

On September 3, I connected virtually to the conference at NIST’s Gaithersburg campus for a session called the Medical Device Cybersecurity Roundtable, part of the “Safeguarding Health Information” conference NIST and HHS’s Office for Civil Rights run together. A NIST engineer moderated a panel that included a cybersecurity specialist from FDA’s device center, the clinical engineering lead at a health system, the CISO of a major device manufacturer, and a university researcher who has spent two decades finding vulnerabilities in pacemakers and infusion pumps. Forty-five minutes was not enough.
What the panel kept circling back to is a structural problem with no real equivalent in corporate IT: healthcare runs on a “many-to-many” technology ecosystem. A standard IT department manages laptops, servers, and cloud instances from a handful of vendors on a couple of standardized operating systems. A hospital manages equipment that clinicians selected for what it does for a patient, not for how well it fits a patch cycle.
Panelists put real numbers to that gap. One example on the table: a regional hospital network running around 80,000 active medical devices, sourced from nearly a thousand different manufacturers, spanning thousands of distinct makes and models. Another: a single regional health system managing roughly 20,000 networked devices, running on dozens of proprietary software builds, unsupported legacy operating systems, and just as many different vendor maintenance agreements. For a small practice or a critical access hospital, where one IT person or an outsourced provider is already covering security, compliance, and clinical support, that scale is not a project. It is the whole job.
The federal response to this problem has a name and a timeline. Section 524B of the Food, Drug, and Cosmetic Act, added by the Consolidated Appropriations Act of 2023 and in effect since March 29, 2023, gave the FDA explicit authority to require cybersecurity information in premarket submissions for “cyber devices”: a medical device that includes software, can connect to the internet or a network directly or indirectly, and has characteristics that make it vulnerable to cyber threats (FDA).
For health tech founders and MedTech developers, that authority now shows up as three concrete requirements in every premarket submission:
None of this is theoretical for the people evaluating your company. For healthcare PE firms running diligence on a MedTech acquisition, and for health tech founders trying to close an enterprise sale, an incomplete SBOM or a device architecture that cannot receive patches is not a paperwork problem. It is delayed FDA clearance, a stalled deal, and a cyber liability somebody has to underwrite.
Section 524B applies to new submissions. It does nothing about the enormous volume of equipment already running in hospitals and clinics today. Devices purchased before the cutoff were grandfathered in, and many lack basic enterprise security capabilities: central directory integration, unique user authentication, or an operating system that can be patched at all.
Standard IT remediation does not translate to this environment:
Because legacy equipment cannot be swapped out overnight, the practical answer is compensating controls rather than direct remediation: segmenting legacy devices onto their own VLANs, enforcing zero-trust microsegmentation, and restricting external network traffic by default so an unpatchable device is at least contained.
The tension between security and care delivery is most acute at the bedside. Standard IT security leans on 15-minute screen lockouts, complex passwords, and multi-factor authentication. Applying that directly to a crash cart or a ventilator is not a compliance win, it is a patient safety risk. A clinician reaching for a defibrillator during a cardiac arrest cannot be held up by an MFA prompt.
That is the case for the “break-glass” principle: security architecture built to accommodate emergency clinical overrides, through controls that are workflow-aware rather than one-size-fits-all:
If you are building health technology: Section 524B is now a gate on your FDA clearance and increasingly a line item in enterprise procurement. An SBOM you cannot produce on request, or a postmarket plan that reads like boilerplate, will surface in due diligence long before it surfaces in an audit.
If you run a rural hospital or a small practice: you almost certainly cannot rip and replace your way to compliance, and you don’t need to. A prioritized risk assessment tells you which legacy devices need segmentation now, which need a compensating control, and which genuinely need to be retired.
If you invest in healthcare: biomedical and device risk belongs in the same diligence conversation as HIPAA compliance and cyber liability, not a separate track that gets a rubber stamp. An unpatchable device fleet is a portfolio-level cost, not a facilities issue.
Securing connected medical devices sits at the intersection of federal regulation, legacy IT reality, and clinical workflow, and it is rarely work your MSP is equipped to do. MSPs are essential for keeping the network running, but auditing a vendor’s SBOM or building independent security governance is a different discipline. As a fractional CISO firm working across healthcare, private equity, and small business, I provide the executive-level judgment to build a defensible, business-aligned program, without the cost of a full-time CISO whose base salary alone often exceeds $200,000 a year.
Cybersecurity Advisory Group provides healthcare cybersecurity consulting without the Fortune 500 price tag. Whether you are navigating legacy device risk, preparing for an enterprise client’s security review, or evaluating a MedTech target, a HIPAA Risk Assessment & Compliance Program or a vCISO Retainer is the place to start.
Book a free 30-minute Security Clarity Session. We’ll go through where your device and network controls actually stand today and what a realistic first year looks like. No pressure, no jargon, and no homework before we talk.
Book Your Free 30-Minute Security Clarity Session →
Melissa Thornton is the founder of Cybersecurity Advisory Group, providing virtual CISO and fractional cybersecurity leadership to healthcare organizations, startups, and SMBs. Based in White Plains, NY, serving clients remotely nationwide. sales@cyberadvisor.tech · +1 914-517-0022
This article is provided for general informational purposes and does not constitute legal advice.
Connect with Melissa Thornton on LinkedIn