Person touching screen in futuristic setting

Medical Device Cybersecurity Module 3: Beyond the Patch

Asynchronous Icon

Duration

5 Hours

Curriculum Icon

Format

Blended Learning 
(Virtual + Self-paced)

Flexibility Icon

Certificate + CEUs

Earn Certificate of completion 
+ 0.5 CEUs

Strong Network Icon

Instructors

Matt Dimino and Toby Gouker
Experts, Practitioners, and Executive Leaders in Medical Device Security

This course provides a focused, practical framework for managing vulnerabilities in connected medical devices. Unlike traditional IT assets, medical devices often can’t be patched easily requiring a shift in how vulnerabilities are discovered, prioritized, and mitigated. This session will teach healthcare professionals how to implement a risk-based vulnerability management program for clinical assets that aligns with compliance mandates, patient safety, and operational realities.


Traditional vulnerability management processes do not translate well to the unique constraints of medical devices. Key issues include:

  • Unpatchable systems that limit the ability to update
  • Vendor dependencies for security updates or disclosure
  • Incomplete asset inventories leading to blind spots in vulnerability analysis
  • Lack of context and preemptive risk assessments
  • Most Medical Device Cybersecurity Programs are reactive, not lifecycle-based

Participants will be able to:

  • Identify and track vulnerabilities in medical devices across the hospital ecosystem
  • Prioritize vulnerabilities based on technical severity and clinical impact
  • Apply compensating controls when patching is not feasible or permitted
  • Understand how to operationalize tools to provide actions against vulnerabilities
  • Reduce risk exposure and create efficiencies in managing vulnerabilities
  • Include any metrics and statistics that support the impact
  • Include participant feedback, testimonials, or any quantifiable success metrics (if available)
  • Communicate risks and remediation plans effectively with clinical, HTM, and IT/IS teams
  • Establish processes and documentation procedures that align with the organizations risk appetite

Questions?

Interested in learning more about this module or how it fits into your organization’s needs?

Start the Conversation