No AI without security
Why cybersecurity is the key to AI applications in medical technology?
Author: Manne Kreuzer, Technical Writer at TQ-Group
An AI-powered surgical robot, an intelligent monitoring system, or connected imaging solutions can significantly improve clinical workflows today — as long as these systems function reliably. However, this is precisely where the greatest threat emerges: Across global healthcare systems, reports of critical IT disruptions and outages have increased significantly in recent years. At the same time, cybersecurity experts warn that ransomware attacks remain a persistent threat, with several major incidents occurring on a daily basis.
AI models are only as good as the data they are trained and operated on. This creates a fundamental challenge in medical technology: High-quality data is required for powerful applications such as automated patient monitoring or medication management. At the same time, healthcare data is particularly sensitive and must be protected accordingly.
AI in Medical Technology Requires Secure Data
Sebastian Peralta Friedburg, an expert in cybersecurity, AI, and software development at the technology company TQ, is deeply engaged with this challenge. The system provider for electronics engineering and manufacturing services employs more than 300 experienced developers who support manufacturers in embedding cybersecurity from the outset – securing systems across the entire stack, from embedded solutions and device software to cloud applications.
Peralta Friedburg explains: “For collected data to be suitable for training AI models, it must be representative, well-structured, and traceable.”
The use of unsuitable or flawed training data can lead to biased models and incorrect decisions — with potentially serious consequences for medical diagnoses or treatment processes. Equally critical is the question of who has access to this data and how that access is controlled. Without clear access regulations, the risk of manipulation, data breaches, or even targeted cyberattacks that compromise critical systems increases significantly.
The Three Core Objectives of Information Security
Data collection and processing in AI-based medical applications must therefore meet stringent requirements, which can be structured along the classic objectives of information security.
- Integrity: Data must remain accurate and protected against manipulation. Incorrect data can dangerously distort an AI system and lead to false predictions.
- Confidentiality: Access to patient data must be strictly controlled and secured. Sensitive information should only be accessible to authorized individuals and, wherever possible, be anonymized or pseudonymized.
- Availability: Data, services, and devices must be accessible at all times while being protected against outages, sabotage, and ransomware attacks.
Holistic Security Measures
From TQ’s perspective, ensuring secure data collection requires a combination of technical, organizational, and regulatory measures.
“We distinguish between three categories: technical, organizational, and regulatory. Only their effective interaction ensures true security,” explains Peralta Friedburg.
Technical foundations include end-to-end encryption for data transmission and storage, as well as pseudonymization or anonymization to make data usable for AI applications without exposing personal identities. Role-based access models and clearly defined responsibilities determine who can view or process specific data. Zero-trust approaches complement this by rigorously verifying every access request — regardless of the originating network, system, or user.
Interfaces are another critical aspect: When medical data is exchanged between systems, only standardized and secured APIs with clearly defined authentication and authorization mechanisms should be used. This is the only way to prevent insecure integrations or uncontrolled data leakage due to faulty implementations.
On the organizational side, audits, logs, and monitoring ensure traceability of data access and enable early detection of anomalies. Clearly defined access rights and role-based permission concepts are essential to ensure that sensitive information is only accessed or processed by authorized individuals.
Training for clinical and IT staff promotes secure handling of data and cyber risks. Incident response plans are equally important: They should not only be documented but also regularly tested to ensure that, in the event of an incident, systems can be isolated, damage contained, and operations restored in a structured manner.
A clear regulatory framework also exists, requiring “privacy and security by design.” In medical device regulation, IT security is increasingly becoming a mandatory component of connected medical products. The MDR and the IEC 81001-5-1 standard define specific cybersecurity requirements, while the GDPR establishes principles such as data minimization. Additional regulations include the Cyber Resilience Act (CRA) and — depending on the device type — the Radio Equipment Directive (RED). Manufacturers must therefore not only implement security measures but also document them comprehensively and maintain them throughout the entire product lifecycle.
Security by Design with DevSecOps
The pace of change is accelerating with the rise of AI: “Cyber threats are constantly evolving, more powerful AI models are emerging, and new regulatory requirements are being introduced,” warns the software expert. “This is why we at TQ follow a holistic approach based on the Secure Software Development Lifecycle.”
Specifically, the company uses a DevSecOps (Development, Security, Operations) framework. This is a continuous development and operations model that treats cybersecurity as an ongoing process rather than a one-time cycle. In practice, this means that security requirements are embedded early in architecture and design, security testing is automated within build and test pipelines, and operations are supported by vulnerability management, structured update processes, and continuous monitoring to ensure ongoing system improvement.
Why Early Security Pays Off
Beyond patient safety and compliance, there is another strong argument for “security early”: cost efficiency. The later vulnerabilities are identified and resolved, the more expensive it becomes – technically, organizationally, and in terms of regulatory approval.
This is where the “shift-left” principle comes into play. Security requirements, testing, and validation are moved forward into the early stages of development – integrated into architecture, design, and initial development phases rather than being addressed only before approval or during operation. This reduces risks, improves quality, prevents rework, and avoids unpleasant surprises during certification. As a result, time-to-market is reduced, even if planning and development initially require greater effort.
End-to-End Expertise at TQ
AI in medical applications offers enormous potential but also comes with demanding requirements in terms of security, computing performance, and regulatory compliance. To manage this complexity, partnering with experienced experts is essential.
TQ supports manufacturers throughout the entire product lifecycle – from requirements engineering and specification development to consulting workshops. Customers benefit from the company’s close interdisciplinary collaboration (cybersecurity, AI, software, etc.) and its 360-degree approach. This includes not only holistic development but also fully certified manufacturing, an accredited testing laboratory, and after-sales services such as obsolescence management for sustainable and resilient electronics.
“At TQ, we not only have the necessary capacity but also more than 30 years of experience and numerous successful medical projects, enabling us to develop secure systems in a highly demanding environment such as medical technology,” emphasizes Sebastian Peralta Friedburg.





