Security Magazine logo
search
cart
facebook twitter linkedin youtube
  • Sign In
  • Create Account
  • Sign Out
  • My Account
Security Magazine logo
  • NEWS
    • Security Newswire
    • Technologies & Solutions
  • MANAGEMENT
    • Leadership Management
    • Enterprise Services
    • Security Education & Training
    • Logical Security
    • Security & Business Resilience
    • Profiles in Excellence
  • PHYSICAL
    • Access Management
    • Fire & Life Safety
    • Identity Management
    • Physical Security
    • Video Surveillance
    • Case Studies (Physical)
  • CYBER
    • Cybersecurity News
    • More
  • BLOG
  • COLUMNS
    • Career Intelligence
    • Cyber Tactics
    • Cybersecurity Education & Training
    • Leadership & Management
    • Security Talk
  • EXCLUSIVES
    • Annual Guarding Report
    • Most Influential People in Security
    • The Security Benchmark Report
    • Top Guard and Security Officer Companies
    • Top Cybersecurity Leaders
    • Women in Security
  • SECTORS
    • Arenas / Stadiums / Leagues / Entertainment
    • Banking/Finance/Insurance
    • Construction, Real Estate, Property Management
    • Education: K-12
    • Education: University
    • Government: Federal, State and Local
    • Hospitality & Casinos
    • Hospitals & Medical Centers
    • Infrastructure:Electric,Gas & Water
    • Ports: Sea, Land, & Air
    • Retail/Restaurants/Convenience
    • Transportation/Logistics/Supply Chain/Distribution/ Warehousing
  • EVENTS
    • Industry Events
    • Webinars
    • Solutions by Sector
    • Security 500 Conference
  • MEDIA
    • Interactive Spotlight
    • Photo Galleries
    • Podcasts
    • Polls
    • Videos
      • Cybersecurity & Geopolitical Discussion
      • Ask Me Anything (AMA) Series
  • MORE
    • Call for Entries
    • Classifieds & Job Listings
    • Continuing Education
    • Newsletter
    • Sponsor Insights
    • Store
    • White Papers
  • EMAG
    • eMagazine
    • This Month's Content
    • Advertise
  • SIGN UP!
CybersecurityManagementSecurity NewswireSecurity Leadership and ManagementLogical SecuritySecurity Education & TrainingCybersecurity NewsHospitals & Medical Centers

Healthcare organizations must prepare for looming cybersecurity legislation

By Dave Bailey
medical device security

Image from Pixabay

August 1, 2022

As the healthcare industry faces growing cybersecurity threats, Senators Rosen and Young recently introduced a bill targeting one particularly concerning issue: The Strengthening Cybersecurity for Medical Devices Act would require the FDA to ensure medical devices are protected from hackers. Working with CISA and the GAO, the FDA would update policies, identify vulnerabilities, draft guidelines, improve coordination of resources – and conduct regular, biannual updates.

While the industry is prepared for new regulations, companies cannot afford to wait for Congress to act. Organizations must proactively improve their protections ahead of this legislation, rather than risking lives and businesses during a period of hyperaggressive attacks on medical targets.

A dynamic landscape

This all comes at a critical time for healthcare. Hospitals are shifting from pen-and-paper records to digital databases. Devices are now valuable for both the care they provide and the subsequent data they generate.

Yet these transformations have expanded organizations’ attack surfaces, exposing them to new threats. Beyond the danger of threats themselves, healthcare is unique in the degree to which those threats tangibly impact patient care and lives. The Ponemon Institute reported that nearly 25% of providers suffered increased mortality rates following attacks; 70% said attacks led to treatment delays, contributing to poorer outcomes.

How this bill makes a difference

The new bill could, for the first time, introduce much-needed guidance and rigor into securing and protecting devices. Understanding the risks associated with network-connected medical devices is critical in proactively managing and mitigating risk. Having more frequent guidance and understanding the resources made available by the government can reduce risk and help organizations build resilience. Security is critical in all phases of system development lifecycles, and everyone must do their part in understanding today’s threats, knowing the state of their security posture, and what actions must be taken to mitigate risk. This holds true for improved security architecture design by the manufacturers or the ability of a provider to patch vulnerabilities within a hospital network.

The bill is flexible, recognizing the ever-changing nature of cyber attackers and the need for regular review and updating. The potential downside of this approach is it lacks specificity, and it’s not clear how it will be enforced and what the penalties will be for non-compliance.

There are a few key elements to bring cybersecurity requirements for FDA-approved medical devices across their entire lifecycle — starting with requiring the pre-market approval of all components, including a Software Bill of Materials, continuing to post-market requirements for management of vulnerabilities, through to ensuring a secure decommissioning process. These requirements are designed to ensure medical devices are developed with security in mind, and maintained in a way that keeps patient and data safety a priority.

Get ahead of the curve

While this latest bill would provide welcome guidance for the industry, organizations shouldn’t wait to prepare: The time to establish proactive cybersecurity measures is now. Instead of reacting to cybersecurity laws when they arrive, organizations should proactively improve their practices and treat future legislation as validation.

The process of securing medical devices begins with several initial steps.

  1. Ensure full visibility: Organizations often underestimate their numbers and types of network-connected devices. Creating a robust map of connected devices is the first and most critical step in securing a network.
  2. Test and assess regularly: Cybersecurity is a journey, not a destination. As the bill suggests, regularly scheduled reassessments are critical to modern cybersecurity.
  3. Remain proactive and vigilant: Adopting a proactive, vigilant cybersecurity program will ensure the integrity and security of medical devices, as well as broader networks.

A new standard in medical device security

The Strengthening Cybersecurity in Medical Devices Act marks a welcome shift in medical device cybersecurity, with the potential to introduce unprecedented standards and rigor in ensuring the integrity of medical devices. This added enforcement will translate to peace of mind for patients, who can trust that medical device OEMs and owners have comprehensively secured their devices from the ground up, from manufacturing through implementation and operation.

As this legislation takes shape, however, it remains imperative that healthcare providers remain on the front foot with regard to their security, treating new legislation as validation of their existing approach, rather than an impetus for change.

KEYWORDS: cyber security legislation health care security medical device security pen testing proactive security risk assessment

Share This Story

Looking for a reprint of this article?
From high-res PDFs to custom plaques, order your copy today!

Dave Bailey is Vice President, Security Services at CynergisTek.

Recommended Content

JOIN TODAY
To unlock your recommendations.

Already have an account? Sign In

  • Iintegration and use of emerging tools

    Future Proof Your Security Career with AI Skills

    AI’s evolution demands security leaders master...
    Security Education & Training
    By: Jerry J. Brennan and Joanne R. Pollock
  • The 2025 Security Benchmark Report

    The 2025 Security Benchmark Report

    The 2025 Security Benchmark Report surveys enterprise...
    The Security Benchmark Report
    By: Rachelle Blair-Frasier
  • The Most Influential People in Security 2025

    Security’s Most Influential People in Security 2025

    Security Magazine’s 2025 Most Influential People in...
    Most Influential People in Security
    By: Security Staff
Manage My Account
  • Security Newsletter
  • eMagazine Subscriptions
  • Manage My Preferences
  • Online Registration
  • Mobile App
  • Subscription Customer Service

More Videos

Sponsored Content

Sponsored Content is a special paid section where industry companies provide high quality, objective, non-commercial content around topics of interest to the Security audience. All Sponsored Content is supplied by the advertising company and any opinions expressed in this article are those of the author and not necessarily reflect the views of Security or its parent company, BNP Media. Interested in participating in our Sponsored Content section? Contact your local rep!

close
  • critical event management
    Sponsored byEverbridge

    Why a Unified View Across IT, Continuity, and Security Makes or Breaks Crisis Response

  • Charlotte Star Room
    Sponsored byAMAROK

    In an Uncertain Economy, Security Is a Necessity - Not an Afterthought

  • Sureview screen
    Sponsored bySureView Systems

    The Evolution of Automation in the Command Center

Popular Stories

Cybersecurity trends of 2025

3 Top Cybersecurity Trends from 2025

Red laptop

Security Leaders Discuss SitusAMC Cyberattack

Green code

Logitech Confirms Data Breach, Security Leaders Respond

Neon human and android hands

65% of the Forbes AI 50 List Leaked Sensitive Information

The Louvre

After the Theft: Why Camera Upgrades Should Begin With a Risk Assessment

Top Cybersecurity Leaders

Events

September 18, 2025

Security Under Fire: Insights on Active Shooter Preparedness and Recovery

ON DEMAND: In today’s complex threat environment, active shooter incidents demand swift, coordinated and well-informed responses.

December 11, 2025

Responding to Evolving Threats in Retail Environments

Retail security professionals are facing an increasingly complex array of security challenges — everything from organized retail crime to evolving cyber-physical threats and public safety concerns.

View All Submit An Event

Products

Security Culture: A How-to Guide for Improving Security Culture and Dealing with People Risk in Your Organisation

Security Culture: A How-to Guide for Improving Security Culture and Dealing with People Risk in Your Organisation

See More Products

Related Articles

  • healthcare-screen

    Healthcare Organizations Must Balance the Growing Cybersecurity Threat Landscape with Meeting Regulatory Mandates

    See More
  • Here are the top political and security risks for 2021 that your organization needs to take prepare for

    Organizations must prepare for these 2021 security risks now, or may fail to make it in a post-COVID world

    See More
  • cyber security network graphic

    4 cybersecurity threats that organizations should prepare for in 2022

    See More

Related Products

See More Products
  • security culture.webp

    Security Culture: A How-to Guide for Improving Security Culture and Dealing with People Risk in Your Organisation

  • 150 things.jpg

    The Handbook for School Safety and Security

  • Physical Security and Safety: A Field Guide for the Practitioner

See More Products
×

Sign-up to receive top management & result-driven techniques in the industry.

Join over 20,000+ industry leaders who receive our premium content.

SIGN UP TODAY!
  • RESOURCES
    • Advertise
    • Contact Us
    • Store
    • Want More
  • SIGN UP TODAY
    • Create Account
    • eMagazine
    • Newsletter
    • Customer Service
    • Manage Preferences
  • SERVICES
    • Marketing Services
    • Reprints
    • Market Research
    • List Rental
    • Survey/Respondent Access
  • STAY CONNECTED
    • LinkedIn
    • Facebook
    • YouTube
    • X (Twitter)
  • PRIVACY
    • PRIVACY POLICY
    • TERMS & CONDITIONS
    • DO NOT SELL MY PERSONAL INFORMATION
    • PRIVACY REQUEST
    • ACCESSIBILITY

Copyright ©2025. All Rights Reserved BNP Media.

Design, CMS, Hosting & Web Development :: ePublishing