Map the cybersecurity attack surface of a connected medical device across its procurement-to-disposal lifecycle.
Healthcare Cybersecurity for Connected Medical Devices
Secure infusion pumps, imaging systems and other connected medical devices across procurement, network architecture and incident response, aligned to FDA cybersecurity expectations.
Course Overview
A hospital network can contain thousands of connected infusion pumps, monitors and imaging systems, many running operating systems no longer supported by their vendor, and each one is a potential entry point for an attacker or a device that fails when a network segment goes down during an incident. This course gives biomedical engineering, IT security and clinical engineering teams a practical way to manage that risk across the device lifecycle. Participants map attack surfaces from procurement through disposal, and study how ransomware incidents have disrupted clinical operations to understand the real-world stakes of device compromise. The regulatory module covers FDA premarket and postmarket cybersecurity expectations, the software bill of materials as a tool for tracking vulnerable components, and relevant international standards for medical device security. Technical sessions teach network segmentation and zero trust principles adapted for clinical environments where devices cannot always be taken offline for patching, alongside vulnerability scanning approaches suited to fragile legacy equipment. The course closes with incident response planning specific to device compromise and a procurement module that teaches how to evaluate a vendor's security documentation, including the manufacturer disclosure statement, before a device is purchased.
Expected Learning Outcomes
Assess a vendor's software bill of materials to identify components with known vulnerabilities.
Apply FDA premarket and postmarket cybersecurity expectations to a device evaluation or renewal decision.
Design a network segmentation architecture that isolates clinical devices without disrupting patient care.
Plan a vulnerability scanning approach appropriate to fragile or unpatchable legacy medical devices.
Develop an incident response plan specific to a compromised or malfunctioning connected medical device.
Evaluate a manufacturer disclosure statement for medical device security as part of a procurement decision.
Who Should Attend
Biomedical and clinical engineering staff responsible for connected device fleets
Healthcare IT security teams securing hospital networks and medical device segments
Procurement officers evaluating vendor security documentation before device purchase
Chief information security officers building incident response plans for clinical environments
Regulatory affairs staff tracking FDA and international medical device cybersecurity requirements
Hospital risk managers assessing cybersecurity exposure from legacy equipment
Course Modules
Select any module to see its sessions and points.
01Connected Medical Device Threat Landscape
2 sessions · 8 points
Session 1Attack Surfaces Across the Medical Device Lifecycle
- Map attack surfaces at procurement, configuration, operation, maintenance and disposal stages.
- Identify common vulnerabilities in embedded operating systems and unsecured wireless interfaces.
- Assess third-party remote maintenance access as a frequently overlooked entry point.
- Document device inventory data needed to support ongoing vulnerability tracking.
Session 2Ransomware and Clinical Impact Scenarios
- Trace how a ransomware attack propagates from an office network into clinical device segments.
- Assess clinical impact scenarios where device or network unavailability directly affects patient care.
- Identify early warning indicators that distinguish a developing attack from routine network issues.
- Evaluate downtime procedures that keep critical clinical functions running during a network isolation event.
02Device Cybersecurity Regulation and Documentation
2 sessions · 8 points
Session 1FDA Premarket and Postmarket Cybersecurity Requirements
- Apply FDA premarket cybersecurity documentation expectations to a new device submission review.
- Distinguish premarket security design requirements from postmarket vulnerability disclosure obligations.
- Assess a manufacturer's coordinated vulnerability disclosure process for adequacy and responsiveness.
- Track how postmarket cybersecurity patches interact with a device's existing regulatory clearance.
Session 2Software Bill of Materials and IEC 81001-5-1
- Request and interpret a software bill of materials from a medical device manufacturer.
- Cross-reference bill of materials components against known vulnerability databases.
- Apply relevant health software security lifecycle standards to internal device management processes.
- Build a component-level risk register that flags devices containing unsupported software.
03Network Architecture and Vulnerability Management
2 sessions · 8 points
Session 1Network Segmentation and Zero Trust for Clinical Networks
- Design a network segmentation scheme that isolates clinical device traffic from general hospital traffic.
- Apply zero trust principles to device authentication without disrupting time-critical clinical workflows.
- Configure monitoring at segment boundaries to detect anomalous device communication patterns.
- Balance segmentation strictness against clinical staff access needs during emergencies.
Session 2Vulnerability Scanning and Legacy Device Patch Management
- Select vulnerability scanning methods safe to run against fragile or unpatchable legacy devices.
- Prioritise patching decisions using exploitability, clinical criticality and compensating controls.
- Apply compensating controls, such as network isolation, where a device cannot be patched directly.
- Maintain a patch management schedule coordinated with clinical engineering downtime windows.
04Incident Response and Procurement Controls
2 sessions · 8 points
Session 1Clinical Incident Response Planning for Device Compromise
- Draft an incident response plan defining roles for IT security, clinical engineering and clinical staff.
- Establish device isolation procedures that protect patients when a compromise is suspected mid-use.
- Design a communication plan that informs clinical teams without causing unnecessary care disruption.
- Run a tabletop exercise simulating a compromised infusion pump or monitoring system fleet.
Session 2Procurement Security Requirements and MDS2 Evaluation
- Build security requirements into procurement specifications before a device purchase is finalised.
- Evaluate a manufacturer disclosure statement for medical device security against internal risk criteria.
- Negotiate contractual commitments for patch support duration and vulnerability disclosure timelines.
- Establish an onboarding checklist that verifies a new device meets network and configuration standards.
What the participant receives
4 course modules
A structured syllabus
8 training sessions
across 5 days
32 detailed points
Applied, detailed content
Accredited attendance certificate
On completing the programme
Complete your registration
We will contact you within one business day to confirm.
Ready to start?
Reserve your seat and start building the skill.
