REVIEW 4 major objections 4 minor 31 references
Exploring Challenges and Opportunities in Cybersecurity Risk and Threat Communications Related To The Medical Internet Of Things (MIoT)
T0 review · 4 major / 4 minor · reviewed 2026-08-14 · deepseek-v4-flash
Pith's one-line read This paper claims that cybersecurity risk and threat communications for patients with cardiac implantable electronic devices are predominantly reactive, media-driven, and muted, leaving patients who depend on life-sustaining connected…
desk verdict A small qualitative case study with a genuinely useful topic, but its central claim rests on specialist self-reports rather than patient data, and the conclusion overstates it. read the letter →
The pith
A machine-rendered reading of the paper's core claim, the machinery that carries it, and where it could break.
The reading
What carries the argument
The carrying mechanism is a multiple case study built on thirty-minute semi-structured telephone interviews with sixteen purposively sampled U.S. cardiac device specialists, each with at least one year of experience with CIED patients using home monitoring systems. The data were analyzed with thematic analysis, a qualitative technique for identifying and organizing patterns in interview data: transcripts were coded, organized into patterns and categories, and recursively re-examined until five core themes emerged. The method works by treating the specialists' reports as evidence of actual communication practice, and the themes themselves constitute the study's findings rather than a formal statistical result.
What would settle it
Directly survey or interview a larger sample of CIED patients about where they first learned of device cybersecurity risks and whether their care team raised the topic proactively; if a substantial share report receiving structured, proactive cybersecurity counseling from providers or manufacturers, the paper's central portrait of media-driven, on-demand communication would fail.
Extended reading notes
Core claim
On the authors' own terms, the central discovery is that cybersecurity risk and threat communications for CIED patients are, in practice, muted and reactive. The study found that patients' most consistent first source of information about device cybersecurity is the media, not their care team or device manufacturer, and that the prevailing practice among specialists is to respond to patient concerns on demand. The rationale offered by participants is that no identified cybersecurity attack has harmed a CIED patient, so providers judge the risk too small to raise unprompted. The patient's recommended role, according to the same professionals, is to understand what their implanted device does, how and why it communicates, and to stay actively engaged in device-management decisions. These findings are presented as five themes derived from the interviews.
Load-bearing premise
The load-bearing premise is that the 16 specialists' accounts of their own communication practices accurately represent what CIED patients actually experience, since the study did not interview patients directly, observe consultations, or check medical records.
Editorial extensions
If this is right
- If cybersecurity communications are as reactive as described, then patients who are not already asking questions are unlikely to hear about device risks until a widely publicized incident occurs.
- Manufacturers' public-facing cybersecurity information is effectively reachable mainly by younger or technically informed patients, so reliance on websites is not equitable communication.
- Providers' risk/benefit reasoning means communication will remain muted unless evidence of actual harm to patients emerges or regulatory guidance requires proactive disclosure.
- Patient education materials and consent conversations should be redesigned around the finding that patients trust their cardiologist or electrophysiologist most, making those clinicians the key channel for cybersecurity messaging.
- The patient's role in MIoT cybersecurity is under-researched; this study's conclusion that patients must understand their device and stay engaged implies a need for structured patient curricula.
Reading between the lines
- An implication the authors leave implicit: if media is the primary trigger of patient concern, then the timing and framing of media coverage, not clinical risk statistics, may drive patient anxiety and demand, making cybersecurity risk communication a media-literacy problem as much as a medical one.
- A testable extension would compare CIED patients' self-reported awareness with their specialists' reports in the same clinics; mismatches would quantify how much the specialist-only design overstates or understates actual patient experience.
- The same reactive-communication pattern may hold for other MIoT cohorts such as insulin pump and neurostimulator users, all of whom face connected-device risks; a parallel study across device types could show whether cardiac patients are unusually protected or representative.
- Policymakers could use the five themes as a checklist for regulatory disclosure requirements: if proactive risk communication were mandated, the observed culture of non-communication would be directly testable by measuring changes in patient knowledge.
Signed reviews
Editorial analysis
A structured set of objections, weighed in public.
Referee Report
Summary. This paper presents a qualitative multiple-case study investigating how cybersecurity risks and threats related to wireless implantable cardiac devices are communicated to patients. The authors conducted semi-structured telephone interviews with sixteen cardiac device specialists in the United States and analyzed the transcripts using thematic analysis with NVivo. The analysis produced five themes: the influence of the media on patient cybersecurity awareness; the need for risk/benefit analysis at all levels of patient interaction; a culture of non-communication in healthcare and the medical device industry; the need for collaboration and education among manufacturers, providers, and patients; and obstacles across all phases of MIoT patient care. The paper's central claims are that patients' primary and most consistent source of cybersecurity information is the media and that provider communications are predominantly reactive and muted, with specialists responding to patient concerns on demand rather than proactively educating patients.
Significance. The topic is timely and important: patients with cardiac implantable electronic devices are a vulnerable population for whom cybersecurity threats can have life-threatening consequences, and there is little empirical research on how risk information reaches them. The study's strengths include a clearly stated research question, a purposively sampled expert population, a transparent description of the coding approach, and the use of qualitative software to organize the analysis. If the findings are valid, they highlight a significant practical gap in patient-facing cybersecurity communication. The contribution is, however, exploratory and limited by the single-source perspective of specialist self-reports; the paper would be substantially stronger if the conclusions were framed as specialists' perceptions rather than as direct evidence about patients' actual information sources and experiences.
major comments (4)
- [Sections 6 and 7] The conclusion states, 'It was found their primary and most consistent source of information came from the media,' and Section 6 similarly states that a patient's first source of information is the media. These are assertions about patients' actual behavior and experiences, but the data were collected exclusively from sixteen cardiac device specialists, not from patients. No patient interviews, direct observation, or medical records were used to triangulate these accounts. The claim may be valid, but as presented it overstates the evidentiary basis. The authors should either reframe the finding as 'specialists reported that patients' primary source of information is the media' or add patient-side data to support the stronger claim.
- [Section 5] The description of the thematic analysis is not sufficiently transparent to support the reported findings. The paper states that initial codes were derived directly from the research question and that 'choices were made as to which participant's input was delineative or depictive of a theme,' but it does not provide a codebook, theme definitions, participant quotations, or an audit trail. Table 2 is said to show 'exactly which case studies were used as the primary data sources for each theme,' but the actual table content is missing from the manuscript, as is the content of Table 1. Without direct quotes or a coding matrix, a reader cannot assess whether the five themes are grounded in the data or shaped by the researchers' discretionary choices. The authors should include the tables and add representative participant quotes illustrating each theme.
- [Section 6] The paper reports a 'consensus opinion' among participants that no harm has ever come to a CIED patient through cybersecurity threats, leading specialists to avoid proactive communication. This belief sits in tension with the paper's own earlier discussion of documented cybersecurity vulnerabilities in implantable devices (Section 3) and a high-profile FDA cybersecurity device recall (Section 4). The manuscript does not interrogate the accuracy of this belief or its implications for patient safety. At minimum, the authors should discuss whether specialists' risk perceptions align with the published literature and how a potentially inaccurate belief might affect the quality of risk communication.
- [Sections 4 and 7] The study design is a purposive sample of sixteen specialists with 30-minute phone interviews, which is appropriate for exploratory qualitative work, but the conclusions are generalizing beyond the data. The conclusion that 'MIoT patients have a significant role in their device cybersecurity' is presented as a confirmed finding even though the study did not collect data from MIoT patients. The authors should explicitly restrict claims to the experiences and perceptions of the participating specialists, and discuss transferability rather than generalizability throughout the paper.
minor comments (4)
- [Throughout] The manuscript contains numerous grammatical and typographical errors, including 'once a medical device whether it be standalone, wearable or implanted is has become networked,' 'It was found. However,' and 'An -other study opportunity.' A careful proofreading pass is needed.
- [References [23]-[31]] A substantial portion of the reference list consists of the second author's own prior work on cloud security and IoT topics that are only tangentially related to the interview findings. These citations should be trimmed or better integrated to avoid the appearance of citation padding.
- [Section 6, Figure 1] Figure 1 is described as a cluster analysis of the top 50 words within the five themes, but the text does not explain how the cluster analysis was performed or what the figure is intended to show. The figure is also not referenced in a way that helps the reader interpret the results.
- [Section 7.1] The future study section recommends 'research with MIoT patients as far as their lived experience,' which appropriately acknowledges the absence of patient perspectives in this study. This limitation, however, should be stated explicitly in the main body and discussion, not deferred to future work.
Circularity Check
No circular derivation: the thematic findings are grounded in interview data, and the self-citations are background references rather than load-bearing premises.
full rationale
The paper contains no mathematical derivation, parameter fitting, or first-principles prediction that could reduce to its own inputs. Its central claims—that CIED patients primarily receive cybersecurity information from the media and that provider communications are reactive and muted—are presented as thematic findings from sixteen semi-structured interviews with cardiac device specialists. The authors explicitly describe their analytic path: transcripts were coded, initial codes were derived from the research question, patterns were organized into themes, and choices were made about which participant contributions were delineative of each theme. This is a qualitative data-analysis process, not a circular derivation. The self-citations in references [23] through [31] are attached to general background statements about cloud computing, IoT, and cybersecurity; none of these citations supplies the interview findings or forbids alternative interpretations, so they are not load-bearing. The study's evidentiary weakness—relying on specialists' self-reports rather than patient interviews or direct observation—is a validity concern about how well the data support the conclusion, not a circularity concern under the definitions used here. No step in the paper's argument is equivalent by construction to its inputs, and no fitted parameter is renamed as a prediction. Therefore the circularity score is 0.
Assumptions & free parameters
assumptions (3)
- domain assumption The self-reported perceptions of 16 cardiac device specialists accurately reflect the actual cybersecurity risk communications delivered to CIED patients.
- domain assumption Purposive sampling produced a representative set of expert perspectives on the target population.
- ad hoc to paper The researchers' thematic analysis coding choices, including decisions about which participant contributions were 'delineative' of a theme, are valid and reliable.
Cite this review
Pith. "Pith review of Exploring Challenges and Opportunities in Cybersecurity Risk and Threat Communications Related To The Medical Internet Of Things (MIoT)." pith.science (2026). https://pith.science/paper/4FXL4V22
@misc{pith2026190800666,
author = {Pith},
title = {Pith review of: Exploring Challenges and Opportunities in Cybersecurity Risk and Threat Communications Related To The Medical Internet Of Things (MIoT)},
year = {2026},
howpublished = {\url{https://pith.science/paper/4FXL4V22}},
note = {Machine review of arXiv:1908.00666}
}
read the original abstract
As device interconnectivity and ubiquitous computing continues to proliferate healthcare, the Medical Internet of Things (MIoT), also well known as the, Internet of Medical Things (IoMT) or the Internet of Healthcare Things (IoHT), is certain to play a major role in the health, and well-being of billions of people across the globe. When it comes to issues of cybersecurity risks and threats connected to the IoT in all of its various flavors the emphasis has been on technical challenges and technical solution. However, especially in the area of healthcare there is another substantial and potentially grave challenge. It is the challenge of thoroughly and accurately communicating the nature and extent of cybersecurity risks and threats to patients who are reliant upon these interconnected healthcare technologies to improve and even preserve their lives. This case study was conducted to assess the scope and depth of cybersecurity risk and threat communications delivered to an extremely vulnerable patient population, semi-structured interviews were held with cardiac medical device specialists across the United States. This research contributes scientific data in the field of healthcare cybersecurity and assists scholars and practitioners in advancing education and research in the field of MIoT patient communications.
Figures
Reference graph
Works this paper leans on
-
[1]
Ankarali, Z., Abbasi, Q. H., Demir, A. F., Serpedin, E., Qaraqe, K., & Arslan, H. (2014). A comparative review on the wireless implantable medical devices privacy and security. Proceedings of the 4th International Conference on Wireless Mobile Communication and Healthcare, 246 -249
work page 2014
-
[2]
Fu, K. (2009). Inside risks: Reducing risks of implantable medical devices. Communications of the ACM, 52(6), 25–27
work page 2009
-
[3]
Fu, K., & Blum, J. (2013). Controlling for cybersecurity risks of medical device software. Communications of the ACM, 56(10), 35–37
work page 2013
-
[4]
Gupta, S. (2012). Implantable Medical Devices -Cyber Risks and Mitigation Approaches. In Proceedings of the Cybersecurity in Cyber -Physical Work -shop, The National Institute of Standards and Technology (NIST)
work page 2012
-
[5]
Murphy, S. (2015). Is cyber securit y possible in healthcare? National Cyber -security Institute Journal, 1(3) 49-63 International Journal of Network Security & Its Applications (IJNSA) Vol. 11, No.4, July 2019 85
work page 2015
-
[6]
Burns, A. J., Johnson, M. E., & Honeyman, P. (2016). A brief chronology of medical device security. Communications of the ACM, 59(10), 66–72. https://doi.org/10.1145/2890488
-
[7]
Garfinkel, S. L. (2012). The cybersecurity risk. Communications of the ACM, 55(6), 29 –32
work page 2012
-
[8]
Williams, P. A., & Woodward, A. J. (2015). Cybersecurity vulnerabilities in medical devices: A complex environment and multifaceted problem. Medical Dev ices: Evidence and Research, 8, 305 - 316
work page 2015
Show all 31 references
-
[9]
Sun, W., Cai, Z., Li, Y., Liu, F., Fang, S., & Wang, G. (2018). Security and privacy in the medical Internet of Things: A review. Security and Communication Networks, 2018
2018
-
[10]
J., Segundo, D
Rodrigues, J. J., Segundo, D. B. D. R., Junqueira, H. A., Sabino, M. H., Prince, R. M., Al -Muhtadi, J., & De Albuquerque, V. H. C. (2018). Enabling Technologies for the Internet of Health Things. IEEE Access, 6, 13129-13141
2018
-
[11]
Kotz, D. (2011). A threat taxonomy for mHealth privacy. Proceedings of Third International Conference on Communication Systems and Network (COMSNETS), (pp. 1 -6)
2011
-
[12]
Sametinger, J., Rozenblit, J., Lysecky, R., & Ott, P. (2015). Security challenges for medical devices. Communications of the ACM, 58(4), 74–82
2015
-
[13]
T., Kohno, T., & Maisel, W
Denning, T., Borning, A., Friedman, B., Gill, B. T., Kohno, T., & Maisel, W. H. (2010). Patients, pacemakers, and implantable defibrillators: Human values and security for wireless implantable medical devices. Proceedings of the SIGCHI Conference on Human Factors in Computing ...
2010
-
[14]
Ray, A., Jones, P., & Zhang, Y. (2013). Medical device security -a new frontier. Biomedical Instrumentation & Technology, 47(1, Suppl), 72–72
2013
-
[15]
Camara, C., Peris -Lopez, P., & Tapiador, J. E. (2015). Security and privacy issues in implantable medical devices: A comprehensive survey. Journal of Biomedical Informatics, 55, 272 –289
2015
-
[16]
Hollis, D. B. (2011). An e-SOS for cyberspace. Harvard International Law Journal, 52(2), 374–432
2011
-
[17]
Braun, V., & Clarke, V. (2017). Thematic analysis. The Journal of Positive Psychology, 12(3), 297 – 298
2017
-
[18]
Braun, V., & Clarke, V. (2006). Using thematic analysis in psychology. Qualitative Research in Psychology, 3(2), 77–101
2006
-
[19]
Sarma, S. K. (2015). Qualitative research: Examining the misconceptions. South Asian Journal of Management, 22(3), 176–191
2015
-
[20]
Orcher, L. T. (2005). Conducting Research: Social and Behavioral Science Methods. Glendale, CA: Pyrczak Publishing
2005
-
[21]
Rybak, K. (2017). Active cardiac implantable electronic devices: What is possible in ambulatory health care in 2017? Herzschrittmachertherapie El-ektrophysiologie,28(3), 279-286
2017
-
[22]
Vaismoradi, M., Jones, J., Turunen, H., & Snelgrov e, S. (2016). Theme devel -opment in qualitative content analysis and thematic analysis. Journal of Nursing Education and Practice, 6(5)
2016
-
[23]
7, no.1, 2019, Pages: 1 -14 International Journal of Network Security & Its Applications (IJNSA) Vol
Faizi, Salman and Rahman, Shawon;” Securing Cloud Computing Through IT Governance”; International Journal of Information Technology in Industry (ITII), vol. 7, no.1, 2019, Pages: 1 -14 International Journal of Network Security & Its Applications (IJNSA) Vol. 11, No.4, July 2019 86
2019
-
[24]
Exploring Facets of Trust in Older Adult Decisions to Adopt Mobile Commerce
Morga, John and Rahman, Shawon; “Exploring Facets of Trust in Older Adult Decisions to Adopt Mobile Commerce”; International Journal of Engineering and Technology (IJET), 7 (4) (2 018) 4954- 4961, doi: 10.14419/ijet.v7i4.20658
-
[25]
Towards Cloud of Things from Internet of Things
Dharmalingam, Vaishnavi and Rahman, Shawon; “Towards Cloud of Things from Internet of Things”; International Journal of Engineering and Technology, Vol. 7, No 4.6, 2018, Pages: 112 -116,
2018
-
[26]
The Effect of Information Technology using Enterprise Security Risk Management
Adekanye, Michael and Rahman, Shawon “The Effect of Information Technology using Enterprise Security Risk Management ”; International Journal of Network Security & Its Applications (IJNSA), Vol. 10, No.5, September 2018
2018
-
[27]
Enhancing and Measuring the Performance in Software Defined Networking
Hossain, Md; Sheikh, Nowsin; Rahman, S hawon; Biswas, Sujan and Islam, Md “Enhancing and Measuring the Performance in Software Defined Networking”; International Journal of Computer Networks & Communications (IJCNC), Vol.10, No.5, September 2018
2018
-
[28]
Discove ring New Cyber Protection Approaches From a Security Professional Prospective
Loukaka, Alain and Rahman, Shawon; “Discove ring New Cyber Protection Approaches From a Security Professional Prospective”; International Journal of Computer Networks & Communications (IJCNC) Vol.9, No.4, July 2017,
2017
-
[29]
Security Analysis of AES and Enhancing its Security by Modifying S-Box with an Additional Byte
Al-Mamun, Abdullah, Rahman, Shawon and et al;“ Security Analysis of AES and Enhancing its Security by Modifying S-Box with an Additional Byte ”; International Journal of Computer Networks & Communications (IJCNC), Vol.9, No.2, March 2017
2017
-
[30]
The Influence of In formation Security on the Adoption of Cloud computing: An Exploratory Analysis
Opala, Omondi John; Rahman, Shawon; and Alelaiwi, Abdulhameed; “The Influence of In formation Security on the Adoption of Cloud computing: An Exploratory Analysis”, International Journal of Computer Networks & Communications (IJCNC), Vol.7, No.4, July 2015
2015
-
[31]
The Top 10 Best Cloud -Security Pr actices in Next - Generation Networking
Halton, Michael and Rahman, Syed (Shawon); "The Top 10 Best Cloud -Security Pr actices in Next - Generation Networking"; International Journal of Communication Networks and Distributed Systems (IJCNDS); Special Issue on: "Recent Advances in Next -Generation and Resource -Const...
2012
Reviewed August 14, 2026 · model on record in the stance chip above.
Discussion (0). Continue with ORCID to comment.