Accepted for/Published in: JMIR Research Protocols
Date Submitted: Apr 21, 2026
Date Accepted: Jul 30, 2026
CYMEDSEC: Protocol for an Observational Study on Cybersecurity Performance in Remote Patient Monitoring Systems in a Hospital Live Setting
ABSTRACT
Background:
Remote Patient Monitoring (RPM) systems based on Internet of Medical Things (IoMT) technologies are increasingly integrated into chronic disease management and telemedicine pathways. Despite their widespread adoption, cybersecurity performance, system resilience, and user behaviour in real-world clinical environments remain underexplored. Existing evidence is fragmented, often limited to laboratory simulations or vendor-driven assessments, leaving a critical gap in understanding how cybersecurity risks emerge and evolve across the full lifecycle of RPM systems deployed in healthcare settings.
Objective:
To systematically analyse cybersecurity posture, system resilience, and user behaviour across the full lifecycle of IoMT-enabled RPM systems in a real-world hospital and home-care environment. The study aims to generate empirical evidence on how technical safeguards, operational workflows, and human factors jointly influence cybersecurity risks during procurement, integration, deployment, routine use, and decommissioning of those platforms.
Methods:
This observational study will analyse two independent RPM systems used for chronic disease monitoring in a real-world hospital setting. The assessment framework includes: (1) system-log analytics to evaluate authentication events, device connectivity, update and patch management, and anomalous behaviours; (2) a controlled phishing simulation targeting healthcare professionals to assess susceptibility and response patterns; (3) evaluation of update management processes and vendor-hospital interactions; (4) measurement of cybersecurity awareness and practices among patients and healthcare professionals using validated instruments; and (5) mapping of vulnerabilities across all lifecycle phases, from procurement to decommissioning. Quantitative data will be analysed using descriptive and inferential statistics, while qualitative insights from operational workflows will be integrated to contextualise systems performance. Ethical approval has been obtained from the institutional ethics committee.
Results:
The CYMEDSEC project received funding from the European Union’s Horizon Europe programme (grant No. 101094218). The study obtained ethical approval on December 18, 2025, and institutional authorization on January 29, 2026. Patient enrollment is scheduled to begin on April 1, 2026.
Conclusions:
This study will provide structured real-world evidence on the cybersecurity performance of IoMT-enabled RPM systems, capturing the interplay between technical safeguards, operational processes, and human factors. The findings are expected to support the development of security-by-design approaches, inform procurement and regulatory frameworks, and guide the safe integration of connected medical devices into routine care.
Citation
Request queued. Please wait while the file is being generated. It may take some time.
Copyright
© The authors. All rights reserved. This is a privileged document currently under peer-review/community review (or an accepted/rejected manuscript). Authors have provided JMIR Publications with an exclusive license to publish this preprint on it's website for review and ahead-of-print citation purposes only. While the final peer-reviewed paper may be licensed under a cc-by license on publication, at this stage authors and publisher expressively prohibit redistribution of this draft paper other than for review purposes.