The ultimate guide to medical device cybersecurity.
105+ organized, actionable tips across every phase, from concept and SPDF, through threat modeling and FDA submission, to postmarket monitoring. We meet you where you are and walk you to what's next.
What changed recently
The most recent published entries from our regulatory and threat feed. Scheduled posts are hidden until their publish date.
-
FDA · 6d ago
Mid-2026 field notes: what's tripping up 524B submissions right now
Five months into the Feb 3, 2026 guidance, a clear pattern of deficiencies has emerged around SBOM depth, VEX handling, and AI/ML threat modeling. Here's what reviewers are flagging most this quarter.
Read update -
Standards · 16d ago
HHS 405(d) HICP 2026 refresh: what changes for MedTech manufacturers
The Health Industry Cybersecurity Practices (HICP) 2026 refresh from HHS 405(d) tightens the manufacturer-facing sections, especially around SBOM disclosure to HDOs and coordinated vulnerability handling.
Read update -
FDA · 1mo ago
PCCPs and cybersecurity: what changes when your AI model updates itself
FDA's Predetermined Change Control Plans let AI/ML devices ship updates without a new submission - but the cyber risk surface moves with every retrain. Here's how to scope a PCCP that doesn't quietly invalidate your 524B package.
Read update
Where are you in your MedTech security journey?
Pick the option that fits best. We'll send you straight to the right roadmap with the tips that matter right now.
Five phases. One canonical artifact per phase.
Real incidents. Real patients.
Pacemakers recalled by the hundreds of thousands. Insulin pumps deemed unpatchable. Imaging fleets locked by ransomware. The full sourced record lives on Code Blue Chart, our sister timeline.
- Documented events
- 86
- Tied to patient harm
- 9
From Therac-25 to Synnovis
-
Real-world attackMay 2024
Ascension ransomware - EHR down across 140 hospitals
Black Basta ransomware took Ascension's EHR, MyChart, and connected medical-device workflows offline for nearly a month across 140 hospitals. Nurses reverted to paper charting and manual medication checks; ambulance diversions were reported in multiple states.
Read the case -
Real-world attackFeb 2024
Change Healthcare - largest US healthcare breach on record
ALPHV/BlackCat ransomware against UnitedHealth-owned Change Healthcare disrupted claims, prescriptions, and prior auth for weeks. ~190 million people had PHI exposed - the largest medical-data breach ever reported to HHS.
Read the case -
Patient harmJun 2024
Synnovis ransomware - first NHS-attributed cyber death
Qilin ransomware crippled NHS pathology for King's College, Guy's and St Thomas'. 10,000+ appointments and 1,700 surgeries cancelled. NHS England later confirmed one patient death tied to the attack - the first cyber death the NHS has formally attributed.
Read the case -
Real-world attackMay 2021
Conti ransomware shuts down Ireland's HSE
Conti ransomware took the Irish Health Service Executive offline nationwide. Imaging, oncology, and maternity services were degraded for months; the post-incident review put the recovery cost above €100M and flagged systemic underinvestment in healthcare cyber.
Read the case -
Patient harmSep 2020
Düsseldorf University Hospital ransomware - patient diversion death
A ransomware attack on Düsseldorf University Hospital forced ambulance diversion; a patient died en route to a more distant hospital. German prosecutors investigated it as the first ransomware-linked death, though causation was later contested.
Read the case -
Real-world attackOct 2020
UHS Ryuk attack - 400+ US hospitals offline
Ryuk ransomware took Universal Health Services' 400+ US facilities offline simultaneously, forcing manual workflows for nearly a month. The largest single-operator hospital outage in US history.
Read the case -
Recall / advisoryJun 2019
Medtronic MiniMed insulin pump recall
FDA recalled MiniMed 508 and Paradigm insulin pumps after researchers showed an attacker within wireless range could change pump settings. The first cyber-driven recall of a wearable insulin pump.
Read the case -
Recall / advisoryAug 2017
465,000 St. Jude / Abbott pacemakers - firmware update
FDA issued a Class II safety communication and firmware update for 465,000 implanted pacemakers to fix vulnerabilities that could let an attacker drain batteries or alter pacing. The defining cyber-driven advisory for implantable devices.
Read the case -
Real-world attackMay 2017
WannaCry cripples NHS - imaging fleets go dark
WannaCry disrupted at least 80 of 236 NHS trusts (37 directly infected, 44 further disrupted, per the UK NAO). Multiple medical devices including Bayer Medrad imaging consoles were reported infected, taking MRI and CT workflows offline mid-care.
Read the case -
Real-world attackFeb 2016
Hollywood Presbyterian - first major hospital ransomware payout
Locky ransomware crippled Hollywood Presbyterian Medical Center for 10 days. The hospital paid 40 BTC (~$17,000) - the incident that put hospital ransomware on every CISO's threat model.
Read the case -
Patient harmJun 1985
Therac-25 - software flaws cause radiation overdoses
Between 1985 and 1987 the Therac-25 linear accelerator delivered massive radiation overdoses across six known incidents; multiple patients died (Leveson & Turner, 1993). The foundational case study for software safety in medical devices.
Read the case
Or browse every phase end-to-end
Five phases, from concept to incident response. Click any phase to dive in.
Defining the device, risks, and security architecture.
Building, testing, and documenting before submission.
FDA review, deficiencies, and clearance.
Operating the device safely in the field.
Responding to vulnerabilities and breaches.
Nine topics, end to end
Overview
Start here. The big picture for MedTech security.
Why It Matters
The case for taking cybersecurity seriously: patients, brand, and revenue.
SPDF
Bake security into every stage of the device lifecycle.
Threat Modeling
Identify and reason about threats before they ship.
Pentesting
What's in scope (hardware, firmware, wireless, cloud, mobile), the methods reviewers expect, and how to read a pentest report against FDA cybersecurity guidance.
Premarket
Submit a cybersecurity package the FDA will accept.
FDA Response
Turn an FDA cybersecurity hold into a clean clearance.
Postmarket
Stay compliant and secure after your device is on the market.
Monitoring
Continuous vulnerability monitoring for fielded devices.
AI/ML Devices
Adversarial ML, model integrity, PCCPs, and the security surface unique to learning-enabled devices.
Vuln Management
The end-to-end lifecycle: discovery, CVSS/rubric assessment, coordinated disclosure (CVD), and patch validation for fielded medical devices.
This guide is sponsored by Blue Goat Cyber℠, a MedTech-focused security firm. Editorial decisions are independent.
Book a discovery sessionStay current as guidance evolves
FDA guidance, threat patterns, and submission expectations shift constantly. Track what's changed and why it matters for your program.