Medical Device Cybersecurity Module 2: Lifecycle in Focus
Managing Medical Device Cyber Risk From Procurement to Retirement
Duration
4 Hours
Format
Blended Learning
(Virtual + Self-paced)
Certificate + CEUs
Earn Certificate of completion
+ 0.4 CEUs
Instructors
Matt Dimino and Toby Gouker
Experts, Practitioners, and Executive Leaders in Medical Device Security
Many healthcare delivery organizations (HDOs) only begin thinking about medical device cybersecurity after the device is deployed, or when a vulnerability is discovered. This reactive approach leads to:
- Procurement lacks security screening – devices are acquired without an adequate vendor risk assessment, security specification documentation (MDS2, SBOMs, etc), or contraction protections.
- Onboarding processes are inconsistent – outside of traditional initial acceptance, HTM/CE should register all attributes, have coordinated practices and SOPs with IT, and harden devices at time of deployment.
- Operational Security is minimal – most security activities are reactive, not embedding security practices within daily operations to ensure continuity and standardization.
- Decommissioning is insecure – sensitive data is often left on devices, and network access is may not be revoked upon retirement.
Questions?
Interested in learning more about this module or how it fits into your organization’s needs?