An analysis finds nine in 10 cleared ultrasound system designs predate the US cyber-device statute—and all four CISA advisories naming ultrasound lines had incomplete patch coverage.
Rongtao Medical Technology has released an evidence-based framework designed to help healthcare organizations determine whether older ultrasound systems should be patched, segmented, isolated, or replaced.
The model is based on an analysis of US Food and Drug Administration (FDA) clearance records, Cybersecurity and Infrastructure Security Agency (CISA) advisories, medical device adverse-event data, and original equipment manufacturer (OEM) support notices. The report suggests that equipment age alone is insufficient for fleet decisions, proposing instead that healthcare technology management professionals evaluate supportability across five separate timelines: clinical usefulness, OEM product support, software and component support, security-control supportability, and physical serviceability.
Analyzing Device Clearances and Support Timelines
According to the report, 90.1% of the 2,066 FDA 510(k) clearances for cart and console ultrasound systems issued between 1977 and mid-2026 were cleared before federal cyber-device requirements under Section 524B took effect on March 29, 2023.
The analysis indicates that every console system cleared between 2006 and 2020 predates the statute. Because annual clearance volume has remained steady at 55 to 83 systems per year, the pre-statute population of ultrasound devices will remain in clinical service for years to come, according to the company.
Evaluating Patch Coverage and Safety Data
The report also evaluated federal advisory and safety records, finding limits in software patch availability for medical imaging devices. Across 18 verified CISA medical advisories involving imaging products, half left at least one named system without a software fix at the time of publication, and all four advisories naming ultrasound product lines had incomplete patch coverage. Stated remedies in those cases included network restriction, physical access controls, or replacement.
In addition, the analysis found that zero of the 8,525 ultrasound adverse-event reports filed with the FDA since 2019 cite malware, ransomware, hacking, or viruses, and the FDA recall database contains only one ultrasound cybersecurity recall, which occurred in 2008. The report notes that this absence reflects reporting pathways rather than actual risk levels, meaning facilities cannot wait for adverse safety signals to determine equipment disposition.
Distinguishing Hardware Maintenance from Cybersecurity
The report highlights that physical serviceability and software security follow different lifecycles and require distinct management approaches.
“The most useful sentence in the whole record comes from an OEM end-of-support letter that stopped a product’s software clock and kept its hardware clock running in the same document,” says Frank Zhu, general manager of Rongtao Medical, in a release. “That is the reality of legacy fleets: The clocks are separable. When the software clock stops, somebody still has to keep the hardware running—and that is the lane independent service occupies, inside the disposition framework, never as a substitute for it.”
The company states that hardware repair does not generate OEM patches, validate operating system modifications, or resolve digital vulnerabilities. Instead, independent service providers contribute physical serviceability documentation, board-level fault isolation, and parts testing to support clinical engineering teams in making informed equipment disposition decisions.
The full report includes a five-clock framework, four dispositions with evidence gates and stop conditions, an OEM disclosure survey, procurement clauses for future purchases, and 38 source citations.
ID 58848025 © Zlikovec | Dreamstime.com