Skip to main content

Post Topic: Medical Device Security

Phil Englert, VP Medical Device Security, featured in TechNation article on using the FDA's MAUDE database.

Uncatchable Silence: How MAUDE Can Amplify the Call for Safer Devices

Medical Device blog by Phil Englert, Health-ISAC VP of Medical Device Security

Medical device owners are increasingly frustrated by the limited information medical device manufacturers share about known but undisclosed vulnerabilities in medical technologies and the speed at which they patch known vulnerabilities. Leveraging the Food and Drug Administration’s MAUDE may be a way to drive expediency.

The FDA’s MAUDE database – short for Manufacturer and User Facility Device Experience – is a public repository of adverse event reports involving medical devices and is part of the FDA’s postmarket surveillance strategy. Its primary purpose is to help the FDA monitor device performance, detect potential safety issues, and support benefit-risk assessments after devices are on the market. Mandatory reporters (like manufacturers, importers, and healthcare facilities) must submit reports when a device may have caused or contributed to a death, serious injury, or malfunction. Voluntary reporters (such as healthcare professionals, patients, or caregivers) can also submit reports if they observe or experience a device-related issue.

Read more about MAUDE, including an example of a cyber-related MAUDE report narrative, in TechNation.

Click Here

Medical Device Security: What Healthcare Buyers Really Want, Health-ISAC Navigator Program whitepaper by RunSafe Security.

Medical Device Security: What Healthcare Buyers Really Want

Cybersecurity is now the gatekeeper to market access

EXECUTIVE BRIEF FROM THE 2025 MEDICAL DEVICE CYBERSECURITY INDEX

Healthcare has reached a cybersecurity tipping point. 22% of healthcare organizations have experienced cyberattacks that compromised medical devices, with 75% of these incidents directly impacting patient care. When attacks force patient transfers to other facilities—which happened in nearly a quarter of cases—we’re no longer talking about IT inconvenience, but medical emergencies.

 

THE DEMAND FOR MEDICAL DEVICE SECURITY IS HIGH

1. Transparency Through SBOMs – 78% consider Software Bills of Materials essential in procurement decisions. This isn’t just regulatory compliance—it’s practical vulnerability management in an interconnected ecosystem.

2. Built-In vs. Bolt-On Security – 60% prioritize integrated cybersecurity protections over retrofitted solutions. Healthcare leaders have learned that band-aid security measures fail against sophisticated attacks.

3. Advanced Runtime Protection36% actively seek devices with runtime protection, while another 38% are aware but don’t yet require it—suggesting rapid market evolution from early adoption to mainstream expectation.

Read the white paper by RunSafe Security, a Health-ISAC Navigator. Click Here

Phil Englert, VP Medical Device Security, quoted on threat actors targeting healthcare organizations.

State of Healthcare Cybersecurity: Progress and Pitfalls

Phil Englert of Health-ISAC and Murad Dikeidek of UI Health speak about the challenges of health sector security and offer insights.

While the healthcare sector is making progress in cyber resilience, it still faces deep-rooted challenges, including collaboration, cyber workforce issues, and budget constraints, necessitating a constant demand for adaptation and re-prioritization as adversaries shift their tactics, said security experts Phil Englert and Murad Dikeidek.

“One of the things that we see happening more and more, and still not enough, is information sharing,” said Englert, vice president of medical device security at the Health Information Sharing and Analysis Center.

Information sharing can be vital to helping the overall sector better understand the threats it is facing, yet there’s still uncertainty at many organizations about the level of details healthcare providers should disclose, he said.

Read or listen to this conversation in Data Breach Today. Click Here

Phil Englert, VP Medical Device Security at Health-ISAC, featured in TechNation article on device vulnerabilities.

Contec CMS8000 Vulnerability

Contec CMS8000 Vulnerability: A Critical Cybersecurity Concern or Poor Coding Practice?

Health-ISAC Medical Device Security Blog in TechNation

Written by Phil Englert, Health-ISAC VP of Medical Device Security

On January 30, 2025, the Cybersecurity and Infrastructure Security Agency (CISA) released medical advisory ICSMA-25-030-01, highlighting critical vulnerabilities in the Contec CMS8000 patient monitors. These vulnerabilities – which include an out-of-bounds write, hidden backdoor functionality, and privacy leakage – pose significant risks to patient safety and data security. The U.S. Food and Drug Administration (FDA) issued a safety communication on the same day, emphasizing the risks associated with these vulnerabilities. The FDA highlighted that the Contec CMS8000 and relabeled versions, such as the Epsimed MN-120, may be remotely controlled by unauthorized users, potentially compromising patient data and device functionality. The CMS8000 came on the market around 2005 and obtained FDA 510(k) clearance in June 2011.

The FDA’s recommendations for healthcare providers and patients were twofold: Unplug and discontinue using the device if you rely on remote monitoring features. Second, the FDA recommended using local monitoring features only, such as disabling wireless capabilities and unplugging ethernet cables. Physiological monitors do not provide lifesaving or life-sustaining treatment, but they are essential in monitoring the condition of at-risk patients. Patient monitors are monitored centrally to promptly notify caregivers of patient condition changes. Rapid response can be the difference between good and bad outcomes.

The Contec CMS8000 vulnerabilities disclosed by CISA and analyzed by the FDA, Claroty, and Cylera highlight the critical need for robust cybersecurity measures in healthcare settings. It also highlights that vulnerabilities may stem from insecure design rather than malicious intent, their potential impact on patient safety and data security cannot be underestimated. Healthcare providers should act swiftly to mitigate these risks and ensure the integrity of their medical devices.

Read the full blog in TechNation. Click Here

 

Healthcare Finance graphic highlighting medical device cybersecurity challenges from HHS staffing cuts.

Medical device cybersecurity could be challenged by HHS staffing cuts

House subcommittee hearing on cybersecurity protection for legacy medical devices overshadowed by HHS cuts.

Panelists taking part in the Oversight and Investigations Subcommittee discussion on “Aging Technology, Emerging Threats: Examining Cybersecurity Vulnerabilities in Legacy Medical Devices” were asked about the impact of FDA staff reductions on medical device security. 

“Tremendous,” said Kevin Fu, professor from the department of Electrical and Computer Engineering at the Khoury College of Computer Sciences at Northeastern University. Fu formerly served as the inaugural acting director of Medical Device Cybersecurity at the FDA’s Center for Devices and Radiological Health (CDRH) and program director for Cybersecurity at the Digital Health Center of Excellence.

Erik Decker, vice president and CISO at Intermountain Health, said the FDA is a key stakeholder in cybersecurity efforts.

“Yes, it will have an impact,” Decker said. 

Medical device manufacturers, hospitals and the FDA partner, he said. HHS, the FDA and the healthcare industry have established numerous task groups under the Health Sector Coordinating Council (HSCC) Cybersecurity Working Group (CWG).

However, Decker said, analysis shows that on average, hospitals only have about 55% of the Health Industry Cybersecurity Practices (HICP) recommended practices for medical device security implemented. 

Decker said there are four groups of threat actors: nation-state actors, organized crime, “hacktivists” and insider threats. 

Panelist Greg Garcia, executive director, Health Sector Coordinating Council Cybersecurity Working Group, said next week they will release a white paper on how health systems are undersourced in finances and staffing for cybersecurity protection.

Read the full article in Healthcare Finance News. Click Here

Phil Englert, VP Medical Device Security, featured in TechNation article on proposed HIPAA Security Rule changes.

How HTM Staff Can Prepare for the Proposed HIPAA Security Rule Changes

Health-ISAC Medical Device Security Blog in TechNation

Written by Phil Englert, Health-ISAC VP of Medical Device Security

 

On December 27, 2024, the Office for Civil Rights (OCR) at the U.S. Department of Health and Human Services (HHS) issued a Notice of Proposed Rulemaking (NPRM) to amend the Health Insurance Portability and Accountability Act of 1996 (HIPAA) Security Rule. The goal is to fortify cybersecurity defenses that protect electronic health information (ePHI). This proposed update represents a proactive approach to safeguarding sensitive health information in an era of escalating cyber threats.

The proposed amendments highlight several critical measures to bolster ePHI protection. Some of these rules are process-oriented, and several are technical. Incorporating these proposed changes into the procurement process will help organizations prepare for the changes when they go into effect. Here is a selection specifically pertinent to medical devices.

Continue reading this article in TechNation. Click Here

Phil Englert, VP Medical Device Security, featured in a graphic on Medical Device Risk Impact Analysis (MDRIA).

Medical Device Risk Impact Analysis for Healthcare Providers

Health-ISAC Medical Device Security Blog in TechNation

Written by Phil Englert, Health-ISAC VP of Medical Device Security

In the health care industry, ensuring the safety and efficacy of medical devices is paramount. Too often, cybersecurity focuses on vulnerabilities and, while important, vulnerability analysis is too narrow. Vulnerabilities are evaluated using the Common Vulnerability Scoring System (CVSS), which attempts to determine how dangerous a vulnerability is. This is useful information but considers the vulnerability risk within the component it resides in rather than the product. This limited view fails to consider the risks the vulnerability poses to a specific environment. Contextual factors such as asset importance, how the asset is used, or the controls in place, either within the product or within the network must also be considered when evaluating risk. Given these limitations, conducting a Medical Device Risk Impact Analysis (MDRIA) is a critical process that helps health care providers identify, assess and mitigate risks associated with medical devices. This essay outlines the essential components of an MDRIA.

Read the full blog in TechNation.  Click Here

Industrial Cyber logo on top Image of a TV screen with a screenshot of this article on it. Pulled mention: Timeline of shifting responsibilities during the medical device lifecycle

Health-ISAC whitepaper highlights cybersecurity responsibilities in medical device lifecycle, focuses on resilience

 

Health-ISAC published a whitepaper addressing the tasks needed to maintain the cyber resilience of medical devices and how the responsibilities may shift from party to party throughout the total product. As medical devices move through the lifecycle phases, the responsibility for tasks may transfer between the manufacturers and the customer. The Health-ISAC whitepaper identifies that communication between the two parties is essential as the device moves through the lifecycle so that tasks are coordinated, and security gaps within the product are reduced.

Titled ‘Exploring the Cybersecurity Roles of Manufacturers and Healthcare Organizations During the Medical Device Lifecycle,’ the white paper identified that medical devices go through four lifecycle phases, with varying levels of responsibilities placed on the medical device manufacturer and the healthcare delivery organization. Healthcare delivery organizations (HDOs) should perform more regular risk assessments going into end of life (EOL) and end of support (EOS) to determine if they can accept the risk of continued use. It also points out that the responsibility for maintaining a medical device’s cybersecurity posture evolves throughout the lifecycle of a device. 

Read the full article in Industrial Cyber. Click Here

Health-ISAC report, Exploring the Cybersecurity Roles of Manufacturers and Healthcare Organizations During Device Lifecycle.

Exploring the Cybersecurity Roles of Manufacturers and Healthcare Organizations During the Medical Device Lifecycle

 

TLP: WHITE This report may be shared without restriction.
Health-ISAC Members be sure to download the full version of the report from the Health-ISAC Threat Intelligence Portal (HTIP)

Key Judgements

  • Medical devices go through four lifecycle phases, with varying levels of responsibilities placed on the medical device manufacturer and the healthcare delivery organization.

  • Healthcare Delivery Organizations should perform more regular risk assessments going into End of Life and End of Support to determine if they can accept the risk of continued use.

  • The manufacturer implements Security Control Categories in the development phase to ensure that the device is Secure by Design, Secure by Default, and Secure by Demand.

  • Documentation and Transparency are critical in maintaining cybersecurity. This includes providing detailed security documentation, a Software Bill of Materials (SBOM), and clear communication about vulnerabilities and updates. 

 

Download this white paper.

Exploring The Cybersecurity Roles Of Manufacturers And Healthcare Organizations During The Medical Device Lifecycle
Size : 3.2 MB Format : PDF

Introduction

As medical devices become more interconnected and have internet and wireless communications capabilities, understanding the lifecycle stages and the tasks needed to maintain their security posture will help organizations secure devices against cybersecurity threats. The device lifecycle is the various stages a device will go through, from research and development, on the market, and eventually, end of life and end of support. As medical devices move through the lifecycle phases, the responsibility for tasks may transfer between the manufacturers and the customer. Communication between the two parties is essential as the device moves through the lifecycle so that tasks are coordinated, and security gaps within the product are reduced.

This document explores the tasks needed to maintain the cyber resilience of medical devices and how the responsibilities may shift from party to party throughout the total product. The responsibility for maintaining a medical device’s cybersecurity posture evolves throughout the lifecycle of a device. The process begins with the device manufacturer during the design and development phase and may increasingly shift to the Healthcare Delivery Organization (HDO) once in clinical use. The International Medical Device Regulators Forum (IMDRF) Principles and Practices for the Cybersecurity of Legacy Medical Devices outlines four lifecycle phases. The Food and Drug Administration (FDA) provides requirements for the cybersecurity of medical devices in the pre-and post-market guidance. Manufacturers can address a device’s cybersecurity during design and development using the premarket requirements. Post-market requirements are needed due to cybersecurity risks continuing to evolve after the medical device reaches the market.

Phil Englert, VP Medical Device Security at Health-ISAC, quoted on managing cyber risk in medical device procurement.

How to Manage Cyber Risk of Medical Devices – for Life

Experts Offer Advice for Managing Growing Inventories, Resources for Providers

The HSCC’s “Health Industry Cybersecurity – Managing Legacy Technology Security” – or HIC-MaLTS – guidance offers organizations best practices that can be used to manage cyber risks of legacy medical technologies, said Phil Englert, vice president of medical device security at the Health Information Sharing and Analysis Center.

HIC-MaLTS takes on common healthcare cybersecurity challenges. For example, “many different types of medical devices and the diverse locations in which they are used possess unique risk profiles and include diagnostic, therapeutic, wearable, implantable and software-as-a-medical device features, among others, that can be used in hospitals, clinics, and other non-clinical and home healthcare settings,” he said.

Also in this article:

  • four life cycle phases of medical devices
  • “system-view” inventories combined with segmentation and network access controls
  • HSCC’s Model Contract-Language for Medtech Cybersecurity 

Read the article in Healthcare Infosecurity here. Click Here

Phil Englert, VP Medical Device Security, on how Health-ISAC reduces healthcare cyber breaches in TechNation.

Enhancing Cybersecurity in Healthcare: The Role of Health-ISAC

Participation in Health-ISAC can make healthcare providers less susceptible to hacks and breaches.

 

In an era of increasingly sophisticated and prevalent cyber threats, health care providers face unique challenges in protecting sensitive patient data and maintaining the integrity of their systems. One powerful tool in the fight against cybercrime is participation in the Health Information Sharing and Analysis Center (Health-ISAC). This collaborative organization makes health care providers less susceptible to hacks and breaches.

One of the most significant benefits of Health-ISAC membership is access to real-time threat intelligence. Cyber threats evolve rapidly, and having up-to-date information is critical for effective defense. Health-ISAC collects and disseminates information about emerging threats, vulnerabilities and attack vectors. This intelligence allows health care providers to address potential risks before malicious actors can exploit them proactively. For example, if a new ransomware strain is detected targeting health care systems, Health-ISAC can quickly alert its members, providing details on the threat and recommended mitigation strategies. This rapid dissemination of information can be the difference between a minor incident and a significant breach.

Cybersecurity is not a solitary endeavor.

Read the full blog by Health-ISAC VP of Medical Device Security Phil Englert in TechNation. Click Here

Cyber Focus Podcast on evolving health sector cybersecurity challenges, featuring Errol Weiss, Chief Security Officer.

AI, Ransomware, and Medical Devices: Safeguarding Healthcare

McCrary Institute Cyber Focus Podcast

Host Frank Cilluffo interviews Errol Weiss, Chief Security Officer at the Health Information Sharing and Analysis Center (Health ISAC).

They discuss the evolving cybersecurity challenges in the healthcare sector, including ransomware, supply chain vulnerabilities, and the critical need for better security measures to protect medical devices and patient data. Weiss shares insights from his extensive experience in both healthcare and financial services cybersecurity, highlighting lessons learned, the role of information sharing, and the importance of proactive measures to mitigate risks.

Listen to the podcast on YouTube Click Here

Topics include:

  • Health and Ransomware

  • Outages in hospitals

  • Health cyber budgets

  • Security and Compliance

  • Lessons from FS

  • Future technology

  • Medical Devices

  • Cross-sector info sharing

  • Practical steps toward security