A new career path is taking shape inside HTM as employers and training programs formalize the biomed cybersecurity specialist role.


By Alyx Arnett

When Nadia Elkaissi, CHTM, joined the Department of Veterans Affairs (VA) as a biomedical engineer more than a decade ago, cybersecurity training was built into the job from day one. Her supervisor, she says, was a โ€œcybersecurity guruโ€ who made cybersecurity a core part of the teamโ€™s training, and the VAโ€™s structure gave biomeds a formal role in the networking and security of medical devices.

That kind of on-ramp is still relatively rare, but it’s becoming less so. As connected medical devices multiply and cyberattacks against health systems accelerate, a distinct career track is emerging inside healthcare technology management (HTM): the cyber biomed. These professionals combine medical device expertise with cybersecurity skills, and employers and colleges are beginning to formalize the roles and training programs that support that career path.

โ€œThe future of HTM cybersecurity will depend on professionals who can speak both languagesโ€”the language of technology and the language of patient care,โ€ says Christopher Falkner, CCE, senior director of digital strategy and cybersecurity for healthcare technology management at Sodexo US.

A Role That Employers Are Beginning to Define

Sodexo is among the employers hiring specifically for cybersecurity-focused HTM roles, including BMET cybersecurity specialists. The company has been developing its approach to medical device cybersecurity for more than a decade. Falkner says Sodexo identified the need for dedicated specialists as medical devices became increasingly networked, and cybersecurity expanded beyond protecting electronic health information.

“Cybersecurity is a patient safety issue, not simply a data privacy issue,” Falkner says. “That’s why we believe cybersecurity is now an essential part of HTM and the care delivery paradigm.”

Today, all 600-plus Sodexo HTM employees complete a six-week cybersecurity training program, while a smaller group of BMET cybersecurity specialists provides deeper, proactive expertise at client hospitals. Falkner describes the specialist role as the point where medical device expertise and cybersecurity risk mitigation converge.

“Unlike traditional IT infrastructure, medical devices often require hands-on remediation, careful assessment of clinical impact, and coordination with the OEM to validate that security fixes can be safely implemented,” he says. “BMET cybersecurity specialists lead that process while coaching fellow BMETs on cybersecurity requirements, remediation, and device availability.”

What sets these specialists apart, Falkner says, is their clinical fluency. “They understand the realities of working in ICUs, operating rooms, and other care environments where cybersecurity decisions can directly affect the care patients receive,” he says.

What the Work Looks Like Day-to-Day

At the VA Central Office, Elkaissi serves as a biomedical engineer in the Medical Device Networking and Cybersecurity Division, where she oversees networking and cybersecurity for VA HTM and supports biomeds across the country.

Her work ranges from coordinating with IT on high-priority vulnerabilities to investigating medical devices following cyber incidents, reviewing access control lists, and overseeing nine work groups responsible for areas including firewalls, technology implementation, and standardized HTM policies.

The role requires close collaboration with IT, but Elkaissi says medical device knowledge changes how cybersecurity decisions are made. โ€œIT has a more general role,โ€ she says. โ€œHowever, they don’t have the medical device aspect or knowledge. So that’s the thing that differentiates us.โ€

That distinction becomes particularly important when vulnerabilities need to be addressed. IT staff may understand the necessary security controls, Elkaissi says, but not whether those controls can safely be applied to a particular medical device. โ€œThey don’t know what patches need to be installed on a medical device,โ€ she says. โ€œThey don’t know how it applies, how it should be configured in the group policy.โ€

For Elkaissi, one of the most interesting parts of the work is seeing what that connectivity can make possible. โ€œProbably my favorite part is seeing how much you can gain from a medical device, not just a standalone medical device, but what opportunities it can provide if itโ€™s networked,โ€ she says. She points to integrations that can give hospitals greater visibility into information such as CT scanner utilization.

Building Cyber Expertise From Within

As the need for cybersecurity expertise grows within HTM, some organizations are developing those skills within their existing workforce.

At the VA, Elkaissi says biomeds receive extensive internal cybersecurity training as part of the job, supplemented by CompTIA training and vendor-led courses. Elkaissi has also pursued additional credentials to deepen her own IT and cybersecurity knowledge. She points to CompTIA Network+, Security+ and A+ as useful starting points for biomeds looking to build foundational knowledge of computers and networking. She says Network+ has also become a focus for VA trainees and interns, helping ensure they develop foundational networking knowledge as they enter the field.

The value of that foundational education is understanding the reasoning behind the work, Elkaissi says. Before learning the underlying concepts, she says, biomeds might be told to build an access control list without understanding what it was or why it was needed. โ€œAt least having the knowledge of what we’re supposed to be doing โ€ฆ is really important before you dive into the weeds,โ€ she says.

24×7 LinkedIn Poll

Does Your HTM Department Have Someone Specifically Responsible for Medical Device Cybersecurity?

We polled 24×7 Magazine followers on LinkedIn about how their HTM departments are approaching medical device cybersecurity. Hereโ€™s how 32 respondents answered:

Yes, a dedicated cyber role 50%
Yes, part of another HTM role 15%
No 34%
Not yet, but considering it 0%

Poll conducted on LinkedIn; 32 responses. Results may not total 100% because of rounding.

Follow 24×7 Magazine on LinkedIn for more HTM polls and industry discussions.

She is currently working toward the Cisco Certified Network Associate certification and plans to pursue the more advanced Certified Information Systems Security Professional (CISSP) next.

At Sodexo, cybersecurity education extends across the HTM workforce. Every HTM employee completes a six-week Cybersecurity Foundations program developed with the College of Biomedical Equipment Technology (CBET), with foundational content aligned with CompTIA Network+ and Security+. Sodexo also supports its BMET cybersecurity specialists in pursuing advanced certifications, including CISSP.

A College Program Built Around the Role

When John Schmidt, MA, vice president of operations at CBET, joined the college six years ago, he brought an IT background and began helping expand cybersecurity and networking education within its biomed programs. He saw parallels with consumer technology, where even appliance technicians increasingly need networking skills.

โ€œWhen your Maytag repairman has to have a Network+ certification because your refrigerator and your stove and your washer dryer are all connecting to the internet, that kind of makes sense that inside of the healthcare organization we’re in the same boat,โ€ he says.

Schmidt also saw more biomed departments moving from facilities management to IT, reinforcing the need for biomeds to understand networking. โ€œThere’s only two departments at a hospital that own the medical Internet of Thingsโ€”the IT department and the biomeds,โ€ Schmidt says. โ€œEverybody else is a user. But biomeds own that equipment that’s connected to the network, and IT owns that network. So together, they are the medical Internet of Things.โ€

That growing overlap between biomed and IT helped shape CBET’s approach to its training programs. About four years ago, the college began developing the Biomedical Equipment Support Specialist (BESS) program, which incorporates cybersecurity and IT education into a broader biomed curriculum. The certificate and associate degree program includes electronics, biomedical equipment, and other core coursework alongside cybersecurity, networking, servers, and medical device integration. Students also learn how to bring that knowledge into areas such as procurement and change management, including identifying technology that may not be appropriate to connect to a hospital network. The associate degree can be completed in about 15 months on CBET’s condensed schedule, Schmidt says.

For working biomeds seeking additional training rather than a degree, CBET offers shorter programs through its HTM Training Solutions, where the college works with employers to upskill existing staff. Its Biomedical Imaging and Information Systems (BIIS) course is a six-week program taught by an HTM cybersecurity professional over Zoom, paired with reading, quizzes, and discussion posts. Schmidt says more than 1,000 people have completed BIIS, which has been offered for five to six years. Sodexo was an early participant, with about 460 of its biomeds completing the program.

For biomeds looking specifically for healthcare networking training, CBET’s Phase Connect covers DICOM, PACS, HL7, cybersecurity, and networking fundamentals through six weeks online followed by a four-day in-person lab.

Speaking the Same Language

Additional education gives biomeds the technical knowledge to take on cybersecurity work, but Schmidt and Elkaissi say it also helps them communicate more effectively across biomedical, IT, and clinical teams. Schmidt refers to the divide between those groups as โ€œthe basement of Babylon.โ€

“IT and biomeds and all those lab techs and all those niche organizations are all in the basement, and they all are for the same common goal of patient care. But they all talk a different language,” he says. “What a biomed needs to do is overcome that. They need to learn how to speak to them and build trust, confidence, and camaraderie.”

Elkaissi says that ability becomes especially important when HTM and IT are deciding how to address security risks on medical devices. IT may know which cybersecurity controls it would ordinarily apply to a networked system, but a biomed understands the equipment well enough to know whether those controls are appropriate for the device and its clinical use, she says.

She points to defibrillators as one example. She says IT personnel have pushed to install PIV cards on the devices, even though a defibrillator cannot support them. A biomed with cybersecurity training can assess the device within a risk framework and determine which security controls can safely be applied.That requires biomeds to understand IT well enough to communicate those needs, Elkaissi says.

“It’s not just knowing the network, but it’s kind of how to explain it to IT,” she says, “so that everyone’s on the same page.”

At Sodexo, that combination of skills is built into the specialist role. Enterprise cybersecurity teams provide intelligence, monitoring, and analysis of emerging threats, but the onsite HTM cybersecurity specialists are responsible for translating that information into action at the medical device level.

โ€œThese specialists donโ€™t just identify the vulnerability; they know the device in and out, as well as understanding the clinical environment and can drive the fix,โ€ Falkner says.

That can mean assessing the clinical impact of a vulnerability, working with an OEM to determine whether a security fix can be safely implemented, and coordinating with clinical teams before making changes to equipment. For Falkner, that hands-on role is critical.

โ€œMedical device risk cannot be mitigated from a distance,โ€ he says.

Where the Career Is Headed

As cybersecurity becomes a larger part of managing connected medical devices, Falkner expects HTM to develop along two tracks: broader cybersecurity knowledge across the workforce and dedicated roles for those with deeper expertise. Cybersecurity fundamentals, he says, will increasingly become a core competency for HTM professionals, while “specialized hybrid roles will provide the deeper expertise needed to manage complex medical-device security risks.”

Elkaissi also expects specialized roles to become more common, particularly as medical devices integrate more deeply with electronic health records, and cybersecurity becomes part of decisions throughout the equipment lifecycleโ€”from procurement through implementation and sustainment. How those responsibilities are divided will continue to vary by organization, she says, particularly in health systems where HTM falls under IT.

Interest in additional training may already reflect the growing demand for cybersecurity and IT skills within HTM. Schmidt says CBET is seeing increased demand on its HTM Training Solutions side, describing employee upskilling, particularly around IT, as โ€œincreasing exponentially.โ€

He also sees a generational shift underway as people who have spent their lives using connected technology enter HTM. “The kids nowadays that are starting, they’re natives. They were born with the internet. They were raised on the internet,” Schmidt says.

For biomeds who aren’t planning to specialize in cybersecurity, Elkaissi still sees value in developing that knowledge. “Even if you’re not a cybersecurity guru, or that’s not your future, just having that as a knowledge base definitely will help your career,” she says.

For those who do choose to specialize, Schmidt expects the skills that define today’s cyber biomed to become increasingly central to HTM.

“The cyber biomed is going to be a requirement, not a nicety,” he says. “The understanding and the adaptability of cyber into the medical device industry is going to be a basic requirement.”

Cybersecurity Training and Certification Options for Biomeds

The certifications and training programs discussed by sources in this article offer a range of starting points for biomeds looking to build cybersecurity and IT expertise. While not an exhaustive list, the options below span foundational credentials, advanced certifications, and HTM-specific training.

Industry Certifications

CompTIA A+ โ€” Covers foundational IT skills across hardware, networking, operating systems and security. Nadia Elkaissi recommends A+, along with Network+ and Security+, for biomeds looking to build a base of IT and networking knowledge.

CompTIA Network+ โ€” Validates skills in areas including network connectivity, configuration, monitoring, troubleshooting and security hardening. Elkaissi recommends Network+ as a starting point for biomeds and says it has become a focus for trainees and interns at the VA.

CompTIA Security+ โ€” Covers core cybersecurity skills, including securing networks, applications and devices and protecting the confidentiality, integrity and availability of data. Elkaissi recommends it as a foundational credential for biomeds developing cybersecurity expertise. CBET’s John Schmidt also points to Security+ knowledge as an important baseline.

Cisco Certified Network Associate (CCNA) โ€” Validates knowledge of network fundamentals and access, IP connectivity and services, and security fundamentals. Elkaissi is currently pursuing the CCNA as she continues to deepen her networking and cybersecurity expertise.

Certified Information Systems Security Professional (CISSP) โ€” An advanced ISC2 certification focused on the ability to design, implement and manage a cybersecurity program. Elkaissi plans to pursue CISSP after completing her CCNA, while Sodexo supports its BMET cybersecurity specialists in pursuing the credential.

HTM-Specific Education and Training

Biomedical Equipment Support Specialist (BESS) โ€” CBET’s 30-credit certificate program prepares students to support the lifecycle management of networks, networked medical equipment and associated systems. Coursework incorporates cybersecurity, networking, servers and medical device integration alongside broader biomedical equipment education.

Biomedical Imaging and Information Systems (BIIS) โ€” A six-week CBET course designed to establish an IT, information systems and cybersecurity foundation for biomedical equipment and imaging technicians. Schmidt says more than 1,000 people have completed the program.

IDย 267732515ย |ย Healthcare Abstractย ยฉย Yuri Arcursย |ย Dreamstime.com

Alyx Arnett is chief editor of 24×7. Questions or comments? Email [email protected].