Medical Device Cybersecurity Module 5: Governance in Action
Building Accountability for Medical Device Security
Duration
4 Hours
Format
Blended Learning
(Virtual + Self-paced)
Certificate + CEUs
Earn Certificate of completion
+ 0.4 CEUs
Instructors
Matt Dimino and Toby Gouker
Experts, Practitioners, and Executive Leaders in Medical Device Security
Healthcare Delivery Organizations (HDOs) increasingly depend on connected medical devices (IoMT), yet often lack clear ownership, accountability, and structured governance around their cybersecurity. Responsibilities across clinical engineering, IT, IS, compliance, and vendors are often siloed or undefined, leading to missed vulnerabilities, slow response to threats, and audit failures.
This governance gap directly contributes to fragmented risk management, unaddressed security exceptions, and devices remaining unpatched or unmonitored—creating long-term exposure across clinical environments.
Key topics include:
- Discuss the role of governance in medical device cybersecurity.
- Identify governance frameworks and discuss best practices.
- How to build out policies and processes to align with the enterprise.
- Defining ownership and accountability.
- Understanding the risk acceptance and exception management process.
- Promoting accountability and transparency in strategies.
Participants will be able to:
- Define the role of governance in medical device cybersecurity and its alignment with enterprise risk.
- How to apply RACI and RAPID models to clarify ownership of cybersecurity tasks and decisions.
- How to Build or participate in governance committees focused on cybersecurity, patient safety, and risk mitigation.
- How to establish a policy framework that covers medical device procurement, deployment, maintenance, and decommissioning.
- Discuss tracking exceptions, vulnerabilities, and risk acceptances in a formal governance workflow.
Questions?
Interested in learning more about this module or how it fits into your organization’s needs?