The FDA has issued 18 medical device cybersecurity alerts. Almost all were high-risk
A content analysis of every FDA cybersecurity safety communication from 2013 to 2025 finds a small corpus, rising over time, and 94% of the flagged vulnerabilities rated severe.
Hospital cybersecurity is usually reported as an IT story — ransomware, downtime, a health system running on paper for a fortnight. The device layer underneath it gets less attention, and a content analysis published on 30 March in Frontiers in Digital Health gives one reason why: the public regulatory record on medical device cybersecurity is remarkably thin.
What the study counted
The analysis examined the cybersecurity safety communications issued by the US Food and Drug Administration between 2013 and 2025, using a systematic qualitative content analysis approach, and looked at the frequency of alerts, the severity of the vulnerabilities described, and the risks posed to healthcare infrastructure and patient safety [s1].
Across thirteen years, it found 18 safety communications related to cybersecurity breaches in medical devices [s1]. Of the vulnerabilities reported in them, 94% were classified as high-risk — a category the study characterises as covering severe potential consequences including unauthorised remote access to devices, possible device malfunctions, and exposure of sensitive patient data [s1]. The number of such communications increased notably over the period [s1].
Why 18 is the interesting number
Eighteen public alerts in thirteen years is roughly one and a half per year, against a device population that has been getting more connected the entire time. The study's framing is that integration of connected devices and internet-of-things technologies into healthcare has improved patient care and operational efficiency while introducing serious vulnerabilities that can allow unauthorised remote access, cause malfunctions, and lead to data breaches [s1].
Two readings are available and the study does not adjudicate between them. Either device cybersecurity events severe enough to warrant a public FDA safety communication are genuinely rare, or safety communications are a narrow instrument that captures only part of what happens. The count is a count of one specific regulatory artefact, not of incidents.
That the near-totality of what does get published is rated high-risk points weakly toward the second reading. A communication channel used almost exclusively for severe findings is, by construction, not a census of the problem.
The limits of this particular analysis
The paper is a single-author qualitative content analysis of publicly available documents. It does not link vulnerabilities to patient harm, does not sample devices in the field, and does not compare FDA communications against the parallel advisory streams run by other agencies or by manufacturers. Its own conclusion is a call for stronger cybersecurity strategies and for collaboration among manufacturers, providers and regulators, alongside continuous monitoring and regulatory compliance [s1] — a recommendation set that is reasonable and also nearly unfalsifiable.
What the study does establish reliably is the shape of the public record: small, severity-skewed, and growing.
The scoring problem underneath
A separate paper published in Scientific Reports on 28 November 2025 identifies a more tractable failure inside that record — how severity gets assigned in the first place [s2].
The Common Vulnerability Scoring System is the de facto standard for rating the severity of cybersecurity vulnerabilities, but the paper argues it is often misused: most stakeholders rely solely on the CVSS "Base Score", a measure of technical severity, and ignore the contextual Threat and Environmental metrics introduced in version 4.0 [s2]. In safety-critical domains such as healthcare, the authors argue, that narrow use produces poor prioritisation [s2].
The paper reports what it describes as the first large-scale application of full CVSS 4.0 Base, Threat and Environmental scoring to a comprehensive dataset of medical device vulnerabilities [s2]. Two findings matter operationally. The Threat group can be partially automated using structured data sources, and meaningful environmental profiles — the paper's example is home versus hospital care — allow semi-automatic compilation of the Environmental metrics [s2]. Applying the full BTE score significantly changes how vulnerabilities are prioritised, producing a risk representation the authors describe as both more accurate and more actionable, particularly where safety is involved [s2].
Why the environmental metric is the one to watch
The home-versus-hospital distinction is the substantive point buried in a scoring-methodology paper. The same infusion pump vulnerability does not carry the same risk on a segmented hospital network with monitored egress as it does on a patient's home Wi-Fi. A base score cannot express that difference; the environmental metrics exist precisely to.
As device categories move outward — continuous glucose monitors, home dialysis machines, remote-programmable implants — the population of devices sitting on unmanaged networks grows faster than the population sitting behind hospital security teams. A prioritisation scheme that ignores where a device lives will systematically misrank exactly the vulnerabilities that are migrating fastest.
What to watch
Whether the annual rate of FDA cybersecurity safety communications continues rising, and whether the severity mix broadens below "high-risk" — a wider distribution would suggest the channel is being used for more than emergencies. And whether contextual scoring of the kind the Scientific Reports group demonstrates moves from research paper into the advisories that hospitals and patients actually receive.
Sources
- [s1] Cybersecurity breaches in medical devices: analyzing FDA safety communications in response to patient security concerns. Frontiers in Digital Health, 30 March 2026. https://doi.org/10.3389/fdgth.2026.1701551
- [s2] Quantifying medical device cybersecurity risk with CVSS BTE. Scientific Reports, 28 November 2025. https://doi.org/10.1038/s41598-025-26898-x
Sources
- Cybersecurity breaches in medical devices: analyzing FDA safety communications in response to patient security concerns — Frontiers in Digital Health , March 30, 2026
- Quantifying medical device cybersecurity risk with CVSS BTE — Scientific Reports , November 28, 2025
The FDA has cleared 1,357 AI medical devices. Three were tested on patient outcomes.
A researcher who expected the evidence base to be thin says even she was surprised by how thin. Most cleared devices never appear in a registered clinical trial at all.
FDA opens comment on how to regulate AI medical devices that generate their own answers
A new discussion paper proposes a two-axis risk framework and a physician-training analogy for evaluating generative AI devices. It is not a rule, and the agency is asking what one should look like.
One trial has compared an over-the-counter hearing aid with an audiologist fitting
It found no meaningful difference at six weeks. It enrolled 64 people, tested one device, and ran for six weeks. That is the entire head-to-head evidence base three years after the category opened.
FDA creates a new device category for AI that reads skin wounds without touching them
The agency granted its first authorization for a software-aided adjunctive diagnostic device in wound assessment, a category built for tools that analyze a wound optically.