Beyond Clinical Risk: An Experimental Study of Cybersecurity Informed Consent and Patient Choice for Connected Medical Devices
Authors
Paper Title
Beyond Clinical Risk: An Experimental Study of Cybersecurity Informed Consent and Patient Choice for Connected Medical Devices
Publication Info
- Topic area: Cybersecurity-informed consent and patient decision-making for connected medical devices.
- Keywords: Cybersecurity, informed consent, connected medical devices, patient decision-making, risk communication, trust, vulnerability disclosure, healthcare, human-computer interaction, medical ethics.
Background and Problem
- Problem / challenge: Internet-connected medical devices introduce cybersecurity risks that are difficult for patients and providers to evaluate. Current informed consent practices do not adequately address these risks, leaving patients ill-equipped to make informed decisions.
- Significance: Understanding how patients weigh cybersecurity risks against clinical benefits is critical for improving informed consent processes and ensuring patient safety in the era of connected healthcare technologies.
- Motivation and related work: Prior research has identified the need for "cybersecurity informed consent" but lacks empirical data on how patients perceive and act on cybersecurity risks. Existing studies focus on usability and risk communication but do not address the unique challenges of medical device security in high-stakes contexts.
Solution
- Proposed approach: A large-scale (N=2,666) vignette-based experiment to study patient decision-making when choosing between connected and non-connected pacemakers, with systematic variations in risk communication factors.
- Novelty:
- Empirical investigation of how patients weigh cybersecurity risks versus clinical benefits.
- Analysis of the impact of risk framing, information source, and vulnerability disclosures on patient choices.
- Identification of internal patient attributes (e.g., trust in physicians) as key decision drivers.
- Evidence that detailed vulnerability disclosures can enhance patient confidence.
- Procedure and key techniques:
- Participants were presented with a scenario requiring them to choose between a connected and non-connected pacemaker.
- Risk communication factors (e.g., source, framing, verbosity) were systematically varied.
- A second phase introduced a vulnerability disclosure, allowing participants to re-evaluate their initial choice.
- Bayesian ordinal regression models and qualitative coding were used to analyze decision-making and confidence.
Results
- Concrete findings:
- 66% of participants initially preferred the connected device.
- Framing risks as physical safety threats reduced the likelihood of choosing the connected device (59.9% vs. 74.5% for data privacy risks).
- Initial choices strongly anchored subsequent decisions, with 82.1% of participants who initially rejected the connected device opting to disable connectivity after a vulnerability disclosure.
- Detailed, verbose disclosures from the FDA increased security confidence, while verbose manufacturer disclosures improved clinical confidence.
- Advantage over baselines:
- Internal attributes like physician trust were stronger predictors of choice than external factors like the information source.
- Detailed disclosures enhanced confidence without causing alarm, countering assumptions that transparency might erode trust.
- Experiments / evaluation:
- Participants were recruited via Prolific with a census-balanced sample of 2,666 U.S. adults.
- Key variables included information source (provider, FDA, manufacturer), risk framing (data privacy vs. physical safety), and verbosity of disclosures.
- Bayesian modeling and qualitative coding were used to analyze decision-making and confidence.
- Limitations and future work:
- Hypothetical scenarios may not fully capture real-world decision-making.
- Focused on pacemakers; results may not generalize to other devices.
- Future research should include longitudinal studies, real-world clinical settings, and exploration of scalable risk communication strategies.
Summary
This study provides empirical insights into how patients weigh cybersecurity risks against clinical benefits when deciding on connected medical devices. Key findings highlight the importance of physician trust, the impact of risk framing (e.g., physical safety vs. data privacy), and the anchoring effect of initial decisions. Detailed vulnerability disclosures were found to increase patient confidence, particularly when issued by trusted entities like the FDA. These results suggest that improving cybersecurity-informed consent requires leveraging patient-provider trust, framing risks effectively, and embracing transparency in risk communication. Future research should explore real-world applications, longitudinal effects, and strategies to address systemic risks in connected healthcare.
Research Questions / Practical Problems
Question signals indexed for this paper.
- 67%
Right Information, Right Time, Right Place: Physical Alignment and Misalignment in Healthcare Practice
CHI '20· Telemedicine & Remote Patient Monitoring +2
- 67%
Understanding Personal Protective Equipment Use in Interdisciplinary Medical Settings: Design Considerations for Just-in-Time Interactive Compliance Alerts
DIS '25· Privacy by Design & User Control +2
- 60%
Electronic Health Records Are More Than a Work Tool: Conflicting Needs of Direct and Indirect Stakeholders
CHI '19· Telemedicine & Remote Patient Monitoring +1
Based on Jaccard similarity of research subtopics & professions (≥60%)