
Fifty three percent of connected medical devices and other IoT devices in hospitals carry at least one known critical vulnerability, a 2022 finding from Cynerio’s device-security research that the FBI also cited in its own 2022 industry notification. The technical frameworks for fixing that have never been more developed. The FDA’s final cybersecurity guidance is in force, the Software Bill of Materials requirement exists, and postmarket management obligations are written down in detail. The vulnerability rate has not moved because the problem was never a shortage of frameworks. It is a shortage of accountability.
. The technical frameworks for fixing that have never been more developed. The FDA’s final cybersecurity guidance is in force, the Software Bill of Materials requirement exists, and postmarket management obligations are written down in detail. The vulnerability rate has not moved because the problem was never a shortage of frameworks. It is a shortage of accountability.
Where the Failure Actually Happens
Devices that harm patients through cybersecurity failures are almost never the ones designed insecurely from the start. They are devices whose security posture was adequate at launch and then allowed to degrade, because inside the manufacturer’s organisation, nobody has clear ownership of whether an upstream vendor’s patch gets evaluated, prioritised and deployed. Fresh 2026 breach data from ORDR’s medical device security report puts a sharper edge on this: 99% of hospitals now manage at least one connected device with a known exploited vulnerability, and 60% of medical devices in service are end-of-life systems with no security patches available at all. Claroty’s 2025 State of CPS Security research sharpens that picture at the device level: 28% of imaging devices and more than 70% of patient devices already carry vulnerabilities that attackers are actively exploiting. That is a governance choice made, and remade, every time a patch review gets deprioritised, rather than a purely technical shortfall.
The Consequence Is Already Measurable
The clinical cost of that choice is no longer abstract. RunSafe Security’s 2026 industry survey found that 24% of healthcare organisations experienced a cyberattack or exploited vulnerability affecting a medical device in the past year, with 80% of those organisations reporting moderate or significant patient care impact and nearly half reporting extended stays and manual clinical workarounds. Separate 2026 reporting on the sector’s threat landscape found that 22% of healthcare organisations had already faced at least one medical device cyberattack that year, consistent across both surveys despite different methodologies. The chain of decisions behind such an incident runs through a manufacturer’s governance structure long before it reaches a hospital network team.
What Procurement Is Already Doing About It
Health systems have stopped waiting for manufacturers to fix this voluntarily. RunSafe’s survey found that 84% of healthcare organisations now write cybersecurity requirements directly into vendor RFPs, more than half have already rejected a device on cybersecurity grounds, and 81% rate a Software Bill of Materials as having strong influence or essential value in a purchasing decision. The SBOM is a useful test case for the whole argument: it is a list of components with version numbers, and its entire value depends on whether anyone inside the manufacturer actually monitors those components for newly disclosed vulnerabilities. A manufacturer that produces an SBOM and never checks it against new advisories has completed the paperwork without doing the work.
The Governance Architecture Most Organisations Still Lack
The FDA’s final guidance on cybersecurity in medical devices, effective from 27 June 2025, treats cybersecurity as a design and quality system requirement running across the whole product lifecycle, not a one-time premarket check. Meeting that standard requires a named owner for postmarket vulnerability management, a defined severity and patch-priority process, a published disclosure policy, and a board that understands cybersecurity as an ongoing lifecycle obligation rather than a launch-day certification. The manufacturers facing the sharpest regulatory and reputational exposure will typically be the ones that built adequate devices and then failed to govern what happened next, rather than the ones that built insecure devices in the first place.
Where to Start This Quarter
A board can test this in one question: who owns postmarket vulnerability management for every device category currently in service, by name, with a published patch-priority process behind it. Manufacturers that can already answer, with an SBOM someone actually monitors rather than merely files, are the ones procurement teams are choosing to buy from. That question costs nothing to ask. Answering it honestly, rather than deferring it to the next audit cycle, is the actual compliance work, everything else on the checklist is paperwork around it.