The post has been translated automatically. Original language: Russian
The radiologist looks at the CT scan. There are hundreds of slices and thousands of details in front of him. He reviews dozens of such studies per day. By the end of the shift — fatigue, decreased concentration, cognitive load.
The computer vision algorithm looks at the same image. He doesn't get tired. He doesn't get distracted. Processes each pixel with the same accuracy — the first image per shift and the last one.
This does not mean that the algorithm is better than the doctor. This means that they are good at different things. And it is this combination that changes the medical diagnosis.
Why medical imaging is an ideal task for computer vision
Computer vision works best where there is a large amount of labeled data and a clear criterion for the correct answer.
Medical imaging is ideal: decades of CT scans, MRI scans, X-rays, and histological preparations with verified diagnoses. Millions of images where the correct answer is known. This is an ideal training dataset.
Convolutional neural networks (CNNs) are able to extract hierarchical features from images: from edges and textures at a low level to complex anatomical patterns at a high level. This is what makes them a powerful tool for analyzing medical images.
Where computer vision is already changing diagnostics
Oncology. The detection of skin cancer from dermatoscopic photographs is one of the first areas where algorithms have achieved the accuracy of a dermatologist. A 2017 Stanford study showed that CNN diagnoses melanoma with an accuracy comparable to an experienced specialist based on a sample of 130,000 images.
Screening of cervical cancer by cytological smears, detection of polyps during colonoscopy in real time, analysis of biopsy preparations for prostate cancer — everywhere algorithms are already working in clinical practice or are undergoing final tests.
Ophthalmology. Diabetic retinopathy is one of the leading causes of blindness in the world. Screening requires the analysis of fundus images by an experienced ophthalmologist. There are not enough specialists, especially in countries with developing medicine.
Google has developed an algorithm that detects diabetic retinopathy with 90% sensitivity and 98% specificity — surpassing the average ophthalmologist. The system has already been deployed in clinics in Thailand and India, where the shortage of specialists is critical.
Radiology. Pneumonia, pneumothorax, fractures on X—rays - algorithms detect them with high accuracy. Stanford's CheXNet detects pneumonia on an X-ray better than the average radiologist on a standard dataset.
An important caveat: "better than the average radiologist on a standard dataset" does not equal "better in real clinical practice." The real pictures are dirtier, the patients are more complex, and the context is richer. This is an honest limitation that is important to understand.
Pathology. The analysis of histological preparations is one of the most time—consuming processes in oncology. The pathologist spends hours examining tissue sections under a microscope. Computer vision algorithms can automatically segment cells, classify tissue types, and detect malignant changes — many times faster than humans.
Where does the algorithm see what a human is missing
This is the most interesting part. There are tasks where computer vision detects patterns that humans are physically unable to see.
Prediction of cardiovascular risk based on retinal imaging. It sounds incredible, but Google's algorithm has found that based on the characteristics of the blood vessels in the fundus image, it is possible to predict the patient's age, gender, diabetes, and risk of heart attack. The human eye does not see these patterns — they are statistically significant only in large samples.
Prediction of genetic mutations based on histological images of a tumor — without expensive genetic testing. The algorithm finds visual correlates of genetic changes that the pathologist is not trained to notice.
Technical challenges
There are several problems that engineers are solving right now.
Data quality and markup. Medical images from different clinics — different equipment, different protocols, different quality. A model trained on data from one clinic may not work well in another. Domain adaptation — adapting the model to new data sources is an active area of research.
Explainability. The doctor should understand why the algorithm made this particular diagnosis. Activation visualization methods — Grad-CAM, SHAP — show which areas of the image the model is looking at. But there is no complete explainability yet.
Rare diseases. The algorithm is good where there are many training examples. For rare pathologies, there is little data, and accuracy drops sharply. Few-shot learning and synthetic data augmentation partially solve the problem.
What does this mean for IT developers?
Medical computer vision is a specialized field with its own standards. DICOM, a medical image format, requires specific libraries and an understanding of metadata. The regulatory requirements for model validation are much stricter than in a conventional CV.
But the market is huge. It is estimated that the market for AI-based medical imaging solutions alone will exceed $20 billion by 2030. And this is one of the few areas where AI has already proven its clinical value with a solid evidence base.
Computer vision is not a substitute for a radiologist or pathologist. It makes their work more accurate, faster and more accessible where there are not enough specialists. This is a rare case when AI in medicine has gone from hype to real clinical results.
Большинство разработчиков воспринимают кибербезопасность как набор практик: шифровать данные, валидировать входные данные, не хранить пароли в открытом виде. Это правильные базовые принципы — но для медицинских устройств их недостаточно.
Кибербезопасность в медтехе — это не дополнение к разработке. Это отдельная инженерная дисциплина со своей методологией, стандартами и образом мышления.
Почему медицинские устройства — особая категория риска
Уязвимость в обычном приложении приводит к утечке данных или финансовым потерям. Уязвимость в медицинском устройстве может напрямую угрожать жизни пациента.
Инсулиновая помпа, кардиостимулятор, аппарат ИВЛ, инфузионный насос — каждое из этих устройств управляется программным обеспечением. Если злоумышленник получит контроль над этим ПО — последствия физические, а не цифровые.
В 2017 году FDA впервые отозвала с рынка кардиостимулятор из-за обнаруженной уязвимости, которая теоретически позволяла удалённо изменить настройки устройства. С тех пор регуляторы по всему миру кардинально пересмотрели требования к кибербезопасности медицинских изделий.
Что изменилось в регуляторике
С 2023 года FDA требует от производителей всех новых медицинских устройств с цифровыми компонентами предоставлять Software Bill of Materials — полный список всех программных компонентов, включая стороннние библиотеки, с указанием известных уязвимостей в каждой из них.
Это означает: производитель должен точно знать каждую зависимость в своём коде, отслеживать публикуемые уязвимости для каждой из них и иметь план обновления на весь жизненный цикл устройства — который может составлять 10–15 лет.
Европейский MDR также явно включает cybersecurity как обязательный раздел технической документации, без которого сертификация невозможна.
Принципы, специфичные для медицинской кибербезопасности
Security by design, не security as afterthought. Архитектура устройства должна закладывать защиту с первого дня — шифрование каналов связи, разграничение прав доступа, защищённое хранение данных сессий — как часть базовой конструкции, а не как патч после обнаружения проблемы.
Threat modeling специфичный для медицинского контекста. Стандартные модели угроз не учитывают специфику медицинских устройств — например, риск того, что устройство физически находится у пациента дома без сетевого администратора, который может оперативно реагировать на инциденты. Это требует специализированной методологии оценки рисков, объединяющей кибербезопасность с клиническим risk management по ISO 14971.
Долгий жизненный цикл против быстро меняющегося ландшафта угроз. Обычное программное обеспечение обновляется часто. Медицинское устройство может работать в клинике десятилетие — но каждое обновление требует повторной валидации. Это создаёт фундаментальное противоречие: чем дольше живёт устройство без обновлений, тем больше накапливается неисправленных уязвимостей.
Современный подход — закладывать архитектуру, позволяющую обновлять отдельные изолированные компоненты безопасности без полной повторной валидации всей системы. Это сложная инженерная задача, требующая модульной архитектуры с самого начала проектирования.
Сегментация и изоляция критических функций. Жизнеобеспечивающие функции устройства должны быть архитектурно изолированы от компонентов, подключённых к сети — например, от модуля передачи данных для удалённого мониторинга. Даже если сетевой компонент будет скомпрометирован, это не должно угрожать основной клинической функции устройства.
Координированное раскрытие уязвимостей. Медицинская индустрия выработала специфические протоколы — производитель должен иметь публичный процесс получения отчётов об уязвимостях от исследователей безопасности, оценки их критичности именно с точки зрения риска для пациента, и координированного выпуска патчей.
Что это означает для команд
Специалист по кибербезопасности в MedTech должен понимать не только классические векторы атак, но и клинический контекст — как конкретная уязвимость транслируется в риск для здоровья пациента, а не просто в риск утечки данных.
Это создаёт нишу специалистов на стыке двух областей экспертизы, которых на рынке критически не хватает. Большинство университетских программ по кибербезопасности не покрывают медицинскую специфику, а медицинские инженеры редко имеют глубокую security-экспертизу.
📌 Кибербезопасность в медицине — это не чек-лист, который можно пройти перед релизом. Это образ мышления, который должен пронизывать архитектуру устройства с первого дня проектирования и сопровождать его весь жизненный цикл — иногда дольше десятилетия.