Skip to content
Cybersecurity

Medical Device Hacking and the Vulnerability of Connected Medical Devices

I work on medical device cybersecurity because the failure mode is a person, not a spreadsheet. That reframes every argument about cost, timeline, and what good enough looks like.

The takeaways

  1. 01

    Every connected medical device is an attack surface, and most were designed before that sentence was true.

  2. 02

    FD&C Act 524B moved cybersecurity from nice-to-have to a gate for market clearance.

  3. 03

    The hard part is almost never the technology. It is the team culture that thought cybersecurity was someone else's job.

  4. 04

    Threat modeling early costs a fraction of what a post-market vulnerability disclosure costs.

Hacked medical devices are now a top security threat. Pacemakers, hospital equipment, anything connected wirelessly can be compromised. I spoke with Kim on Komando on Demand about the myths and realities of medical device hacking and security. We discussed what’s being done to make devices and hospitals more secure.

“A vulnerability in a medical device is not a data breach. It is a patient safety event with a network stack.”

Frequently asked

Christian Espinosa, headshot

About the author

Christian Espinosa · Founder, Blue Goat Cyber · Author · Speaker

I'm the founder and CEO of Blue Goat Cyber, a medical device cybersecurity firm where my team has supported 250+ FDA submissions with zero failing to clear on cybersecurity. I previously founded and sold Alpine Security. I host The Med Device Cyber Podcast and wrote The Smartest Person in the Room and The In-Between: Life in the Micro, with Medical Device Cybersecurity: An In-Depth Guide out in 2026. Air Force Academy grad, 24x Ironman, climber of two of the Seven Summits.