Cybersecurity for Connected Medical Devices
SBOMs, network segmentation, and how FDA premarket guidance is reshaping bedside procurement.
The threat landscape
Hospitals absorbed a disproportionate share of ransomware incidents through the early 2020s, with the HHS Office for Civil Rights breach portal listing hundreds of covered-entity incidents annually. Connected bedside devices are rarely the initial entry point, but a flat network lets an EHR-server compromise reach the infusion pump.
SBOMs and premarket expectations
Section 524B of the FD&C Act (added by the December 2022 omnibus) requires manufacturers of cyber devices to submit a Software Bill of Materials (SBOM), a plan to monitor and patch vulnerabilities, and reasonable assurance that the device is cybersecure. The FDA 2023 Premarket Cybersecurity Guidance operationalizes this.
Network segmentation
- Biomedical VLANs isolate device traffic from clinical PCs.
- Micro-segmentation limits east-west movement between devices in the same VLAN.
- NAC (Network Access Control) enforces posture at connection.
- Passive discovery (deep packet inspection) is preferred over active scanning, which can crash legacy devices.
Standards and frameworks
- NIST Cybersecurity Framework 2.0 — the reference risk framework.
- HHS 405(d) HICP — Health Industry Cybersecurity Practices, tailored guidance.
- IEC 81001-5-1 — health software security lifecycle.
- ANSI/AAMI SW96 — medical-device security risk management.
References & further reading
Help us improve
Spotted something wrong, outdated, or unclear? Let the editors know.
Continue reading
Related guides
Networking
Hospital Wi-Fi
Why coverage in a hospital is harder than in an office — and what 'medical-grade' actually means.
9 min · Updated Apr 2026
Privacy
HIPAA Basics
What HIPAA does, what it doesn't, and how it applies inside the room.
10 min · Updated Mar 2026
Technology
Medical Device Integration
The middleware layer that quietly determines whether a smart room actually works.
12 min · Updated Jun 2026