Issued2025-12-22

AAMI CR515:2025 – Cybersecurity Considerations Unique to Machine Learning–Enabled Medical Devices

Consensus ReportVoluntary

Summary

Consensus report addressing cybersecurity threats unique to machine-learning-enabled medical device software, distinct from general medical-device cybersecurity risks. The report covers threats that may arise during data collection, product design, deployment, use, and maintenance, and FDA recognizes the complete standard in its medical-device consensus standards database.

Healthcare Implications

Provides AI/ML medical-device manufacturers with a recognized reference for cybersecurity risk analysis and documentation, including model- and data-related threats. Providers and health systems can use the standard in vendor due diligence for AI/ML-enabled devices, while developers should still account for FDA cybersecurity guidance and statutory cybersecurity requirements beyond this consensus report.

Impact Level

Medium

Keywords

Safety & Risk; Privacy & Data; Transparency & Governance

Stakeholders

Developers & Vendors; Providers & Health Systems; Regulators & Government