How to Manage Cyber Risk of Medical Devices – for Life

Experts Offer Advice for Managing Growing Inventories, Resources for Providers
The HSCC’s “Health Industry Cybersecurity – Managing Legacy Technology Security” – or HIC-MaLTS – guidance offers organizations best practices that can be used to manage cyber risks of legacy medical technologies, said Phil Englert, vice president of medical device security at the Health Information Sharing and Analysis Center.
HIC-MaLTS takes on common healthcare cybersecurity challenges. For example, “many different types of medical devices and the diverse locations in which they are used possess unique risk profiles and include diagnostic, therapeutic, wearable, implantable and software-as-a-medical device features, among others, that can be used in hospitals, clinics, and other non-clinical and home healthcare settings,” he said.
Also in this article:
- four life cycle phases of medical devices
- “system-view” inventories combined with segmentation and network access controls
- HSCC’s Model Contract-Language for Medtech Cybersecurity
Read the article in Healthcare Infosecurity here. Click Here
- Related Resources & News
- New critical infrastructure cybersecurity framework features government, regional council options
- Frontier AI in the Health Sector: Managing Supply Chain and Vendor Risk
- The State of Enterprise Cyber Crisis Readiness (report)
- Human Risk Management 90-Day Playbook
- Cybercriminals Flock to Healthcare Businesses as Attacks Surge
- DHS Revives Critical Infrastructure Threat Sharing, Without the Legal Shield Industry Wants
- Healthcare’s Governance Needs To Speed Up To Combat Unsanctioned AI Usage
- Monthly Newsletter – July 2026
- Healthcare Cybersecurity in an Era of Geopolitical Instability
- Health-ISAC AAMI eXhange Interview – Medical Device Security