MARATTO

article · Patient Safety in Surgery

Current cybersecurity threats to patient safety in the operating room: a review

In plain language

Modern surgical and anaesthetic care increasingly relies on interconnected systems, spanning wireless devices, robotic consoles, perioperative monitors, and cloud infrastructure known as the Internet of Medical Things. While this connectivity supports routine operations and advanced techniques such as telesurgery, it also creates critical vulnerabilities during cyber incidents. Cyber threats targeting the operating theatre include ransomware, supply chain and firmware compromises, wireless interception, attacks on teleoperated robotics, and insider exposures. Disrupted access to digital systems, schedules, and device data has led to cancelled hospital admissions, delayed cancer surgeries, and worse patient outcomes. Vulnerabilities are documented across robotic platforms, cardiac devices, infusion pumps, and monitors. Addressing these risks requires secure design engineering, specialty-specific threat modelling, clinical workforce readiness, and improved incident registries to bridge fragmented regulatory frameworks and protect patient safety across perioperative pathways.

Key takeaways

  • Surgical pathways face cybersecurity risks including ransomware, firmware compromises, wireless interception, insider threats, and attacks on teleoperated robotics.
  • Cyber incidents have directly disrupted patient care by causing cancelled hospital admissions, delayed cancer operations, and worse clinical outcomes.
  • Vulnerabilities are documented across connected technologies such as robotic platforms, cardiac implants, infusion pumps, and perioperative monitors.
  • Current regulatory and governance responses remain fragmented, creating an urgent need for secure design engineering, clinical workforce preparation, and dedicated registries.

Why it matters

Hospitals and operating theatres increasingly depend on connected digital tools to perform complex procedures. When these systems are compromised by cyberattacks, the consequences extend beyond data theft to physical patient harm, interrupted cancer treatments, and disrupted emergency care. Understanding these vulnerabilities enables healthcare leaders, clinicians, and technology developers to strengthen defences before critical systems fail during surgery.

Commercialisation angle

The review outlines opportunities for medical device manufacturers, software developers, and hospital leaders seeking to implement secure design engineering and specialty-specific threat models. While connected surgical tools such as robotic platforms and infusion systems are already in commercial use, the development of specialised threat models, secure engineering solutions, and dedicated surgical cyber registries appears to be at an early to intermediate planning and policy stage.

AI-generated from the published abstract. Always read the original work before citing.

Abstract

Abstract Surgical, anesthetic, and intensive care practices now depend on a large ecosystem of wired and wireless devices, robotic consoles, imaging and laboratory systems, and cloud infrastructure: the Internet of Medical Things and the smart operating room, which extends care beyond the physical theatre to transcontinental telesurgery. Connectivity that is useful in routine care becomes a failure mode during a cyber incident because surgical pathways depend on uninterrupted access to scheduling, imaging, electronic records, and device data. This narrative review sets out the architecture of the surgical Internet of Medical Things and the main threat categories: ransomware, supply chain and firmware compromise, wireless interception, attacks on teleoperated robotic systems, and insider or workforce-related exposure. It then examines documented incidents at the hospital, emergency, and procedural levels, together with the vulnerability profiles of robotic surgical platforms, cardiac implantable electronic devices, infusion systems, and perioperative monitors. Reported harms include cancelled admissions, interrupted cancer surgery and radiotherapy, and worse outcomes after out-of-hospital cardiac arrest, although most of this evidence is healthcare-wide or device-class specific rather than surgery-specific. Although regulatory and governance responses are strengthening, they remain fragmented. The review highlights secure design engineering, human factors, workforce readiness, specialty-specific threat models, and registries as priorities and draws out what each implies for surgeons, anesthetists, device manufacturers, regulators, and hospital leaders.

Research topics

  • Healthcare Technology and Patient Monitoring
  • Patient Safety and Medication Errors
  • Surgical Simulation and Training

Sustainable Development Goals

Read the original research

This page summarises published work. The authoritative version sits with the publisher.

DOI: 10.1186/s13037-026-00510-1

Is something wrong with this record? Report it or request removal.

Discussion

Discuss this research

Have you built on this work, tried to replicate it, or seen it applied in practice? Share what you know. Verified researchers and MARATTO™ domain experts can open a discussion, and any member can reply. Contributions are reviewed before they appear.

No discussion yet. Open the first thread.