Security Magazine logo
search
cart
facebook twitter linkedin youtube
  • Sign In
  • Create Account
  • Sign Out
  • My Account
Security Magazine logo
  • NEWS
    • Security Newswire
    • Technologies & Solutions
  • MANAGEMENT
    • Leadership Management
    • Enterprise Services
    • Security Education & Training
    • Logical Security
    • Security & Business Resilience
    • Profiles in Excellence
  • PHYSICAL
    • Access Management
    • Fire & Life Safety
    • Identity Management
    • Physical Security
    • Video Surveillance
    • Case Studies (Physical)
  • CYBER
    • Cybersecurity News
    • More
  • BLOG
  • COLUMNS
    • Career Intelligence
    • Cyber Tactics
    • Cybersecurity Education & Training
    • Leadership & Management
    • Security Talk
  • EXCLUSIVES
    • Annual Guarding Report
    • Most Influential People in Security
    • The Security Benchmark Report
    • Top Guard and Security Officer Companies
    • Top Cybersecurity Leaders
    • Women in Security
  • SECTORS
    • Arenas / Stadiums / Leagues / Entertainment
    • Banking/Finance/Insurance
    • Construction, Real Estate, Property Management
    • Education: K-12
    • Education: University
    • Government: Federal, State and Local
    • Hospitality & Casinos
    • Hospitals & Medical Centers
    • Infrastructure:Electric,Gas & Water
    • Ports: Sea, Land, & Air
    • Retail/Restaurants/Convenience
    • Transportation/Logistics/Supply Chain/Distribution/ Warehousing
  • EVENTS
    • Industry Events
    • Webinars
    • Solutions by Sector
    • Security 500 Conference
  • MEDIA
    • Interactive Spotlight
    • Photo Galleries
    • Podcasts
    • Polls
    • Videos
      • Cybersecurity & Geopolitical Discussion
      • Ask Me Anything (AMA) Series
  • MORE
    • Call for Entries
    • Classifieds & Job Listings
    • Newsletter
    • Sponsor Insights
    • Store
    • White Papers
  • EMAG
    • eMagazine
    • This Month's Content
    • Advertise
  • SIGN UP!
CybersecurityManagementSecurity NewswireSecurity Leadership and ManagementLogical SecuritySecurity Education & TrainingCybersecurity NewsHospitals & Medical Centers

Healthcare organizations must prepare for looming cybersecurity legislation

By Dave Bailey
medical device security

Image from Pixabay

August 1, 2022

As the healthcare industry faces growing cybersecurity threats, Senators Rosen and Young recently introduced a bill targeting one particularly concerning issue: The Strengthening Cybersecurity for Medical Devices Act would require the FDA to ensure medical devices are protected from hackers. Working with CISA and the GAO, the FDA would update policies, identify vulnerabilities, draft guidelines, improve coordination of resources – and conduct regular, biannual updates.

While the industry is prepared for new regulations, companies cannot afford to wait for Congress to act. Organizations must proactively improve their protections ahead of this legislation, rather than risking lives and businesses during a period of hyperaggressive attacks on medical targets.

A dynamic landscape

This all comes at a critical time for healthcare. Hospitals are shifting from pen-and-paper records to digital databases. Devices are now valuable for both the care they provide and the subsequent data they generate.

Yet these transformations have expanded organizations’ attack surfaces, exposing them to new threats. Beyond the danger of threats themselves, healthcare is unique in the degree to which those threats tangibly impact patient care and lives. The Ponemon Institute reported that nearly 25% of providers suffered increased mortality rates following attacks; 70% said attacks led to treatment delays, contributing to poorer outcomes.

How this bill makes a difference

The new bill could, for the first time, introduce much-needed guidance and rigor into securing and protecting devices. Understanding the risks associated with network-connected medical devices is critical in proactively managing and mitigating risk. Having more frequent guidance and understanding the resources made available by the government can reduce risk and help organizations build resilience. Security is critical in all phases of system development lifecycles, and everyone must do their part in understanding today’s threats, knowing the state of their security posture, and what actions must be taken to mitigate risk. This holds true for improved security architecture design by the manufacturers or the ability of a provider to patch vulnerabilities within a hospital network.

The bill is flexible, recognizing the ever-changing nature of cyber attackers and the need for regular review and updating. The potential downside of this approach is it lacks specificity, and it’s not clear how it will be enforced and what the penalties will be for non-compliance.

There are a few key elements to bring cybersecurity requirements for FDA-approved medical devices across their entire lifecycle — starting with requiring the pre-market approval of all components, including a Software Bill of Materials, continuing to post-market requirements for management of vulnerabilities, through to ensuring a secure decommissioning process. These requirements are designed to ensure medical devices are developed with security in mind, and maintained in a way that keeps patient and data safety a priority.

Get ahead of the curve

While this latest bill would provide welcome guidance for the industry, organizations shouldn’t wait to prepare: The time to establish proactive cybersecurity measures is now. Instead of reacting to cybersecurity laws when they arrive, organizations should proactively improve their practices and treat future legislation as validation.

The process of securing medical devices begins with several initial steps.

  1. Ensure full visibility: Organizations often underestimate their numbers and types of network-connected devices. Creating a robust map of connected devices is the first and most critical step in securing a network.
  2. Test and assess regularly: Cybersecurity is a journey, not a destination. As the bill suggests, regularly scheduled reassessments are critical to modern cybersecurity.
  3. Remain proactive and vigilant: Adopting a proactive, vigilant cybersecurity program will ensure the integrity and security of medical devices, as well as broader networks.

A new standard in medical device security

The Strengthening Cybersecurity in Medical Devices Act marks a welcome shift in medical device cybersecurity, with the potential to introduce unprecedented standards and rigor in ensuring the integrity of medical devices. This added enforcement will translate to peace of mind for patients, who can trust that medical device OEMs and owners have comprehensively secured their devices from the ground up, from manufacturing through implementation and operation.

As this legislation takes shape, however, it remains imperative that healthcare providers remain on the front foot with regard to their security, treating new legislation as validation of their existing approach, rather than an impetus for change.

KEYWORDS: cyber security legislation health care security medical device security pen testing proactive security risk assessment

Share This Story

Looking for a reprint of this article?
From high-res PDFs to custom plaques, order your copy today!

Dave Bailey is Vice President, Security Services at CynergisTek.

Recommended Content

JOIN TODAY
To unlock your recommendations.

Already have an account? Sign In

  • Cyber tech background

    Security’s Top Cybersecurity Leaders 2026

    Security magazine’s Top Cybersecurity Leaders 2026 award...
    Cybersecurity
  • Iintegration and use of emerging tools

    Future Proof Your Security Career with AI Skills

    AI’s evolution demands security leaders master...
    Career Intelligence
    By: Jerry J. Brennan and Joanne R. Pollock
  • The 2025 Security Benchmark Report

    The 2025 Security Benchmark Report

    The 2025 Security Benchmark Report surveys enterprise...
    The Security Benchmark Report
    By: Rachelle Blair-Frasier
Manage My Account
  • Security Newsletter
  • eMagazine Subscriptions
  • Manage My Preferences
  • Online Registration
  • Mobile App
  • Subscription Customer Service

More Videos

Popular Stories

Opened padlock on computer keyboard

10 Data Breaches to Know About (April 2026)

Laptop with desktop screen showing

Research: Microsoft Edge Loads Stored Passwords in Cleartext

Diverse Team Collaborating on Business Analysis

12 Tips for Building an Effective Security Budget

SEC Podcast Header Podcast

Credential Management in High Turnover Environments

Laptop in darkness

Reframing MFA Bypass: Four Identity Gaps Attackers Exploit

SEC 2026 Benchmark Banner

Events

June 3, 2026

The Role of AI and Video in Measuring Health, Safety, and Security Standards

OSHA fines grab headlines, but most compliance issues start with everyday operational gaps: missed protocols, unsecured areas, or slow response. Learn how emerging technologies & AI can be leveraged towards a more proactive model of compliance.

June 10, 2026

Applying Agentic AI in Security Operations for Faster Decisions & Better Outcomes

Security teams have never had more visibility. We’ll explore how a new decision layer is helping security teams move from detection to decision. Turn alerts into decision-ready context, reducing reliance on manual triage and enabling faster action.

View All Submit An Event

Products

Security Culture: A How-to Guide for Improving Security Culture and Dealing with People Risk in Your Organisation

Security Culture: A How-to Guide for Improving Security Culture and Dealing with People Risk in Your Organisation

See More Products


The Role of AI and Video - Free Webinar - June 3, 2026

Related Articles

  • Here are the top political and security risks for 2021 that your organization needs to take prepare for

    Organizations must prepare for these 2021 security risks now, or may fail to make it in a post-COVID world

    See More
  • AI computer chip

    AI-Generated Image-Based Harm Is Becoming a Security Issue — Organizations Must Prepare

    See More
  • healthcare-screen

    Healthcare Organizations Must Balance the Growing Cybersecurity Threat Landscape with Meeting Regulatory Mandates

    See More

Related Products

See More Products
  • security culture.webp

    Security Culture: A How-to Guide for Improving Security Culture and Dealing with People Risk in Your Organisation

  • 150 things.jpg

    The Handbook for School Safety and Security

See More Products
×

Sign-up to receive top management & result-driven techniques in the industry.

Join over 20,000+ industry leaders who receive our premium content.

SIGN UP TODAY!
  • RESOURCES
    • Advertise
    • Contact Us
    • Store
    • Want More
  • SIGN UP TODAY
    • Create Account
    • eMagazine
    • Newsletter
    • Customer Service
    • Manage Preferences
  • SERVICES
    • Marketing Services
    • Reprints
    • Market Research
    • List Rental
    • Survey/Respondent Access
  • STAY CONNECTED
    • LinkedIn
    • Facebook
    • YouTube
    • X (Twitter)
  • PRIVACY
    • PRIVACY POLICY
    • TERMS & CONDITIONS
    • DO NOT SELL MY PERSONAL INFORMATION
    • PRIVACY REQUEST
    • ACCESSIBILITY

Copyright ©2026. All Rights Reserved BNP Media, Inc. and BNP Media II, LLC.

Design, CMS, Hosting & Web Development :: ePublishing