Independent industry coverage
FDA • MedTech • Biotechnology • Healthcare Business

The New Dealbreaker in Medical Device Procurement? Cybersecurity | By Phil Englert is the VP of Medical Device Security for Health-ISAC

Any connected device can be exploited. Recognizing that truth, we must try to ensure that when a vulnerability inevitably emerges, there’s a plan, and everyone involved knows what to do next
Cybersecurity

The medical device industry is booming, expanding by around 6% CAGR each year, and expected to reach a valuation of $900 billion by 2030. For better or worse, that means medical device companies are getting a wealth of attention, and not just from regulators and investors.

Cybercriminals, always eager for new targets, are one cohort paying particular attention. Between 2013 and 2025, the FDA issued 18 safety communications regarding cybersecurity breaches in medical devices, including unauthorized remote access to medical devices and exposure of patient data. CISA issued 14 ICS Medical Advisories in 2026 alone. (https://www.cisa.gov/news-events/ics-advisories#:~:text=ICS%20Medical%20Advisory%20(ICSMA)%3A%20Cybersecurity,and%20systems%20supporting%20medical%20devices.)

Consequently, healthcare companies are now demanding a more proactive approach to cybersecurity in the devices they purchase. Rather than accepting broad assurances from manufacturers that a device is “secure,” more procurement teams now perform cybersecurity risk assessments and require detailed information before a purchase is approved, and increasingly, these requirements are being written directly into Requests for Proposal (RFPs) and purchasing contracts.

Avoiding emergencies

Software enabled medical devices are incredibly diverse, spanning everything from mostly mechanical devices like wheelchairs to network connected patient monitors to fully integrated Computer Aided tomography (CT) systems. Many perform therapies or life-critical functions, so a cybersecurity incident can have serious consequences beyond data loss. If a device is compromised, unavailable, or operating incorrectly, patient care could be disrupted and, in the most grave cases, put lives at risk.

Vulnerabilities in a single device can provide attackers with a pathway into wider hospital networks, disrupting clinical workflows and placing additional strain on already stretched healthcare services.

Hospitals can often isolate or replace standard IT systems during a cyberattack, but taking a ventilator, infusion pump or patient monitor out of service is a far more difficult decision. It’s not an easy choice, and one that would best be avoided from the get-go.

What buyers should ask

The stakes are obviously high, so rather than relying on vendors’ claims, healthcare organizations are increasingly asking manufacturers to demonstrate that their products incorporate security at the core. Procurement teams often now require evidence that vendors have planned for the entire lifecycle of a device and that they can respond quickly as new threats emerge.

In the European Union, the EU Agency for Cybersecurity (ENISA) published procurement guidelines for hospitals and healthcare providers last July. The guidelines focus on improving the security of 500,000 types of medical devices.

And in the U.S., the FDA published its own framework: Cybersecurity in Medical Devices: Quality System Considerations and Content of Premarket Submissions. These include suggestions of documentation to request from medical device suppliers. Procurement teams are also developing their own checklists of documentation to gauge whether a medical device meets their bar for security.

One of the most important documents for these buyers is a Software Bill of Materials (SBOM), which provides an inventory of the software components used within a medical device. An SBOM helps healthcare organizations quickly determine whether devices contain software affected by newly discovered vulnerabilities, allowing them to prioritize risk assessments and remediation. One survey found 35% of healthcare providers would not consider purchasing a medical device without a SBOM.

Another important document is the Manufacturer Disclosure Statement for Medical Device Security or MDS2 which is essentially a standardized cybersecurity fact sheet completed by a medical-device manufacturer. Its purpose is to give healthcare organizations the technical information they need to evaluate how securely a device can be deployed, configured, operated and maintained in their specific environment. The MDS2 does not tell you whether a medical device is secure. It gives you information needed to determine whether you can securely operate and manage the cyber resilience of that device.

Organizations are also requesting network architecture diagrams that show how devices communicate across hospital networks. These diagrams help security teams understand where devices should reside, what systems they interact with, what protocols and ports they use, and whether internet connectivity is required. This information allows hospitals to design appropriate network segmentation, implement monitoring, and minimize the potential impact if a device is compromised.

Equally important are documented patching policies. Healthcare organizations want to understand how manufacturers identify and investigate vulnerabilities; whether they participate in coordinated vulnerability disclosure programmes; how customers are notified when security issues are discovered; and what service level commitments exist for developing and releasing patches.

Crucially, healthcare providers want assurance that security updates can be deployed without disrupting clinical operations.

Getting it in print

As these requirements become more standardized, healthcare organizations are looking for ways to ensure every prospective vendor meets the same security baseline. And they’re turning to an old system to fill the gap: the Request for Proposal (RFP).

In the past, RFPs focused on factors such as clinical performance, interoperability, and cost and service agreements. Cybersecurity questions, if they appeared at all, were often limited to a short questionnaire that was completed after a vendor had already been identified.

Recognizing that procurement is one of the few opportunities to influence a manufacturer’s security practices before a device enters the clinical environment, buyers are making cybersecurity a valued requirement within the RFP process. This lets them compare vendors on objective criteria instead of relying on promises made during sales presentations.

Final thoughts

It’s almost become cliche to say: the best cybersecurity approach is proactive, not reactive. Nevertheless, that phrase holds some truth. Cybersecurity must be built into an organization, not simply tacked on as an afterthought.

For healthcare organizations, that means starting before a medical device is purchased. Asking the right questions during procurement can reveal whether a manufacturer understands their security responsibilities, has a plan for addressing vulnerabilities, and will continue supporting the device long after it is installed.

Any connected device can be exploited. Recognizing that truth, we must try to ensure that when a vulnerability inevitably emerges, there’s a plan, and everyone involved knows what to do next.

Editor’s Note: Phil Englert is the VP of Medical Device Security for Health-ISAC, working with Medical Device Manufacturers (MDMs) to help improve privacy and security while coordinating with Health Delivery Organizations (HDOs) to ensure implementations are practical and achievable. Phil has over 30 years of technical and operational leadership in healthcare and life sciences, focusing on strategy, operations, data, and technology-enabled business optimization, IoT security, and privacy. He possesses deep knowledge of healthcare & clinical settings and extensive knowledge of medical technology and innovation. As the National Director of Technology Operations at Catholic Health Initiatives, Phil led strategic and tactical development to support 380,000 medical devices for a $250M in-house service organization supporting over 130 Acute Care facilities across 22 states.