When Security Meets Patient Care: How Health Tech Startups, Rural Hospitals, and PE Investors Can Secure Connected Medical Devices

September 26, 2026
September 26, 2026
By Melissa Thornton, CISSP | Cybersecurity Advisory Group | cyberadvisor.tech
Device inventory graphic illustrating the connected medical device landscape discussed in this article

‍

On September 3, I connected virtually to the conference at NIST’s Gaithersburg campus for a session called the Medical Device Cybersecurity Roundtable, part of the “Safeguarding Health Information” conference NIST and HHS’s Office for Civil Rights run together. A NIST engineer moderated a panel that included a cybersecurity specialist from FDA’s device center, the clinical engineering lead at a health system, the CISO of a major device manufacturer, and a university researcher who has spent two decades finding vulnerabilities in pacemakers and infusion pumps. Forty-five minutes was not enough.

What the panel kept circling back to is a structural problem with no real equivalent in corporate IT: healthcare runs on a “many-to-many” technology ecosystem. A standard IT department manages laptops, servers, and cloud instances from a handful of vendors on a couple of standardized operating systems. A hospital manages equipment that clinicians selected for what it does for a patient, not for how well it fits a patch cycle.

Panelists put real numbers to that gap. One example on the table: a regional hospital network running around 80,000 active medical devices, sourced from nearly a thousand different manufacturers, spanning thousands of distinct makes and models. Another: a single regional health system managing roughly 20,000 networked devices, running on dozens of proprietary software builds, unsupported legacy operating systems, and just as many different vendor maintenance agreements. For a small practice or a critical access hospital, where one IT person or an outsourced provider is already covering security, compliance, and clinical support, that scale is not a project. It is the whole job.

What FDA Section 524B actually requires

‍

The federal response to this problem has a name and a timeline. Section 524B of the Food, Drug, and Cosmetic Act, added by the Consolidated Appropriations Act of 2023 and in effect since March 29, 2023, gave the FDA explicit authority to require cybersecurity information in premarket submissions for “cyber devices”: a medical device that includes software, can connect to the internet or a network directly or indirectly, and has characteristics that make it vulnerable to cyber threats (FDA).

For health tech founders and MedTech developers, that authority now shows up as three concrete requirements in every premarket submission:

  • A postmarket cybersecurity management plan. Sponsors have to show how they will monitor, identify, and address vulnerabilities for as long as the device is on the market, including a process for coordinated disclosure.
  • A software bill of materials (SBOM). A transparent, ideally machine-readable inventory of every commercial, open-source, and third-party software component in the device, built to the National Telecommunications and Information Administration’s minimum elements. Much like an ingredient label, it lets a hospital determine in minutes whether a newly disclosed vulnerability affects equipment it already owns.
  • Secure-by-design evidence. Manufacturers need to demonstrate the device is designed to stay secure in its intended environment and can receive patches and updates throughout its life, generally through a documented secure product development process (Black Duck; FDA final guidance, June 27, 2025).

None of this is theoretical for the people evaluating your company. For healthcare PE firms running diligence on a MedTech acquisition, and for health tech founders trying to close an enterprise sale, an incomplete SBOM or a device architecture that cannot receive patches is not a paperwork problem. It is delayed FDA clearance, a stalled deal, and a cyber liability somebody has to underwrite.

Devices bought before March 2023 did not get a pass

‍

Section 524B applies to new submissions. It does nothing about the enormous volume of equipment already running in hospitals and clinics today. Devices purchased before the cutoff were grandfathered in, and many lack basic enterprise security capabilities: central directory integration, unique user authentication, or an operating system that can be patched at all.

Standard IT remediation does not translate to this environment:

  • Endpoint agents can break devices. Installing off-the-shelf endpoint detection and response or antivirus software on medical equipment can freeze performance, void the manufacturer’s warranty, or invalidate the device’s regulatory clearance.
  • Vulnerability scanning is a routine MSP task that can crash clinical equipment. Active network scans have been known to lock up or crash infusion pumps and other delicate devices.
  • Patch timelines run long. Panelists described a six-to-twelve-month window as typical between a manufacturer disclosing a vulnerability and a validated patch being safe to deploy against clinical software.

Because legacy equipment cannot be swapped out overnight, the practical answer is compensating controls rather than direct remediation: segmenting legacy devices onto their own VLANs, enforcing zero-trust microsegmentation, and restricting external network traffic by default so an unpatchable device is at least contained.

Break-glass: why the badge reader cannot work like the login screen

‍

The tension between security and care delivery is most acute at the bedside. Standard IT security leans on 15-minute screen lockouts, complex passwords, and multi-factor authentication. Applying that directly to a crash cart or a ventilator is not a compliance win, it is a patient safety risk. A clinician reaching for a defibrillator during a cardiac arrest cannot be held up by an MFA prompt.

That is the case for the “break-glass” principle: security architecture built to accommodate emergency clinical overrides, through controls that are workflow-aware rather than one-size-fits-all:

  • Proximity-based badge readers or biometric authentication in clinical areas instead of manual password entry.
  • Role-based session management that keeps clinical interfaces active while still isolating background network traffic.
  • Direct, standing communication channels between biomedical engineering, IT security, and clinical leadership, so a control is never deployed without someone checking what it does to patient care first.

Where this leaves you, depending on where you sit

‍

If you are building health technology: Section 524B is now a gate on your FDA clearance and increasingly a line item in enterprise procurement. An SBOM you cannot produce on request, or a postmarket plan that reads like boilerplate, will surface in due diligence long before it surfaces in an audit.

If you run a rural hospital or a small practice: you almost certainly cannot rip and replace your way to compliance, and you don’t need to. A prioritized risk assessment tells you which legacy devices need segmentation now, which need a compensating control, and which genuinely need to be retired.

If you invest in healthcare: biomedical and device risk belongs in the same diligence conversation as HIPAA compliance and cyber liability, not a separate track that gets a rubber stamp. An unpatchable device fleet is a portfolio-level cost, not a facilities issue.

How Cybersecurity Advisory Group helps

‍

Securing connected medical devices sits at the intersection of federal regulation, legacy IT reality, and clinical workflow, and it is rarely work your MSP is equipped to do. MSPs are essential for keeping the network running, but auditing a vendor’s SBOM or building independent security governance is a different discipline. As a fractional CISO firm working across healthcare, private equity, and small business, I provide the executive-level judgment to build a defensible, business-aligned program, without the cost of a full-time CISO whose base salary alone often exceeds $200,000 a year.

  • Biomedical & Infrastructure Risk Assessments: mapping connected medical assets, identifying legacy software debt, and designing compensating controls, like zero-trust microsegmentation, that protect clinical systems without disrupting care.
  • Health Tech & MedTech Vendor Governance: helping digital health startups with FDA 524B alignment, SBOM documentation, SOC 2 readiness, and enterprise B2B security reviews.
  • Healthcare PE Due Diligence: evaluating cyber liabilities, unaddressed HIPAA gaps, and biomedical tech debt during acquisition diligence, before they become a post-close surprise.
  • Cyber Insurance & Regulatory Readiness: preparing small practices and rural facilities for insurance renewals, OCR audits, and emergency downtime procedures.

Start with 30 minutes

‍

Cybersecurity Advisory Group provides healthcare cybersecurity consulting without the Fortune 500 price tag. Whether you are navigating legacy device risk, preparing for an enterprise client’s security review, or evaluating a MedTech target, a HIPAA Risk Assessment & Compliance Program or a vCISO Retainer is the place to start.

Book a free 30-minute Security Clarity Session. We’ll go through where your device and network controls actually stand today and what a realistic first year looks like. No pressure, no jargon, and no homework before we talk.

Book Your Free 30-Minute Security Clarity Session →

‍

Melissa Thornton is the founder of Cybersecurity Advisory Group, providing virtual CISO and fractional cybersecurity leadership to healthcare organizations, startups, and SMBs. Based in White Plains, NY, serving clients remotely nationwide. sales@cyberadvisor.tech · +1 914-517-0022

This article is provided for general informational purposes and does not constitute legal advice.

Connect with Melissa Thornton on LinkedIn

Sources

‍

Related Blogs

September 2, 2026
September 2, 2026

$11.5 Million Is the Average. You're Not Average — And That's the Problem.

Read More
September 1, 2026
September 1, 2026

Nobody Told Them To

Read More
Card headed “Every record you no longer hold is exposure you no longer need to insure.” What sizes a limit is not how many clients you have but when a record leaves your systems — usually it never does. Retention and secure disposal cut exposure.
September 18, 2026
September 18, 2026

How Much Cyber Insurance Should You Buy, and How Much Should You Pay?

Read More