Tips on medical device security from the product leaders’ perspective

Business News

Medical device innovations have enhanced healthcare and improved patient care, but they present a broad attack surface for healthcare organizations.

NETSpi, a security service company, hosted medical device product security experts to talk about the business and challenges of securing connected technologies in healthcare. They addressed sharing information across teams throughout the product lifecycle, building product security teams, legislative changes governing the space and strategies to increase the pipeline of talent.

Business News Where does product security sit within the enterprise?

Matt Russo, senior director of product security at Medtronic, Curt Blythe, director of product security at Abbott and Matt Weir, principal cybersecurity engineer at MITRE, all agreed that regardless of where product security teams sit, they need to be partners in product development.

Where it makes sense from a scale and efficiency perspective, there’s one team dedicated to scanning devices as a centralized function with a distributed model, Blythe said.

But the key point is embedding design and security practices into what developers do every day, which ultimately enables them to move fast, “but in a safe way.”

Russo said that at Medtronic, “You can really see that across the landscape.” 

While resource restrictions make centralized product security functions more feasible, and that generally works for Medtronic and other large organizations, he said many device companies need to look at the technical aptitude of security teams. 

Is product security just a part of what they do?

Weir noted that it’s hard to have a dedicated security team if you have a small product base. 

“The big thing though is that you do have that integration during your product development lifecycle,” he said. 

When medical device developers try to add cybersecurity later into the process, it makes it much harder to be successful, he added. 

Weir advised integrating product security as early as possible into the product lifecycle, and continuing communication as products evolve. 

Product security specialists bring visibility into systems – they can then see how the devices are being used, and are better positioned to recommend mitigations, he said. 

Business News How do you get buy-in for product security? Build a program and get executive support

Blythe said that by making leaders aware of policy changes on the horizon, you can get their buy-in.

“Tap into your government affairs organization and find out what policies are coming out and how you stay out front of what is changing,” and make sure leaders have that awareness, he said. 

“They are bought into that, right, and that can be translated down into their business and their leaders, and ultimately, they can be successful in what they are trying to do.”

Get your foot in the door by encouraging that process, Weir advised.

He noted that the Food & Drug Administration’s premarket guidance recommends threat modeling. 

“When you can actually start to solve problems and you know, get ahead of these issues, that’s when you start to realize the full buy-in to be able to do more,” said Weir.

Business News The ‘new’ legislative compliance climate for medical device security

With the passage of the 2022 Omnibus Appropriations Act, “including a rider essentially for the PATCH Act,” said Blythe, the FDA has legislative authority over medical device manufacturers. 

They need to provide a software bill of materials, show a post-marketing monitoring process with threat intelligence and maintain the security posture of devices out in customers’ hands. 

“I’ll say that none of that is really new,” said Blythe.

“All those main messages have been communicated previously,” and the omnibus just shifts FDA’s regulatory guidance to a legislative authority the agency will be looking to enforce, he said.

“It’s really tough to go ahead and actually do it,” Weir said of the SBOM. Having the ability to respond to new vulnerabilities is really important, he added.

Creating SBOMs is not a trivial task, Russo agreed. “It’s still something the industry needs to work through.”

Business News Like to tinker? Become a medical device tester

Weir said that understanding the clinical workflows are more challenging than the cybersecurity aspects of medical device development.

While there are now more certifications than ever, Russo said the personality for the job of product security is the “tinkerer.” 

The key difference with the product security function is, “We want to break what the engineers build, right? We want to see how we can make it fail or how we can break apart what they’ve done,” he said, adding that whether it’s through threat modeling or penetration testing, product security specialists are partners in product development.

They want to “feed that [information] back into the system, so it can be built back up better” and give that knowledge to the engineers that want to be the builders. 

Andrea Fox is senior editor of Healthcare IT News.
Email: af**@***ss.org

Healthcare IT News is a HIMSS Media publication.

Jeremy Petch will offer more detail at the HIMSS23 session “Opening the Black Box: Promise and Limitations of Explainable AI.” It’s scheduled for Wednesday, April 19 at 10 a.m. – 11 a.m. CT at the South Building, Level 5, room S503.

Read More
Elroy Badon

Latest

Glenmark Pharma Q1 profit jumps over 10-fold as India, North America businesses power growth

Pharma major Glenmark Pharmaceuticals Ltd on Friday (July 31) reported a 930% year-on-year increase in consolidated net profit to ₹483 crore for the first quarter, compared with ₹47 crore in the corresponding quarter last year. The company's revenue rose 23% year-on-year to ₹4,018 crore, compared with ₹3,264 crore a year earlier. At the operating level

Crypto Hack : COLDCARD Wallet Flaw Linked to $38 Million BTC Theft

Coinkite has disclosed a critical entropy-generation flaw affecting certain COLDCARD Mk2 and Mk3 firmware versions that may have weakened the security of wallet recovery seeds. According to PeckShield, the vulnerability has been linked to the theft of about $38 million in Bitcoin. Users who generated seeds using affected firmware are advised to update to the

Could STX See a Resurgence Through Institutional Bitcoin Capital?

Stacks (STX) powering Bitcoin-native Finance targets idle Bitcoin, an op portunity that remains one of the largest untapped pools of capital in crypto. According to Binance Research, less than 1% of total BTC supply is currently used productively across DeFi, against staking ratios above 30% for Ethereum and 60% for Solana. Whoever converts even a

FTX Repayments: Creditors to Receive Another $900 Million

FTX will begin distributing another $900 million to creditors starting tomorrow, bringing total repayments since the exchange’s 2022 collapse to nearly $10 billion. Many creditors are expected to recover more than 100% of their original claim value based on the bankruptcy filing date, while some smaller accounts could receive up to 120%. The latest payout

Newsletter

Don't miss

Glenmark Pharma Q1 profit jumps over 10-fold as India, North America businesses power growth

Pharma major Glenmark Pharmaceuticals Ltd on Friday (July 31) reported a 930% year-on-year increase in consolidated net profit to ₹483 crore for the first quarter, compared with ₹47 crore in the corresponding quarter last year. The company's revenue rose 23% year-on-year to ₹4,018 crore, compared with ₹3,264 crore a year earlier. At the operating level

Crypto Hack : COLDCARD Wallet Flaw Linked to $38 Million BTC Theft

Coinkite has disclosed a critical entropy-generation flaw affecting certain COLDCARD Mk2 and Mk3 firmware versions that may have weakened the security of wallet recovery seeds. According to PeckShield, the vulnerability has been linked to the theft of about $38 million in Bitcoin. Users who generated seeds using affected firmware are advised to update to the

Could STX See a Resurgence Through Institutional Bitcoin Capital?

Stacks (STX) powering Bitcoin-native Finance targets idle Bitcoin, an op portunity that remains one of the largest untapped pools of capital in crypto. According to Binance Research, less than 1% of total BTC supply is currently used productively across DeFi, against staking ratios above 30% for Ethereum and 60% for Solana. Whoever converts even a

FTX Repayments: Creditors to Receive Another $900 Million

FTX will begin distributing another $900 million to creditors starting tomorrow, bringing total repayments since the exchange’s 2022 collapse to nearly $10 billion. Many creditors are expected to recover more than 100% of their original claim value based on the bankruptcy filing date, while some smaller accounts could receive up to 120%. The latest payout

Hyperliquid News: HYPE Whales Unstake Millions as Protocol Revenue Tops $1.21 Billion

Hyperliquid is drawing attention after large HYPE holders unstaked millions of tokens, including one wallet that withdrew 1.02 million HYPE and another that transferred 1.89 million HYPE worth about $105.9 million to institutional brokers, a move often associated with over-the-counter sales. Despite the whale activity, the protocol generated $1.18 million in daily fees and burned

‘Sabah is open for business’: Hajiji courts investors with promise of sustainable growth, carbon‑negative credentials

Sabah is pitching itself as an Asia-Pacific hub for impact investing, betting that its forests, biodiversity and natural resources can become drivers of economic growth as it seeks private capital for sustainable development. — Picture by Firdaus Latif By Julia Chan First Published: Monday, 13 Jul 2026 11:44 AM MYT KOTA KINABALU, July 13 —

Want Your Business to Be Seen Everywhere? Meet Tonia Ryan, Creator of Fix Your Search

Some people are good at their jobs. Then there is Tonia Ryan, who has turned “getting found online” into something close to magic. She is the creator of Fix Your Search, and if you have ever wondered why some businesses pop up everywhere while others seem invisible...

Grey Business processes $61 million as stablecoins dominate payments

Grey Business enables startups and SMEs to open US Dollar (USD) corporate accounts, send and receive international payments, convert currencies, and transact using stablecoins such as USDC and USDT...