Skip to content
MarketScale
‹ Back to IndustriesHealthcare

SECURITY CONCERNS WITH SMART MEDICAL DEVICES

The world has embraced connected devices. They’ve become a technology that people rely on, both personally and professionally. This is reflected in the medical field, where connected device usage is steadily increasing. A report by Statista claims over 161 million medical connected devices will be installed by 2020. The demand for these Internet of Things (IoT) devices…

This story was produced through MarketScale. See how Healthcare teams put it to work with Executive Thought Leadership.

Share

Get featured

Want to get featured in MarketScale Healthcare?

Create a free MarketScale workspace and get your company's expertise featured across our Healthcare coverage. No credit card, no demo required.

Start free

The world has embraced connected devices. They’ve become a technology that people rely on, both personally and professionally. This is reflected in the medical field, where connected device usage is steadily increasing. A report by

Statista

claims over 161 million medical connected devices will be installed by 2020. The demand for these Internet of Things (IoT) devices is obvious.

However, there is an opportunity for these devices to be a security risk. In fact, it’s making a new approach to security necessary.

Security Risk

The crux of the risk is that connected medical devices are no longer stand-alone, they are part of a network with multitudes of other devices. For example, some types of infusion pumps communicate with electronic health record (EMR) systems or priority monitoring systems. This communication often includes personal health information (PHI). This communication must be safeguarded to maintain patient confidentiality and safety.

Without proper security, connected medical devices can be easily breached. A malicious actor (aka ‘hacker’) looking to infiltrate a network often only needs one weak device to be successful. McAfee Labs’ Threat Report reveals a 210% increase in disclosed security incidents related to healthcare. This surge indicates that hackers are finding programs on the network that are vulnerable.

Many of these vulnerabilities involve leveraging attack techniques such as phishing, ransomware or denial of service. However devices are often also vulnerable to more targeted attacks such as “replay attacks where communication is intercepted that is designated for the device. The communication can then be replayed to the device to cause it to repeat the action the communication originally intended to do.

The FDA confirmed

that connected pacemakers and defibrillators can be exploited. Leveraging these exploits a malicious actor could drain batteries or trigger shocks to the patient.

Steps to Improve Connected Device Security

To realize the advantages of connected devices, resolve concerns about security by employing these essential best practices:

  • Building security into the design process. Consider security concerns early in development to ensure the final product does not need to compromise on security.
  • Evaluate security risk. No two devices risk profiles are the same. Thus no two devices have the same security risks. Security risk need to be evaluated to ensure a device is safe as possible.
  • Utilize standard industry practices. Techniques exist for encryption, authorization and authentication. Utilizing the existing practices employs the magnitude of effort already invested into solving difficult security challenges.
  • Test the security of the device. Often devices have vulnerabilities that are not the result of bad design but is merely a mistake that can be easily resolved. Testing ensures that misconfiguration or software anomalies do not lead to vulnerabilities in the field.
  • Understand the security life cycles once a device is in the wild. Plan on how to respond and address security vulnerabilities when they occur in the field.
  • Emphasize the encryption of all sensitive data, especially Protected Health Information (PHI). This is critical in ensuring privacy and control over data.
  • Institute more security measures after the initial configuration by the manufacturer. You should be able to update and adjust security settings throughout the life of the product.

Such a bright future for connected medical devices shouldn’t be compromised by lax security.

Learn more

about Sunrise Labs and cyber security for medical devices.

Read more at sunriselabs.com

Your experts belong here

Every story in MarketScale Healthcare starts with a company putting its clinicians, service-line leaders, and field engineers on the record. Buyers are already reading this topic. The only question is whose experts they find.

Service-line buyers vet vendors quietly, and your clinicians become the proof they find while doing it.

Get your team featuredSee how it works15 minutes, straight to a calendar.
B2B Weekly

The week in Healthcare, and sixteen other industries, every Monday.

Ten stories, one-line takes, five minutes. Free.

Healthcare: are you visible to AI?

Before they reach out, Healthcare buyers ask AI engines which vendors to trust. Explore how your experts, customers, and partners can become useful content for buyers and AI search.

Free plan

You just read one Healthcare expert. Your company is full of them.

This article was produced through MarketScale. The same platform turns your clinicians, service-line leaders, and field engineers into the articles, video, and social content Healthcare buyers are searching for. Create a free workspace and see it with your own people. No credit card, no demo required.

NPS +73 · 1,000+ creators · 38+ countries

What you get, free

Your own MarketScale workspace, up to 10 people
One professional video edit a month for qualifying companies
Media requests to your crowd, remote recording, AI writing tools
$0, no credit card, nothing that expires

More Healthcare Insights

Waiting for perfectly clean data is stalling healthcare AI, not protecting it

Healthcare organizations often delay AI initiatives waiting for perfectly clean data, but this assumption no longer holds: reliable subsets and synthetic data allow projects to start now while data work continues in parallel. Success requires starting with business outcomes rather than technology capabilities, and embedding governance in product strategy before implementation, not after.

  • 01Waiting for 100% clean data is effectively a decision never to start; hospital AI projects can begin on reliable data subsets while quality work continues in parallel.
  • 02Frame AI decisions around business outcomes (revenue growth, cost reduction, competitive advantage, new products, or ecosystem influence) rather than asking what AI can do.
  • 03Governance should be part of product strategy before design or purchase, especially as agentic AI takes actions—such as handling many revenue-cycle denials—while routing the rest to humans.

Sep 21, 2026

July partnerships show hospitals aligning without ownership change

July partnerships show hospitals aligning without ownership change

A July McDermott Will & Schulte analysis and four July partnership announcements tracked by Becker’s Hospital Review point to affiliation models that stop short of mergers. St. Christopher’s signed a nonbinding letter of intent with Nemours, Jefferson and Temple; Palomar UC San Diego Health began operating July 1 under a joint powers authority. Several announcements explicitly rule out ownership change, shifting the work to contracts covering governance and other terms.

  • 01In an alliance, the contract does the integrating that an org chart does in a merger: McDermott Will & Schulte says governance design, exclusivity, antitrust review, community commitments and exit rights all have to be settled before signing.
  • 02Purchasing is now explicitly on the table in at least one no-ownership deal, the St. Peter's Health and Billings Clinic-Logan Health talks in Montana, which means shared supply contracts can arrive without a change of control.

Sep 19, 2026

Eye telemedicine hits limits without home retinal imaging

Eye telemedicine hits limits without home retinal imaging

An Ophthalmology Times commentary by T.Y. Alvin Liu, Ferdinand Hui and Phillip Phan sorts eye patients into three telemedicine tiers by clinical need. Patients needing regular OCT scans benefit less unless a home device can send the image. Video tools already sit inside Epic and Cerner; the deciding purchase for retina clinics is the imaging device in the patient's living room.

  • 01The dividing line for eye telemedicine is imaging, not video: patients who need regular OCT scans benefit less from remote visits unless a device at home can send the scan, so a video license alone shifts few of those encounters.
  • 02The provider-side requirement, a HIPAA-compliant secured video platform, was already built into Epic and Cerner by 2020; the patient-side requirements (1.5 MB up and down bandwidth, a quiet private room, comfort with the technology) sit outside the health system's control and are the ones worth screening for at scheduling.
  • 03Self-administered home color fundus photography for tracking non-proliferative diabetic retinopathy was named as the nearer route into retina telemedicine; home OCT for wet AMD is the harder gate and the device to watch.

Sep 19, 2026

Explore More Healthcare Insights

Read more expert perspectives from across Healthcare.

Browse Healthcare Hub

For B2B teams

Your experts could be publishing here

Stories like this one run on content MarketScale captures from real practitioners. See how your team's expertise becomes coverage in Healthcare and beyond.

Book a 15-minute demo

Or call us. No forms required. We pick up. 214-945-2512