Tips on medical device security from the product leaders’ perspective

Business News

Medical device innovations have enhanced healthcare and improved patient care, but they present a broad attack surface for healthcare organizations.

NETSpi, a security service company, hosted medical device product security experts to talk about the business and challenges of securing connected technologies in healthcare. They addressed sharing information across teams throughout the product lifecycle, building product security teams, legislative changes governing the space and strategies to increase the pipeline of talent.

Business News Where does product security sit within the enterprise?

Matt Russo, senior director of product security at Medtronic, Curt Blythe, director of product security at Abbott and Matt Weir, principal cybersecurity engineer at MITRE, all agreed that regardless of where product security teams sit, they need to be partners in product development.

Where it makes sense from a scale and efficiency perspective, there’s one team dedicated to scanning devices as a centralized function with a distributed model, Blythe said.

But the key point is embedding design and security practices into what developers do every day, which ultimately enables them to move fast, “but in a safe way.”

Russo said that at Medtronic, “You can really see that across the landscape.” 

While resource restrictions make centralized product security functions more feasible, and that generally works for Medtronic and other large organizations, he said many device companies need to look at the technical aptitude of security teams. 

Is product security just a part of what they do?

Weir noted that it’s hard to have a dedicated security team if you have a small product base. 

“The big thing though is that you do have that integration during your product development lifecycle,” he said. 

When medical device developers try to add cybersecurity later into the process, it makes it much harder to be successful, he added. 

Weir advised integrating product security as early as possible into the product lifecycle, and continuing communication as products evolve. 

Product security specialists bring visibility into systems – they can then see how the devices are being used, and are better positioned to recommend mitigations, he said. 

Business News How do you get buy-in for product security? Build a program and get executive support

Blythe said that by making leaders aware of policy changes on the horizon, you can get their buy-in.

“Tap into your government affairs organization and find out what policies are coming out and how you stay out front of what is changing,” and make sure leaders have that awareness, he said. 

“They are bought into that, right, and that can be translated down into their business and their leaders, and ultimately, they can be successful in what they are trying to do.”

Get your foot in the door by encouraging that process, Weir advised.

He noted that the Food & Drug Administration’s premarket guidance recommends threat modeling. 

“When you can actually start to solve problems and you know, get ahead of these issues, that’s when you start to realize the full buy-in to be able to do more,” said Weir.

Business News The ‘new’ legislative compliance climate for medical device security

With the passage of the 2022 Omnibus Appropriations Act, “including a rider essentially for the PATCH Act,” said Blythe, the FDA has legislative authority over medical device manufacturers. 

They need to provide a software bill of materials, show a post-marketing monitoring process with threat intelligence and maintain the security posture of devices out in customers’ hands. 

“I’ll say that none of that is really new,” said Blythe.

“All those main messages have been communicated previously,” and the omnibus just shifts FDA’s regulatory guidance to a legislative authority the agency will be looking to enforce, he said.

“It’s really tough to go ahead and actually do it,” Weir said of the SBOM. Having the ability to respond to new vulnerabilities is really important, he added.

Creating SBOMs is not a trivial task, Russo agreed. “It’s still something the industry needs to work through.”

Business News Like to tinker? Become a medical device tester

Weir said that understanding the clinical workflows are more challenging than the cybersecurity aspects of medical device development.

While there are now more certifications than ever, Russo said the personality for the job of product security is the “tinkerer.” 

The key difference with the product security function is, “We want to break what the engineers build, right? We want to see how we can make it fail or how we can break apart what they’ve done,” he said, adding that whether it’s through threat modeling or penetration testing, product security specialists are partners in product development.

They want to “feed that [information] back into the system, so it can be built back up better” and give that knowledge to the engineers that want to be the builders. 

Andrea Fox is senior editor of Healthcare IT News.
Email: af**@***ss.org

Healthcare IT News is a HIMSS Media publication.

Jeremy Petch will offer more detail at the HIMSS23 session “Opening the Black Box: Promise and Limitations of Explainable AI.” It’s scheduled for Wednesday, April 19 at 10 a.m. – 11 a.m. CT at the South Building, Level 5, room S503.

Read More
Elroy Badon

Latest

Philippines SEC Signals Readiness for Real-World Asset Tokenization

You are here: Home / Cryptocurrency News / Philippines SEC Signals Readiness for Real-World Asset Tokenization The Philippines SEC has signalled the readiness of the country to tokenize its real-world assets (RWAs), with more and more trust being invested in the blockchain-powered financial tools. As per the opinion of the regulator, all the legal frameworks

FIFA president Infantino brushes off World Cup criticism as crypto ambitions linger in the background

Giovanni Infantino has never been accused of lacking confidence. At press conferences held between June 10-14, the FIFA president addressed a growing list of complaints about the 2026 World Cup by telling critics to “chill and relax.” The tournament, he insisted, would be a success. The critics have material to work with. Ticket prices for

Morocco’s World Cup win over Scotland sparks crypto prediction market frenzy

Morocco’s 1-0 victory over Scotland on June 19 wasn’t just a statement win for the Atlas Lions. It was also one of the most heavily traded sporting events in crypto prediction market history, with volumes exceeding $2 billion around the Group C opener alone. Ismael Saibari scored just 71 seconds into the match at Boston

Newsletter

Don't miss

Philippines SEC Signals Readiness for Real-World Asset Tokenization

You are here: Home / Cryptocurrency News / Philippines SEC Signals Readiness for Real-World Asset Tokenization The Philippines SEC has signalled the readiness of the country to tokenize its real-world assets (RWAs), with more and more trust being invested in the blockchain-powered financial tools. As per the opinion of the regulator, all the legal frameworks

FIFA president Infantino brushes off World Cup criticism as crypto ambitions linger in the background

Giovanni Infantino has never been accused of lacking confidence. At press conferences held between June 10-14, the FIFA president addressed a growing list of complaints about the 2026 World Cup by telling critics to “chill and relax.” The tournament, he insisted, would be a success. The critics have material to work with. Ticket prices for

Morocco’s World Cup win over Scotland sparks crypto prediction market frenzy

Morocco’s 1-0 victory over Scotland on June 19 wasn’t just a statement win for the Atlas Lions. It was also one of the most heavily traded sporting events in crypto prediction market history, with volumes exceeding $2 billion around the Group C opener alone. Ismael Saibari scored just 71 seconds into the match at Boston

5 Small Business Ideas for Retirees Who Don’t Want to Sit Still

Please enable JS and disable any ad blocker

Business delegation visits Kazakhstan to strengthen economic and trade cooperation

Astana, Kazakhstan, Jun 2, 2026 - (ACN Newswire) - A business delegation led by the Chief Executive of the Hong Kong Special Administrative Region (HKSAR), John Lee, and organised by the Hong Kong Trade Development Council (HKTDC), began its visit to Astana, the capital of Kazakhstan, on 1 June. During the visit, a total of 43

13 Real Business Trip Stories That Prove Work Travel Collects More Stories Than Miles

Real business trips almost never go the way the itinerary promised. They start with a confidently-packed suitcase and an eight-page agenda, and somewhere between the airport gate and the hotel breakfast they quietly turn into something nobody could have invented — equal parts comedy, chaos, and unscheduled adventure. These 13 real business trip moments are exactly that kind of work-trip plot

Your business texts could look like scam messages from July 1 if you don’t act now

From July 1, any branded SMS your business sends without a registered sender ID will be labelled “Unverified” and grouped with scam messages.  What’s happening: From 1 July 2026, any business or organisation that sends SMS using a branded name, such as “MyShop” or “AcmeServices”, instead of a phone number, must have that sender ID