{"id":24750,"date":"2023-07-10T18:12:12","date_gmt":"2023-07-11T01:12:12","guid":{"rendered":"https:\/\/www.privateinternetaccess.com\/blog\/?p=24750"},"modified":"2025-04-16T00:39:18","modified_gmt":"2025-04-16T07:39:18","slug":"medical-device-cybersecurity","status":"publish","type":"post","link":"https:\/\/www.privateinternetaccess.com\/blog\/medical-device-cybersecurity\/","title":{"rendered":"Why Medical Device Cybersecurity Is Essential"},"content":{"rendered":"\n<p class=\"wp-block-paragraph\">Everything from wearable and remote devices to the CT, MRI, ultrasound, and X-ray machines you find in hospitals is connected to a network, and<strong> anything connected to the internet is vulnerable to cyber attacks \u2014 no exceptions<\/strong>. That includes your smartwatch, and health apps on your smartphone, which contain location and sensitive health information.\u00a0<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Unfortunately, the growing cybersecurity risks for medical devices hasn\u2019t increased healtcare\u2019s attention to security. Many providers have inadequate budgets for development or testing and don\u2019t provide necessary updates to the software, primarily because they never planned for it when first developing the devices and software.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The healthcare sector isn\u2019t any better, as only<strong> 4-7% of the average healthcare facility\u2019s budget is spent on cybersecurity<\/strong>. Most other industries spend up to 15%, including companies in the financial sector. There\u2019s a pressing demand for stronger medical device cybersecurity, and the FDA\u2019s recent addition of Section 524B (Ensuring the Cybersecurity of Devices) to the FD&amp;C Act, reflects this need.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Read on to <strong>discover why cybersecurity is essential for network-connected medical devices<\/strong>, what the government is doing to address the problem, and why your data is at risk.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><\/p>\n\n\n\n<div style=\"background-color: #d5dde3; padding: 15px; border-radius: 10px; width: 500px;\">\n<h4>Table of Contents<\/h4>\n<a href=\"#what\">What Is Medical Device Cybersecurity?<\/a><br>\n<section style=\"text-indent: 15px;\"><a href=\"#device\">Medical Device Cybersecurity Vulnerabilities<\/a><\/section>\n<section style=\"text-indent: 15px;\"><a href=\"#cmd\">CMD Examples, Uses &amp; Risks<\/a><\/section>\n<a href=\"#recent\">Recent Healthcare Cybersecurity Breaches &amp; Attacks<\/a><br>\n<section style=\"text-indent: 15px;\"><a href=\"#diving\">Diving Deeper \u2014 Other Well-Publicized CMD Security Incidents<\/a><\/section>\n<a href=\"#current\">Current FDA Medical Device Cybersecurity Standards<\/a><br>\n<section style=\"text-indent: 15px;\"><a href=\"#fdc\">FD&amp;C Act, Section 524B \u2014 A Brief Overview of Key Points<\/a><\/section>\n<section style=\"text-indent: 15px;\"><a href=\"#changes\">What the Changes Mean for Healthcare Providers &amp; Manufacturers<\/a><\/section>\n<section style=\"text-indent: 15px;\"><a href=\"#hospitals\">Do Hospitals &amp; Healthcare Providers Currently Meet FDA Guidelines?<\/a><\/section>\n<a href=\"#how\">How to Protect Your ePHI and PII<\/a><br>\n<a href=\"#be\">Be Proactive \u2014 Protect Your ePHI and PII<\/a><br>\n<a href=\"#faq\">FAQ<\/a><br>\n<\/div>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"what\"><strong>What Is Medical Device Cybersecurity?<\/strong><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Medical device cybersecurity refers to the<strong> steps taken to ensure any medical device connected to a network is protected from cyberthreats<\/strong>, so patient electronic protected health information (ePHI) and personally identifiable information (PII) remain private. This <strong>includes all remote and in-house technologies in the healthcare sector<\/strong>, as well as any apps that are part of healthcare services.\u00a0<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The International Medical Device Regulatory Forum provides <strong>several ways for medical device manufacturers to improve cybersecurity<\/strong>, urging them to consider the following factors:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>How the device interacts with other devices and networks<\/strong>, how it communicates with devices supporting less secure methods of communication, and how to prevent unauthorized access and modification during data transfer.<\/li>\n\n\n\n<li><strong>How the device could interfere with other devices and networks<\/strong>, if it may cause the software to lag or work improperly, if it\u2019s cross-compatible with other devices, and whether custom-made devices (CMDs) may cause network disruption.\u00a0<\/li>\n\n\n\n<li>Whether the level of encryption and other security measures for data storage and transfer are adequate, and <strong>if confidentiality risk control measures are required<\/strong>.<\/li>\n\n\n\n<li>Any <strong>risks affecting device integrity<\/strong>, including evaluating system-level architecture to determine if all obligatory design features are present alongside anti-malware controls.<\/li>\n\n\n\n<li>Methods of user access control and <strong>how to securely assign user roles and privileges<\/strong>.<\/li>\n\n\n\n<li>How to communicate information about regular updates, <strong>how software and hardware will be updated,<\/strong> requirements for conducting updates, and code verification for connection authenticity, as well as any other control measures in place.<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\"><\/p>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"device\"><strong>Medical Device Cybersecurity Vulnerabilities<\/strong><\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">The biggest concern with any form of medical device is the large quantities of ePHI and PII they collect and store daily. Add poor cybersecurity to the mix and medical devices are prime targets for <strong>malware attacks, data theft, and device hijacking<\/strong>.\u00a0<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">It isn\u2019t just the new medical gadgets that are vulnerable \u2014 the FBI has increased concerns over legacy devices, as they pose some of the worst risks. Legacy software, protocols, and hardware are often outdated as <strong>medical firms don\u2019t put much focus on upgrades or on cybersecurity of any kind<\/strong>. An overall lack of security makes older devices like insulin pumps a prime target for cybercriminals and results in deadly consequences.\u00a0<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Medical devices are constrained by <strong>ethical, budgetary, and regulatory factors<\/strong>, including compliance with regulations in the US, EU, China, Australia and the UK to enter medical devices into the market.\u00a0<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><br>Legislation surrounding medical device cybersecurity also varies from one region to another. For example, the European Medical Device Regulation (MDR) and In Vitro Diagnostics Medical Device Regulation (IVDR) define multiple cybersecurity regulations under \u2018\u2019general safety and performance requirements\u2019. The US Food and Drug Administration (FDA) offers guidance documents explaining how manufacturers can meet all necessary cybersecurity requirements for medical devices.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">While CMDs give patients more freedom in terms of where and when medical treatments and monitoring can happen, they <strong>raise<\/strong> <strong>serious concerns over the privacy challenges associated with transmitting large amounts of patient information<\/strong>. Several laws are in place to help safeguard patient data including the EU\u2019s General Data Protection Regulation (GDPR), the US\u2019s FD&amp;C Act Section 524B, and the UK\u2019s Data Protection Act 18 (DPA18).<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Violating any of the above regulations can be incredibly expensive<\/strong>, not to mention the damage it does to the manufacturer or healthcare facility\u2019s reputation. Penalties can range from millions in fines and damages to patent refusals. Despite this, <strong>many CMD manufacturers still don\u2019t take cybersecurity seriously<\/strong> during and after device development.\u00a0<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Unauthorized access<\/strong> <strong>is also a major concern <\/strong>as it can have more severe consequences than data theft. Attacks on CMDs can put a patient in danger and even cause fatalities. Without proper management, cybersecurity incidents can easily result in unintentional device malfunctions or delay necessary treatments.\u00a0<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Other key areas of neglect <strong>include establishing product security incident report teams<\/strong>, providing timely updates and patches to devices, and post-development cybersecurity planning. <strong>Providing updates and patches in a timely manner<\/strong> ties into the lack of ownership and responsibility for legacy and non-legacy CMDs within healthcare institutions. Similarly, a small budget can influence the adequacy of pre and post-development planning, ultimately leaving devices more vulnerable to threats.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">This gross oversight means cybercriminals view healthcare providers, and the medical industry in general, as easy targets. So, <strong>exactly how much ePHI and PII do you put at risk using a CMD<\/strong>? Let\u2019s take a look at the various types of CMDs and the cybersecurity risks accompanying them.<\/p>\n\n\n\n<style>\ntr {padding: 10px;}\ntd {padding: 10px;}\n<\/style>\n<table class=\"center\" rules=\"all\" style=\"border: 1px solid black; width: 100%; margin: auto;\">\n  <thead><tr><th id=\"cmd\" colspan=\"4\" class=\"has-text-align-center\" data-align=\"center\" style=\"background-color: #6d9eeb; color: none; border: none; padding: 5px;\"><strong>Medical Device Examples, Uses &amp; Risks\n<\/strong><\/th><\/tr><\/thead> \n  <tbody><tr>\n   <td class=\"has-text-align-center\" data-align=\"center\" style=\"background-color: #f1c232; color: none; padding: 5px;\"><strong>Type of Device<\/strong><\/td>\n   <td class=\"has-text-align-center\" data-align=\"center\" style=\"background-color: #f1c232; color: none; padding: 5px;\"><strong>Example<\/strong><\/td>\n     <td class=\"has-text-align-center\" data-align=\"center\" style=\"background-color: #f1c232; color: none; padding: 5px;\"><strong>Uses<\/strong><\/td>\n<td class=\"has-text-align-center\" data-align=\"center\" style=\"background-color: #f1c232; color: none; padding: 5px;\"><strong>Risk<\/strong><\/td>\n   \n  <\/tr><\/tbody><tbody><tr> <td>Remote Patient Monitors (RPMs)<\/td>\n    <td>\u269a Continuous glucose monitoring<br><br>\n\u269a Digital blood monitors<\/td>\n    <td>\u2705 Reminds patients to take meds, allows doctors to track health, and\/or send vitals to healthcare professionals<\/td>\n<td>\u26a0\ufe0fRPMs collect and store massive amounts of ePHI, so unauthorized users could access this data and exploit your PII<\/td>\n    <\/tr>\n    <tr>\n     <td>Wearables<br><\/td>\n      <td>\u269a Smartwatches<br><br>\n\u269a Software as a medical device (SaMD)\n<\/td>\n      <td>\u2705 Monitor menstrual cycles, heart rate, sleep patterns, and more<\/td>\n <td>\u26a0\ufe0fSaMDs use behavioral and location tracking, and most share your data with third parties<\/td>\n      <\/tr>\n    <tr>\n      <td>Robotics<br><\/td>\n      <td>\u269a Intelligent drug dispensers<br><br>\n\u269a Life alert tags\n<\/td>\n      <td>\u2705 Help maintain medication schedules, alert EMS and law enforcement, and detect falls or other trauma<\/td>\n<td>\u26a0\ufe0fMalware and fatal misinformation<\/td>\n    <\/tr>\n    <tr>\n      <td>Artificial Intelligence (AI) &amp; Machine Learning (ML) technologies<br><\/td>\n      <td>\u269a Smart sensors<br><br>\n\u269a Some wearables and robotics\n<\/td>\n      <td>\u2705 This form of technology could eventually detect an oncoming heart attack, stroke, seizure, or other medical issues<\/td>\n<td>\u26a0\ufe0fDifficult to manage user consent, which AI also raises serious cybersecurity and ethical issues<\/td>\n    <\/tr>\n  \n\n<\/tbody><\/table>\n\n\n\n<a style=\"text-decoration: none;\" href=\"https:\/\/www.privateinternetaccess.com\/buy-vpn-online?conversionpoint=medical_device_cybersecurity\"><button class=\"bg-btn-1\"> Get PIA VPN <\/button><\/a>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"recent\"><strong>Recent Healthcare Cybersecurity Breaches &amp; Attacks<\/strong><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">In the past eight years, healthcare cybersecurity breaches have skyrocketed. According to Privacy Rights Clearinghouse, the healthcare sector accounted for 76.59% of all data breaches between 2015 and 2019. The <strong>WannaCry cyber attack in 2017<\/strong> <strong>practically crippled the National Health Service<\/strong>.\u00a0<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Once the <strong>crypto ransomware worm had access to critical files, it encrypted and held them ransom. <\/strong>The worm had the ability to spread across systems and networks: once a PC was infected, cybercriminals demanded hefty ransom payments to unlock those files as well. This meant many hospitals and other healthcare facilities were unable to provide care to patients. Worse yet, all of it was entirely preventable with regular updates. In fact, two months prior to the WannaCry attack, Microsoft issued a patch which, if applied, would\u2019ve stopped the ransomware.\u00a0<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Recovering from these cyber attacks isn\u2019t cheap either. Companies face ransom demands from cybercriminals, penalties\/fines from the government, not to mention damages and legal fees. This is on top of the cost of downtime and upgrades, patches, or replacements for outdated devices and software.\u00a0<\/p>\n\n\n\n<div style=\"background-color: #cfe2f3; padding: 10px; border-radius: 25px;\">\n <h3 id=\"diving\"><strong>Diving Deeper \u2014 Other Well-Publicized Medical Device Security Incidents<\/strong><\/h3>\n  <p>Independent parties have uncovered<strong> <\/strong>plenty of other cybersecurity vulnerabilities in medical device software and hardware. Here are just a few examples:<\/p>\n<li>The FDA issued <strong>a recall of 460,000+ cardiac pacemaker implants in 2017<\/strong> after discovering a vulnerability in the design allowing third parties to modify device commands.<\/li><br>\n<li>In 2018, <strong>a medical syringe pump<\/strong> had a vulnerability that <strong>allowed attackers to control the operation of the pump<\/strong> while connected to a terminal server.<\/li><br>\n<li>The <strong>FDA identified a set of unique vulnerabilities in a third-party medical device component in 2019<\/strong>, which could potentially allow anyone to remotely control the software. This could result in information leaks, logic flows that interfere with regular device functions, and a complete change in the device\u2019s overall function.<\/li><br>\n<li>In 2020, the <strong>FDA notified the medical industry of a vulnerability in clinical information servers used in healthcare environments<\/strong>. These vulnerabilities could allow attackers to take control of medical devices remotely using the servers. Potential risks associated with the vulnerabilities included false alarm generation, general device malfunctions, and silencing patient monitor alarms.<\/li>\n <p><\/p><\/div>\n\n\n\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/www.privateinternetaccess.com\/blog\/cyberattacks-hospitals\/\">Cyber attacks on the healthcare industry<\/a> aren\u2019t showing signs of slowing down. Based on a study by Check Point Research, <strong>cyber attacks against the healthcare industry increased by 60% between 2021 and 2022<\/strong> \u2014 averaging a cost of over $10 million per incident.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"current\"><strong>Current FDA Medical Device Cybersecurity Standards<\/strong><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">In late 2018, it became clear there was an increased need to address medical devices\u2019 security vulnerabilities. <strong>The FDA and US Department of Homeland Security agreed to work together<\/strong> to develop written procedures for sharing sensitive information about cybersecurity threats with major stakeholders in an attempt to mitigate the risk of leaks.\u00a0<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The 2022 PATCH Act helped ensure <strong>any device requiring FDA approval after March 2023 would include cybersecurity measures<\/strong> to increase patient safety. Consequently, an amendment to the FD&amp;C Act, Section 524B, became effective March 29, 2023. This created a cybersecurity standard for manufacturers of medical devices in the US.\u00a0<\/p>\n\n\n\n<div style=\"background-color: #f6b26b; padding: 10px; border-radius: 25px;\">\n <h3 id=\"fdc\"><strong>FD&amp;C Act, Section 524B<\/strong> \u2013 <strong>A Brief Overview of Key Points<\/strong><\/h3>\n  <p>Section 524B of the FD&amp;C Act was amended in 2023 to include \u201cEnsuring Cybersecurity of Devices.\u201d This requires sponsors, aka manufacturers, developing medical devices to <strong>submit plans for monitoring, identifying, and addressing potential cybersecurity threats<\/strong> with their device development plan.\u00a0<\/p>\n<p>These plans also <strong>need to contain information about potential threats and vulnerabilities<\/strong> in the device during all stages of design and development. Sponsors must outline how they will continue to monitor processes and post-market vulnerabilities to ensure the device software and related systems remain cyber-secure.\u00a0<\/p>\n<p>Manufacturers <strong>must update and patch devices <\/strong>and all related systems to help prevent cyber attacks. This includes addressing (a) unacceptable vulnerabilities in a relatively timely manner on a justified regular cycle, and (b) critical vulnerabilities which may cause unnecessary risk as soon as possible.<\/p>\n<p>All <strong>sponsors are expected to comply with additional cybersecurity requirements<\/strong> from the Secretary when needed, ensuring devices and related systems have working cybersecurity measures in place.\u00a0<\/p>\n<p>Manufacturers and sponsors of medical devices <strong>must submit information on how they meet current requirements <\/strong>under section 524B. Additionally, they need to <strong>provide the Secretary with a software bill of materials<\/strong>, including commercial,<\/p>\n<p>open-source, and off-the-shelf software components.<br><strong>Punishments for non-compliance can range from refusing approval <\/strong>pending the sponsor submitting required information, <strong>to regulatory and legal consequences<\/strong> for failing to provide adequate cybersecurity for existing devices.<\/p>\n <\/div> <br>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"changes\"><strong>What Section 524B of the FD&amp;C Act Means for Healthcare Providers &amp; Manufacturers<\/strong><\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Healthcare providers and manufacturers face potential fines for non-compliance with section 524B. Manufacturers could have patents for new devices refused because they don\u2019t meet regulations. There\u2019s also additional costs associated with reworking plans, device downtime, and, in some cases, civil damages.\u00a0<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The <strong>changes to the FD&amp;C Act under section 524B pose plenty of challenges<\/strong> for healthcare providers and manufacturers, including:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Updating thousands of legacy medical devices <strong>adds an additional burden for healthcare facilities, <\/strong>especially since some legacy devices may not support updates.<\/li>\n\n\n\n<li>Dealing with <strong>the cost of replacing outdated devices<\/strong> recalled by the FDA can be daunting for hospitals.\u00a0<\/li>\n\n\n\n<li>Many healthcare facilities don\u2019t keep<strong> an updated inventory of all network-connected medical devices, <\/strong>which makes it virtually impossible to determine if devices have adequate protection.<\/li>\n\n\n\n<li>Updating or replacing medical devices requires solid planning and collaboration between manufacturers and healthcare facilities, which can be difficult.<\/li>\n\n\n\n<li>Manufacturers will need to provide <strong>better custom security controls throughout the device lifecycle.<\/strong><\/li>\n\n\n\n<li>Manufacturers will need to <strong>develop better service schedules <\/strong>to ensure all medical device software and hardware have proper cybersecurity in place.<\/li>\n\n\n\n<li>Manufacturers must commit to <strong>open and honest communication with healthcare facilities <\/strong>if software or hardware for their devices is no longer considered secure per the FDA\u2019s standards.<\/li>\n\n\n\n<li>It\u2019s not feasible for hospitals to replace every outdated device due to budget restrictions. This means manufacturers will need to supply alternative solutions and work on developing security patches.<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Do Hospitals &amp; Healthcare Providers Currently Meet FDA Guidelines?<\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Not even close<\/strong>. Most manufacturers of medical devices and apps, as well as the healthcare facilities using them, definitely don\u2019t focus on cybersecurity enough, yet section <strong>524B contains security requirements for medical devices <\/strong>\u2014 legacy and new. It\u2019s a critical step toward ensuring cyber medical devices offer adequate online security.\u00a0<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The requirements are fairly straightforward for the most part, but some areas are open to interpretation \u2014 especially when it comes to legacy devices, as it primarily includes \u2018recommendations\u2019 for how cybersecurity \u2018should\u2019 be handled.\u00a0<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Manufacturers and healthcare providers need to be more diligent<\/strong> to ensure a device or SaMD is secure before making it available to patients. Efforts to create data protection measures, thoroughly test device integrity, maintain software and hardware by providing updates and patches regularly, and include 2FA options for user authentication would go a long way. But individuals can also help by protecting their PHI.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"how\"><strong>How to Protect Your ePHI and PII<\/strong><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">If you use <a href=\"https:\/\/www.privateinternetaccess.com\/blog\/improve-smart-home-security\/\">smart watches or smartphone apps<\/a> to track and monitor your health, you can add some much-needed protection by <a href=\"https:\/\/www.privateinternetaccess.com\/buy-vpn-online?conversionpoint=medical_device_cybersecurity\"><strong>setting up a VPN<\/strong><\/a> on your router. This secures <strong>any network-connected device you use to access medical information,<\/strong> including computers, smartphones, smartwatches, and more.\u00a0<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">PIA provides <strong>unbreakable AES encryption<\/strong> <strong>to make your health data unreadable <\/strong>when in transit. We also have dedicated apps for iOS, Android, Windows, macOS, and Linux, so you can <strong>access online medical records and use SaMDs privately<\/strong>.\u00a0<\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"be\"><strong>Be Proactive \u2014 Protect Your ePHI and PII<\/strong><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Most of the blame tends to shift toward the manufacturer of the medical device or app and healthcare facilities, but this doesn\u2019t mean you\u2019re off the hook. As a user, <strong>you can also be diligent in protecting your privacy<\/strong> while using medical devices and SaMDs.\u00a0<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">If your device is getting older, talk to your medical provider to find out whether a newer version is available and see if you can replace your old one. Medical device manufacturers are held more accountable under 524B, so <strong>newer devices must be compliant with higher cybersecurity standards<\/strong>.\u00a0<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Make sure you apply medical device and SaMD updates to maintain device integrity, use 2FA and anti-malware measures when available, and <a href=\"https:\/\/www.privateinternetaccess.com\/buy-vpn-online?conversionpoint=medical_device_cybersecurity\"><strong>use PIA VPN<\/strong><\/a> for added security.<\/p>\n\n\n\n<a style=\"text-decoration: none;\" href=\"https:\/\/www.privateinternetaccess.com\/buy-vpn-online?conversionpoint=medical_device_cybersecurity\"><button class=\"bg-btn-1\"> Get PIA VPN <\/button><\/a>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"faq\"><strong>FAQ<\/strong><\/h2>\n\n\n\n<div class=\"schema-faq wp-block-yoast-faq-block\"><div class=\"schema-faq-section\" id=\"faq-question-1688165481877\"><h3 class=\"schema-faq-question\">What is medical device cybersecurity?<\/h3> <p class=\"schema-faq-answer\">Medical device cybersecurity encompasses<strong> all the security measures taken during development and after the medical device is in use<\/strong>, including providing updates, security patches, adequate encryption, malware protection, and more. This helps ensure any medical device connected to a network is secure, and decreases the risk of cyber attacks.\u00a0<br><br>While medical device cybersecurity standards only pertain to device manufacturers and healthcare facilities, <strong>you can do things to mitigate the risk of a cyber attack while using SaMDs like fitness and health tracking apps<\/strong>. Pay close attention to app permissions requests and download a trustworthy <a href=\"https:\/\/www.privateinternetaccess.com\/\">VPN service<\/a> to ensure traffic encryption.<br><br><\/p> <\/div> <div class=\"schema-faq-section\" id=\"faq-question-1688165524167\"><h3 class=\"schema-faq-question\">Why is cybersecurity important for medical devices?<\/h3> <p class=\"schema-faq-answer\">Medical devices collect, store, and transfer massive amounts of ePHI and PII \u2014 some can even tell you what dose of medication to take.\u00a0<br><br><strong>Without adequate cybersecurity in place, your medical devices are easy targets for ransomware.<\/strong> This puts your personal information, and potentially your life, at risk any time you connect your device to a network \u2014 especially <a href=\"https:\/\/www.privateinternetaccess.com\/wifi-vpn\">public wifi<\/a>.<br><br><\/p> <\/div> <div class=\"schema-faq-section\" id=\"faq-question-1688165536906\"><h3 class=\"schema-faq-question\">What is the NIST Cybersecurity Framework for medical devices?<\/h3> <p class=\"schema-faq-answer\"><strong>NIST is a five-step framework for continuously managing cybersecurity on medical devices<\/strong>. The five steps are identify, protect, detect, respond, and recover.\u00a0<br><br>Gartner Research estimated the NIST framework would be used by 50% of US organizations in 2020. Yet, a 2023 Healthcare Cybersecurity Benchmarking Study found 40% of facilities using NIST still aren\u2019t compliant with response and recovery planning.\u00a0<br><br>Some medical devices are not compatible with <a href=\"https:\/\/www.privateinternetaccess.com\/\">VPNs<\/a>. Including this capability could go a long way toward meeting the \u2018protect\u2019 stage of the NIST framework in medical equipment.<br><br><\/p> <\/div> <div class=\"schema-faq-section\" id=\"faq-question-1688165555587\"><h3 class=\"schema-faq-question\">Do VPNs improve cybersecurity?<\/h3> <p class=\"schema-faq-answer\">Yes, but not just any VPN. PIA VPN <a href=\"https:\/\/www.privateinternetaccess.com\/buy-vpn-online?conversionpoint=medical_device_cybersecurity\"><strong>improves your network\u2019s security<\/strong><\/a> and gives you the privacy you need. We offer strong <a href=\"https:\/\/www.privateinternetaccess.com\/vpn-features\/vpn-encryption\">VPN encryption<\/a> methods to make your traffic unreadable. Our VPN also has a strict No Logs policy, so your online activity remains private while you\u2019re connected.<br><br>Please note <strong>some medical devices don\u2019t support the use of VPNs yet<\/strong>. Contact your healthcare professional or the manufacturer of your device to know if configuring PIA to your home router can increase device security. Fortunately, you can use our dedicated iOS and Android apps on your smartphone to increase data privacy while using SaMDs.<br><\/p> <\/div> <\/div>\n","protected":false},"excerpt":{"rendered":"<p>The US govt updated the FD&#038;C Act to ensure the healthcare sector and medical manufacturers take cybersecurity seriously.<\/p>\n","protected":false},"author":73,"featured_media":24751,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_stopmodifiedupdate":false,"_modified_date":"","footnotes":""},"categories":[2900],"tags":[],"class_list":["post-24750","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-general-thought-leadership"],"yoast_head":"<!-- This site is optimized with the Yoast SEO Premium plugin v26.9 (Yoast SEO v26.9) - https:\/\/yoast.com\/product\/yoast-seo-premium-wordpress\/ -->\n<title>Why We Need Medical Device Cybersecurity | PIA VPN<\/title>\n<meta name=\"description\" content=\"The US govt updated the FD&amp;C Act to ensure the healthcare sector and medical manufacturers take cybersecurity seriously.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.privateinternetaccess.com\/blog\/medical-device-cybersecurity\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Why Medical Device Cybersecurity Is Essential\" \/>\n<meta property=\"og:description\" content=\"The US govt updated the FD&amp;C Act to ensure the healthcare sector and medical manufacturers take cybersecurity seriously.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.privateinternetaccess.com\/blog\/medical-device-cybersecurity\/\" \/>\n<meta property=\"og:site_name\" content=\"PIA\" \/>\n<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/privateinternetaccess\/\" \/>\n<meta property=\"article:published_time\" content=\"2023-07-11T01:12:12+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2025-04-16T07:39:18+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.privateinternetaccess.com\/blog\/wp-content\/uploads\/2023\/06\/feature_medical_cybersecurity.png\" \/>\n\t<meta property=\"og:image:width\" content=\"1200\" \/>\n\t<meta property=\"og:image:height\" content=\"800\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/png\" \/>\n<meta name=\"author\" content=\"Kristin Hassel\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@buyvpnservice\" \/>\n<meta name=\"twitter:site\" content=\"@buyvpnservice\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Kristin Hassel\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"13 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\/\/www.privateinternetaccess.com\/blog\/medical-device-cybersecurity\/#article\",\"isPartOf\":{\"@id\":\"https:\/\/www.privateinternetaccess.com\/blog\/medical-device-cybersecurity\/\"},\"author\":{\"name\":\"Kristin Hassel\",\"@id\":\"https:\/\/www.privateinternetaccess.com\/blog\/#\/schema\/person\/286e5fb351ecd2ce551e5fb44b547dee\"},\"headline\":\"Why Medical Device Cybersecurity Is Essential\",\"datePublished\":\"2023-07-11T01:12:12+00:00\",\"dateModified\":\"2025-04-16T07:39:18+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\/\/www.privateinternetaccess.com\/blog\/medical-device-cybersecurity\/\"},\"wordCount\":2936,\"commentCount\":0,\"publisher\":{\"@id\":\"https:\/\/www.privateinternetaccess.com\/blog\/#organization\"},\"image\":{\"@id\":\"https:\/\/www.privateinternetaccess.com\/blog\/medical-device-cybersecurity\/#primaryimage\"},\"thumbnailUrl\":\"https:\/\/www.privateinternetaccess.com\/blog\/wp-content\/uploads\/2023\/06\/feature_medical_cybersecurity.png\",\"articleSection\":[\"General Thought Leadership\"],\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\/\/www.privateinternetaccess.com\/blog\/medical-device-cybersecurity\/#respond\"]}]},{\"@type\":[\"WebPage\",\"FAQPage\"],\"@id\":\"https:\/\/www.privateinternetaccess.com\/blog\/medical-device-cybersecurity\/\",\"url\":\"https:\/\/www.privateinternetaccess.com\/blog\/medical-device-cybersecurity\/\",\"name\":\"Why We Need Medical Device Cybersecurity | PIA VPN\",\"isPartOf\":{\"@id\":\"https:\/\/www.privateinternetaccess.com\/blog\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\/\/www.privateinternetaccess.com\/blog\/medical-device-cybersecurity\/#primaryimage\"},\"image\":{\"@id\":\"https:\/\/www.privateinternetaccess.com\/blog\/medical-device-cybersecurity\/#primaryimage\"},\"thumbnailUrl\":\"https:\/\/www.privateinternetaccess.com\/blog\/wp-content\/uploads\/2023\/06\/feature_medical_cybersecurity.png\",\"datePublished\":\"2023-07-11T01:12:12+00:00\",\"dateModified\":\"2025-04-16T07:39:18+00:00\",\"description\":\"The US govt updated the FD&C Act to ensure the healthcare sector and medical manufacturers take cybersecurity seriously.\",\"breadcrumb\":{\"@id\":\"https:\/\/www.privateinternetaccess.com\/blog\/medical-device-cybersecurity\/#breadcrumb\"},\"mainEntity\":[{\"@id\":\"https:\/\/www.privateinternetaccess.com\/blog\/medical-device-cybersecurity\/#faq-question-1688165481877\"},{\"@id\":\"https:\/\/www.privateinternetaccess.com\/blog\/medical-device-cybersecurity\/#faq-question-1688165524167\"},{\"@id\":\"https:\/\/www.privateinternetaccess.com\/blog\/medical-device-cybersecurity\/#faq-question-1688165536906\"},{\"@id\":\"https:\/\/www.privateinternetaccess.com\/blog\/medical-device-cybersecurity\/#faq-question-1688165555587\"}],\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/www.privateinternetaccess.com\/blog\/medical-device-cybersecurity\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/www.privateinternetaccess.com\/blog\/medical-device-cybersecurity\/#primaryimage\",\"url\":\"https:\/\/www.privateinternetaccess.com\/blog\/wp-content\/uploads\/2023\/06\/feature_medical_cybersecurity.png\",\"contentUrl\":\"https:\/\/www.privateinternetaccess.com\/blog\/wp-content\/uploads\/2023\/06\/feature_medical_cybersecurity.png\",\"width\":1200,\"height\":800},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/www.privateinternetaccess.com\/blog\/medical-device-cybersecurity\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\/\/www.privateinternetaccess.com\/blog\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Why Medical Device Cybersecurity Is Essential\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/www.privateinternetaccess.com\/blog\/#website\",\"url\":\"https:\/\/www.privateinternetaccess.com\/blog\/\",\"name\":\"PIA\",\"description\":\"Online privacy news from around the world.\",\"publisher\":{\"@id\":\"https:\/\/www.privateinternetaccess.com\/blog\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/www.privateinternetaccess.com\/blog\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\/\/www.privateinternetaccess.com\/blog\/#organization\",\"name\":\"Private Internet Access\",\"url\":\"https:\/\/www.privateinternetaccess.com\/blog\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/www.privateinternetaccess.com\/blog\/#\/schema\/logo\/image\/\",\"url\":\"https:\/\/www.privateinternetaccess.com\/blog\/wp-content\/uploads\/2018\/07\/pialogowhitekglogo.png\",\"contentUrl\":\"https:\/\/www.privateinternetaccess.com\/blog\/wp-content\/uploads\/2018\/07\/pialogowhitekglogo.png\",\"width\":1200,\"height\":1200,\"caption\":\"Private Internet Access\"},\"image\":{\"@id\":\"https:\/\/www.privateinternetaccess.com\/blog\/#\/schema\/logo\/image\/\"},\"sameAs\":[\"https:\/\/www.facebook.com\/privateinternetaccess\/\",\"https:\/\/x.com\/buyvpnservice\",\"https:\/\/www.instagram.com\/piavpn\/\",\"https:\/\/www.youtube.com\/channel\/UClyJZ47Rizb1xnwuKXDI0_w\"]},{\"@type\":\"Person\",\"@id\":\"https:\/\/www.privateinternetaccess.com\/blog\/#\/schema\/person\/286e5fb351ecd2ce551e5fb44b547dee\",\"name\":\"Kristin Hassel\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/www.privateinternetaccess.com\/blog\/#\/schema\/person\/image\/\",\"url\":\"https:\/\/www.privateinternetaccess.com\/blog\/wp-content\/uploads\/2023\/01\/kristin.h-96x96.jpg\",\"contentUrl\":\"https:\/\/www.privateinternetaccess.com\/blog\/wp-content\/uploads\/2023\/01\/kristin.h-96x96.jpg\",\"caption\":\"Kristin Hassel\"},\"description\":\"Kristin Hassel is an Information Systems Specialist and writer. Passionate about helping users of all experience levels find, utilize, and manage software solutions, she\u2019s experienced in a wide range of cybersecurity topics and strives to educate people about the importance of online security.\",\"url\":\"https:\/\/www.privateinternetaccess.com\/blog\/author\/kristinh\/\"},{\"@type\":\"Question\",\"@id\":\"https:\/\/www.privateinternetaccess.com\/blog\/medical-device-cybersecurity\/#faq-question-1688165481877\",\"position\":1,\"url\":\"https:\/\/www.privateinternetaccess.com\/blog\/medical-device-cybersecurity\/#faq-question-1688165481877\",\"name\":\"What is medical device cybersecurity?\",\"answerCount\":1,\"acceptedAnswer\":{\"@type\":\"Answer\",\"text\":\"Medical device cybersecurity encompasses<strong> all the security measures taken during development and after the medical device is in use<\/strong>, including providing updates, security patches, adequate encryption, malware protection, and more. This helps ensure any medical device connected to a network is secure, and decreases the risk of cyber attacks.\u00a0<br\/><br\/>While medical device cybersecurity standards only pertain to device manufacturers and healthcare facilities, <strong>you can do things to mitigate the risk of a cyber attack while using SaMDs like fitness and health tracking apps<\/strong>. Pay close attention to app permissions requests and download a trustworthy <a href=\\\"https:\/\/www.privateinternetaccess.com\/\\\">VPN service<\/a> to ensure traffic encryption.<br\/><br\/>\",\"inLanguage\":\"en-US\"},\"inLanguage\":\"en-US\"},{\"@type\":\"Question\",\"@id\":\"https:\/\/www.privateinternetaccess.com\/blog\/medical-device-cybersecurity\/#faq-question-1688165524167\",\"position\":2,\"url\":\"https:\/\/www.privateinternetaccess.com\/blog\/medical-device-cybersecurity\/#faq-question-1688165524167\",\"name\":\"Why is cybersecurity important for medical devices?\",\"answerCount\":1,\"acceptedAnswer\":{\"@type\":\"Answer\",\"text\":\"Medical devices collect, store, and transfer massive amounts of ePHI and PII \u2014 some can even tell you what dose of medication to take.\u00a0<br\/><br\/><strong>Without adequate cybersecurity in place, your medical devices are easy targets for ransomware.<\/strong> This puts your personal information, and potentially your life, at risk any time you connect your device to a network \u2014 especially <a href=\\\"https:\/\/www.privateinternetaccess.com\/wifi-vpn\\\">public wifi<\/a>.<br\/><br\/>\",\"inLanguage\":\"en-US\"},\"inLanguage\":\"en-US\"},{\"@type\":\"Question\",\"@id\":\"https:\/\/www.privateinternetaccess.com\/blog\/medical-device-cybersecurity\/#faq-question-1688165536906\",\"position\":3,\"url\":\"https:\/\/www.privateinternetaccess.com\/blog\/medical-device-cybersecurity\/#faq-question-1688165536906\",\"name\":\"What is the NIST Cybersecurity Framework for medical devices?\",\"answerCount\":1,\"acceptedAnswer\":{\"@type\":\"Answer\",\"text\":\"<strong>NIST is a five-step framework for continuously managing cybersecurity on medical devices<\/strong>. The five steps are identify, protect, detect, respond, and recover.\u00a0<br\/><br\/>Gartner Research estimated the NIST framework would be used by 50% of US organizations in 2020. Yet, a 2023 Healthcare Cybersecurity Benchmarking Study found 40% of facilities using NIST still aren\u2019t compliant with response and recovery planning.\u00a0<br\/><br\/>Some medical devices are not compatible with <a href=\\\"https:\/\/www.privateinternetaccess.com\/\\\">VPNs<\/a>. Including this capability could go a long way toward meeting the \u2018protect\u2019 stage of the NIST framework in medical equipment.<br\/><br\/>\",\"inLanguage\":\"en-US\"},\"inLanguage\":\"en-US\"},{\"@type\":\"Question\",\"@id\":\"https:\/\/www.privateinternetaccess.com\/blog\/medical-device-cybersecurity\/#faq-question-1688165555587\",\"position\":4,\"url\":\"https:\/\/www.privateinternetaccess.com\/blog\/medical-device-cybersecurity\/#faq-question-1688165555587\",\"name\":\"Do VPNs improve cybersecurity?\",\"answerCount\":1,\"acceptedAnswer\":{\"@type\":\"Answer\",\"text\":\"Yes, but not just any VPN. PIA VPN <a href=\\\"https:\/\/www.privateinternetaccess.com\/buy-vpn-online?conversionpoint=medical_device_cybersecurity\\\"><strong>improves your network\u2019s security<\/strong><\/a> and gives you the privacy you need. We offer strong <a href=\\\"https:\/\/www.privateinternetaccess.com\/vpn-features\/vpn-encryption\\\">VPN encryption<\/a> methods to make your traffic unreadable. Our VPN also has a strict No Logs policy, so your online activity remains private while you\u2019re connected.<br\/><br\/>Please note <strong>some medical devices don\u2019t support the use of VPNs yet<\/strong>. Contact your healthcare professional or the manufacturer of your device to know if configuring PIA to your home router can increase device security. Fortunately, you can use our dedicated iOS and Android apps on your smartphone to increase data privacy while using SaMDs.<br\/>\",\"inLanguage\":\"en-US\"},\"inLanguage\":\"en-US\"}]}<\/script>\n<!-- \/ Yoast SEO Premium plugin. -->","yoast_head_json":{"title":"Why We Need Medical Device Cybersecurity | PIA VPN","description":"The US govt updated the FD&C Act to ensure the healthcare sector and medical manufacturers take cybersecurity seriously.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.privateinternetaccess.com\/blog\/medical-device-cybersecurity\/","og_locale":"en_US","og_type":"article","og_title":"Why Medical Device Cybersecurity Is Essential","og_description":"The US govt updated the FD&C Act to ensure the healthcare sector and medical manufacturers take cybersecurity seriously.","og_url":"https:\/\/www.privateinternetaccess.com\/blog\/medical-device-cybersecurity\/","og_site_name":"PIA","article_publisher":"https:\/\/www.facebook.com\/privateinternetaccess\/","article_published_time":"2023-07-11T01:12:12+00:00","article_modified_time":"2025-04-16T07:39:18+00:00","og_image":[{"width":1200,"height":800,"url":"https:\/\/www.privateinternetaccess.com\/blog\/wp-content\/uploads\/2023\/06\/feature_medical_cybersecurity.png","type":"image\/png"}],"author":"Kristin Hassel","twitter_card":"summary_large_image","twitter_creator":"@buyvpnservice","twitter_site":"@buyvpnservice","twitter_misc":{"Written by":"Kristin Hassel","Est. reading time":"13 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.privateinternetaccess.com\/blog\/medical-device-cybersecurity\/#article","isPartOf":{"@id":"https:\/\/www.privateinternetaccess.com\/blog\/medical-device-cybersecurity\/"},"author":{"name":"Kristin Hassel","@id":"https:\/\/www.privateinternetaccess.com\/blog\/#\/schema\/person\/286e5fb351ecd2ce551e5fb44b547dee"},"headline":"Why Medical Device Cybersecurity Is Essential","datePublished":"2023-07-11T01:12:12+00:00","dateModified":"2025-04-16T07:39:18+00:00","mainEntityOfPage":{"@id":"https:\/\/www.privateinternetaccess.com\/blog\/medical-device-cybersecurity\/"},"wordCount":2936,"commentCount":0,"publisher":{"@id":"https:\/\/www.privateinternetaccess.com\/blog\/#organization"},"image":{"@id":"https:\/\/www.privateinternetaccess.com\/blog\/medical-device-cybersecurity\/#primaryimage"},"thumbnailUrl":"https:\/\/www.privateinternetaccess.com\/blog\/wp-content\/uploads\/2023\/06\/feature_medical_cybersecurity.png","articleSection":["General Thought Leadership"],"inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/www.privateinternetaccess.com\/blog\/medical-device-cybersecurity\/#respond"]}]},{"@type":["WebPage","FAQPage"],"@id":"https:\/\/www.privateinternetaccess.com\/blog\/medical-device-cybersecurity\/","url":"https:\/\/www.privateinternetaccess.com\/blog\/medical-device-cybersecurity\/","name":"Why We Need Medical Device Cybersecurity | PIA VPN","isPartOf":{"@id":"https:\/\/www.privateinternetaccess.com\/blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.privateinternetaccess.com\/blog\/medical-device-cybersecurity\/#primaryimage"},"image":{"@id":"https:\/\/www.privateinternetaccess.com\/blog\/medical-device-cybersecurity\/#primaryimage"},"thumbnailUrl":"https:\/\/www.privateinternetaccess.com\/blog\/wp-content\/uploads\/2023\/06\/feature_medical_cybersecurity.png","datePublished":"2023-07-11T01:12:12+00:00","dateModified":"2025-04-16T07:39:18+00:00","description":"The US govt updated the FD&C Act to ensure the healthcare sector and medical manufacturers take cybersecurity seriously.","breadcrumb":{"@id":"https:\/\/www.privateinternetaccess.com\/blog\/medical-device-cybersecurity\/#breadcrumb"},"mainEntity":[{"@id":"https:\/\/www.privateinternetaccess.com\/blog\/medical-device-cybersecurity\/#faq-question-1688165481877"},{"@id":"https:\/\/www.privateinternetaccess.com\/blog\/medical-device-cybersecurity\/#faq-question-1688165524167"},{"@id":"https:\/\/www.privateinternetaccess.com\/blog\/medical-device-cybersecurity\/#faq-question-1688165536906"},{"@id":"https:\/\/www.privateinternetaccess.com\/blog\/medical-device-cybersecurity\/#faq-question-1688165555587"}],"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.privateinternetaccess.com\/blog\/medical-device-cybersecurity\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.privateinternetaccess.com\/blog\/medical-device-cybersecurity\/#primaryimage","url":"https:\/\/www.privateinternetaccess.com\/blog\/wp-content\/uploads\/2023\/06\/feature_medical_cybersecurity.png","contentUrl":"https:\/\/www.privateinternetaccess.com\/blog\/wp-content\/uploads\/2023\/06\/feature_medical_cybersecurity.png","width":1200,"height":800},{"@type":"BreadcrumbList","@id":"https:\/\/www.privateinternetaccess.com\/blog\/medical-device-cybersecurity\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.privateinternetaccess.com\/blog\/"},{"@type":"ListItem","position":2,"name":"Why Medical Device Cybersecurity Is Essential"}]},{"@type":"WebSite","@id":"https:\/\/www.privateinternetaccess.com\/blog\/#website","url":"https:\/\/www.privateinternetaccess.com\/blog\/","name":"PIA","description":"Online privacy news from around the world.","publisher":{"@id":"https:\/\/www.privateinternetaccess.com\/blog\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.privateinternetaccess.com\/blog\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/www.privateinternetaccess.com\/blog\/#organization","name":"Private Internet Access","url":"https:\/\/www.privateinternetaccess.com\/blog\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.privateinternetaccess.com\/blog\/#\/schema\/logo\/image\/","url":"https:\/\/www.privateinternetaccess.com\/blog\/wp-content\/uploads\/2018\/07\/pialogowhitekglogo.png","contentUrl":"https:\/\/www.privateinternetaccess.com\/blog\/wp-content\/uploads\/2018\/07\/pialogowhitekglogo.png","width":1200,"height":1200,"caption":"Private Internet Access"},"image":{"@id":"https:\/\/www.privateinternetaccess.com\/blog\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/www.facebook.com\/privateinternetaccess\/","https:\/\/x.com\/buyvpnservice","https:\/\/www.instagram.com\/piavpn\/","https:\/\/www.youtube.com\/channel\/UClyJZ47Rizb1xnwuKXDI0_w"]},{"@type":"Person","@id":"https:\/\/www.privateinternetaccess.com\/blog\/#\/schema\/person\/286e5fb351ecd2ce551e5fb44b547dee","name":"Kristin Hassel","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.privateinternetaccess.com\/blog\/#\/schema\/person\/image\/","url":"https:\/\/www.privateinternetaccess.com\/blog\/wp-content\/uploads\/2023\/01\/kristin.h-96x96.jpg","contentUrl":"https:\/\/www.privateinternetaccess.com\/blog\/wp-content\/uploads\/2023\/01\/kristin.h-96x96.jpg","caption":"Kristin Hassel"},"description":"Kristin Hassel is an Information Systems Specialist and writer. Passionate about helping users of all experience levels find, utilize, and manage software solutions, she\u2019s experienced in a wide range of cybersecurity topics and strives to educate people about the importance of online security.","url":"https:\/\/www.privateinternetaccess.com\/blog\/author\/kristinh\/"},{"@type":"Question","@id":"https:\/\/www.privateinternetaccess.com\/blog\/medical-device-cybersecurity\/#faq-question-1688165481877","position":1,"url":"https:\/\/www.privateinternetaccess.com\/blog\/medical-device-cybersecurity\/#faq-question-1688165481877","name":"What is medical device cybersecurity?","answerCount":1,"acceptedAnswer":{"@type":"Answer","text":"Medical device cybersecurity encompasses<strong> all the security measures taken during development and after the medical device is in use<\/strong>, including providing updates, security patches, adequate encryption, malware protection, and more. This helps ensure any medical device connected to a network is secure, and decreases the risk of cyber attacks.\u00a0<br\/><br\/>While medical device cybersecurity standards only pertain to device manufacturers and healthcare facilities, <strong>you can do things to mitigate the risk of a cyber attack while using SaMDs like fitness and health tracking apps<\/strong>. Pay close attention to app permissions requests and download a trustworthy <a href=\"https:\/\/www.privateinternetaccess.com\/\">VPN service<\/a> to ensure traffic encryption.<br\/><br\/>","inLanguage":"en-US"},"inLanguage":"en-US"},{"@type":"Question","@id":"https:\/\/www.privateinternetaccess.com\/blog\/medical-device-cybersecurity\/#faq-question-1688165524167","position":2,"url":"https:\/\/www.privateinternetaccess.com\/blog\/medical-device-cybersecurity\/#faq-question-1688165524167","name":"Why is cybersecurity important for medical devices?","answerCount":1,"acceptedAnswer":{"@type":"Answer","text":"Medical devices collect, store, and transfer massive amounts of ePHI and PII \u2014 some can even tell you what dose of medication to take.\u00a0<br\/><br\/><strong>Without adequate cybersecurity in place, your medical devices are easy targets for ransomware.<\/strong> This puts your personal information, and potentially your life, at risk any time you connect your device to a network \u2014 especially <a href=\"https:\/\/www.privateinternetaccess.com\/wifi-vpn\">public wifi<\/a>.<br\/><br\/>","inLanguage":"en-US"},"inLanguage":"en-US"},{"@type":"Question","@id":"https:\/\/www.privateinternetaccess.com\/blog\/medical-device-cybersecurity\/#faq-question-1688165536906","position":3,"url":"https:\/\/www.privateinternetaccess.com\/blog\/medical-device-cybersecurity\/#faq-question-1688165536906","name":"What is the NIST Cybersecurity Framework for medical devices?","answerCount":1,"acceptedAnswer":{"@type":"Answer","text":"<strong>NIST is a five-step framework for continuously managing cybersecurity on medical devices<\/strong>. The five steps are identify, protect, detect, respond, and recover.\u00a0<br\/><br\/>Gartner Research estimated the NIST framework would be used by 50% of US organizations in 2020. Yet, a 2023 Healthcare Cybersecurity Benchmarking Study found 40% of facilities using NIST still aren\u2019t compliant with response and recovery planning.\u00a0<br\/><br\/>Some medical devices are not compatible with <a href=\"https:\/\/www.privateinternetaccess.com\/\">VPNs<\/a>. Including this capability could go a long way toward meeting the \u2018protect\u2019 stage of the NIST framework in medical equipment.<br\/><br\/>","inLanguage":"en-US"},"inLanguage":"en-US"},{"@type":"Question","@id":"https:\/\/www.privateinternetaccess.com\/blog\/medical-device-cybersecurity\/#faq-question-1688165555587","position":4,"url":"https:\/\/www.privateinternetaccess.com\/blog\/medical-device-cybersecurity\/#faq-question-1688165555587","name":"Do VPNs improve cybersecurity?","answerCount":1,"acceptedAnswer":{"@type":"Answer","text":"Yes, but not just any VPN. PIA VPN <a href=\"https:\/\/www.privateinternetaccess.com\/buy-vpn-online?conversionpoint=medical_device_cybersecurity\"><strong>improves your network\u2019s security<\/strong><\/a> and gives you the privacy you need. We offer strong <a href=\"https:\/\/www.privateinternetaccess.com\/vpn-features\/vpn-encryption\">VPN encryption<\/a> methods to make your traffic unreadable. Our VPN also has a strict No Logs policy, so your online activity remains private while you\u2019re connected.<br\/><br\/>Please note <strong>some medical devices don\u2019t support the use of VPNs yet<\/strong>. Contact your healthcare professional or the manufacturer of your device to know if configuring PIA to your home router can increase device security. Fortunately, you can use our dedicated iOS and Android apps on your smartphone to increase data privacy while using SaMDs.<br\/>","inLanguage":"en-US"},"inLanguage":"en-US"}]}},"_links":{"self":[{"href":"https:\/\/www.privateinternetaccess.com\/blog\/wp-json\/wp\/v2\/posts\/24750","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.privateinternetaccess.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.privateinternetaccess.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.privateinternetaccess.com\/blog\/wp-json\/wp\/v2\/users\/73"}],"replies":[{"embeddable":true,"href":"https:\/\/www.privateinternetaccess.com\/blog\/wp-json\/wp\/v2\/comments?post=24750"}],"version-history":[{"count":15,"href":"https:\/\/www.privateinternetaccess.com\/blog\/wp-json\/wp\/v2\/posts\/24750\/revisions"}],"predecessor-version":[{"id":28995,"href":"https:\/\/www.privateinternetaccess.com\/blog\/wp-json\/wp\/v2\/posts\/24750\/revisions\/28995"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.privateinternetaccess.com\/blog\/wp-json\/wp\/v2\/media\/24751"}],"wp:attachment":[{"href":"https:\/\/www.privateinternetaccess.com\/blog\/wp-json\/wp\/v2\/media?parent=24750"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.privateinternetaccess.com\/blog\/wp-json\/wp\/v2\/categories?post=24750"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.privateinternetaccess.com\/blog\/wp-json\/wp\/v2\/tags?post=24750"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}