SHARE
Facebook X Pinterest WhatsApp

IoT Medical Device Organizations Face Security Issues

Deloitte Cyber Risk Services reports that identifying and mitigating risks in IoT and legacy devices to be biggest challenge of IoT Medical Devices.

Written By
thumbnail
Sue Walsh
Sue Walsh
Aug 17, 2017

IoT Medical Device Organizations Face Security IssuesThe Internet of Things (IoT) has made great strides in the medical field, with more and more medical devices being connected.

Now the bad news; Given the IoT’s poor track record with security, it makes such devices vulnerable to cyberattacks, and such attacks could have grave consequences including shutting down critical medical processes and exposing patient data. This puts patient safety at great risk.

IoT medical devices don’t have security in mind

Despite this, like most other IoT devices, smart medical devices are generally not built with security in mind. A recent survey by Deloitte Cyber Risk Services found that of the 370 medical organizations polled, 36.5 percent have suffered a cyberattack in the past 12 months. 30 percent of respondents added that identifying and mitigating the risks of connected devices is their biggest security challenge.

[ Related: Testing Medical Device Integration in the IoT ]

Deloitte also reports that 19.7 percent said embedding vulnerability management into the design phase of devices was their big challenge, and 19.5 percent said it was monitoring and responding to security incidents. Nearly 20 percent (17.9 percent) said their biggest challenge was the lack of collaboration on security and threat management throughout the smart medical device supply chain.

Advertisement

No silver bullets for medical IoT security

“It’s not surprising that managing cyber risks of existing IoT medical devices is the top concern facing manufacturers, providers, and regulators,” says Russell Jones, Deloitte Risk and Financial Advisory partner at Deloitte.

[ Related: Blockchain, IoT, AI Will Converge in Healthcare ]

“Legacy devices can have outdated operating systems and may be on hospital networks without proper security controls,” Jones said.  “Connected device cybersecurity can start in the early stages of new device development, and should extend throughout the product’s entire lifecycle; but even this can lead to a more challenging procurement process. There is no magic bullet solution.”

Just over 55 percent said they felt their organization was somewhat prepared to address internal investigations, regulatory matters or litigation relating to medical device security incidents in the last 12 months. Just 18% said they were very prepared and 12 percent said they weren’t prepared at all.

thumbnail
Sue Walsh

Sue Walsh is News Writer for RTInsights, and a freelance writer and social media manager living in New York City. Her specialties include tech, security and e-commerce. You can follow her on Twitter at @girlfridaygeek.

Recommended for you...

Open Source Talent Shortage Expected To Increase in 2022
David Curry
Jul 12, 2022
Volvo Puts IoT and AI in the Driver’s Seat for Vehicle Connectivity
Sue Walsh
Nov 6, 2020
Cybersecurity and Digital Trust Companies Team for IoT Threats Detection
Sue Walsh
Oct 12, 2020
Cornell Researchers Create the Country’s First Statewide IoT Network
Sue Walsh
Oct 9, 2020

Featured Resources from Cloud Data Insights

Why Network Services Need Automation
The Shared Responsibility Model and Its Impact on Your Security Posture
The Role of Data Governance in ERP Systems
Sandip Roy
Nov 28, 2025
What Is Sovereign AI? Why Nations Are Racing to Build Domestic AI Capabilities
RT Insights Logo

Analysis and market insights on real-time analytics including Big Data, the IoT, and cognitive computing. Business use cases and technologies are discussed.

Property of TechnologyAdvice. © 2025 TechnologyAdvice. All Rights Reserved

Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.