Question to the Department of Health and Social Care:
To ask the Secretary of State for Health and Social Care, how many cybersecurity vulnerabilities affecting medical devices have been reported to the Medicines and Healthcare products Regulatory Agency in each of the last three years.
The Medicines and Healthcare products Regulatory Agency (MHRA) is responsible for ensuring medicines, medical devices, and blood components for transfusion meet applicable standards of safety, quality, and efficacy. The MHRA rigorously assesses available data, including from the Yellow Card scheme, and seeks advice from their independent advisory committee, the Commission on Human Medicines, where appropriate to inform regulatory decisions.
The presence of a report on the adverse incident database does not necessarily demonstrate a causal relationship between the device and the event reported. The reported event may be attributable to patient, user, or other factors. As such, the data should not be regarded as a summary of confirmed adverse reactions to the device and should be interpreted with caution.
Adverse incidents are classified using the terminology developed by the International Medical Device Regulators Forum (IMDRF), with further information available at the following link:
This provides a standardised approach to coding information, including medical device malfunctions and patient or user outcomes. Annex A of the IMDRF coding system contains the codes used to describe medical device problems and malfunctions reported in adverse incident reports, with further information available at the following link:
https://www.imdrf.org/working-groups/adverse-event-terminology/annex-medical-device-problem
The following table shows the number of Yellow Card reports reporting IMDRF Annex A code A1105 – Computer System Security Problem in 2024, 2025, and 2026 until 14 July:
Year | Number of reports |
2024 | 2 |
2025 | 8 |
2026 | 3 |