Events Calendar

Mon
Tue
Wed
Thu
Fri
Sat
Sun
M
T
W
T
F
S
S
27
28
29
30
31
1
2
3
4
5
6
7
8
9
10
12
13
14
15
16
19
21
22
24
26
27
28
29
30
11 Jun
2019-06-11 - 2019-06-13    
All Day
HIMSS and Health 2.0 European Conference Helsinki, Finland 11-13 June 2019 The HIMSS & Health 2.0 European Conference will be a unique three day event you [...]
7th Epidemiology and Public Health Conference
2019-06-17 - 2019-06-18    
All Day
Time : June 17-18, 2019 Dubai, UAE Theme: Global Health a major topic of concern in Epidemiology Research and Public Health study Epidemiology Meet 2019 in [...]
Inaugural Digital Health Pharma Congress
2019-06-17 - 2019-06-21    
All Day
Inaugural Digital Health Pharma Congress Join us for World Pharma Week 2019, where 15th Annual Biomarkers & Immuno-Oncology World Congress and 18th Annual World Preclinical Congress, two of Cambridge [...]
International Forum on Advancements in Healthcare - IFAH USA 2019
2019-06-18 - 2019-06-20    
All Day
International Forum on Advancements in Healthcare - IFAH (formerly Smart Health Conference) USA, will bring together 1000+ healthcare professionals from across the world on a [...]
Annual Congress on  Yoga and Meditation
2019-06-20 - 2019-06-21    
All Day
About Conference With the support of Organizing Committee Members, “Annual Congress on Yoga and Meditation” (Yoga Meditation 2019) is planned to be held in Dubai, [...]
Collaborative Care & Health IT Innovations Summit
2019-06-23 - 2019-06-25    
All Day
Technology Integrating Pre-Acute and LTPAC Services into the Healthcare and Payment EcosystemsHyatt Regency Inner Harbor 300 Light Street, Baltimore, Maryland, United States of America, 21202 [...]
2019 AHA LEADERSHIP SUMMIT
2019-06-25 - 2019-06-27    
All Day
Welcome Welcome to attendee registration for the 27th Annual AHA/AHA Center for Health Innovation Leadership Summit! The 2019 AHA Leadership Summit promotes a revolution in thinking [...]
Events on 2019-06-11
11 Jun
Events on 2019-06-17
Events on 2019-06-20
Events on 2019-06-23
Events on 2019-06-25
2019 AHA LEADERSHIP SUMMIT
25 Jun 19
San Diego
Articles Latest News

More than 75% of healthcare leaders have increased their budgets for medical devices and cybersecurity.

EMR Industry

A recent report highlights the security challenges and spending trends among healthcare cybersecurity leaders. Based on a survey of over 600 healthcare IT decision-makers involved in medical device procurement, the findings reveal that 22% have faced cyberattacks specifically targeting their organizations’ medical devices.

A new report sheds light on the cybersecurity challenges and spending behaviors among healthcare IT leaders. Based on a survey of over 600 healthcare IT decision-makers involved in medical device procurement, the study found that 22% had experienced cyberattacks targeting their organization’s medical devices—and of those, 75% reported that the incidents directly compromised patient care.

Why It Matters:

A significant number of respondents expressed a lack of confidence in their organization’s ability to protect medical devices from cyber threats. This concern is so pronounced that 46% admitted to having declined to purchase certain devices due to security fears, according to McLean, Virginia-based Runsafe Security, which commissioned the study.

The 2025 Medical Device Cybersecurity Index, released on Thursday, is based on research involving IT professionals from both the U.S. and internationally who have direct knowledge of medical device security. According to researchers, the findings highlight a troubling trend regarding the vulnerability of diagnostic, treatment, and monitoring devices critical to patient care.

“While electronic health records (EHR) systems had the highest compromise rate at 52%, cyber attackers are increasingly shifting focus from data theft to disrupting operations,” the report states. This includes deliberate attacks on life-sustaining medical devices that directly interact with patients.

Attackers are intentionally targeting mission-critical infrastructure, including the software and firmware within medical devices and health IT applications, aiming for maximum disruption—even at the cost of patient lives.

Over the past year, one-third of surveyed organizations reported experiencing ransomware attacks aimed at crippling device operations. Malware infections (51%) and network intrusions (44%) were also cited as the most common methods used by cybercriminals.

These threats have forced many healthcare systems to isolate devices, quarantine systems from networks, and prioritize security features built into devices to reduce the need for post-deployment patching.

Among organizations that reported medical device compromises:

43% experienced 1–4 hours of downtime

31% faced outages lasting 5–12 hours

19% suffered device outages exceeding 13 hours

Researchers also emphasized the rising importance of software bills of materials (SBOMs) in procurement decisions, with 78% of respondents rating them as “essential” or “important.”

Additionally, 79% of device buyers expressed a willingness to pay more for advanced runtime protection or built-in exploit prevention capabilities.

The Broader Trend:

There is growing demand across the healthcare sector for collective action to address vulnerabilities exploited by advanced persistent threat actors. However, progress on industry-wide efforts—such as implementing SBOMs—has been slow, despite a surge in cyberattack activity in recent years.

SBOMs are vital tools for helping enterprise IT teams assess and monitor the software components used in medical devices. Darren Lacey, former Chief Information Security Officer at Johns Hopkins, previously noted that understanding underlying technologies is essential for evaluating new tools, such as large language models, and developing appropriate testing protocols.

Expert Insight:

“With healthcare buyers now willing to pay a premium for enhanced security features, medical device manufacturers have a clear economic incentive to invest more in cybersecurity innovation,” researchers concluded. “This shift could help elevate the overall security baseline across the industry.”