Cybersecurity considerations are coming earlier in medical device purchasing as HTM teams look more closely at vendor support, contract terms, and long-term security risks.
By Alyx Arnett
Cybersecurity is becoming an increasingly important part of medical device purchasing, and healthcare technology management (HTM) teams are more often considering potential risks earlier in the buying process, according to Scott Skinner, PhD, MBA, FACHE, CHTM, founder and principal of consulting firm HTMPOWER.
โFor years, as we’ve evaluated technologies, we’ve certainly looked at the clinical features, reliability, supportability, and total cost of ownership. But we’ve got to the point now where the cybersecurity elements are really one of the main criteria,โ says Skinner, also an assistant professor of health management and systems sciences at the University of Louisville.
Those considerations are increasingly influencing purchasing decisions. RunSafe Security’s 2026 Medical Device Cybersecurity Index found that 84% of organizations include cybersecurity requirements in vendor requests for proposals, while 56% have rejected a device because of cybersecurity concerns, up from 46% in 2025.ย
For Skinner, the timing of that evaluation is key.
โI think originally everybody was sort of treating this as a checklist that you do right before you give the vendor the purchase order (PO),โ he says. โWell, if that’s where it is in the process, it’s way too late. Cybersecurity needs to have a seat at the table right from the very beginning.โ
Why Cybersecurity Is Moving Earlier
Katie Connor, senior director of cybersecurity at Intermountain Health, says the inclusion of cybersecurity in procurement decisions reflects how much the device landscape has changed.
โMedical devices used to be really just on their own and operate in a silo, and they would plug into the wall and not be interconnected. The interconnectivity of medical devices today is more critical than ever and more prevalent than ever,โ Connor says. โIt’s no longer an option for a medical device to just show up, and you plug it in and start operating it.โ
Scott Trevino, senior vice president of cybersecurity at Trimedx, points to another factor accelerating the shift: the pace of attacks.ย
“The growing volume and speed of cyberattacks, particularly AI-enabled attacks, have heightened the urgency of evaluating cybersecurity during the medical device purchasing process,” he says.ย
Regulatory expectations are adding to the pressure. The RunSafe survey found that 79% of respondents said US Food and Drug Administration guidance or EU Medical Device Regulation requirements have influenced their medical device procurement practices.
Where HTM Fits In
Skinner says HTMโs position between clinical staff, IT, and manufacturers gives the department an important role in evaluating devices for cybersecurity.
โWe’re really good at relating with the clinicians and the users because we’re responsible for supporting the physical device. We often have to collaborate with technical teams to bring things onto the network to do commissioning, work through patching and cyber events, and we’re really good at relating with the manufacturer for service and support,โ he says.
That position often makes HTM a translator between groups that don’t necessarily speak the same technical language, Skinner says.
โThe clinicians don’t always understand the language that IT, for example, is speaking in. And we may not be IT experts, but we often have an operating knowledge that makes us able to functionally relate to IT to get things done for medical devices,โ he says.
Connor also describes HTM as a bridge between vendors and the teams that will support the technology.
โWhen they can come in and help us understand how the device will actually be implemented, deployed, maintained, and supported in the patient care environment … we can then ensure security is embedded in that design and that plan,โ she says.
What to Ask Forโand What to Watch For
Trevino says HTM teams should start by obtaining key cybersecurity information from the manufacturer. โHTM teams should request MDS2 forms, SBOMs, and documentation outlining any known vulnerabilities affecting a device,โ he says. โThey should also review vulnerability disclosures and confirm whether identified vulnerabilities have been patched or mitigated before deploying the device.โ
The RunSafe Index found that 81% of respondents rate an SBOM as โimportantโ or โessential,โ and 35% say they will not consider a device without one.
Additionally, Skinner says, โTeams should ask whether they have a documented process to respond to security events that addresses notification timelines and transparency, as well as the regulations, standards, and guidance that inform their response approach.”
He says HTM teams should also be asking vendors how the device’s operating system will be supported over its expected life. That includes whether the operating system already has an established end-of-life or end-of-service date and whether the manufacturer will provide a path to a newer operating system.
โWhat’s the plan look like for when we get to that seven to 10 years? Is there going to be an upgrade path to move to the next operating system?โ he says.
Connor says teams should also ask how the manufacturer handles vulnerabilities after a device is in use, including how quickly vulnerabilities are disclosed and addressed and how the vendor approaches patches and updates.
โWe expect vulnerabilities to happen, but how are they going to respond and support us in achieving better vulnerability management? What’s their patching update processes, and really, how do they support the lifecycle of the device end to end?โ she says.
The vendor’s response to those questions can itself be revealing, Connor says.
โThe biggest red flags are when a vendor is not willing to cooperate, doesn’t really understand the question set around security,โ she says. โYou get a pretty good idea pretty early on as to the security posture of a vendor and their willingness to participate in security.โ
Getting Requirements Into the Contract
Once an organization has identified its cybersecurity requirements, Skinner says those expectations need to be addressed before the contract is finalized and the PO is issued.
โIf you have leverage until you consummate the contract and until you cut the PO, that’s where there just needs to be a lot of partnership internally,โ he says. โWe need to make sure that we get those requirements baked into the contract terms and conditions and in the actual PO before we let the horse out of the barn because then it’s too late, and we don’t have any leverage with the manufacturers.โ
Teams may want to have patching timelines included, for example. โIf we want to see, like within one week in general, the patch is tested and validated and allowed to be pushed and we somehow want the manufacturer to work with us on that, then those are elements that should be baked into the contract,โ Skinner says.
Connor says contracts should also spell out who is responsible for maintaining the device’s security after purchase.
โOftentimes there’s confusion about who will be actually patching the systems,โ she says. โWill it be us, and we’re waiting for a patch from the vendor, and the HTM team will help to apply that once it is available? Or will the vendor need to log in remotely and support updating, patching critical vulnerabilities? And are there additional costs required to do that?โ
Trevino says a vendor’s track record can also influence what an organization requires in the contract.
“Past experiences with a vendor’s support and responsiveness can influence purchasing decisions and drive organizations to seek stronger cybersecurity commitments within purchase contracts,” he says.
Does Cyber Risk Mean It’s Time to Replace?
For hospitals operating older or unsupported medical devices, cybersecurity can raise another purchasing question: Is it time to replace them? The RunSafe Index found that 28% of organizations operate devices past end-of-support, while 44% acknowledge running end-of-support devices with known, unpatched vulnerabilities.
But replacing those devices with newer equipment isn’t necessarily an automatic cybersecurity improvement, Skinner says.
โSometimes replacing something isn’t going to change that risk profile a whole lot,โ he says. โI think sometimes we assume that, โOh, this thing’s a really high risk. It’s running on Windows XP. We just need to get a new one and bring it in.โ Well, hold on … the new device may be as bad or worse from a compliance standpoint with the environment.โ
At the same time, Connor says some medical equipment can remain clinically useful long after its software becomes difficult to support securely. She points to large imaging systems as an example.
โWe have some very large imaging systems out there, and many of them last for 20 years or 30 years, or longer,โ she says. โThe hardware itself would work, the device itself would work much longer than the integration into the system securely.โ
For Skinner, that makes cybersecurity one consideration in replacement planning, not a reason to assume that purchasing a newer device will solve the problem. The proposed replacement still needs to be assessed for its own risks.
โThere may be things that are fundamental things around how the device is designed that may not have changed,โ he says. โSo I think just coming in and saying, โOh, we need to replace all this, and it’s going to drive our risk down.โ Well, you really need to do the assessment and really see if that’s true or not.โ
For organizations that cannot immediately replace an unsupported device, compensating controls may provide another option. The RunSafe Index found that 82% of organizations have deployed or are piloting runtime exploit protection, including 53% that have deployed it on some devices and 29% that have deployed it widely. The report identifies such protections as an option for devices that cannot be patched or replaced.
Pushing VendorsโTogether
Healthcare organizations are increasingly using their purchasing decisions to hold manufacturers accountable for cybersecurity, says Trevino.
โIn some cases, healthcare organizations have reconsidered purchasing from a vendor after experiencing issues such as being charged for security patches or receiving insufficient support for maintaining device cybersecurity,โ he says. โEven when organizations continue purchasing from the same manufacturer, those past experiences often lead to stronger contract language requiring patch support and cybersecurity maintenance commitments.โ
The RunSafe Index shows that those experiences are affecting vendor relationships more broadly. Nearly 40% of organizations said cybersecurity incidents have affected their trust in specific vendors and led them to require additional verification, up from 32% in 2025. Seven percent said they have stopped purchasing from specific vendors entirely, while 23% said they are exercising greater caution when evaluating vendors.
Hospitals are also willing to put more money behind stronger security. The index found that 76% of respondents would pay a premium for devices with advanced cybersecurity protections, including 49% who would pay at least 5% more.
Connor says that purchasing pressure becomes more powerful when healthcare organizations apply it collectively.
โ[In some security conversations with manufacturers], they’ll say, โThis is the first time I’m hearing this. Nobody else is making us fix this.โ And that’s just simply not true,โ she says. โAll of us in healthcare are pushing on the vendors to improve to ensure that they are doing their part as part of our healthcare systems to support us.โ
Connor says she has also seen larger healthcare organizations work directly with manufacturers to identify security problems, including conducting penetration testing on medical devices and connected software and sharing what they find with vendors. She says that type of collaboration can help manufacturers address problems that extend beyond a single healthcare system.
What Comes Next
Looking ahead, Connor expects healthcare organizations to require more from manufacturers. โWe’re moving really from asking manufacturers and vendors if the device is secure to really having them demonstrate how security will be maintained throughout the device’s lifecycle and making sure that we address that in contract terms,โ she says.
AI-enabled devices will add more considerations to that evaluation. The RunSafe Index found that 57% of organizations already use AI-enabled or AI-assisted medical devices, and 80% express at least moderate concern about the cybersecurity risks they introduce. Connor says procurement teams will need to consider data integrity, model risk, privacy, and resilience as AI becomes more embedded in medical technology.
Ultimately, she says the purchasing process is about understanding those risks upfront and making sure they can be managed over time.
โWe do expect there to be risks. There’s always going to be risks, and the threat landscape is evolving our risk posture over time,โ Connor says. โSo the goal is not to be 100% secure. The goal is to be able to manage those risks over time as partners and make sure that we’re securing and protecting our healthcare ecosystem overall.โ
IDย 465062173ย ยฉย Vadzim Shubichย |ย Dreamstime.com
Alyx Arnett is chief editor of 24×7 Magazine. Questions or comments? Email [email protected].