Articles

Expert analysis on medical device cybersecurity

Regulatory updates, standards guidance, and practical takeaways for medical device and health IT manufacturers.

Cybersecurity Risk in GenAI-Enabled Medical Devices: Connecting Security to Safety and Effectiveness

FDA's discussion paper on generative-AI-enabled medical devices is framed around safety and effectiveness. Viewed through a cybersecurity lens, GenAI opens new pathways — prompt injection, poisoned retrieval, foundation-model drift, agentic tool use — by which a security event becomes a clinical risk.

The CVSS 4.0 Transition: What Medical Device Manufacturers Should Know Before July 2028

FDA's recognition of CVSS v4.0 sunsets CVSS v3.1 for medical device submissions on July 2, 2028 — what manufacturers need to do to stay compliant.

FDA's February 2026 Cybersecurity Guidance Revision: QMSR Takes Effect

FDA's February 3, 2026 revision to its premarket cybersecurity guidance realigns the document to the Quality Management System Regulation, mapping cybersecurity expectations to specific ISO 13485 clauses.

Cybersecurity in Quality: FDA's Guidance on Computer Software Assurance

FDA's Computer Software Assurance (CSA) guidance changes how manufacturers should validate the computers and automated systems used in production and quality operations.

Microsoft Windows 10 End of Life: What It Means for Medical Devices?

Microsoft ended Windows 10 support on October 14, 2025 — a decade-long lifecycle closing that raises cybersecurity and regulatory concerns for connected medical devices still running it.

CISA Publishes Draft Update on SBOM Minimum Elements

CISA's 2025 draft update to the Software Bill of Materials minimum elements builds on the 2021 NTIA standard, with implications for medical device supply chain transparency.

Cybersecurity requirements for FDA Submission

A practical outline of the cybersecurity documentation and requirements medical device manufacturers need for PMA or 510(k) submissions.

FDA publishes new premarket cybersecurity guidance (June 2025)

FDA's June 27, 2025 guidance on Cybersecurity in Medical Devices replaces the 2023 version, incorporating draft updates and additional new requirements.