HTM professionals bring critical clinical context to medical device cybersecurity, but the growing role also requires new skills and training.

By Scott Trevino, senior vice president of cybersecurity, Trimedx

Healthcare technology management (HTM) has always focused on keeping medical equipment safe, reliable, and available for patient care. That mission remains the same, but the way HTM teams achieve it is evolving.

Medical device cybersecurity is no longer solely the responsibility of IT teams. As new vulnerabilities emerge, health systems need to understand which devices are affected, how critical those devices are to patient care, and which risks require immediate attention. Doing so depends on pairing cybersecurity expertise and technology with clinical engineering knowledge and experienceโ€”neither is sufficient alone.

Bringing Cybersecurity and Clinical Expertise Together

Biomedical equipment technicians (BMETs) understand each device’s clinical context, helping ensure remediation efforts do not disrupt patient care. Pairing that knowledge with vulnerability intelligence and risk-based prioritization helps organizations focus on the issues that matter most. From there, teams can actโ€”applying validated patches, using compensating controls where no patch exists, and measuring risk reduction as part of a true closed-loop remediation process.

The most prepared health systems will prioritize equipping BMETs with the cybersecurity skills they need to successfully work in todayโ€™s threat environment. Training programs and professional development opportunities should incorporate cybersecurity fundamentals, risk management concepts, and cross-functional collaboration skills alongside traditional technical competencies.

The line between clinical engineering and cybersecurity is thinning, and the people entering the field will not experience them as separate disciplines the way their predecessors did. Cybersecurity is a necessary skill for HTM. Organizations that invest in that education now will have HTM teams capable of the work the role demands, rather than scrambling to hire it later.

Using AI to Support HTM Expertise

As HTM professionals take on a greater role in cybersecurity, they also face an increasing volume of data to interpret and act on as connected device inventories grow and new vulnerabilities are identified every day. AI has the potential to help teams make sense of that information faster by providing easier access to cybersecurity insights, automating routine analysis, and helping prioritize actions based on risk.

One example is the use of conversational AI tools that allow users to ask natural-language questions about medical device inventory, vulnerabilities, risk scores, remediation efforts, and overall cybersecurity posture. These capabilities can surface high-risk assets and generate reports on demand, without navigating multiple systems or manually analyzing data.

AI can also correlate newly discovered vulnerabilities with device inventories, making it easier to identify affected assets, support more dynamic risk assessments, and take a more proactive approach across the device lifecycle.

Used well, AI should raise the value of human expertise by putting sharper information in the hands of the people who understand each device and the impact it has on patient care.

Looking Ahead

Medical devices will keep getting smarter, and the threats against them will keep pace. The health systems that handle it best will be the ones that stop treating cybersecurity solely as a separate specialty and build it into how their HTM teams are trained, staffed, and equipped.

For HTM, cybersecurity is no longer adjacent to the work of keeping equipment safe, reliable, and available. It is an essential part of it.

IDย 27085957ย ยฉย Sudok1ย |ย Dreamstime.com


About the author: Scott Trevino is senior vice president of cybersecurity at Trimedx. He leads efforts to define the strategy to deliver value, growth, and evolution of Trimedxโ€™s cybersecurity solutions. Prior to joining Trimedx, Trevino spent over 20 years at GE Healthcare holding multiple leadership positions in product management, product development, services, technology/engineering, operations, and quality & regulatory.