← All insights
Digital OR

Cybersecurity in the Connected OR: The Questions to Ask First

1 September 2026 · 6 min read
Digital operating room information hub connecting surgical devices on one touch interface

A modern operating room is no longer a closed room. Navigation carts, imaging robots, planning workstations and video routing hubs all sit on the hospital network, and many of them reach outside it for updates, remote support and image sharing. That connectivity is what makes the digital OR useful. It is also what makes it a target.

The numbers are no longer theoretical. Healthcare organisations worldwide recorded 410 ransomware attacks in the first half of 2026, up roughly 14 percent on the 360 recorded in the second half of 2025. Among organisations hit, 64 percent reported delays to procedures or tests. In February 2026 an attack on the University of Mississippi Medical Center closed clinics across the state and cancelled elective surgery for close to two weeks. Emergency care stayed open, but scheduled operating lists did not.

The operating room became a network endpoint

Look at what a well equipped theatre now runs. Brainlab Buzz Digital O.R. is a network-based information hub that routes, displays, streams and records images, software and video from multiple OR devices on a single touch interface. Curve is a mobile 4K navigation cart that lets the team plan, navigate, visualise, document and live-stream a case. Both are clinical tools. Both are also endpoints with an IP address, an operating system and a support channel.

Navigation platform in the operating room
Navigation and digital OR platforms are clinical systems and network systems at the same time.

The uncomfortable part is that surgical systems age differently from office IT. A navigation platform installed today may still be in daily use in ten years. Procurement decisions made now therefore set a security posture that has to hold for a decade, which is why the questions asked before purchase matter more than anything done afterwards.

The rules changed, and they are now enforceable

Device cybersecurity moved from good practice to legal obligation. In the United States, Section 524B of the Federal Food, Drug, and Cosmetic Act makes cybersecurity a statutory requirement for cyber devices, and a machine-readable Software Bill of Materials, in SPDX or CycloneDX format, is now part of the premarket submission. A vendor that cannot produce an SBOM cannot clear the door.

In Europe, MDCG 2019-16 remains the reference guidance for the cybersecurity requirements of Annex I of the MDR, and IEC 81001-5-1 has become the standard notified bodies look to for the software life cycle behind it. Separately, the NIS2 Directive puts obligations on the hospital as an operator rather than on the manufacturer, which is why procurement teams in Europe are now passing those obligations down the supply chain in their tenders.

In the UAE, the Abu Dhabi Healthcare Information and Cyber Security Standard applies to Department of Health regulated healthcare entities and sets controls across domains including access control, communications security and protection of health information. Dubai Health Authority requirements run in parallel. Any hospital connecting a surgical system should confirm, in writing and before signature, how the vendor supports those controls.

Six questions to ask before a system joins your network

1. Who patches it, and how quickly. Ask for the vendor's published vulnerability disclosure route and their committed timeline for security updates on this specific product, not on the company in general.

2. What is inside it. Request the Software Bill of Materials. It tells your security team which third-party components you are inheriting and which advisories will apply to you later.

3. How does remote support work. Most modern platforms are serviced remotely. Ask who initiates the session, whether the hospital can approve or refuse each one, whether it is logged, and what the technician can see.

4. Where does data go. Distinguish clearly between data that stays on the device, data that crosses the hospital network, and data that leaves the building. Each has a different owner and a different control.

5. What happens when the network is down. A surgical system that stops working the moment the network drops is a clinical risk, not just an IT one. Ask what degrades and what continues.

6. What is the end-of-support date. Get it in the contract. Devices that outlive their software support are the single largest source of unpatchable risk in a hospital estate.

Surgical planning software workstation
Planning, navigation and imaging share one data path, so they share one security question.

Where the data lives, and why it matters in the GCC

Cloud image sharing is now normal practice in neurosurgery and spine surgery, and it is where residency questions become concrete. Brainlab publishes its position for Brainlab Cloud Services: files are encrypted at rest with AES-256, transmission uses SSL/TLS with deprecated protocol versions blocked at the platform, data centres are ISO 27001 and SOC 1 certified, user credentials and patient data are stored separately, and uploads can be pseudonymised. Access is granted per contact, per patient folder, with defined permissions for viewing, downloading and uploading.

Brainlab also states that patient data for registered users in the United States is stored only on servers in the US, and data for registered users in Europe only on servers in the EU. For a hospital in the UAE or the wider GCC, the right move is to ask the vendor directly which region serves your account and to align that answer with what your regulator requires before the first upload, not after.

What Brainz does at installation

Security is not a feature the hospital buys once. It is a set of agreements that has to survive installation, staff turnover and ten years of software updates. Brainz sits between the manufacturer and the hospital IT team during that process: collecting the manufacturer security documentation, walking through network placement and remote support arrangements with biomedical and IT staff, and making sure the end-of-support and update commitments are understood before the system goes live rather than discovered later.

If you are planning a digital OR or navigation project and want the security conversation to happen at the design stage, talk to us before the tender closes. It is far cheaper than having it afterwards.

Share

Product availability, indications, regulatory status and clinical use vary by country and follow manufacturer documentation and applicable regulatory approvals. Trademarks belong to their respective owners.