCID: https://orcid.org/0000-0002-1997-1689)
- Francesco Giuliani (ORCID: https://orcid.org/0000-0002-5707-2158)
- Oscar Freyer (ORCID: https://orcid.org/0000-0003-3323-2492)
- Michela Falcone (ORCID: https://orcid.org/0009-0007-5575-9865)
Publication Details
- Journal
- JMIR Research Protocols
- Published
- 2026-10-05
- DOI
- https://doi.org/10.2196/98934
- Primary Topic
- Information and Cyber Security
- Type
- article
- Field-Weighted Citation Impact
- 0.00