Pith. sign in

REVIEW 4 major objections 4 minor 31 references

Exploring Challenges and Opportunities in Cybersecurity Risk and Threat Communications Related To The Medical Internet Of Things (MIoT)

T0 review · 4 major / 4 minor · reviewed 2026-08-14 · deepseek-v4-flash

Pith's one-line read This paper claims that cybersecurity risk and threat communications for patients with cardiac implantable electronic devices are predominantly reactive, media-driven, and muted, leaving patients who depend on life-sustaining connected…

desk verdict A small qualitative case study with a genuinely useful topic, but its central claim rests on specialist self-reports rather than patient data, and the conclusion overstates it. read the letter →

arxiv 1908.00666 v1 pith:4FXL4V22 submitted 2019-08-02 cs.CY cs.CR

classification cs.CYcs.CR
keywords MedicalInternetofThingscybersecurityriskcommunicationcardiacimplantableelectronicdevicespatientawarenessthematicanalysiswirelessmediainfluence
verification ladder T0 review T1 audit T2 compute T3 formal

The pith

A machine-rendered reading of the paper's core claim, the machinery that carries it, and where it could break.

The reading

This paper reports a qualitative case study of how cybersecurity risks and threats are communicated to patients who depend on cardiac implantable electronic devices (CIEDs) such as pacemakers and defibrillators with home monitoring. Based on semi-structured interviews with sixteen U.S. cardiac device specialists, the authors argue that patient cybersecurity awareness is shaped mainly by the media, and that healthcare providers and device manufacturers communicate about device cybersecurity only reactively, responding to patient concerns on demand rather than initiating discussion. They identify five recurring themes: media influence on patient awareness; a need for risk/benefit analysis at every level of patient interaction; a culture of non-communication in healthcare and the device industry; a need for collaboration and education among manufacturers, providers, and patients; and obstacles across all phases of MIoT care. The importance of the claim, if true, is that patients with life-sustaining connected implants are making decisions without reliable, proactively delivered information about the security of the devices inside their bodies.

What carries the argument

The carrying mechanism is a multiple case study built on thirty-minute semi-structured telephone interviews with sixteen purposively sampled U.S. cardiac device specialists, each with at least one year of experience with CIED patients using home monitoring systems. The data were analyzed with thematic analysis, a qualitative technique for identifying and organizing patterns in interview data: transcripts were coded, organized into patterns and categories, and recursively re-examined until five core themes emerged. The method works by treating the specialists' reports as evidence of actual communication practice, and the themes themselves constitute the study's findings rather than a formal statistical result.

What would settle it

Directly survey or interview a larger sample of CIED patients about where they first learned of device cybersecurity risks and whether their care team raised the topic proactively; if a substantial share report receiving structured, proactive cybersecurity counseling from providers or manufacturers, the paper's central portrait of media-driven, on-demand communication would fail.

Watch

Extended reading notes

Core claim

On the authors' own terms, the central discovery is that cybersecurity risk and threat communications for CIED patients are, in practice, muted and reactive. The study found that patients' most consistent first source of information about device cybersecurity is the media, not their care team or device manufacturer, and that the prevailing practice among specialists is to respond to patient concerns on demand. The rationale offered by participants is that no identified cybersecurity attack has harmed a CIED patient, so providers judge the risk too small to raise unprompted. The patient's recommended role, according to the same professionals, is to understand what their implanted device does, how and why it communicates, and to stay actively engaged in device-management decisions. These findings are presented as five themes derived from the interviews.

Load-bearing premise

The load-bearing premise is that the 16 specialists' accounts of their own communication practices accurately represent what CIED patients actually experience, since the study did not interview patients directly, observe consultations, or check medical records.

Editorial extensions

If this is right

  • If cybersecurity communications are as reactive as described, then patients who are not already asking questions are unlikely to hear about device risks until a widely publicized incident occurs.
  • Manufacturers' public-facing cybersecurity information is effectively reachable mainly by younger or technically informed patients, so reliance on websites is not equitable communication.
  • Providers' risk/benefit reasoning means communication will remain muted unless evidence of actual harm to patients emerges or regulatory guidance requires proactive disclosure.
  • Patient education materials and consent conversations should be redesigned around the finding that patients trust their cardiologist or electrophysiologist most, making those clinicians the key channel for cybersecurity messaging.
  • The patient's role in MIoT cybersecurity is under-researched; this study's conclusion that patients must understand their device and stay engaged implies a need for structured patient curricula.

Reading between the lines

Editorial extensions of the paper, not claims the author makes directly.

  • An implication the authors leave implicit: if media is the primary trigger of patient concern, then the timing and framing of media coverage, not clinical risk statistics, may drive patient anxiety and demand, making cybersecurity risk communication a media-literacy problem as much as a medical one.
  • A testable extension would compare CIED patients' self-reported awareness with their specialists' reports in the same clinics; mismatches would quantify how much the specialist-only design overstates or understates actual patient experience.
  • The same reactive-communication pattern may hold for other MIoT cohorts such as insulin pump and neurostimulator users, all of whom face connected-device risks; a parallel study across device types could show whether cardiac patients are unusually protected or representative.
  • Policymakers could use the five themes as a checklist for regulatory disclosure requirements: if proactive risk communication were mandated, the observed culture of non-communication would be directly testable by measuring changes in patient knowledge.
Share X Bluesky LinkedIn Reddit HN

Signed reviews

No signed human review yet.

Editorial analysis

A structured set of objections, weighed in public.

Desk editor's note, referee report, and a circularity audit.

Referee Report

4 major / 4 minor

Summary. This paper presents a qualitative multiple-case study investigating how cybersecurity risks and threats related to wireless implantable cardiac devices are communicated to patients. The authors conducted semi-structured telephone interviews with sixteen cardiac device specialists in the United States and analyzed the transcripts using thematic analysis with NVivo. The analysis produced five themes: the influence of the media on patient cybersecurity awareness; the need for risk/benefit analysis at all levels of patient interaction; a culture of non-communication in healthcare and the medical device industry; the need for collaboration and education among manufacturers, providers, and patients; and obstacles across all phases of MIoT patient care. The paper's central claims are that patients' primary and most consistent source of cybersecurity information is the media and that provider communications are predominantly reactive and muted, with specialists responding to patient concerns on demand rather than proactively educating patients.

Significance. The topic is timely and important: patients with cardiac implantable electronic devices are a vulnerable population for whom cybersecurity threats can have life-threatening consequences, and there is little empirical research on how risk information reaches them. The study's strengths include a clearly stated research question, a purposively sampled expert population, a transparent description of the coding approach, and the use of qualitative software to organize the analysis. If the findings are valid, they highlight a significant practical gap in patient-facing cybersecurity communication. The contribution is, however, exploratory and limited by the single-source perspective of specialist self-reports; the paper would be substantially stronger if the conclusions were framed as specialists' perceptions rather than as direct evidence about patients' actual information sources and experiences.

major comments (4)
  1. [Sections 6 and 7] The conclusion states, 'It was found their primary and most consistent source of information came from the media,' and Section 6 similarly states that a patient's first source of information is the media. These are assertions about patients' actual behavior and experiences, but the data were collected exclusively from sixteen cardiac device specialists, not from patients. No patient interviews, direct observation, or medical records were used to triangulate these accounts. The claim may be valid, but as presented it overstates the evidentiary basis. The authors should either reframe the finding as 'specialists reported that patients' primary source of information is the media' or add patient-side data to support the stronger claim.
  2. [Section 5] The description of the thematic analysis is not sufficiently transparent to support the reported findings. The paper states that initial codes were derived directly from the research question and that 'choices were made as to which participant's input was delineative or depictive of a theme,' but it does not provide a codebook, theme definitions, participant quotations, or an audit trail. Table 2 is said to show 'exactly which case studies were used as the primary data sources for each theme,' but the actual table content is missing from the manuscript, as is the content of Table 1. Without direct quotes or a coding matrix, a reader cannot assess whether the five themes are grounded in the data or shaped by the researchers' discretionary choices. The authors should include the tables and add representative participant quotes illustrating each theme.
  3. [Section 6] The paper reports a 'consensus opinion' among participants that no harm has ever come to a CIED patient through cybersecurity threats, leading specialists to avoid proactive communication. This belief sits in tension with the paper's own earlier discussion of documented cybersecurity vulnerabilities in implantable devices (Section 3) and a high-profile FDA cybersecurity device recall (Section 4). The manuscript does not interrogate the accuracy of this belief or its implications for patient safety. At minimum, the authors should discuss whether specialists' risk perceptions align with the published literature and how a potentially inaccurate belief might affect the quality of risk communication.
  4. [Sections 4 and 7] The study design is a purposive sample of sixteen specialists with 30-minute phone interviews, which is appropriate for exploratory qualitative work, but the conclusions are generalizing beyond the data. The conclusion that 'MIoT patients have a significant role in their device cybersecurity' is presented as a confirmed finding even though the study did not collect data from MIoT patients. The authors should explicitly restrict claims to the experiences and perceptions of the participating specialists, and discuss transferability rather than generalizability throughout the paper.
minor comments (4)
  1. [Throughout] The manuscript contains numerous grammatical and typographical errors, including 'once a medical device whether it be standalone, wearable or implanted is has become networked,' 'It was found. However,' and 'An -other study opportunity.' A careful proofreading pass is needed.
  2. [References [23]-[31]] A substantial portion of the reference list consists of the second author's own prior work on cloud security and IoT topics that are only tangentially related to the interview findings. These citations should be trimmed or better integrated to avoid the appearance of citation padding.
  3. [Section 6, Figure 1] Figure 1 is described as a cluster analysis of the top 50 words within the five themes, but the text does not explain how the cluster analysis was performed or what the figure is intended to show. The figure is also not referenced in a way that helps the reader interpret the results.
  4. [Section 7.1] The future study section recommends 'research with MIoT patients as far as their lived experience,' which appropriately acknowledges the absence of patient perspectives in this study. This limitation, however, should be stated explicitly in the main body and discussion, not deferred to future work.

Circularity Check

0 steps flagged · score 0.0 of 10

No circular derivation: the thematic findings are grounded in interview data, and the self-citations are background references rather than load-bearing premises.

full rationale

The paper contains no mathematical derivation, parameter fitting, or first-principles prediction that could reduce to its own inputs. Its central claims—that CIED patients primarily receive cybersecurity information from the media and that provider communications are reactive and muted—are presented as thematic findings from sixteen semi-structured interviews with cardiac device specialists. The authors explicitly describe their analytic path: transcripts were coded, initial codes were derived from the research question, patterns were organized into themes, and choices were made about which participant contributions were delineative of each theme. This is a qualitative data-analysis process, not a circular derivation. The self-citations in references [23] through [31] are attached to general background statements about cloud computing, IoT, and cybersecurity; none of these citations supplies the interview findings or forbids alternative interpretations, so they are not load-bearing. The study's evidentiary weakness—relying on specialists' self-reports rather than patient interviews or direct observation—is a validity concern about how well the data support the conclusion, not a circularity concern under the definitions used here. No step in the paper's argument is equivalent by construction to its inputs, and no fitted parameter is renamed as a prediction. Therefore the circularity score is 0.

Assumptions & free parameters 0 free parameters · 3 assumptions · 0 invented entities

The paper introduces no new entities, particles, forces, or formal constructs. Its axioms are standard qualitative research assumptions about participant truthfulness, sampling representativeness, and coding validity.

assumptions (3)
  • domain assumption The self-reported perceptions of 16 cardiac device specialists accurately reflect the actual cybersecurity risk communications delivered to CIED patients.
    The study's research question is about what patients are told, but data collection asks specialists, not patients. The validity of the findings depends on this proxy being accurate. Introduced in Sections 3 and 4.
  • domain assumption Purposive sampling produced a representative set of expert perspectives on the target population.
    Section 4 states purposive sampling was used to ensure participants mirrored the target population, but no evidence is provided that these 16 specialists are representative of all US cardiac device specialists.
  • ad hoc to paper The researchers' thematic analysis coding choices, including decisions about which participant contributions were 'delineative' of a theme, are valid and reliable.
    Section 5 acknowledges that 'at the level of theming, choices were made as to which participant's input was delineative or depictive of a theme.' There is no inter-rater reliability check or audit trail.

how reviews work

0 comments
Cite this review

Pith. "Pith review of Exploring Challenges and Opportunities in Cybersecurity Risk and Threat Communications Related To The Medical Internet Of Things (MIoT)." pith.science (2026). https://pith.science/paper/4FXL4V22

@misc{pith2026190800666,
  author       = {Pith},
  title        = {Pith review of: Exploring Challenges and Opportunities in Cybersecurity Risk and Threat Communications Related To The Medical Internet Of Things (MIoT)},
  year         = {2026},
  howpublished = {\url{https://pith.science/paper/4FXL4V22}},
  note         = {Machine review of arXiv:1908.00666}
}
read the original abstract

As device interconnectivity and ubiquitous computing continues to proliferate healthcare, the Medical Internet of Things (MIoT), also well known as the, Internet of Medical Things (IoMT) or the Internet of Healthcare Things (IoHT), is certain to play a major role in the health, and well-being of billions of people across the globe. When it comes to issues of cybersecurity risks and threats connected to the IoT in all of its various flavors the emphasis has been on technical challenges and technical solution. However, especially in the area of healthcare there is another substantial and potentially grave challenge. It is the challenge of thoroughly and accurately communicating the nature and extent of cybersecurity risks and threats to patients who are reliant upon these interconnected healthcare technologies to improve and even preserve their lives. This case study was conducted to assess the scope and depth of cybersecurity risk and threat communications delivered to an extremely vulnerable patient population, semi-structured interviews were held with cardiac medical device specialists across the United States. This research contributes scientific data in the field of healthcare cybersecurity and assists scholars and practitioners in advancing education and research in the field of MIoT patient communications.

Figures

Figures reproduced from arXiv: 1908.00666 by the authors.

Figure 1
Figure 1. Cluster analysis of the top 50 words within the five thematic analysis themes. [PITH_FULL_IMAGE:figures/full_fig_p008_1.png] view at source ↗

Discussion (0). Continue with ORCID to comment.

Reference graph

Works this paper leans on

31 extracted references · 30 canonical work pages

  1. [1]

    H., Demir, A

    Ankarali, Z., Abbasi, Q. H., Demir, A. F., Serpedin, E., Qaraqe, K., & Arslan, H. (2014). A comparative review on the wireless implantable medical devices privacy and security. Proceedings of the 4th International Conference on Wireless Mobile Communication and Healthcare, 246 -249

  2. [2]

    Fu, K. (2009). Inside risks: Reducing risks of implantable medical devices. Communications of the ACM, 52(6), 25–27

  3. [3]

    Fu, K., & Blum, J. (2013). Controlling for cybersecurity risks of medical device software. Communications of the ACM, 56(10), 35–37

  4. [4]

    Gupta, S. (2012). Implantable Medical Devices -Cyber Risks and Mitigation Approaches. In Proceedings of the Cybersecurity in Cyber -Physical Work -shop, The National Institute of Standards and Technology (NIST)

  5. [5]

    Murphy, S. (2015). Is cyber securit y possible in healthcare? National Cyber -security Institute Journal, 1(3) 49-63 International Journal of Network Security & Its Applications (IJNSA) Vol. 11, No.4, July 2019 85

  6. [6]

    J., Johnson, M

    Burns, A. J., Johnson, M. E., & Honeyman, P. (2016). A brief chronology of medical device security. Communications of the ACM, 59(10), 66–72. https://doi.org/10.1145/2890488

  7. [7]

    Garfinkel, S. L. (2012). The cybersecurity risk. Communications of the ACM, 55(6), 29 –32

  8. [8]

    A., & Woodward, A

    Williams, P. A., & Woodward, A. J. (2015). Cybersecurity vulnerabilities in medical devices: A complex environment and multifaceted problem. Medical Dev ices: Evidence and Research, 8, 305 - 316

Show all 31 references
  1. [9]

    Sun, W., Cai, Z., Li, Y., Liu, F., Fang, S., & Wang, G. (2018). Security and privacy in the medical Internet of Things: A review. Security and Communication Networks, 2018

  2. [10]

    J., Segundo, D

    Rodrigues, J. J., Segundo, D. B. D. R., Junqueira, H. A., Sabino, M. H., Prince, R. M., Al -Muhtadi, J., & De Albuquerque, V. H. C. (2018). Enabling Technologies for the Internet of Health Things. IEEE Access, 6, 13129-13141

  3. [11]

    Kotz, D. (2011). A threat taxonomy for mHealth privacy. Proceedings of Third International Conference on Communication Systems and Network (COMSNETS), (pp. 1 -6)

  4. [12]

    Sametinger, J., Rozenblit, J., Lysecky, R., & Ott, P. (2015). Security challenges for medical devices. Communications of the ACM, 58(4), 74–82

  5. [13]

    T., Kohno, T., & Maisel, W

    Denning, T., Borning, A., Friedman, B., Gill, B. T., Kohno, T., & Maisel, W. H. (2010). Patients, pacemakers, and implantable defibrillators: Human values and security for wireless implantable medical devices. Proceedings of the SIGCHI Conference on Human Factors in Computing ...

  6. [14]

    Ray, A., Jones, P., & Zhang, Y. (2013). Medical device security -a new frontier. Biomedical Instrumentation & Technology, 47(1, Suppl), 72–72

  7. [15]

    Camara, C., Peris -Lopez, P., & Tapiador, J. E. (2015). Security and privacy issues in implantable medical devices: A comprehensive survey. Journal of Biomedical Informatics, 55, 272 –289

  8. [16]

    Hollis, D. B. (2011). An e-SOS for cyberspace. Harvard International Law Journal, 52(2), 374–432

  9. [17]

    Braun, V., & Clarke, V. (2017). Thematic analysis. The Journal of Positive Psychology, 12(3), 297 – 298

  10. [18]

    Braun, V., & Clarke, V. (2006). Using thematic analysis in psychology. Qualitative Research in Psychology, 3(2), 77–101

  11. [19]

    Sarma, S. K. (2015). Qualitative research: Examining the misconceptions. South Asian Journal of Management, 22(3), 176–191

  12. [20]

    Orcher, L. T. (2005). Conducting Research: Social and Behavioral Science Methods. Glendale, CA: Pyrczak Publishing

  13. [21]

    Rybak, K. (2017). Active cardiac implantable electronic devices: What is possible in ambulatory health care in 2017? Herzschrittmachertherapie El-ektrophysiologie,28(3), 279-286

  14. [22]

    Vaismoradi, M., Jones, J., Turunen, H., & Snelgrov e, S. (2016). Theme devel -opment in qualitative content analysis and thematic analysis. Journal of Nursing Education and Practice, 6(5)

  15. [23]

    7, no.1, 2019, Pages: 1 -14 International Journal of Network Security & Its Applications (IJNSA) Vol

    Faizi, Salman and Rahman, Shawon;” Securing Cloud Computing Through IT Governance”; International Journal of Information Technology in Industry (ITII), vol. 7, no.1, 2019, Pages: 1 -14 International Journal of Network Security & Its Applications (IJNSA) Vol. 11, No.4, July 2019 86

  16. [24]

    Exploring Facets of Trust in Older Adult Decisions to Adopt Mobile Commerce

    Morga, John and Rahman, Shawon; “Exploring Facets of Trust in Older Adult Decisions to Adopt Mobile Commerce”; International Journal of Engineering and Technology (IJET), 7 (4) (2 018) 4954- 4961, doi: 10.14419/ijet.v7i4.20658

  17. [25]

    Towards Cloud of Things from Internet of Things

    Dharmalingam, Vaishnavi and Rahman, Shawon; “Towards Cloud of Things from Internet of Things”; International Journal of Engineering and Technology, Vol. 7, No 4.6, 2018, Pages: 112 -116,

  18. [26]

    The Effect of Information Technology using Enterprise Security Risk Management

    Adekanye, Michael and Rahman, Shawon “The Effect of Information Technology using Enterprise Security Risk Management ”; International Journal of Network Security & Its Applications (IJNSA), Vol. 10, No.5, September 2018

  19. [27]

    Enhancing and Measuring the Performance in Software Defined Networking

    Hossain, Md; Sheikh, Nowsin; Rahman, S hawon; Biswas, Sujan and Islam, Md “Enhancing and Measuring the Performance in Software Defined Networking”; International Journal of Computer Networks & Communications (IJCNC), Vol.10, No.5, September 2018

  20. [28]

    Discove ring New Cyber Protection Approaches From a Security Professional Prospective

    Loukaka, Alain and Rahman, Shawon; “Discove ring New Cyber Protection Approaches From a Security Professional Prospective”; International Journal of Computer Networks & Communications (IJCNC) Vol.9, No.4, July 2017,

  21. [29]

    Security Analysis of AES and Enhancing its Security by Modifying S-Box with an Additional Byte

    Al-Mamun, Abdullah, Rahman, Shawon and et al;“ Security Analysis of AES and Enhancing its Security by Modifying S-Box with an Additional Byte ”; International Journal of Computer Networks & Communications (IJCNC), Vol.9, No.2, March 2017

  22. [30]

    The Influence of In formation Security on the Adoption of Cloud computing: An Exploratory Analysis

    Opala, Omondi John; Rahman, Shawon; and Alelaiwi, Abdulhameed; “The Influence of In formation Security on the Adoption of Cloud computing: An Exploratory Analysis”, International Journal of Computer Networks & Communications (IJCNC), Vol.7, No.4, July 2015

  23. [31]

    The Top 10 Best Cloud -Security Pr actices in Next - Generation Networking

    Halton, Michael and Rahman, Syed (Shawon); "The Top 10 Best Cloud -Security Pr actices in Next - Generation Networking"; International Journal of Communication Networks and Distributed Systems (IJCNDS); Special Issue on: "Recent Advances in Next -Generation and Resource -Const...

Pith tools

Reviewed August 14, 2026 · model on record in the stance chip above.