Hospitals and medical device manufacturers have more cybersecurity guidance and requirements than ever, but third-party attacks, AI-assisted vulnerability discovery, and aging equipment continue to complicate efforts to reduce risk.
By Alyx Arnett
In 2026, more healthcare organizations are reporting cyber incidents involving medical devicesโand more of those incidents are affecting patient care. RunSafe Securityโs 2026 Medical Device Cybersecurity Index found that 24% reported an attack or exploited vulnerability involving a medical device, up from 22% in 2025.1 Among those, 80% said it had a moderate or significant effect on patient care, up from 75%.1
The risk is also reaching hospitals through companies they depend on, with third parties involved in 32% of confirmed healthcare breaches.2 Scott Gee, deputy national advisor for cybersecurity and risk at the American Hospital Association, sees another source of pressure: Artificial intelligence (AI) is shortening the time attackers need to turn a disclosed software vulnerability into an exploit.
โEverything has gotten bigger and badder and more in your face,โ says Naomi Schwartz, vice president of services and regulatory strategy at MedCrypt and a former US Food and Drug Administration (FDA) reviewer.
For medical device manufacturers, those growing risks are accompanied by more specific cybersecurity guidance, while hospitals have gained new resources to assess their risks and prepare for disruptions to care.
For Schwartz, the challenge is turning a growing volume of cybersecurity information into decisions hospitals can act on. โItโs very hardโ to keep up, she says.
Cybersecurity Guidance Expands on Both Sides of the Device
While risks are increasing, the good news is that the FDAโs recently updated final cybersecurity guidance and Section 524B of the FD&C Act have โsignificantly raised expectationsโ for medical device manufacturers, says Priyanka Sollinger, CHTM, DSL, AAMIF, FACCE, vice president of cybersecurity and risk reduction services at Asimily.ย
โThey now have responsibilities around securely deploying these devices, postmarket vulnerability management, and then having a good patching strategy,โ she says. Section 524B also requires manufacturers submitting covered cyber devices for premarket review to provide a software bill of materials (SBOM).
Expectations for that information are spreading globally. The International Medical Device Regulators Forum published principles for medical device SBOMs in 2023. In July, CISA and government partners from eight other countries updated the minimum elements for SBOMs.
โItโs not the United States government and CISA focusing on software bill of materials,โ Schwartz says. โItโs the whole world, effectively.โ
RunSafeโs report found that 81% of respondents considered an SBOM important or essential when evaluating devices; 35% said they would not consider a device without one.ยน
Hospitals have also received new resources for assessing and responding to cyber risks. In March, the US Department of Health and Human Services (HHS) added a cybersecurity module to its RISC 2.0 toolkit, allowing healthcare organizations to assess cyber threats alongside other hazards. HHS also updated its Security Risk Assessment Tool, which is intended primarily for small and medium providers.
Gee points hospitals to the FBIโs Operation Winter SHIELD, released this year. Its 10 recommended defenses draw on weaknesses seen in FBI investigations. The American Hospital Association and the Joint Commission also launched a voluntary Cyber Resilience Readiness program in May to help hospitals assess their ability to sustain safe, quality care during cyber disruptions.
The HIPAA Proposal Raises Questions
The proposed HIPAA Security Rule update, intended to strengthen cybersecurity protections for electronic protected health information, could go further by setting more specific requirements for hospitals.
โThe HIPAA law needs to be updated,โ Schwartz says. โAbsolutely, it is stale. There are a bunch of things it doesnโt cover.โ
Still, stakeholders have raised concerns about how some provisions work. For one, it would remove the distinction between โrequiredโ and โaddressableโ implementation specifications, making most specifications mandatory with limited exceptions, says Eddie Myers, HCISPP, CBET, national director of cybersecurity at Intelas. โA lot of hospitals are saying, โOK, yes, we donโt have the bandwidth to do that,โ but theyโre making it mandatory,โ Myers says.
It would also require network segmentation. โMany organizations understand segmentation conceptuallyโthat they should segment medical devices,โ says Sollinger. โBut now translating thousands of those device communication patterns into enforceable network policies, and then doing all of that without disrupting patient care or annoying your clinicians, thatโs going to be difficult.โ
Recovery raises a separate concern. The proposed rule calls for written procedures to restore critical relevant electronic information systems and data within 72 hours of their loss. “I donโt know anybody that can do that, government agencies included,โ says Gee. โWithin the first 72 hours, youโre quite often still trying to figure out what happened, how it happened, how the bad guys got in, and make sure theyโre not in anymore.โ
Gee says he supports stronger cybersecurity measures but that the proposed requirements must be workable for hospitals. HHS issued the proposal in December 2024; the federal regulatory agenda now projects final action in July 2027. Meanwhile, Sollinger cautions against treating the delayed rulemaking as a reason to wait.
โJust because it is still proposed doesnโt mean itโs not coming,โ she says.
Third-Party Risks Are at the Front Door
According to Gee, โThe biggest challenge we see in the sector writ large right now is and continues to be third-party risk.โ
Verizonโs 2026 Data Breach Investigations Report found third-party involvement in 32% of confirmed healthcare breaches.2 A separate 2026 study found that 85% of healthcare practices experienced at least one operational disruption caused by a third-party or โvendor-of-a-vendorโ failure during the past 12 months.3
Gee points to recent examples like the March cyberattack on Stryker that disrupted the manufacturerโs order processing, manufacturing, and shipping. In August, a cyber incident at Boston Scientific affected manufacturing and order fulfillment, along with the activation of some cardiac remote-monitoring devices.
Neither incident began inside a hospitalโs network, but hospitals still had to consider their dependence on the manufacturers. Myers says the Stryker incident prompted Intelas to identify potentially affected devices across its clientsโ inventories and evaluate their remote connections. Where disabling remote access would not interfere with patient care, the company recommended turning off those connections until the manufacturer provided an all-clear.
Third-party risk also extends to the companies that provide hospitals with billing, software, and IT services. Gee points to the 2024 attack on claims and payment processor Change Healthcare and an incident at healthcare software provider Craneware as examples.
Health-ISACโs 2026 threat report identifies medical billing, software, IT support, and file-transfer providers among the outside companies attackers target.4
AI Changes the Threat and the Response
AI is adding to the risk by helping attackers exploit newly disclosed vulnerabilities faster, Gee says. Before AI, he says, an attacker might have needed weeks to develop an exploit. โWith AI, theyโre doing it in minutes. AI is incredibly good at determining what vulnerabilities are and how to exploit them,โ he says.
AI could also add to the number of flaws demanding attention. In April, Anthropic reported that its Claude Mythos Preview model had found thousands of previously unknown software vulnerabilities. Anthropic has made the model available to selected defenders through Project Glasswing. For Myers, the finding is a reminder that even recently installed devices may have security weaknesses no one has discovered yet.
And, finding a vulnerability is only the beginning of the response, Schwartz says. A manufacturer must evaluate a fix and test it before releasing a patch. โAnd thatโs not fast,โ she says.
To help hospitals respond to attackers using increasingly capable AI, the Coalition for Health AI convened a nearly 100-member work group earlier this year. It is developing cybersecurity playbooks for health systems, with guidance expected by the end of 2026.
While AI may be speeding attacks, it can also help defenders. Sollinger says security and healthcare technology management (HTM) teams are using it to analyze device, network, and vulnerability data and identify risks that need attention. โWe have enormous amounts of data … Itโs just impossible for a human to do it all,โ she says.
Additionally, AI brings risks through the medical devices and clinical systems hospitals are using, Sollinger says. RunSafe’s report found that 57% of respondentsโ organizations used AI-enabled or AI-assisted medical devices or clinical systems, and 80% expressed at least moderate concern about the associated cybersecurity risks.1
โItโs here; weโre not stopping it, but we need to have a governance structure in place for how to use it appropriately,โ Gee says.
The Security Challenge of Legacy Devices
Hospitals have become better at identifying connected devices and their vulnerabilities, Sollinger says. โBut then knowing that something is vulnerable and then being able to remediate that vulnerability are two very different things.โ
That difficulty is particularly stark with older equipment. โIn our world, HTM, weโre there to extend the useful life of the device,โ Myers says. That often leaves teams maintaining equipment with outdated software or devices that have reached the end of manufacturer support.
RunSafe’s report found that 28% of respondents said their organizations operate medical devices beyond the manufacturerโs end-of-support date.1 Among organizations with legacy equipment, 39% reported using it in emergency departments, 36% in intensive care units, and 33% in operating rooms and procedure suites.1
Asked why they continued using vulnerable devices, 38% said no acceptable replacement was available, 36% cited cost, 34% cited regulatory or approval constraints, and 33% said replacement would cause too much disruption.1 Nearly one-quarter said the manufacturer had not provided an upgrade path.1
Schwartz says large imaging systems are often among the older devices hospitals may need to keep in service as replacing an MRI, for example, can take years of budgeting, and installing a new one can require substantial construction. โThey need to figure out, is there a way to bubble wrap that thing from a cybersecurity perspective to keep it operating as long as they can,โ Schwartz says. โWe have to find defensive measures for older stuff, and we have to really focus on secure by design for anything new.โ
One such measure is runtime exploit protection, which is designed to block attacks on vulnerable software without requiring a patch. Among 419 respondents familiar with the technology in RunSafeโs survey, 82% said their organizations had deployed or were piloting it: 29% widely and 53% on some devices.1
Schwartz says older devices also pose a question for manufacturers: Should they still be selling them? In Japan, medical device manufacturers have had to demonstrate conformity with cybersecurity principles based on JIS T 81001-5-1 since April 2024. She says the framework calls for reassessing โtransitional health softwareโโproducts developed before current secure-development practicesโand identifying additional controls where needed.
โIn Japan, they may actually literally tell you, โGet that old thing off the market right now. Take it out of the hospitals,โโ Schwartz says.
Schwartz expects other countries to take a closer look at older products, too. โI donโt think that that is going to be an outlier for very long,โ she says.
Cybersecurity Planning Shifts Toward Clinical Continuity
Hospitals cannot patch every vulnerability or prevent every disruption, Sollinger says. That is putting more emphasis on limiting an incidentโs effects and protecting the systems most critical to patient care.
โHospitals need to understand that devices are going to have vulnerabilities,โ she says. โThere are going to be new vulnerabilities discovered, and you canโt probably patch all of them. You canโt control the risk with all of them.โ
Gee says teams need plans to keep providing safe care if a cyberattack or other outage takes essential technology offline. The Joint Commission and AHAโs new Cyber Resilience Readiness program gives hospitals a way to assess their ability to maintain care in such an event. โThe time to figure out how to do that is not during an incident,โ he says. โWhat we encourage is build those plans and practice.โ
Sollinger says HTM professionals have a role in those decisions because they know what the equipment does and how clinicians rely on it. For her, that reflects a change in how the field understands medical device cybersecurity.
โUltimately, weโre moving from medical device security just being viewed as a specialized security problem to now being recognized as a core component of patient safety,โ she says.
References
- RunSafe Security. RunSafe Securityโs 2026 medical device cybersecurity index: Insights from healthcare decision-makers on medical device procurement, risk, and resilience. Published 2026. Accessed 2026 Sept 17.
- Verizon. 2026 Data breach investigations report: Healthcare snapshot. Published 2026. Accessed 2026 17 Sept.
- Omega Systems. Under pressure: The 2026 healthcare IT landscape report. Published 2026. Accessed 2026 Sept 17.
- Health-ISAC. 2026 Global health sector threat landscape. Published 2026. Accessed 2026 Sept 17.
ID 71953800 ยฉ Sudok1 | Dreamstime.com