- Peter Wonah Odey; Membu Judy Chude; Nwagbara Chisom Telvin
- DOI: 10.5281/zenodo.22828833
- GAS Journal of Engineering and Technology (GASJET)
Modern
healthcare depends on a dense network of digital systems, connected medical
devices and operational technologies. Electronic health records, imaging
systems, infusion pumps, patient monitors, cloud platforms and building-control
systems now exchange data continuously. This connectivity improves clinical
work, but it also creates routes through which a weakness in one system can
affect many others. The problem is not simply a shortage of security tools. In
many organisations, information technology, clinical engineering, procurement
and operational teams manage risk separately, while suppliers retain
significant control over device updates and remote access. This review examines
recent evidence on medical-device vulnerabilities, healthcare supply-chain
exposure, procurement practice and governance across converged IT/OT
environments. It finds that known weaknesses remain common in connected
devices; cybersecurity conditions are still absent from many tender and
contract documents; and fragmented accountability allows local weaknesses to
become organisation-wide risks. In response, the paper proposes a four-layer
control framework built around shared asset visibility, consistent risk
assessment, unified governance and resilient care delivery supported by
continuous monitoring. The framework draws on the NIST Cybersecurity Framework,
NIST Zero Trust guidance, ISO/IEC 27001, IEC 62443 and medical-device safety
requirements. For Nigerian healthcare organisations, the approach is intended
to be practical: begin with accurate inventories, protect high-risk clinical
systems, place measurable security obligations in procurement documents, and
strengthen coordination between IT, clinical engineering, management and
vendors.
Keywords: IT/OT convergence; healthcare cybersecurity; Internet of Medical Things; medical-device security; cybersecurity governance; Nigeria.
