How to Secure Connected Medical Devices Safely

TL;DR
Medical device security requires protecting devices, network identities, communications, and operational management without obstructing patient care. Healthcare organizations face ransomware, phishing, partner breaches, data breaches, and insider threats, while long-lived devices often have limited computing capacity. Manufacturers are improving by adding security features, establishing product security leadership, and developing more constructive vulnerability disclosure practices.
Transcript
Okay. Well, good afternoon, everybody. Um, I am fully aware that we are in the dreaded after-lunch nap time slot. And so I'm gonna ask you all to help us keep this as lively as possible. Um, we've brought together some really amazing experts here with different perspectives on the topic of medical device security from the Health ISAC. Erol See is r... Read More
Key Insights
- Healthcare cyber threats are broader than direct device manipulation. Health-ISAC members identified ransomware, phishing, third-party and partner breaches, data breaches, and insider threats as their five leading concerns for both 2021 and 2022.
- Nation-sponsored cyber activity during 2021 focused on stealing intellectual property connected to COVID vaccines, research, development, and treatment. The panel specifically associated active interest and recruitment efforts with China, Russia, and North Korea.
- Ransomware can disrupt healthcare operations when hospitals and security teams are already under pressure. During COVID, hospitals faced large numbers of seriously ill patients while security personnel worked remotely and struggled to keep networks secure.
- Medical devices often remain in service longer than ordinary IT systems. Their extended operational lives can preserve legacy infrastructure and security limitations that must be managed long after conventional computing equipment would normally be replaced.
- Limited computing capacity can restrict security options in connected medical devices. Adding complex algorithms may exceed available processing resources, while greater product complexity can also make medical device certification more challenging.
- Network isolation can conflict with clinical value because connected devices need to exchange data. Manufacturers may advise customers not to connect products, but clinicians often gain the greatest benefit when devices interoperate within healthcare environments.
- Medical device security includes the device, its network identity, its communications, and its management processes. Healthcare organizations must consider authentication, encryption, wired or wireless connectivity, provisioning, monitoring, and the operational effort required to deploy each product.
- Manufacturer security culture has improved over roughly 10 to 20 years. More mature companies now provide security contacts, work with vulnerability researchers, add product security features, and appoint chief product security officers dedicated to securing products rather than corporate systems.
Install to Summarize YouTube Videos and Get Transcripts
Explore YouTube Video Summarizer or Get YouTube Transcript Extractor
Questions & Answers
Q: What are the biggest cybersecurity threats facing healthcare organizations?
Health-ISAC members identified ransomware, phishing, third-party and partner breaches, data breaches, and insider threats as the five leading cybersecurity concerns. Survey responses named the same categories for challenges experienced in 2021 and those expected in 2022. These risks affect healthcare delivery organizations, medical device manufacturers, and other health-sector participants, showing that the threat landscape extends beyond attacks that directly manipulate individual devices.
Q: Why is ransomware especially dangerous for healthcare operations?
Ransomware can impair healthcare operations when hospitals and their security personnel are already under severe pressure. During COVID, hospitals were overwhelmed with seriously ill patients, while security teams also had to work remotely and protect their networks under difficult conditions. Ransomware added another operational burden, creating significant challenges for organizations whose systems and connected technologies support the delivery of patient care.
Q: Why are connected medical devices difficult to secure?
Connected medical devices may remain in service longer than normal IT equipment and often operate with less computing power. Those constraints can limit the use of complex security algorithms. Adding complexity may also make certification more challenging. At the same time, devices need to exchange data with other systems, so healthcare organizations cannot always follow the simple recommendation to keep them disconnected from every network.
Q: Why can hospitals not simply isolate medical devices from networks?
Network isolation can reduce exposure, but it can also eliminate much of a medical device's clinical value. Clinicians often benefit most when devices can transfer data and interoperate with other systems. Manufacturers may state that a product should not be connected, yet healthcare environments frequently require wired or wireless connectivity. Security planning must therefore address real operational use instead of assuming every device can remain isolated.
Q: What parts of a medical device must be protected?
Medical device security covers several connected concerns. Organizations must protect the physical device and prevent changes that could affect a patient. They must also manage the device's identity and behavior on wired or wireless networks, secure its communications, and provide workable provisioning and management tools. Authentication and encryption are important questions, but deployment effort and ongoing operational support also shape whether controls are practical.
Q: How has medical device vulnerability disclosure improved?
Manufacturer responses to vulnerability reports have become more constructive. Earlier in the industry's development, researchers could contact a manufacturer and be transferred immediately to its legal department, while security contact information might be absent from the company's website. More mature manufacturers now lean into vulnerability management, maintain security contacts, and create dedicated product security roles that can address reports as security issues rather than only legal concerns.
Q: What does a chief product security officer do for a manufacturer?
A chief product security officer focuses specifically on the security of products rather than the security of the manufacturer's general corporate business. The emergence of this role reflects greater maturity within the manufacturing community. It provides clearer ownership for security features, vulnerability handling, and product-focused risk management, helping manufacturers respond more effectively to researchers and customers concerned about the security of connected devices.
Q: How can manufacturers make medical device security operationally practical?
Manufacturers must address authentication, encryption, connectivity, communications, provisioning, and management as parts of a usable system. A healthcare organization may purchase an expensive connected device, but security becomes difficult if technicians must spend excessive time placing it on the network. Effective protection therefore depends not only on controls inside the product, but also on tools and processes that support efficient deployment and ongoing management.
Summary & Key Takeaways
-
Healthcare organizations face a broad threat landscape rather than only dramatic attacks on insulin pumps or pacemakers. Health-ISAC members identified ransomware, phishing, third-party and partner breaches, data breaches, and insider threats as leading concerns for both 2021 and 2022, while nation-sponsored activity targeted COVID vaccine and treatment research.
-
Medical devices create distinctive security challenges because they remain operational longer than ordinary IT equipment, may lack the computing capacity for complex security algorithms, and can require renewed certification when complexity increases. Although isolation is sometimes recommended, clinical value often depends on transferring data through interconnected hospital environments.
-
The industry has made meaningful progress over roughly 10 to 20 years. More manufacturers now build security features into products, publish appropriate security contacts, engage constructively with vulnerability researchers, and appoint chief product security officers. However, authentication, encryption, communications protection, provisioning, and efficient network management remain practical concerns for healthcare operators.
-
Key Insights
Read in Other Languages (beta)
Share This Summary 📚
Summarize YouTube Videos and Get Video Transcripts with 1-Click
Try YouTube Summary with ChatGPT & Claude or YouTube Transcript Generator
Explore More Summaries from RSAC Cybersecurity 📚






Summarize YouTube Videos and Get Video Transcripts with 1-Click
Try YouTube Summary with ChatGPT & Claude or YouTube Transcript Generator