Tips on medical device security from the product leaders’ perspective

Business News

Medical device innovations have enhanced healthcare and improved patient care, but they present a broad attack surface for healthcare organizations.

NETSpi, a security service company, hosted medical device product security experts to talk about the business and challenges of securing connected technologies in healthcare. They addressed sharing information across teams throughout the product lifecycle, building product security teams, legislative changes governing the space and strategies to increase the pipeline of talent.

Business News Where does product security sit within the enterprise?

Matt Russo, senior director of product security at Medtronic, Curt Blythe, director of product security at Abbott and Matt Weir, principal cybersecurity engineer at MITRE, all agreed that regardless of where product security teams sit, they need to be partners in product development.

Where it makes sense from a scale and efficiency perspective, there’s one team dedicated to scanning devices as a centralized function with a distributed model, Blythe said.

But the key point is embedding design and security practices into what developers do every day, which ultimately enables them to move fast, “but in a safe way.”

Russo said that at Medtronic, “You can really see that across the landscape.” 

While resource restrictions make centralized product security functions more feasible, and that generally works for Medtronic and other large organizations, he said many device companies need to look at the technical aptitude of security teams. 

Is product security just a part of what they do?

Weir noted that it’s hard to have a dedicated security team if you have a small product base. 

“The big thing though is that you do have that integration during your product development lifecycle,” he said. 

When medical device developers try to add cybersecurity later into the process, it makes it much harder to be successful, he added. 

Weir advised integrating product security as early as possible into the product lifecycle, and continuing communication as products evolve. 

Product security specialists bring visibility into systems – they can then see how the devices are being used, and are better positioned to recommend mitigations, he said. 

Business News How do you get buy-in for product security? Build a program and get executive support

Blythe said that by making leaders aware of policy changes on the horizon, you can get their buy-in.

“Tap into your government affairs organization and find out what policies are coming out and how you stay out front of what is changing,” and make sure leaders have that awareness, he said. 

“They are bought into that, right, and that can be translated down into their business and their leaders, and ultimately, they can be successful in what they are trying to do.”

Get your foot in the door by encouraging that process, Weir advised.

He noted that the Food & Drug Administration’s premarket guidance recommends threat modeling. 

“When you can actually start to solve problems and you know, get ahead of these issues, that’s when you start to realize the full buy-in to be able to do more,” said Weir.

Business News The ‘new’ legislative compliance climate for medical device security

With the passage of the 2022 Omnibus Appropriations Act, “including a rider essentially for the PATCH Act,” said Blythe, the FDA has legislative authority over medical device manufacturers. 

They need to provide a software bill of materials, show a post-marketing monitoring process with threat intelligence and maintain the security posture of devices out in customers’ hands. 

“I’ll say that none of that is really new,” said Blythe.

“All those main messages have been communicated previously,” and the omnibus just shifts FDA’s regulatory guidance to a legislative authority the agency will be looking to enforce, he said.

“It’s really tough to go ahead and actually do it,” Weir said of the SBOM. Having the ability to respond to new vulnerabilities is really important, he added.

Creating SBOMs is not a trivial task, Russo agreed. “It’s still something the industry needs to work through.”

Business News Like to tinker? Become a medical device tester

Weir said that understanding the clinical workflows are more challenging than the cybersecurity aspects of medical device development.

While there are now more certifications than ever, Russo said the personality for the job of product security is the “tinkerer.” 

The key difference with the product security function is, “We want to break what the engineers build, right? We want to see how we can make it fail or how we can break apart what they’ve done,” he said, adding that whether it’s through threat modeling or penetration testing, product security specialists are partners in product development.

They want to “feed that [information] back into the system, so it can be built back up better” and give that knowledge to the engineers that want to be the builders. 

Andrea Fox is senior editor of Healthcare IT News.
Email: af**@***ss.org

Healthcare IT News is a HIMSS Media publication.

Jeremy Petch will offer more detail at the HIMSS23 session “Opening the Black Box: Promise and Limitations of Explainable AI.” It’s scheduled for Wednesday, April 19 at 10 a.m. – 11 a.m. CT at the South Building, Level 5, room S503.

Read More
Elroy Badon

Latest

One of the Best Movies of 2025 is Finally Coming to Prime Video

There were a lot of great movies in 2025. Movies like Sinners, Marty Supreme, Weapons, and even Superman not only captured moviegoers attention, but delivered solid entertainment and great stories as well. They’re films that fans keep returning to well after their theatrical runs have ended and now, one of the best of the year

Oregon Sues Oklahoma Transfer Over Alleged Unpaid $10K NIL Contract Buyout

The University of Oregon says one of its former football players owes it $10,000, and the school is willing to go to court to get it. The school filed a lawsuit in Lane County Circuit Court last week against Dakoda Fields, a defensive back who spent two years with the Ducks before transferring to Oklahoma

Breaking Down Ole Miss’ Strengths, Weaknesses and One Thing It Needs to Beat LSU

The hottest location in college football this year brings LSU and Ole Miss together for a matchup that should be as close are expected. Both teams are rebuilt through the transfer portal and new coaching staffs, and this Sept. 19 matchup will be the first big test for either squad. So what gives Ole Miss

What are Indiana Football’s Biggest Trap Games of 2026?

Where will Indiana be ranked to start the 2026 college football season? While debate will rage regardless of the number next to Indiana's name to start the year, the Hoosiers will likely be favored in no fewer than 11 of their 12 regular season contests. That doesn't mean there won't be challenges along the way

Newsletter

Don't miss

One of the Best Movies of 2025 is Finally Coming to Prime Video

There were a lot of great movies in 2025. Movies like Sinners, Marty Supreme, Weapons, and even Superman not only captured moviegoers attention, but delivered solid entertainment and great stories as well. They’re films that fans keep returning to well after their theatrical runs have ended and now, one of the best of the year

Oregon Sues Oklahoma Transfer Over Alleged Unpaid $10K NIL Contract Buyout

The University of Oregon says one of its former football players owes it $10,000, and the school is willing to go to court to get it. The school filed a lawsuit in Lane County Circuit Court last week against Dakoda Fields, a defensive back who spent two years with the Ducks before transferring to Oklahoma

Breaking Down Ole Miss’ Strengths, Weaknesses and One Thing It Needs to Beat LSU

The hottest location in college football this year brings LSU and Ole Miss together for a matchup that should be as close are expected. Both teams are rebuilt through the transfer portal and new coaching staffs, and this Sept. 19 matchup will be the first big test for either squad. So what gives Ole Miss

What are Indiana Football’s Biggest Trap Games of 2026?

Where will Indiana be ranked to start the 2026 college football season? While debate will rage regardless of the number next to Indiana's name to start the year, the Hoosiers will likely be favored in no fewer than 11 of their 12 regular season contests. That doesn't mean there won't be challenges along the way

Green steel startup Boston Metal is doubling down on critical metals

The startup Boston Metal has raised a $75 million funding round to produce critical metals, MIT Technology Review can exclusively report.   The company has been known largely for its efforts to clean up steel production, an industry that's responsible for about 8% of global greenhouse emissions today. With the additional money, the new focus could

Tesla’s Business Has Become Much More Diversified in Just the Past Five Years. Does That Make Its Stock a Better Buy Today?

Key Points Tesla's energy generation and storage segment generated 27% revenue growth last year. The company's non-automotive segments were able to help offset a double-digit decline in auto revenue in 2025. These 10 stocks could mint the next wave of millionaires › Tesla (NASDAQ: TSLA) is known for its electric vehicles (EVs), and while they

WD sees sustainability as key business driver in an ‘AI economy’

Hard drive company WD promoted long-term operations and sustainability executive Jackie Jung to become its first chief sustainability officer in February, as it steps up sales to companies building AI data centers. Her vision: Turn sustainability into a “brand” for WD, a strategy that reduces risk for the $6 billion company (formerly known as Western

5 Business Ideas Worth Starting in 2026

If there is one thing Nigerians understand well, it is how to spot opportunity inside hardship. In 2026, that mindset will matter more than ever. The economy is tough, competition is rising, and many people are looking for smarter ways to earn, build, and survive. But even in a difficult environment, some businesses still stand