Information security
Digitalization has become a ubiquitous part of our lives and offers tremendous potential for advancements in healthcare. With the rise of connected devices and the ongoing development of a wide range of systems, it is vital to ensure that these networked systems are secure in the virtual world. As a manufacturer, mylife understands how important it is to maintain confidentiality, integrity, and the availability of the systems and data, and is constantly working to prepare for potential cyber-attacks and associated risks.
Since we operate in a strictly regulated environment in the healthcare sector, it is essential that personal data is handled carefully. We have gained a wealth of experience in this field, allowing us to focus on two main aspects: patient safety and technical security. We are committed to offering state-of-the-art security and secure interoperability, without compromising on the safety and comfort of our customers.
Regulations and standards with a focus on information security
We don't just talk about what we intend to do, we do it. We base the monitoring and management of our infrastructure cyber security on the following applicable guidelines and standards (not exhaustive):
EU 2016/679: Regulation (EU) on the protection of natural persons with regard to the processing of personal data and on the free movement of such data (GDPR / DSGVO)
IEC 62304: Medical Device Software – Software Life Cycle Processes
IEC 81001-5-1: Health Software and health IT systems safety, effectiveness and security – Part 5-1: Security —Activities in the product life cycle
IEC TR 60601-4-5: Technical Report (TR) on Medical electrical equipment — Part 4-5 Guidance and interpretation — Safety related technical security specifications for medical devices.
IEC 82304-1: Health software — Part 1: General requirements for product safety
YpsoPump cyber security made simple
The downloaded app is approved by the security server to be from a trusted source. A connection between the YpsoPump and the smartphone is established via Bluetooth. The correct insulin pump is selected with the help of the serial number and a 6-digit passkey code displayed on the pump. Due to the security function, the YpsoPump can only be connected to one smartphone at a time.
All communication between the insulin pump and the app is secured end-to-end via authenticated encryption. The security server vouches for the app's authenticity. All communication between the security server and the insulin pump is further safeguarded end-to-end by authenticated encryption. Even though the app acts as an intermediary, it cannot interfere with the communication. Communication between all components is also secured by Bluetooth and TLS encryption. All communication between the app and the YpsoPump insulin pump is safeguarded by encryption specific to the app and insulin pump pair. For example, as an insulin pump cannot read commands directed at another insulin pump, retargeting attacks are impossible.