Cybersecurity
32 articles
CT, MRI & Fluoroscopy FDA Recalls: Siemens, Philips & GE Teardown
A safety teardown of CT, MRI, and fluoroscopy recalls. We review Siemens, Philips, and GE recall volumes, magnet venting risks, and cybersecurity issues.
European Health Data Space (EHDS) Regulation: Guide for Medical Device Manufacturers
How Regulation (EU) 2025/327 applies to medical devices and IVDs. Learn about Article 27 software components, CE marking, 2027-2031 deadlines, and GDPR alignment.
FDA Ventilator Recalls: Class I Events, MAUDE Deaths & Root-Cause Analysis (2024–2026)
A data-driven analysis of FDA ventilator recalls, MAUDE database adverse events, root-cause categories, and major Class I events from Vyaire, Hamilton, Baxter, and Philips.
Medical Device Cybersecurity Compared: FDA §524B vs EU MDR/MDCG/CRA
A comprehensive regulatory comparison of medical device cybersecurity requirements under US FDA Section 524B and the EU MDR, MDCG 2019-16, and Cyber Resilience Act (CRA).
GAMP 5 Computerized System Validation for Medical Devices (2nd Ed.)
A practical guide to GAMP 5 Second Edition for medical device manufacturers: software categories, the V-model, critical thinking, FDA CSA alignment, data integrity, and 21 CFR Part 11.
Medical Device Cybersecurity Is Now a Procurement Gate: 2026 Hospital Buying Data
RunSafe's 2026 Index: 56% of hospitals reject devices over cybersecurity, 35% won't buy without an SBOM, and 84% include security in RFPs. What manufacturers must do now.
Stryker Handala Cyberattack 2026: MedTech Supply Chain and Cybersecurity Lessons
Analyze the March 2026 Handala wiper attack on Stryker, its global manufacturing and order disruption, supply chain impact, and cybersecurity lessons for medtech.
Medical Device Cybersecurity Incident Response and Breach Reporting
Build a device cybersecurity response plan covering FDA 21 CFR 806, EU MDR vigilance, CISA timelines, containment, patient safety review, and coordinated disclosure.
Medical Device Cybersecurity Patch Management Guide (2026)
Plan regulated cybersecurity patch deployment for fielded devices under EU MDR, FDA Section 524B, and the Cyber Resilience Act, from triage to verified rollout.
EU AI Act and MDR Single Evidence Matrix for AI Medical Devices
Guide to building one evidence matrix for AI medical devices under EU MDR and the EU AI Act, mapping Annex II/III files, ISO 14971 risks, PMS/PMCF, cybersecurity, data governance, and QMS evidence.
FDA Cybersecurity Unresolved Anomalies Table for Premarket Submissions
Guide to building an FDA unresolved software anomalies table for cybersecurity submissions, including CVSS, exploitability, clinical impact, controls, SBOM links, VEX status, and labeling.
IEC 62304 Edition 2: 2026 Software Lifecycle Changes for Devices
Prepare for IEC 62304 Edition 2 with process rigor levels, broader health software scope, AI/ML lifecycle provisions, cybersecurity integration, and compliance timelines.
QMSR Supplier Quality Agreements for Cloud, AI, Cybersecurity, and Test Vendors
Draft QMSR supplier quality agreements for cloud, AI, cybersecurity, testing, and sterilization vendors with audit, CAPA, change notice, and evidence clauses.
SBOM-to-VEX Vulnerability Triage Workflow for Medical Device PSIRTs
PSIRT playbook for medical device SBOM-to-VEX triage, covering CVE intake, component matching, exploitability analysis, VEX rationale, severity scoring, CAPA, field action, and communications.
Special 510(k) for Software and Cybersecurity Changes: Decision Tree and Evidence Package
Decision tree for when a software or cybersecurity update can use Special 510(k) vs Traditional 510(k) — risk analysis, V&V summary, FDA guidance, and evidence package requirements.
FDA Cybersecurity Premarket Deficiencies: 12 Rejection Reasons
Guide to 12 common FDA cybersecurity premarket deficiencies in 2026, including SBOM, threat modeling, risk assessment, Section 524B, guidance alignment, and practical fixes.
Coordinated Vulnerability Disclosure for Medical Device Cybersecurity
Practical guide to medical device CVD programs, including PSIRT setup, vulnerability intake, CVSS scoring, SBOM linkage, FDA Section 524B, EU expectations, and customer communication.
Direct-to-Consumer Genetic Tests: FDA, FTC, Privacy, Clinical Validity, and Claims Control
Guide to regulatory, privacy, and commercial risks for DTC genetic tests, including FDA oversight, FTC claim substantiation, clinical validity, GINA, state privacy laws, and risk-report claims.
Medical Device Penetration Testing and Vulnerability Assessment
See how penetration testing, vulnerability scanning, and fuzz testing support FDA and EU MDR cybersecurity evidence for connected medical device submissions.
Medical Device Third-Party Cybersecurity Risk Management Guide
Manage third-party cybersecurity risk for connected medical devices using FDA Section 524B, QMSR and ISO 13485 controls, SBOMs, vendor assessments, and threat modeling.