Medical Device Hacking and the Vulnerability of Connected Medical Devices
I work on medical device cybersecurity because the failure mode is a person, not a spreadsheet. That reframes every argument about cost, timeline, and what good enough looks like.

The takeaways
- 01
Every connected medical device is an attack surface, and most were designed before that sentence was true.
- 02
FD&C Act 524B moved cybersecurity from nice-to-have to a gate for market clearance.
- 03
The hard part is almost never the technology. It is the team culture that thought cybersecurity was someone else's job.
- 04
Threat modeling early costs a fraction of what a post-market vulnerability disclosure costs.
Hacked medical devices are now a top security threat. Pacemakers, hospital equipment, anything connected wirelessly can be compromised. I spoke with Kim on Komando on Demand about the myths and realities of medical device hacking and security. We discussed what’s being done to make devices and hospitals more secure.
“A vulnerability in a medical device is not a data breach. It is a patient safety event with a network stack.”
Frequently asked