From checking passwords to verifying software versions, routine maintenance gives HTM teams opportunities to strengthen medical device cyber-resilience.


By Phil Englert, VP Medical Device Security, Health-ISAC

Medical device cybersecurity is often discussed in terms of threats, vulnerabilities, and technical controls, but for healthcare technology management (HTM) professionals, the conversation is really about something far more familiar: maintaining the reliability, safety, and performance of the devices clinicians depend on every day.

Preventive maintenance helps ensure equipment functions as intended. Cybersecurity activities help ensure those same devices remain trustworthy, available, and safe for patient care. Cyber-resilience should not sit outside normal HTM workflows. It should be incorporated into the routine activities HTM teams already perform to keep medical devices operating safely throughout their lifecycle.

During a scheduled preventive maintenance inspection, technicians inspect physical components, verify calibration, and review device performance. That same visit provides an opportunity to validate cybersecurity controls that support the device’s safe operation.

The Cybersecurity Checkup

Routine maintenance offers a number of opportunities to incorporate these cybersecurity checks.

Consider an infusion pump. During a routine preventive maintenance check, technicians verify delivery volumes and alarm functionality and inspect mechanical components. That same workflow can include rotating passwords, confirming software versions, and confirming that default credentials have not been reintroduced. These actions require a few additional minutes but can significantly reduce the likelihood of unauthorized access to the device.

Ultrasound systems are another example. Many ultrasound machines temporarily store images and patient data locally even after the studies are transferred to the picture archiving and communication system. During routine maintenance, HTM personnel can verify that completed studies have been successfully transferred and that residual patient data is removed from local storage. In addition to helping protect patient information, this practice reduces unnecessary data accumulation and improves overall device hygiene.

Ventilators offer another example. During preventive maintenance, technicians frequently review device settings and operational logs. This can be expanded to include verification that unnecessary services remain disabled. If a service was temporarily enabled for troubleshooting or software support, HTM teams can confirm it has been properly turned off once the work is complete. Limiting unnecessary services reduces the device’s attack surface while having little impact on day-to-day maintenance activities.

The same approach applies to anesthesia machines. During routine inspections, technicians can verify operating system versions, review available manufacturer updates, and confirm antivirus or application control mechanisms remain operational if those technologies are supported by the device manufacturer. These checks can become as routine as inspecting batteries, testing alarms, or evaluating gas delivery performance.

Imaging systems such as CT scanners, MRI scanners, and digital radiography units often contain complex networked components that interact with multiple clinical systems. During maintenance activities, technicians can verify proper communication with authorized systems while confirming that unnecessary external connections have not been established. Reviewing configuration settings, validating approved network paths, and checking that remote access controls remain properly configured can all be incorporated into existing service workflows.

Maintaining Accurate Device Inventories

Cyber-resilience also depends on maintaining accurate device inventories. HTM departments have long recognized the importance of tracking medical equipment throughout its lifecycle. Today, inventory records should also include cybersecurity-relevant information such as software versions, operating systems, network connectivity status, supported security features, and patch status where applicable. Maintaining this information helps organizations quickly assess exposure when new vulnerabilities are identified and supports more efficient remediation efforts.

Another valuable practice is the routine review of device configurations. Medical devices often remain in service for many years and undergo software updates, repairs, network changes, or clinical workflow modifications. Small configuration changes can accumulate over time and move a device away from its approved baseline. Periodic validation of security settings helps ensure devices remain configured as intended. For HTM professionals, this is an extension of the quality and performance verification activities they already perform.

A Fundamental Maintenance Discipline

HTM leaders did not hire a “pump maintenance department,” a “ventilator maintenance department,” and a “monitor maintenance department.” Biomedical technicians developed the skills to incorporate maintenance of these devices into their normal workflows. Medical device cybersecurity should evolve in the same way.

Every HTM technician should be capable of performing basic cybersecurity maintenance activities on the devices they service. These activities should not be treated as separate workflows, although they will take additional time to perform.

Maturing programs can consist of cybersecurity-aware technicians, a few HTM cyber champions, and a small number of dedicated medical device security specialists. By incorporating basic cybersecurity activities into routine device maintenance, HTM teams can embed cyber-resilience into normal workflows while improving the security and reliability of the technologies clinicians depend on.


About the author: Phil Englert is vice president of medical device security at Health-ISAC, where he works with medical device manufacturers to enhance privacy and security and coordinates with health delivery organizations to ensure implementation is practical and achievable. Englert serves as a subject-matter expert and contributor to Health-ISAC’s Medical Device Security Council and also contributes to regulatory and standards efforts. He brings more than 30 years of technical and operational leadership experience across healthcare and life sciences, including prior roles at MedSec, Deloitte, MDISS, and Catholic Health Initiatives.

ID 176619643 © Patrik Slezak | Dreamstime.com

24x7 Appoints Medical Device Cybersecurity Expert to Advisory Board