Skip to content
Cybersecurity

Medical Device Hacking and the Vulnerability of Connected Medical Devices

November 13, 20181 min read78 words

I work on medical device cybersecurity because the failure mode is a person, not a spreadsheet. That reframes every argument about cost, timeline, and what good enough looks like.

A bedside patient monitor and IV infusion pump glowing in a dim, blue-lit hospital room, illustrating the connected medical devices at risk when hospital networks are compromised.

The takeaways

  1. 01

    Every connected medical device is an attack surface, and most were designed before that sentence was true.

    What to do nextAdd medical to the next leadership review as a standing item, not a one-time slide.

  2. 02

    FD&C Act 524B moved cybersecurity from nice-to-have to a gate for market clearance.

    What to do nextRun a 20-minute tabletop with your team this month using market as the scenario.

  3. 03

    The hard part is almost never the technology. It is the team culture that thought cybersecurity was someone else's job.

    What to do nextRun a 20-minute tabletop with your team this month using team as the scenario.

  4. 04

    Threat modeling early costs a fraction of what a post-market vulnerability disclosure costs.

    What to do nextOpen your current threat plan today and identify the one gap you would not want an auditor to find.

Hacked medical devices are now a top security threat. Pacemakers, hospital equipment, anything connected wirelessly can be compromised. I spoke with Kim on Komando on Demand about the myths and realities of medical device hacking and security. We discussed what’s being done to make devices and hospitals more secure.

“A vulnerability in a medical device is not a data breach. It is a patient safety event with a network stack.”

Frequently asked

Share this essay

Christian Espinosa, headshot

About the author

Christian Espinosa · Founder & CEO, Blue Goat Cyber

Christian is the founder and CEO of Blue Goat Cyber, a medical device cybersecurity firm. He's an Air Force Academy graduate, 24x Ironman, climber of two of the Seven Summits, and the author of The Smartest Person in the Room and The In-Between: Life in the Micro.

Keep reading