---
title: "MedTech Cyber Tips | Medical Device Cybersecurity Guide"
description: "105+ organized, vendor-neutral tips on medical device cybersecurity - SPDF, threat modeling, FDA premarket and postmarket, SBOM, and continuous monitoring."
lang: en
json-ld: |
  [
    {
      "@context": "https://schema.org",
      "@graph": [
        {
          "@type": "WebSite",
          "@id": "https://medtechcybertips.com/#website",
          "url": "https://medtechcybertips.com/",
          "name": "MedTech Cyber Tips",
          "description": "The ultimate organized guide to medical device cybersecurity.",
          "inLanguage": "en-US",
          "publisher": {
            "@id": "https://medtechcybertips.com/#org"
          },
          "potentialAction": {
            "@type": "SearchAction",
            "target": "https://medtechcybertips.com/topics?q={search_term_string}",
            "query-input": "required name=search_term_string"
          }
        },
        {
          "@type": "Organization",
          "@id": "https://medtechcybertips.com/#org",
          "name": "MedTech Cyber Tips",
          "url": "https://medtechcybertips.com/",
          "logo": "https://medtechcybertips.com/icon-512.png",
          "sponsor": {
            "@type": "Organization",
            "name": "Blue Goat Cyber",
            "url": "https://bluegoatcyber.com",
            "sameAs": [
              "https://home.bluegoatcyber.com/",
              "https://codebluechart.com/",
              "https://why.bluegoatcyber.com/",
              "https://spdf.bluegoatcyber.com/",
              "https://threatmodel.bluegoatcyber.com/",
              "https://pentesting.bluegoatcyber.com/",
              "https://premarket.bluegoatcyber.com/",
              "https://fdaresponse.bluegoatcyber.com/",
              "https://postmarket.bluegoatcyber.com/",
              "https://goatwatch.bluegoatcyber.com/"
            ]
          }
        }
      ]
    },
    {
      "@context": "https://schema.org",
      "@type": "WebSite",
      "name": "MedTech Cyber Tips",
      "url": "https://medtechcybertips.com",
      "description": "The ultimate guide to medical device cybersecurity, sponsored by Blue Goat Cyber.",
      "potentialAction": {
        "@type": "SearchAction",
        "target": "https://medtechcybertips.com/topics?q={search_term_string}",
        "query-input": "required name=search_term_string"
      }
    },
    {
      "@context": "https://schema.org",
      "@type": "Organization",
      "name": "Blue Goat Cyber",
      "url": "https://bluegoatcyber.com"
    }
  ]
---

[Skip to main content](#main)

[

MedTech Cyber Tips

The Ultimate Guide



](/)

[Home](/)[Find Your Path](/journey)[All Topics](/topics)Reference[About](/about)

Search ⌘K

 ![Hospital patient monitor and infusion pump with an ECG waveform and circuit traces flowing across the scene](/assets/hero-medtech-1536-B7eOAmhH.webp)

Sponsored by Blue Goat Cyber℠

# The ultimate guide to medical device cybersecurity .

105+ organized, actionable tips across every phase, from concept and SPDF, through threat modeling and FDA submission, to postmarket monitoring. We meet you where you are and walk you to what's next.

[Find your path](/journey) [Browse all topics](/topics)

FDA-aligned

Premarket → Postmarket

Vendor-neutral education

Latest updates

## What changed recently

The most recent published entries from our regulatory and threat feed. Scheduled posts are hidden until their publish date.

[RSS](/rss.xml)[View all](/updates)

1.  [
    
    Standards  Sep 2, 2026· 6d ago 
    
    ### EU CRA delegated acts under Article 27 - the technical baseline is taking shape
    
    The European Commission's Article 27 delegated acts translating the Cyber Resilience Act's essential requirements into technical standards are moving through consultation. For medical device makers, three of the draft harmonized standards will do most of the audit work.
    
    Read update
    
    ](/updates/cra-delegated-acts-q3-2026)
2.  [
    
    Vulnerability  Aug 5, 2026· 1mo ago 
    
    ### CISA + FDA joint advisories in 2026: infusion pumps, imaging, and what to do next
    
    Several CISA/FDA joint medical device advisories landed in the first half of 2026, clustered around infusion pumps and imaging modalities. Here's the pattern manufacturers should read from them.
    
    Read update
    
    ](/updates/cisa-fda-joint-advisories-mid-2026)
3.  [
    
    FDA  Jul 22, 2026· 2mo ago 
    
    ### PCCP + 524B check-in: pairing your change-control plan with the Feb 2026 guidance
    
    A quick July 2026 reminder that Predetermined Change Control Plans and Section 524B cybersecurity obligations are not separate workstreams - each PCCP-covered modification needs a matching cyber impact analysis in your SPDF.
    
    Read update
    
    ](/updates/pccp-524b-july-2026-checkin)

30-second quiz

## Where are you in your MedTech security journey?

Pick the option that fits best. We'll send you straight to the right roadmap with the tips that matter right now.

Just starting out

Concept, architecture, security from day one.

Building & testing

Threat modeling, SBOM, pentesting, evidence.

Preparing FDA submission

Premarket package, RTA items, deficiency letters.

Already on market

Postmarket monitoring, patches, vulnerability response.

Active incident

Vulnerability disclosed, breach, or field action.

The Secure Product Development Framework, end to end

### Five phases. One canonical artifact per phase.

1.  [
    
    01 
    
    Concept
    
    Artifact
    
    Threat model
    
    ](/journey/concept)
2.  [
    
    02 
    
    Premarket
    
    Artifact
    
    SBOM
    
    ](/journey/premarket)
3.  [
    
    03 
    
    Submission
    
    Artifact
    
    Pentest report
    
    ](/journey/submission)
4.  [
    
    04 
    
    Postmarket
    
    Artifact
    
    VEX + monitoring
    
    ](/journey/postmarket)
5.  [
    
    05 
    
    Incident
    
    Artifact
    
    CAPA / advisory
    
    ](/journey/incident)

The threats aren't hypothetical

## Real incidents. Real patients.

Pacemakers recalled by the hundreds of thousands. Insulin pumps deemed unpatchable. Imaging fleets locked by ransomware. The full sourced record lives on [Code Blue Chart](https://codebluechart.com), our sister timeline.

Documented events

86

Tied to patient harm

9

Four decades of MedTech cyber incidents

### From Therac-25 to Synnovis

1985

1995

2005

2015

2026

[

Jun 1985

Therac-25 - software flaws cause radiation overdoses



](https://codebluechart.com/incidents/therac-25-1985)[

Feb 2016

Hollywood Presbyterian - first major hospital ransomware payout





](https://codebluechart.com/incidents/hollywood-presbyterian-2016)[

Aug 2017

465,000 St. Jude / Abbott pacemakers - firmware update



](https://codebluechart.com/incidents/stjude-abbott-recall-2017)[

May 2017

WannaCry cripples NHS - imaging fleets go dark





](https://codebluechart.com/incidents/wannacry-nhs-2017)[

Jun 2019

Medtronic MiniMed insulin pump recall



](https://codebluechart.com/incidents/medtronic-minimed-2019)[

Sep 2020

Düsseldorf University Hospital ransomware - patient diversion death





](https://codebluechart.com/incidents/duesseldorf-2020)[

Oct 2020

UHS Ryuk attack - 400+ US hospitals offline



](https://codebluechart.com/incidents/uhs-2020)[

May 2021

Conti ransomware shuts down Ireland's HSE





](https://codebluechart.com/incidents/hse-ireland-2021)[

May 2024

Ascension ransomware - EHR down across 140 hospitals



](https://codebluechart.com/incidents/ascension-2024)[

Feb 2024

Change Healthcare - largest US healthcare breach on record





](https://codebluechart.com/incidents/change-healthcare-2024)[

Jun 2024

Synnovis ransomware - first NHS-attributed cyber death



](https://codebluechart.com/incidents/synnovis-nhs-2024)

-   [
    
    Real-world attack May 2024 
    
    ### Ascension ransomware - EHR down across 140 hospitals
    
    Black Basta ransomware took Ascension's EHR, MyChart, and connected medical-device workflows offline for nearly a month across 140 hospitals. Nurses reverted to paper charting and manual medication checks; ambulance diversions were reported in multiple states.
    
    Read the case
    
    ](https://codebluechart.com/incidents/ascension-2024)
-   [
    
    Real-world attack Feb 2024 
    
    ### Change Healthcare - largest US healthcare breach on record
    
    ALPHV/BlackCat ransomware against UnitedHealth-owned Change Healthcare disrupted claims, prescriptions, and prior auth for weeks. ~190 million people had PHI exposed - the largest medical-data breach ever reported to HHS.
    
    Read the case
    
    ](https://codebluechart.com/incidents/change-healthcare-2024)
-   [
    
    Patient harm Jun 2024 
    
    ### Synnovis ransomware - first NHS-attributed cyber death
    
    Qilin ransomware crippled NHS pathology for King's College, Guy's and St Thomas'. 10,000+ appointments and 1,700 surgeries cancelled. NHS England later confirmed one patient death tied to the attack - the first cyber death the NHS has formally attributed.
    
    Read the case
    
    ](https://codebluechart.com/incidents/synnovis-nhs-2024)
-   [
    
    Real-world attack May 2021 
    
    ### Conti ransomware shuts down Ireland's HSE
    
    Conti ransomware took the Irish Health Service Executive offline nationwide. Imaging, oncology, and maternity services were degraded for months; the post-incident review put the recovery cost above €100M and flagged systemic underinvestment in healthcare cyber.
    
    Read the case
    
    ](https://codebluechart.com/incidents/hse-ireland-2021)
-   [
    
    Patient harm Sep 2020 
    
    ### Düsseldorf University Hospital ransomware - patient diversion death
    
    A ransomware attack on Düsseldorf University Hospital forced ambulance diversion; a patient died en route to a more distant hospital. German prosecutors investigated it as the first ransomware-linked death, though causation was later contested.
    
    Read the case
    
    ](https://codebluechart.com/incidents/duesseldorf-2020)
-   [
    
    Real-world attack Oct 2020 
    
    ### UHS Ryuk attack - 400+ US hospitals offline
    
    Ryuk ransomware took Universal Health Services' 400+ US facilities offline simultaneously, forcing manual workflows for nearly a month. The largest single-operator hospital outage in US history.
    
    Read the case
    
    ](https://codebluechart.com/incidents/uhs-2020)
-   [
    
    Recall / advisory Jun 2019 
    
    ### Medtronic MiniMed insulin pump recall
    
    FDA recalled MiniMed 508 and Paradigm insulin pumps after researchers showed an attacker within wireless range could change pump settings. The first cyber-driven recall of a wearable insulin pump.
    
    Read the case
    
    ](https://codebluechart.com/incidents/medtronic-minimed-2019)
-   [
    
    Recall / advisory Aug 2017 
    
    ### 465,000 St. Jude / Abbott pacemakers - firmware update
    
    FDA issued a Class II safety communication and firmware update for 465,000 implanted pacemakers to fix vulnerabilities that could let an attacker drain batteries or alter pacing. The defining cyber-driven advisory for implantable devices.
    
    Read the case
    
    ](https://codebluechart.com/incidents/stjude-abbott-recall-2017)
-   [
    
    Real-world attack May 2017 
    
    ### WannaCry cripples NHS - imaging fleets go dark
    
    WannaCry disrupted at least 80 of 236 NHS trusts (37 directly infected, 44 further disrupted, per the UK NAO). Multiple medical devices including Bayer Medrad imaging consoles were reported infected, taking MRI and CT workflows offline mid-care.
    
    Read the case
    
    ](https://codebluechart.com/incidents/wannacry-nhs-2017)
-   [
    
    Real-world attack Feb 2016 
    
    ### Hollywood Presbyterian - first major hospital ransomware payout
    
    Locky ransomware crippled Hollywood Presbyterian Medical Center for 10 days. The hospital paid 40 BTC (~$17,000) - the incident that put hospital ransomware on every CISO's threat model.
    
    Read the case
    
    ](https://codebluechart.com/incidents/hollywood-presbyterian-2016)
-   [
    
    Patient harm Jun 1985 
    
    ### Therac-25 - software flaws cause radiation overdoses
    
    Between 1985 and 1987 the Therac-25 linear accelerator delivered massive radiation overdoses across six known incidents; multiple patients died (Leveson & Turner, 1993). The foundational case study for software safety in medical devices.
    
    Read the case
    
    ](https://codebluechart.com/incidents/therac-25-1985)

[Explore all 86 events on Code Blue Chart](https://codebluechart.com/timeline)

The full journey

## Or browse every phase end-to-end

Five phases, from concept to incident response. Click any phase to dive in.

[

PHASE 1

Concept

Defining the device, risks, and security architecture.



](/journey?phase=Concept)[

PHASE 2

Premarket

Building, testing, and documenting before submission.



](/journey?phase=Premarket)[

PHASE 3

Submission

FDA review, deficiencies, and clearance.



](/journey?phase=Submission)[

PHASE 4

Postmarket

Operating the device safely in the field.



](/journey?phase=Postmarket)[

PHASE 5

Incident

Responding to vulnerabilities and breaches.



](/journey?phase=Incident)

The library

## Nine topics, end to end

[View all](/topics)

[

6 tips 

### Overview

Start here. The big picture for MedTech security.

Read guide

](/topics/home)[

10 tips 

### Why It Matters

The case for taking cybersecurity seriously: patients, brand, and revenue.

Read guide

](/topics/why)[

7 tips 

### SPDF

Bake security into every stage of the device lifecycle.

Read guide

](/topics/spdf)[

12 tips 

### Threat Modeling

Identify and reason about threats before they ship.

Read guide

](/topics/threatmodel)[

10 tips 

### Pentesting

What's in scope (hardware, firmware, wireless, cloud, mobile), the methods reviewers expect, and how to read a pentest report against FDA cybersecurity guidance.

Read guide

](/topics/pentesting)[

8 tips 

### Premarket

Submit a cybersecurity package the FDA will accept.

Read guide

](/topics/premarket)[

10 tips 

### FDA Response

Turn an FDA cybersecurity hold into a clean clearance.

Read guide

](/topics/fdaresponse)[

12 tips 

### Postmarket

Stay compliant and secure after your device is on the market.

Read guide

](/topics/postmarket)[

6 tips 

### Monitoring

Continuous vulnerability monitoring for fielded devices.

Read guide

](/topics/goatwatch)[

12 tips 

### AI/ML Devices

Adversarial ML, model integrity, PCCPs, and the security surface unique to learning-enabled devices.

Read guide

](/topics/aiml)[

12 tips 

### Vuln Management

The end-to-end lifecycle: discovery, CVSS/rubric assessment, coordinated disclosure (CVD), and patch validation for fielded medical devices.

Read guide

](/topics/vulnerability-management)

This guide is sponsored by Blue Goat Cyber℠, a MedTech-focused security firm. Editorial decisions are independent.

[Book a discovery session](https://go.bluegoatcyber.com/meetings/blue-goat-cyber/discovery-session)

## Stay current as guidance evolves

FDA guidance, threat patterns, and submission expectations shift constantly. Track what's changed and why it matters for your program.

[See what's changed](/updates) [Browse resources](/resources)

MedTech Cyber Tips

The organized, end-to-end guide to medical device cybersecurity, from concept through postmarket. Part of the Blue Goat Cyber family.

Topics

-   [Overview](/topics/home)
-   [Why It Matters](/topics/why)
-   [SPDF](/topics/spdf)
-   [Threat Modeling](/topics/threatmodel)
-   [Pentesting](/topics/pentesting)

Reference

-   [Glossary](/glossary)
-   [FDA vs MDR](/compare)
-   [Resources](/resources)
-   [Updates](/updates)
-   [RSS feed](/rss.xml)

© 2026 medtechcybertips.com. An educational resource sponsored by Blue Goat Cyber.

Not legal or regulatory advice.