Hospitals have had no shared way to press device makers on cybersecurity before a purchase. Health-ISAC’s Medical Device Security Council has supplied one: a MedTech Security Baselines paper organised around nine capability domains that clinical engineering, procurement and IT teams can put to manufacturers during device evaluation, procurement, deployment and exception reviews.
The paper divides the field in two, separating hardware that runs a full operating system from embedded, real-time or otherwise constrained platforms. Health-ISAC is explicit that this is decision support, not a certification standard or a mandatory procurement list; no device natively delivers every control.
Where a device cannot natively hold a control, the council asks for compensating measures that are documented, alongside governance and oversight shaped by operational burden, the threat model, the device’s clinical context and the impact on patient safety. Any control that leans on hospital infrastructure has to be agreed explicitly between buyer and maker, and final risk acceptance stays with the health organization’s authorized decision-maker.
A Control Summary Matrix acts as the paper’s front end, listing each control’s objective, its baseline capability, the alternatives worth weighing when a device cannot meet that baseline natively, and the evidence a hospital can request.
Medical hardware routinely outlives the operating systems, software components and security tooling it was built around. Validation constraints, specialized hardware and regulatory obligations all narrow the room for patches and upgrades, and capabilities a hospital takes for granted on enterprise IT may need substantial redesign.
Because these systems sit beside patient care, every security decision carries a second test: isolating a device, pushing a patch or taking it offline can ripple into clinical workflows and patient outcomes.
The council points hospitals at the matrix for four jobs: tightening procurement reviews, planning deployments, finding compensating controls and agreeing shared expectations with manufacturers.