Hospitals and medical device manufacturers have more cybersecurity guidance and requirements than ever, but third-party attacks, AI-assisted vulnerability discovery, and aging equipment continue to complicate efforts to reduce risk.


By Alyx Arnett

In 2026, more healthcare organizations are reporting cyber incidents involving medical devicesโ€”and more of those incidents are affecting patient care. RunSafe Securityโ€™s 2026 Medical Device Cybersecurity Index found that 24% reported an attack or exploited vulnerability involving a medical device, up from 22% in 2025.1 Among those, 80% said it had a moderate or significant effect on patient care, up from 75%.1

The risk is also reaching hospitals through companies they depend on, with third parties involved in 32% of confirmed healthcare breaches.2 Scott Gee, deputy national advisor for cybersecurity and risk at the American Hospital Association, sees another source of pressure: Artificial intelligence (AI) is shortening the time attackers need to turn a disclosed software vulnerability into an exploit.

โ€œEverything has gotten bigger and badder and more in your face,โ€ says Naomi Schwartz, vice president of services and regulatory strategy at MedCrypt and a former US Food and Drug Administration (FDA) reviewer. 

For medical device manufacturers, those growing risks are accompanied by more specific cybersecurity guidance, while hospitals have gained new resources to assess their risks and prepare for disruptions to care.

For Schwartz, the challenge is turning a growing volume of cybersecurity information into decisions hospitals can act on. โ€œItโ€™s very hardโ€ to keep up, she says.

Cybersecurity Guidance Expands on Both Sides of the Device

While risks are increasing, the good news is that the FDAโ€™s recently updated final cybersecurity guidance and Section 524B of the FD&C Act have โ€œsignificantly raised expectationsโ€ for medical device manufacturers, says Priyanka Sollinger, CHTM, DSL, AAMIF, FACCE, vice president of cybersecurity and risk reduction services at Asimily.ย 

โ€œThey now have responsibilities around securely deploying these devices, postmarket vulnerability management, and then having a good patching strategy,โ€ she says. Section 524B also requires manufacturers submitting covered cyber devices for premarket review to provide a software bill of materials (SBOM).

Expectations for that information are spreading globally. The International Medical Device Regulators Forum published principles for medical device SBOMs in 2023. In July, CISA and government partners from eight other countries updated the minimum elements for SBOMs

โ€œItโ€™s not the United States government and CISA focusing on software bill of materials,โ€ Schwartz says. โ€œItโ€™s the whole world, effectively.โ€

RunSafeโ€™s report found that 81% of respondents considered an SBOM important or essential when evaluating devices; 35% said they would not consider a device without one.ยน

Hospitals have also received new resources for assessing and responding to cyber risks. In March, the US Department of Health and Human Services (HHS) added a cybersecurity module to its RISC 2.0 toolkit, allowing healthcare organizations to assess cyber threats alongside other hazards. HHS also updated its Security Risk Assessment Tool, which is intended primarily for small and medium providers.

Gee points hospitals to the FBIโ€™s Operation Winter SHIELD, released this year. Its 10 recommended defenses draw on weaknesses seen in FBI investigations. The American Hospital Association and the Joint Commission also launched a voluntary Cyber Resilience Readiness program in May to help hospitals assess their ability to sustain safe, quality care during cyber disruptions.

The HIPAA Proposal Raises Questions

The proposed HIPAA Security Rule update, intended to strengthen cybersecurity protections for electronic protected health information, could go further by setting more specific requirements for hospitals.

โ€œThe HIPAA law needs to be updated,โ€ Schwartz says. โ€œAbsolutely, it is stale. There are a bunch of things it doesnโ€™t cover.โ€

Still, stakeholders have raised concerns about how some provisions work. For one, it would remove the distinction between โ€œrequiredโ€ and โ€œaddressableโ€ implementation specifications, making most specifications mandatory with limited exceptions, says Eddie Myers, HCISPP, CBET, national director of cybersecurity at Intelas. โ€œA lot of hospitals are saying, โ€˜OK, yes, we donโ€™t have the bandwidth to do that,โ€™ but theyโ€™re making it mandatory,โ€ Myers says.

It would also require network segmentation. โ€œMany organizations understand segmentation conceptuallyโ€”that they should segment medical devices,โ€ says Sollinger. โ€œBut now translating thousands of those device communication patterns into enforceable network policies, and then doing all of that without disrupting patient care or annoying your clinicians, thatโ€™s going to be difficult.โ€

Recovery raises a separate concern. The proposed rule calls for written procedures to restore critical relevant electronic information systems and data within 72 hours of their loss. “I donโ€™t know anybody that can do that, government agencies included,โ€ says Gee. โ€œWithin the first 72 hours, youโ€™re quite often still trying to figure out what happened, how it happened, how the bad guys got in, and make sure theyโ€™re not in anymore.โ€

Gee says he supports stronger cybersecurity measures but that the proposed requirements must be workable for hospitals. HHS issued the proposal in December 2024; the federal regulatory agenda now projects final action in July 2027. Meanwhile, Sollinger cautions against treating the delayed rulemaking as a reason to wait.

โ€œJust because it is still proposed doesnโ€™t mean itโ€™s not coming,โ€ she says.

Third-Party Risks Are at the Front Door

According to Gee, โ€œThe biggest challenge we see in the sector writ large right now is and continues to be third-party risk.โ€ 

Verizonโ€™s 2026 Data Breach Investigations Report found third-party involvement in 32% of confirmed healthcare breaches.2 A separate 2026 study found that 85% of healthcare practices experienced at least one operational disruption caused by a third-party or โ€œvendor-of-a-vendorโ€ failure during the past 12 months.3 

Gee points to recent examples like the March cyberattack on Stryker that disrupted the manufacturerโ€™s order processing, manufacturing, and shipping. In August, a cyber incident at Boston Scientific affected manufacturing and order fulfillment, along with the activation of some cardiac remote-monitoring devices.

Neither incident began inside a hospitalโ€™s network, but hospitals still had to consider their dependence on the manufacturers. Myers says the Stryker incident prompted Intelas to identify potentially affected devices across its clientsโ€™ inventories and evaluate their remote connections. Where disabling remote access would not interfere with patient care, the company recommended turning off those connections until the manufacturer provided an all-clear.

Third-party risk also extends to the companies that provide hospitals with billing, software, and IT services. Gee points to the 2024 attack on claims and payment processor Change Healthcare and an incident at healthcare software provider Craneware as examples. 

Health-ISACโ€™s 2026 threat report identifies medical billing, software, IT support, and file-transfer providers among the outside companies attackers target.4

AI Changes the Threat and the Response

AI is adding to the risk by helping attackers exploit newly disclosed vulnerabilities faster, Gee says. Before AI, he says, an attacker might have needed weeks to develop an exploit. โ€œWith AI, theyโ€™re doing it in minutes. AI is incredibly good at determining what vulnerabilities are and how to exploit them,โ€ he says.

AI could also add to the number of flaws demanding attention. In April, Anthropic reported that its Claude Mythos Preview model had found thousands of previously unknown software vulnerabilities. Anthropic has made the model available to selected defenders through Project Glasswing. For Myers, the finding is a reminder that even recently installed devices may have security weaknesses no one has discovered yet.

And, finding a vulnerability is only the beginning of the response, Schwartz says. A manufacturer must evaluate a fix and test it before releasing a patch. โ€œAnd thatโ€™s not fast,โ€ she says.

To help hospitals respond to attackers using increasingly capable AI, the Coalition for Health AI convened a nearly 100-member work group earlier this year. It is developing cybersecurity playbooks for health systems, with guidance expected by the end of 2026.

While AI may be speeding attacks, it can also help defenders. Sollinger says security and healthcare technology management (HTM) teams are using it to analyze device, network, and vulnerability data and identify risks that need attention. โ€œWe have enormous amounts of data … Itโ€™s just impossible for a human to do it all,โ€ she says.

Additionally, AI brings risks through the medical devices and clinical systems hospitals are using, Sollinger says. RunSafe’s report found that 57% of respondentsโ€™ organizations used AI-enabled or AI-assisted medical devices or clinical systems, and 80% expressed at least moderate concern about the associated cybersecurity risks.1

โ€œItโ€™s here; weโ€™re not stopping it, but we need to have a governance structure in place for how to use it appropriately,โ€ Gee says.

The Security Challenge of Legacy Devices

Hospitals have become better at identifying connected devices and their vulnerabilities, Sollinger says. โ€œBut then knowing that something is vulnerable and then being able to remediate that vulnerability are two very different things.โ€

That difficulty is particularly stark with older equipment. โ€œIn our world, HTM, weโ€™re there to extend the useful life of the device,โ€ Myers says. That often leaves teams maintaining equipment with outdated software or devices that have reached the end of manufacturer support.

RunSafe’s report found that 28% of respondents said their organizations operate medical devices beyond the manufacturerโ€™s end-of-support date.1 Among organizations with legacy equipment, 39% reported using it in emergency departments, 36% in intensive care units, and 33% in operating rooms and procedure suites.1

Asked why they continued using vulnerable devices, 38% said no acceptable replacement was available, 36% cited cost, 34% cited regulatory or approval constraints, and 33% said replacement would cause too much disruption.1 Nearly one-quarter said the manufacturer had not provided an upgrade path.1

Schwartz says large imaging systems are often among the older devices hospitals may need to keep in service as replacing an MRI, for example, can take years of budgeting, and installing a new one can require substantial construction. โ€œThey need to figure out, is there a way to bubble wrap that thing from a cybersecurity perspective to keep it operating as long as they can,โ€ Schwartz says. โ€œWe have to find defensive measures for older stuff, and we have to really focus on secure by design for anything new.โ€

One such measure is runtime exploit protection, which is designed to block attacks on vulnerable software without requiring a patch. Among 419 respondents familiar with the technology in RunSafeโ€™s survey, 82% said their organizations had deployed or were piloting it: 29% widely and 53% on some devices.1

Schwartz says older devices also pose a question for manufacturers: Should they still be selling them? In Japan, medical device manufacturers have had to demonstrate conformity with cybersecurity principles based on JIS T 81001-5-1 since April 2024. She says the framework calls for reassessing โ€œtransitional health softwareโ€โ€”products developed before current secure-development practicesโ€”and identifying additional controls where needed.

โ€œIn Japan, they may actually literally tell you, โ€˜Get that old thing off the market right now. Take it out of the hospitals,โ€™โ€ Schwartz says.

Schwartz expects other countries to take a closer look at older products, too. โ€œI donโ€™t think that that is going to be an outlier for very long,โ€ she says.

Cybersecurity Planning Shifts Toward Clinical Continuity

Hospitals cannot patch every vulnerability or prevent every disruption, Sollinger says. That is putting more emphasis on limiting an incidentโ€™s effects and protecting the systems most critical to patient care.

โ€œHospitals need to understand that devices are going to have vulnerabilities,โ€ she says. โ€œThere are going to be new vulnerabilities discovered, and you canโ€™t probably patch all of them. You canโ€™t control the risk with all of them.โ€

Gee says teams need plans to keep providing safe care if a cyberattack or other outage takes essential technology offline. The Joint Commission and AHAโ€™s new Cyber Resilience Readiness program gives hospitals a way to assess their ability to maintain care in such an event. โ€œThe time to figure out how to do that is not during an incident,โ€ he says. โ€œWhat we encourage is build those plans and practice.โ€

Sollinger says HTM professionals have a role in those decisions because they know what the equipment does and how clinicians rely on it. For her, that reflects a change in how the field understands medical device cybersecurity.

โ€œUltimately, weโ€™re moving from medical device security just being viewed as a specialized security problem to now being recognized as a core component of patient safety,โ€ she says.

References

  1. RunSafe Security. RunSafe Securityโ€™s 2026 medical device cybersecurity index: Insights from healthcare decision-makers on medical device procurement, risk, and resilience. Published 2026. Accessed 2026 Sept 17.
  2. Verizon. 2026 Data breach investigations report: Healthcare snapshot. Published 2026. Accessed 2026 17 Sept.
  3. Omega Systems. Under pressure: The 2026 healthcare IT landscape report. Published 2026. Accessed 2026 Sept 17. 
  4. Health-ISAC. 2026 Global health sector threat landscape. Published 2026. Accessed 2026 Sept 17.

ID 71953800 ยฉ Sudok1 | Dreamstime.com