惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

V
Visual Studio Blog
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
N
Netflix TechBlog - Medium
博客园 - 叶小钗
大猫的无限游戏
大猫的无限游戏
S
SegmentFault 最新的问题
V
V2EX
IT之家
IT之家
J
Java Code Geeks
Hacker News - Newest:
Hacker News - Newest: "LLM"
cs.AI updates on arXiv.org
cs.AI updates on arXiv.org
GbyAI
GbyAI
D
Docker
S
Secure Thoughts
Recent Announcements
Recent Announcements
Webroot Blog
Webroot Blog
Application and Cybersecurity Blog
Application and Cybersecurity Blog
云风的 BLOG
云风的 BLOG
博客园_首页
cs.CV updates on arXiv.org
cs.CV updates on arXiv.org
Cyber Security Advisories - MS-ISAC
Cyber Security Advisories - MS-ISAC
Security Archives - TechRepublic
Security Archives - TechRepublic
酷 壳 – CoolShell
酷 壳 – CoolShell
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
N
News | PayPal Newsroom
S
Security @ Cisco Blogs
I
InfoQ
Last Week in AI
Last Week in AI
SecWiki News
SecWiki News
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
W
WeLiveSecurity
T
Troy Hunt's Blog
Recent Commits to openclaw:main
Recent Commits to openclaw:main
H
Hackread – Cybersecurity News, Data Breaches, AI and More
Attack and Defense Labs
Attack and Defense Labs
美团技术团队
T
The Blog of Author Tim Ferriss
Google DeepMind News
Google DeepMind News
Martin Fowler
Martin Fowler
B
Blog
CTFtime.org: upcoming CTF events
CTFtime.org: upcoming CTF events
Scott Helme
Scott Helme
T
Tor Project blog
Know Your Adversary
Know Your Adversary
有赞技术团队
有赞技术团队
Hugging Face - Blog
Hugging Face - Blog
Recorded Future
Recorded Future
C
Cyber Attacks, Cyber Crime and Cyber Security
AI
AI
G
Google Developers Blog

WhatIs

Hims & Hers launches AI agent for lab results Twilio revamps, updates customer engagement platform CISA launches critical infrastructure cyber resilience initiative Most patients find appointment scheduling, billing overly complex Teradata's latest targets putting agentic AI into production AHA, Joint Commission launch cyber resilience program Tableau in transition as AI forces BI vendors to evolve California hospitals sue Elevance over out-of-network penalty CMS Health Tech Ecosystem adds electronic prior auth pledge Atlassian MCP updates take aim at AI token usage Leapfrog: Hospitals improved in 17 patient safety measures United promises another 30% cut to prior auths in 2026 AI outperforms docs on clinical reasoning, but not ready for solo work ServiceNow's Autonomous CRM takes aim at Salesforce ServiceNow reintroduces itself as an AI 'security company' New Tableau leader talks vendor's evolution in era of AI Deloitte warns of a "bubble effect" caused by the GLP-1 boom Tableau repositions for AI, unveils new knowledge layer IBM Bob AI coding agent ships, HashiCorp AIOps previewed DOJ forms West Coast Strike Force to stop healthcare fraud Most people benefit from the ACA's free preventive services SAP acquisitions of Dremio, Prior Labs target AI development Bridging the gap: Legacy tools gain enterprise AI support Amazon Connect Talent: AWS enters AI interviewing market AHA, West Health launch health tech adoption initiative How are states preparing for Medicaid work requirements? Weekly news roundup: Musk vs. Altman, Google’s Pentagon AI deal, China and EU hit Meta Skin substitute spending driven by patients, products, prices Clinical AI company Aidoc snags $150M in new funding Qlik's Capone departs after eight years as CEO OIG: CMS paid millions in improper virtual care payments FDA moves toward real-time review of clinical trial data FQHCs in low-income neighborhoods have lower cancer screening rates Solving quantum computing's longstanding no-cloning problem Qdrant boosts performance, reliability to meet AI needs Racial health disparities still impact U.S. as policy changes loom Agentforce Operations tackles workflow orchestration Boehringer's dual agonist obesity drug spurs up to 16.6% weight loss Legacy architecture, awareness gaps stifle microsegmentation adoption in healthcare AMA alerts officials of health plans' No Surprises Act abuse Latest SAS capabilities focus on fostering reliable AI AHA calls for TEFCA individual access SOP delay, citing patient privacy concerns Actian targets secure, compliant AI with new vector database Payers promise standardized electronic prior auths MIT EmTech: 2026 is the year AI goes to work As Claude Design debuts, Adobe users -- and buyers -- shrug GoodData joins agentic AI development mix with Agent Builder Comfort, affordability top drivers of digital mental health tool use CMS accelerates Medicare coverage for breakthrough medical devices Weekly news roundup: Tim Cook exits Apple, Meta layoffs intensify and Anthropic investigates Claude Merck inks $1 billion AI drug development deal with Google Cloud OCR settles four HIPAA investigations, prioritizes risk analysis OpenAI launches ChatGPT for Clinicians 90% of patients re-check AI chatbot health info with other sources Gemini Enterprise Agent Platform adds 'connective tissue' to Vertex AI AMA urges greater oversight of AI mental health chatbots CMS benches BALANCE Model for Medicare Former ransomware negotiator pleads guilty to BlackCat conspiracy New Google TPUs multiply AI infrastructure efficiency When brand-name drugs need a prior auth, brace for delays Google unveils data cloud purpose built for agentic AI Snowflake updates further goal of being control pane for AI UnitedHealthcare eliminates prior authorization for rural providers Yelp launches appointment scheduling button from Zocdoc Oracle takes steps toward CMS Health Tech Ecosystem goals OpenAI debuts AI model GPT-Rosalind to speed up drug discovery Which patient care access barriers deter cancer screening? Redis unveils Feature Form to improve AI, ML workloads Adobe defines its AI-powered customer experience platform How to escape agentification pilot purgatory for scalable AI New HSCC guidance tackles third-party AI risk Data quality, fast failures and quick wins key to AI success Stop Overpaying for Storage: A FinOps Guide for CIOs AWS launches AI-driven tool to speed up early-stage antibody discovery AMA: Clinician burnout in specialties persists as overall rates drop Mental health parity remains elusive in 43 states Before revenue cycle AI, payers and providers need to get along Edge and physical AI poised to upend enterprise networks Salesforce releases Agentforce dev tools, updates Agent Fabric Cyberattack continues to disrupt operations at Signature Healthcare FDA reminds sponsors, researchers to report clinical trial results AI arms race leading to prior auth problems, reimbursement cuts Abridge dives deeper into clinical decision support with NEJM, AMA AI provider search is here. How can health orgs stay visible? Judge dismisses No Surprises Act lawsuit against HaloMD What IT leaders should know from Nutanix .NEXT HubSpot builds answer engine optimization into its platform Sutter Health, MemorialCare face class action lawsuit over AI scribe use Latest Qlik tools target helping users achieve AI goals CMS taps Verily, Noom, 150+ others to participate in ACCESS model Starburst intros AI assistant to boost analysis, exploration Payers face faster prior authorization approvals under CMS proposal Lenovo deploys AI data agent for marketing, UX, e-commerce Cisco Galileo buy reflects blurring lines in AI observability CMS proposes 2.4% IPPS bump, joint replacement model expansion Patients unsure what to trust amid health information overload Nutanix expands flexibility by building out external storage Amazon Pharmacy adds Lilly's obesity pill with same-day delivery ServiceNow AI pricing change takes on enterprise ROI struggles Oracle's Sudha Raghavan on AI's infrastructure renaissance
Medical device security improves, but cyberattacks remain pervasive
2026-05-01 · via WhatIs

Jill Hughes

By

Published: 01 May 2026

Medical device security has long been a challenge for the healthcare sector. Legacy devices with unpatched vulnerabilities, an expanding attack surface and the rapid adoption of AI-enabled medical devices contribute to the complexity of every health system's device ecosystem, creating challenges that require a thoughtful, proactive security strategy.

Despite these challenges, the healthcare sector has made significant progress in integrating cybersecurity into device procurement and investment decisions, according to new data from RunSafe Security, a company that offers embedded software security tools to critical infrastructure organizations.

RunSafe based its research on survey data collected via Pollfish in March 2026. All 551 respondents were involved in medical device purchasing decisions at their healthcare organizations.

Despite the notable improvements, medical device security progress is at odds with the widening risk exposure and growing frequency of attacks on medical devices, the research asserted.

Healthcare strengthens medical device security

"Medical device cybersecurity has entered a new phase. Healthcare organizations are strengthening procurement requirements, increasing investment, and adopting new security practices," the report stated.

Medical device security has evolved in recent years, with healthcare organizations bolstering procurement requirements and adopting new security practices.

Nearly 81% of respondents rated a software bill of materials (SBOM) as "important" or "essential" when evaluating devices, and 35% said they would not consider a device without one.

Additionally, 56% of respondents said they had rejected a device due to cybersecurity concerns, up from 46% in 2025. More than three-quarters of respondents said they would pay a premium for devices with advanced cybersecurity protections, and 77% of respondents said their organizations increased cybersecurity resources in the past year.

More than 80% of respondents said they had deployed or are actively piloting runtime exploit protection tools, which defend devices when patches cannot be applied.

These notable improvements have been driven in part by regulations and guidance from the FDA -- 79% of respondents said regulations have meaningfully influenced their procurement processes. In June 2025, the FDA finalized its mandatory lifecycle security requirements for medical devices.

The survey responses show that healthcare organizations are  raising their security standards during device procurement, signifying a positive shift for the sector.

Device security risks persist

Cybersecurity standards are rising, but so is risk, the report indicated. Nearly 60% of respondents said they were extremely concerned about a cybersecurity incident impacting medical devices. For nearly a quarter of respondents, that concern had already become a reality.

Of the respondents who experienced a cyberattack, 80% reported moderate or significant impact on patient care, from extended hospital stays to manual workarounds and downtime.

Nearly 30% of respondents said they were operating devices past end-of-support, and 44% said they were running end-of-support devices with known, unpatched vulnerabilities.

AI has added another layer of complexity to medical device security. More than half of respondents said they use AI-enabled medical devices, and most (80%)  were concerned about the potential cybersecurity risks AI introduced.

"Cyberattacks are becoming more frequent, the impact on patient care is worsening, and legacy device exposure persists in critical environments," ther report stated. "The data suggests that while organizations are strengthening how they buy and secure devices, the underlying sources of risk -- unpatchable systems, expanding connectivity, and emerging technologies--are not being reduced at the same pace."

RunSafe recommended that healthcare organizations formalize cybersecurity requirements across all device categories, develop AI-specific cybersecurity frameworks and maintain a complete device inventory to promote full visibility.

As the cyberthreat landscape continues to evolve, healthcare organizations, manufacturers and policymakers will have to continue to prioritize medical device security and balance innovation with risk.

Jill Hughes has covered health tech news since 2021.

Dig Deeper on Health data threats