July 9, 2025 | Policy Brief
Medical Devices Still Vulnerable to Hacking Despite New FDA Guidance
July 9, 2025 | Policy Brief
Medical Devices Still Vulnerable to Hacking Despite New FDA Guidance
Machines such as pacemakers, insulin pumps, and vital signs monitors are the difference between life and death for millions of people, and they are all vulnerable to cyberattack. In its effort to protect the public, the Food and Drug Administration (FDA) on June 27 finalized its latest guidance for securing American medical devices.
But there is a gap that can be exploited by hackers from China and elsewhere: there is no requirement to fix cybersecurity flaws in devices already in the hands of hospitals, medical professionals, or patients.
Protecting the Buyer…
In 2022, Congress passed legislation requiring all pre-market medical devices to meet cybersecurity standards determined by the FDA. Now, before the FDA certifies medical devices are safe, suppliers must demonstrate how they will provide updates to devices to maintain cybersecurity and provide maintenance once they are in use. Companies must also demonstrate how they manage cybersecurity risks during the design, development, and maintenance of the product.
The FDA requires suppliers to provide a Software Bill of Materials listing all software components that the medical device uses to perform its functions. Because software is made up of many recycled and reused pieces of code, these lists provide the FDA with transparency into what the device actually contains, what vulnerabilities are associated with each piece of code, and how the company is patching and mitigating these issues before the device enters the market. The FDA is well ahead of numerous other consumer protection agencies, organizations, and associations in ensuring that crucial devices are being scoured for cyber vulnerabilities.
…But Leaving Already Purchased Devices at Significant Risk
In late June, the FDA released recommendations titled “Cybersecurity in Medical Devices: Quality System Considerations and Content of Premarket Submissions” to help medical device manufacturers implement the cybersecurity requirements for certification. This guidance is largely the same as the guidance the agency issued two years ago.
While the guidance contains recommendations for both pre- and post-market devices, the FDA’s cybersecurity requirements are not mandatory for devices that received certification prior to the 2022 law. As a result, these devices may have unaddressed cybersecurity problems that the manufacturer has no plan to fix.
Nations and Criminals Are Exploiting This Cybersecurity Gap
In January, researchers found that widely used patient monitors were sending data back to a Chinese IP address via a pre-installed, intentionally hidden backdoor coded into the device’s firmware. Manufactured in China, these devices were already for sale and in use in the United States. While the FDA recommended that hospitals stop using the devices, the monitors remain on the market.
Meanwhile, Masimo, an American health care technology company, discovered a separate cyberattack against its systems. Masimo produces noninvasive devices that track blood oxygen levels and brain function. The hackers may have stolen patient data during the attack.
Medical devices hold confidential information about a person’s health and data that makes people easy to identify. With access to this data, cyber-criminals can launch financial scams and insurance fraud. In the worst cases, nation-state actors can control the devices and alter the patient’s apparent vital signs, leading to improper administration of medical care and even death. Alter the care of a world leader or cause enough medical devices to malfunction, and an adversary can cause societal panic. Without proper oversight of post-market medical technology, these risks will continue to plague the American health care industry.
The FDA Must Do More To Protect People
To better protect Americans and their personal health data, the FDA should require suppliers to routinely provide the same information for in-use devices as required for new devices seeking certification. The FDA should also revoke certification for vulnerable devices when suppliers do not promptly address cybersecurity problems.
The FDA should also, by default, deny certification for all Chinese-made medical devices. A proactive rejection of new Chinese medical technology would decrease the cyber threats facing the U.S. health care system and buy time for the government to investigate post-market devices.
Dr. Samantha Ravich is the chairwoman of the Center on Cyber and Technology Innovation at the Foundation for Defense of Democracies (FDD) and was a commissioner on the congressionally mandated Cyberspace Solarium Commission. Johanna (Jo) Yang is a research and editorial associate at the Center on Cyber and Technology Innovation (CCTI) at FDD, where she works on issues related to nation-state cyber threats, critical infrastructure protection, and U.S. cybersecurity policy. For more analysis from Dr. Ravich, Johanna and FDD, please subscribe HERE. Follow FDD on X @FDD. FDD is a Washington, DC-based, nonpartisan research institute focusing on national security and foreign policy.