---
title: "Medical Device Hacking and the Vulnerability of Connected…"
description: "Explore the rising threat of medical device hacking with expert Christian Espinosa, learning how to secure wireless medical equipment and hospitals."
lang: en
json-ld: |
  [
    {
      "@context": "https://schema.org",
      "@type": "Person",
      "@id": "https://christianespinosa.com/#person",
      "name": "Christian Espinosa",
      "url": "https://christianespinosa.com/",
      "image": "https://christianespinosa.com/__l5e/assets-v1/de07e44b-a8e0-4bcc-bcb0-13aec15421f1/headshot-front.jpg",
      "sameAs": [
        "https://www.facebook.com/christian.espinosa.official",
        "https://x.com/Ironracer",
        "https://www.instagram.com/christian.espinosa.official/",
        "https://www.youtube.com/@ChristianEspinosaOfficial",
        "https://www.linkedin.com/in/christianespinosa/"
      ],
      "jobTitle": "Bestselling Author, Keynote Speaker, Entrepreneur",
      "worksFor": {
        "@type": "Organization",
        "name": "Blue Goat Cyber",
        "url": "https://bluegoatcyber.com/"
      }
    },
    {
      "@context": "https://schema.org",
      "@type": "WebSite",
      "@id": "https://christianespinosa.com/#website",
      "name": "Christian Espinosa",
      "url": "https://christianespinosa.com/",
      "publisher": {
        "@id": "https://christianespinosa.com/#organization"
      },
      "inLanguage": "en-US"
    },
    {
      "@context": "https://schema.org",
      "@type": "Organization",
      "@id": "https://christianespinosa.com/#organization",
      "name": "Christian Espinosa",
      "url": "https://christianespinosa.com/",
      "logo": {
        "@type": "ImageObject",
        "url": "https://christianespinosa.com/logo.svg"
      },
      "founder": {
        "@id": "https://christianespinosa.com/#person"
      },
      "sameAs": [
        "https://www.facebook.com/christian.espinosa.official",
        "https://x.com/Ironracer",
        "https://www.instagram.com/christian.espinosa.official/",
        "https://www.youtube.com/@ChristianEspinosaOfficial",
        "https://www.linkedin.com/in/christianespinosa/"
      ]
    },
    {
      "@context": "https://schema.org",
      "@type": "Article",
      "headline": "Medical Device Hacking and the Vulnerability of Connected Medical Devices - Christian Espinosa",
      "description": "Explore the rising threat of medical device hacking with expert Christian Espinosa, learning how to secure wireless medical equipment and hospitals.",
      "image": "https://christianespinosa.com/__l5e/assets-v1/5a74b16a-2308-4287-90c2-4efd7de6d35b/medical-device-hacking-and-the-vulnerability-of-connected-medical-devices-card.png",
      "datePublished": "2018-11-13T06:06:24+00:00",
      "dateModified": "2026-06-26T05:35:59.061Z",
      "mainEntityOfPage": {
        "@type": "WebPage",
        "@id": "https://christianespinosa.com/blog/medical-device-hacking-and-the-vulnerability-of-connected-medical-devices"
      },
      "author": {
        "@type": "Person",
        "name": "Christian Espinosa",
        "url": "https://christianespinosa.com/about"
      },
      "publisher": {
        "@type": "Organization",
        "name": "Christian Espinosa",
        "logo": {
          "@type": "ImageObject",
          "url": "https://christianespinosa.com/logo.svg"
        }
      }
    },
    {
      "@context": "https://schema.org",
      "@type": "FAQPage",
      "mainEntity": [
        {
          "@type": "Question",
          "name": "Where should a small MedTech company start?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "Threat model the intended use, then the misuse. Then map every control to a specific 524B expectation. That single document unlocks most of the submission."
          }
        },
        {
          "@type": "Question",
          "name": "Is legacy device fleet a lost cause?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "No. It is an inventory problem first, a patching problem second, and a monitoring problem third. In that order."
          }
        }
      ]
    }
  ]
---

[Skip to content](#main)

[](/)

[About](/about)[Speaking](/speaking)[Cybersecurity](/cybersecurity)[Programs](/programs)[Books](/books)[Media](/media)

Writing

Search Ctrl K[Connect](/connect)

[Cybersecurity](/blog/category/cybersecurity)

# Medical Device Hacking and the Vulnerability of Connected Medical Devices

November 13, 2018 1 min read 78 words 

I work on medical device cybersecurity because the failure mode is a person, not a spreadsheet. That reframes every argument about cost, timeline, and what good enough looks like.

![A bedside patient monitor and IV infusion pump glowing in a dim, blue-lit hospital room, illustrating the connected medical devices at risk when hospital networks are compromised.](/__l5e/assets-v1/37227301-dd7f-4cd8-b54b-2b85e4729102/medical-device-hacking-and-the-vulnerability-of-connected-medical-devices-hero.jpg)

The takeaways

1.  01 
    
    Every connected medical device is an attack surface, and most were designed before that sentence was true.
    
    What to do next Add medical to the next leadership review as a standing item, not a one-time slide.
    
2.  02 
    
    FD&C Act 524B moved cybersecurity from nice-to-have to a gate for market clearance.
    
    What to do next Run a 20-minute tabletop with your team this month using market as the scenario.
    
3.  03 
    
    The hard part is almost never the technology. It is the team culture that thought cybersecurity was someone else's job.
    
    What to do next Run a 20-minute tabletop with your team this month using team as the scenario.
    
4.  04 
    
    Threat modeling early costs a fraction of what a post-market vulnerability disclosure costs.
    
    What to do next Open your current threat plan today and identify the one gap you would not want an auditor to find.
    

Hacked medical devices are now a top security threat. Pacemakers, hospital equipment, anything connected wirelessly can be compromised. I spoke with Kim on Komando on Demand about the myths and realities of medical device hacking and security. We discussed what’s being done to make devices and hospitals more secure.

> “A vulnerability in a medical device is not a data breach. It is a patient safety event with a network stack.”

Frequently asked

### Where should a small MedTech company start?

### Is legacy device fleet a lost cause?

### Work with me

I help founders and cybersecurity leaders build teams that ship, not teams that stall. If that's the problem you're trying to solve, let's talk.

[Start a conversation](/contact)

Share this essay

[X ](https://twitter.com/intent/tweet?url=https%3A%2F%2Fchristianespinosa.com%2Fblog%2Fmedical-device-hacking-and-the-vulnerability-of-connected-medical-devices&text=Medical%20Device%20Hacking%20and%20the%20Vulnerability%20of%20Connected%20Medical%20Devices) [LinkedIn](https://www.linkedin.com/sharing/share-offsite/?url=https%3A%2F%2Fchristianespinosa.com%2Fblog%2Fmedical-device-hacking-and-the-vulnerability-of-connected-medical-devices) [Facebook](https://www.facebook.com/sharer/sharer.php?u=https%3A%2F%2Fchristianespinosa.com%2Fblog%2Fmedical-device-hacking-and-the-vulnerability-of-connected-medical-devices) [Email](mailto:?subject=Medical%20Device%20Hacking%20and%20the%20Vulnerability%20of%20Connected%20Medical%20Devices&body=https%3A%2F%2Fchristianespinosa.com%2Fblog%2Fmedical-device-hacking-and-the-vulnerability-of-connected-medical-devices)Copy link 

![Christian Espinosa, headshot](/__l5e/assets-v1/de07e44b-a8e0-4bcc-bcb0-13aec15421f1/headshot-front.jpg)

About the author

[Christian Espinosa](/about) · Founder & CEO, Blue Goat Cyber

Christian is the founder and CEO of Blue Goat Cyber, a medical device cybersecurity firm. He's an Air Force Academy graduate, 24x Ironman, climber of two of the Seven Summits, and the author of The Smartest Person in the Room and The In-Between: Life in the Micro.

Keep reading

-   [
    
    ### Hacking Medical Devices for Profit and Terror - Christian Espinosa
    
    Same thread: cybersecurity.
    
    Read essay → ](/blog/hacking-medical-devices-for-profit-and-terror)
-   [
    
    ### Aviation Cybersecurity – Hacking Aircraft - Christian Espinosa
    
    Same thread: cybersecurity.
    
    Read essay → ](/blog/aviation-cybersecurity-hacking-aircraft)
-   [
    
    ### Leetspeak: The History of Hacking Subculture's Native Tongue - Christian Espinosa
    
    Same thread: cybersecurity.
    
    Read essay → ](/blog/leetspeak-the-history-of-hacking-subcultures-native-tongue)

[Next essay → 

Why Small Businesses Are Still the #1 Cybercrime Target in 2026 - Christian Espinosa

](/blog/70-of-cyber-attacks-will-be-against-small-businesses-in-2020)

Related, Cybersecurity

### Need medical-device or offensive security expertise?

Blue Goat Cyber, Christian's firm, runs FDA-aligned premarket submissions, penetration testing, and SBOM/SOUP analysis for medtech and high-stakes industries.

[Explore Blue Goat Cyber](/cybersecurity)

Christian Espinosa

Bestselling author, keynote speaker, and Founding CEO of [Blue Goat Cyber](https://bluegoatcyber.com/). Helping technical leaders develop the soft skills that turn brilliance into impact.

[](https://www.linkedin.com/in/christianespinosa/)[](https://x.com/Ironracer)[](https://www.instagram.com/christian.espinosa.official/)[](https://www.youtube.com/@ChristianEspinosaOfficial)[](https://www.facebook.com/christian.espinosa.official)

Explore

-   [About](/about)
-   [Timeline](/timeline)
-   [Speaking](/speaking)
-   [Cybersecurity](/cybersecurity)
-   [Programs](/programs)

Read

-   [Books](/books)
-   [Guides](/guides)
-   [Blog](/blog)
-   [Media](/media)
-   [Podcast Interviews](/podcasts)
-   [Success Stories](/success-stories)

Connect

-   [Contact Christian](/connect)
-   [LinkedIn ↗](https://www.linkedin.com/in/christianespinosa/)
-   [Blue Goat Cyber ↗](https://bluegoatcyber.com/)
-   [Resources](/resources)

© 2026 Christian Espinosa. All rights reserved.

[Privacy](/privacy-policy)[Terms](/terms-of-use)