Can New Medical Device Cybersecurity Regulations Withstand Escalating Cyberattacks in the Healthcare Industry?
Amid ongoing cyberattacks on the healthcare industry, the U.S. strengthened medical device cybersecurity requirements in 2023 through legislation and FDA guidance. However, vulnerabilities in legacy devices, evolving attacker techniques, and new risks posed by AI put the regulations to the test. Experts remain cautiously optimistic about the regulations' effectiveness over the next 5 to 10 years.

For years, medical device cybersecurity was an afterthought for the industry and regulators, even as hackers continuously targeted the healthcare sector.
That changed last year: Congress wrote stricter medical device cybersecurity requirements into law, and the U.S. Food and Drug Administration (FDA) finalized enhanced guidance for manufacturers. The new measures prioritize security during a period when cybersecurity incidents not only endanger data but also paralyze hospital operations and threaten patient safety.
"I view last year as the beginning of a new era... a whole new world. Because the industry has spent about 15 years collectively thinking and debating: 'What does it really mean to achieve secure healthcare delivery or cybersecurity in medical devices?'" said Kevin Fu, former acting director of medical device cybersecurity at the FDA.
Several measures implemented in 2023 strengthened oversight of medical device cybersecurity risks. First,new FDA regulations passed by Congress in December 2022 as part of an omnibus spending billtook effect in March of last year. The legislation added provisions to the Federal Food, Drug, and Cosmetic Act, defining "cyber devices" and specifying stricter cybersecurity requirements that device manufacturers must meet when submitting premarket applications, such as developing plans to monitor and identify potential vulnerabilities.
Second, the FDA's Center for Devices and Radiological Health (CDRH)released its final premarket guidance in September. This document, over 50 pages, is a significant improvement over previous guidance that was only a few pages long.
Fu, now a professor of electrical and computer engineering at Northeastern University, said the device industry "has reached a good consensus on what needs to be achieved and the better ways to get there."
Although many experts view last year as a high-water mark for device cybersecurity regulation, challenges remain. For example, a large number of devices come to market with operating systems that may quickly become outdated, and hospitals are filled with an unknown number of unsupported older devices (i.e., legacy devices) that are vulnerable to attacks.
Moreover, attackers are unlikely to stop targeting the healthcare sector anytime soon, and the threat landscape has evolved. Fu noted that threats have shifted from "bored teenagers in basements" to "nation-state actors" attempting to harm hospitals.
"This is no longer a game, no longer just entertainment. These are financially motivated adversaries who will cause harm if medical devices leave any door open during manufacturing or use," he added.
What risks do devices face?
Although medical devices themselves are susceptible to cyber threats, attackers rarely aim to compromise and control a single device (such as a pacemaker or insulin pump). However, devices can be used as an entry point to larger targets, such as hospital networks.
Axel Wirth, chief security strategist at cybersecurity company Medcrypt, explained that some attackers may not even initially know they are targeting medical devices or healthcare systems.
"It's more of an opportunistic event—the device is compromised not because the device itself is the target, but because the device fits the attack profile," Wirth said. "Attackers are looking for an old, unpatched Windows XP computer. Even if it happens to be a medical device rather than a desktop, the attacker may not know at all."
Medical devices are often not the target of attacks but can still be affected. Chad Waters, senior cybersecurity engineer at safety watchdog ECRI, said devices may be within the "blast radius" of a cyberattack on a hospital network, such as an MRI machine being shut down. Even if the machine is not the direct target, patient care is delayed as a result.
"This is no longer a game, no longer just entertainment. These are financially motivated adversaries who will cause harm if medical devices leave any door open during manufacturing or use."

Kevin Fu
Former acting director of medical device cybersecurity at the FDA
Part of understanding device risk also involves understanding the full impact an attack can have. Both Fu and Wirth emphasized that attackers not only steal patient data—hospital and healthcare operations and patient safety are also at risk,as demonstrated by the recent attack on Change Healthcareand other incidents over the past few years.
The interconnectivity of healthcare systems with online devices, hospital networks, and electronic health records can amplify the vulnerabilities and impact of cyber incidents.
"In the past, we really had a 'one device, one network, one department' mindset, and I think we're realizing that's not enough. Problems can quickly become much larger," Wirth said. "You have to fix security at the device level, but you have to strategize at the entire system level and look at where the whole system could collapse—like in the Change Healthcare incident."
For companies, hundreds of millions of dollars can also be at risk. Henry Scheinhad to deal with a cyber incident for months, forcing systems offline and affecting more than 29,000 people. The company had a $60 million cyber insurance policy,and ultimately estimated a loss of $350 million to $400 million in sales in the fourth quarter of 2023。
Cyber vulnerabilities are also factored into corporate credit ratings. Gilberto Ramos, assistant vice president at Moody's Ratings, wrote in an email that the burden of building stronger cybersecurity systems and infrastructure may hit smaller companies harder, "because they have fewer resources to invest in cybersecurity, while larger companies can often assign dedicated teams to protect data."
As the industry and regulators recognize the severity of cyber risks, experts say the next step is to fully grasp the potential destructive power of attacks.
The persistent problem of legacy devices
Multiple experts point to legacy devices as one of the biggest risks currently facing the medical technology industry and hospitals. Healthcare facilities are filled with devices running unsupported or soon-to-be-unsupported software, making them vulnerable.
Devices like MRI machines are expensive and difficult to replace, or are too critical to patient care to be taken offline, creating security gaps in the network.
"These systems are basically like being poured into concrete, and we're waiting for the foundation to collapse," Fu said. "A large number of legacy medical devices run on everything from Windows 10 to Windows 95... This threat is self-inflicted because the industry didn't plan ahead."
He added that hospitals are effectively "duped" into buying certain devices that will soon be unsupported, and now have to use machines where "the software ages faster than the mechanical parts."
MITRE, a nonprofit federal research institute, released a report on legacy medical technology in November. The report recommended that suppliers and manufacturers share "joint responsibility" for legacy devices, and that both parties sign information-sharing agreements containing expectations for security controls throughout the product's entire lifecycle.
"Do we need to keep patching for the foreseeable decades? Yes. Is patching enough to provide the security we need? Absolutely not."

Axel Wirth
Chief security strategist at Medcrypt
Nastassia Tamari, director of the CDRH's medical device cybersecurity division, said managing legacy devices is one of the biggest challenges facing the industry and regulators. The key issue is not only the large number of unsupported devices currently in healthcare facilities, but also that no one knows the exact number of legacy devices due to a lack of reliable data.
Tamari said regulators need a better understanding of the scope of the problem before they can develop effective policies to fix or mitigate it.
"This is indeed a formidable challenge," she added. "There is currently no answer."
Secure by design
While addressing the legacy device problem, the FDA is trying to prevent new devices from becoming legacy devices, or at least slow that process as much as possible.
The premarket requirements passed by Congress in 2022are aimed precisely at this. As part of premarket submissions (including 510(k), Premarket Approval, De Novo, etc.), device manufacturers must include plans to monitor, identify, and address vulnerabilities within a "reasonable time"; design and maintain procedures to ensure the cybersecurity of the device and related systems; and provide postmarket updates and patches.
Section 524B, newly added to the Federal Food, Drug, and Cosmetic Act, also requires device manufacturers to provide a software bill of materials (SBOM), which is a list or inventory of all software components used in the device.
"With the new requirements, we are now better equipped than ever to ensure the medical device industry has the tools and information needed to address cybersecurity vulnerabilities and threats," Tamari said.
Although these new cyber regulations are seen as a way to limit the number of legacy devices and as an improvement over the FDA's previously limited authority and guidance, some experts say manufacturers still need to make devices as secure as possible before they come to market, rather than relying on patch systems as a crutch for later remediation.
Ensuring a device is "secure by design" does not mean it is perfect, because all software ages and threats evolve.
"Do we need to keep patching for the foreseeable decades? Yes. Is patching enough to provide the security we need? Absolutely not," said Wirth of Medcrypt.
Wirth added that patch systems are ineffective in part because it "takes weeks or even months, and sometimes never happens," as machines in healthcare environments are interdependent and involved in continuous patient care.
Tamari said that to ensure devices are as secure as possible, manufacturers should conduct rigorous threat modeling, penetration testing, and risk management on their products before submitting market authorization applications, and develop detailed SBOMs.
Leroy Terrelonge, vice president at Moody's Ratings, said in an email statement that new U.S. requirements and international standards may force companies to increase development spending, and products may take longer to reach the FDA review stage. He added that these requirements could even extend FDA review times, keeping devices off the market, but if companies develop innovative products, they can offset short-term costs.

Fu emphasized that SBOMs are one way to mitigate future threats. The list helps manufacturers address potential security issues more systematically and gives hospitals insight into where vulnerabilities may lie.
"It's unrealistic to think you can have a perfectly secure system that never needs adjustment—that's probably impossible," Fu said. "However, there are good designs and better designs."
He added that the goal is to keep manufacturers agile and better able to respond when threats arise, because building an impenetrable device or system is not realistic.
The future of device security
Looking ahead, the question facing the industry and regulators is whether these FDA regulations can function in an environment of rapid technological innovation and evolving threats. Devices equipped with artificial intelligence are becoming increasingly common, bringing new benefits and risks.
AI can help companies test products against cyber threats before market entry at speeds humans cannot match. However, devices with built-in AI capabilities may also be more susceptible to attacks.
Malicious actors can also leverage AI technology. For example, Wirth said hackers could use AI to "identify and discover previously undisclosed vulnerabilities and exploit them before the software vendor itself finds them."
According to Tamari, the FDA's CDRH is already looking at AI in the cybersecurity context, although discussions are still in early stages and there are many questions. Overall, the agency has made structural adjustments to meet cybersecurity needs, such as elevating the Office of Strategic Partnerships and Technology Innovation (OST)to a "super office"。
An FDA spokesperson said in an email statement that OST has added six new members over the past few years, and the Office of Product Evaluation and Quality has also increased staffing to assist with "policy development, policy implementation, and postmarket response."
Fu said he is "cautiously optimistic" about last year's changes and believes they should be sufficient for the next 5 to 10 years. One reason, he explained, is that most of these regulations are "technology-neutral," focusing on device attributes rather than specific types of software.
However, as technology and threats evolve and healthcare attacks continue, regulations will ultimately need to be updated.
"In 2023, people realized this is a common problem for everyone," Wirth said. "Have we achieved it? Not yet. But we're getting closer. Recognizing the problem is the first step to improvement."