health · digital · family: built to be open. now under attack
the ventilator has a password problem
Millions of networked medical devices in hospitals are unpatchable and exposed to cyber attack
Problem statement
Medical devices in clinical use — infusion pumps, ventilators, imaging systems, implantable cardiac devices, patient monitors — are increasingly networked and software-dependent, but the majority of the installed base was designed without cybersecurity controls. The FDA's premarket cybersecurity guidance (finalized September 2023, updated June 2025 and February 2026) and section 524B of the FD&C Act — added by section 3305 of the Consolidated Appropriations Act, 2023, effective March 29, 2023 — now require new submissions for "cyber devices" to include cybersecurity plans, but the installed base of legacy devices remains largely unpatched and unpatchable. There is no validated methodology for assessing and remediating cybersecurity risk across heterogeneous legacy device fleets in clinical environments.
Why this matters
FDA oversees more than 6,500 different medical device products, manufactured at roughly 25,900 FDA-registered medical device facilities worldwide (FDA at a Glance, January 2024), and a significant fraction of fielded devices are networked — a January 2022 research report cited by the FBI found 53% of connected medical and other IoT devices in hospitals had known critical vulnerabilities (FBI PIN 20220912-001). Healthcare has had the highest average data-breach cost of any industry for 13 consecutive years, reaching $10.93 million in IBM's 2023 Cost of a Data Breach report. A successful attack on a safety-critical device — an infusion pump, a ventilator — could directly endanger patients. Since FDA began enforcing the new cybersecurity requirements on October 1, 2023, device-security firm MedCrypt reports a 700% increase in cybersecurity-related deficiency letters among the manufacturers it works with, and FDA has publicly stated that deficiency letters that include cybersecurity deficiencies carry an average of fifteen of them — indicating that even new submissions struggle to meet the standard.
What’s been tried and why it hasn’t worked
The FDA's September 2023 premarket guidance (since updated in June 2025 and February 2026 to address section 524B) superseded 2014 guidance with detailed requirements for threat modeling, software bill of materials (SBOM), coordinated vulnerability disclosure, and cybersecurity risk assessment — but these apply only to new submissions. Section 524B (the enacted successor to the proposed PATCH Act) similarly requires cybersecurity plans, vulnerability monitoring, and an SBOM in premarket submissions but does not mandate remediation of already-marketed legacy devices, creating a two-tier system where legacy devices operate under weaker protections indefinitely. Hospitals rely on network segmentation as a compensating control, but segmentation is imperfect and operationally burdensome across fleets of thousands of devices from dozens of manufacturers. SBOM standards are not yet mature enough for automated vulnerability correlation across the device supply chain. Manufacturers of legacy devices have limited economic incentive to issue patches for products generating no ongoing revenue. Medical device hardware often remains active for 10-30 years while manufacturer-specified software life cycles end far earlier, and legacy devices no longer receive manufacturer support for patches or updates — leaving many running outdated, unsupported operating systems (FBI PIN 20220912-001).
What would unlock progress
A lightweight, standardized risk-scoring framework for triaging cybersecurity vulnerabilities across heterogeneous medical device fleets would enable hospitals to prioritize remediation even without manufacturer cooperation. Automated asset discovery and SBOM analysis tools purpose-built for clinical environments could give hospitals visibility into what is actually running on their networks. A regulatory or economic mechanism that creates incentives (or mandates) for legacy device manufacturers to provide security updates — or at minimum, SBOMs — for fielded devices would close the gap between new and legacy requirements.
Entry points for student teams
A student team could prototype an automated medical device network scanner that identifies connected devices, infers their software components, and maps them against known vulnerability databases (CVE/NVD) to produce a prioritized risk report. Another approach would be designing a network micro-segmentation policy generator specifically for clinical environments that balances security isolation with clinical workflow requirements. Teams with backgrounds in cybersecurity, networking, embedded systems, or healthcare IT would be well-suited. A scoped semester project could work with a simulated hospital network environment (e.g., using open-source medical device emulators) rather than requiring access to live clinical infrastructure.
Genome — every gene is a door
Structural cousins — same reason stuck, other fields
Sources
FDA Final Guidance, "Cybersecurity in Medical Devices: Quality Management System Considerations and Content of Premarket Submissions" (February 2026; supersedes the June 27, 2025 and September 27, 2023 finals), FDA CDRH/CBER, Docket FDA-2021-D-1158, FDA Digital Health Center of Excellence, "Cybersecurity," FBI Private Industry Notification 20220912-001, "Unpatched and Outdated Medical Devices Provide Cyber Attack Opportunities" (2022-09-12), Accessed 2026-08-20. go to source 1 ↗ go to source 2 ↗ go to source 3 ↗
verification notes (working record)
The collection team’s own sourcing notes for this brief, kept verbatim:
Key references include the FDA Premarket Cybersecurity Guidance (September 2023), FDA Postmarket Management of Cybersecurity in Medical Devices guidance (https://www.fda.gov/files/medical%20devices/published/Postmarket-Management-of-Cybersecurity-in-Medical-Devices---Guidance-for-Industry-and-Food-and-Drug-Administration-Staff.pdf), MedCrypt analysis of the PATCH Act's first-year impact (2024), and Sternum IoT's FDA cybersecurity guidelines overview (2024). This brief is related to digital-scada-adversarial-ai-robustness (similar OT security challenges in industrial settings) and digital-autonomous-system-runtime-resilience (analogous challenges in maintaining safety properties of fielded software systems). Tagged as "worsening" because the number of connected medical devices is growing while the legacy installed base remains vulnerable and replacing it would cost billions.
Reconciliation 2026-08-20: The sole cited URL was FDA's generic guidance-search page, not the guidance document; replaced with the guidance's own page (https://www.fda.gov/regulatory-information/search-fda-guidance-documents/cybersecurity-medical-devices-quality-management-system-considerations-and-content-premarket — that page confirms the February 2026 final, Docket FDA-2021-D-1158, supersedes the June 27, 2025 final, which in turn superseded the September 27, 2023 final; retitled "Quality Management System Considerations..." in the current version). Statutory attribution corrected: section 524B was added to the FD&C Act by §3305 of the Consolidated Appropriations Act, 2023 ("Ensuring Cybersecurity of Medical Devices"), effective March 29, 2023 — the PATCH Act itself was never enacted (confirmed on FDA's Cybersecurity page). Quantitative repairs, each checked against its source: "257,000 device types / 22,000 facilities" was unsourceable and did not match FDA's own figures — replaced with FDA at a Glance, Jan 2024 (>6,500 device products; 25,901 registered device facilities; https://www.fda.gov/media/175664/download). Breach-cost claim re-anchored to IBM's 2023 Cost of a Data Breach findings ($10.93M healthcare average, highest industry 13 years running; https://www.ibm.com/think/insights/cost-of-a-data-breach-healthcare-industry). The 700%-deficiency-letter increase is MedCrypt's observation across its client base, and the fifteen-deficiencies average is an FDA public statement reported by MedCrypt — both now attributed (MedCrypt, "One Year Later," Naomi Schwartz, 2024-10-02, https://www.medcrypt.com/blog/one-year-later-the-impact-of-the-patch-act-and-final-premarket-guidance-on-medical-device-cybersecurity). Lifecycle claim ("10–20 yr vs 3–5 yr") re-anchored to the FBI PIN's verified language (hardware active 10–30 yr, software life cycles far shorter, no manufacturer support for legacy devices); the unverified "Windows XP / old embedded Linux" example was softened, and the FBI's 53%-of-connected-devices figure added. The 2026-08-18 retag rationale above kept its original wording; the corrected differential (10–30 yr vs shorter software support) still satisfies the temporal:mismatch sub-type. Postmarket guidance PDF URL in these notes re-verified live (December 2016 final, Docket FDA-2015-D-5105). All Source-line URLs verified live 2026-08-20.