Walk a hospital floor and you’ll see the same tension: new EHR terminals sitting a few feet from an infusion pump running an operating system that stopped receiving patches years ago. That gap is not an oversight. It is structural, and it is why legacy medical devices remain one of healthcare’s toughest security challenges. Security teams understand the risk, but the usual fixes often do not apply.
The numbers remain concerning
Recent reporting backs up what security teams see every day. According to RunSafe’s 2026 Medical Device Cybersecurity Index, 28% of organizations operate devices past end-of-support with 44% acknowledging that they run end-of-support devices with known, unpatched, vulnerabilities. Further, among organizations using legacy devices, the RunSafe report noted that 42% report between 10% and 25% of the devices run unsupported operating systems.
This risk shows up in familiar places, including imaging workstations, infusion pumps, anesthesia machines, patient monitors, and nurse call systems. While these devices were built first for clinical function, many were never designed to be patched, segmented, or monitored the way a laptop is.
The risk is active right now
CISA’s ICS Medical Advisory feed shows how current the issue remains. In March, CISA Advisory ICSMA-26-083-01 disclosed a memory-leak vulnerability in an open-source library used in medical imaging workflows. According to CISA, a specially crafted file could cause an affected system to consume memory it does not release, resulting in a denial-of-service condition. In June, CISA Advisory ICSMA-26-181-01 disclosed five vulnerabilities in a medical imaging toolkit, including a critical path-traversal issue with a CVSS v3.1 score of 9.8. CISA states that successful exploitation could allow an attacker to write files, access unauthorized information, exhaust memory, or crash affected client or server processes.
An imaging system denial-of-service is not just an IT ticket. It can mean a delayed radiology read, a rescheduled cardiology procedure, or a diagnosis that waits. That difference matters when teams prioritize remediation. On a laptop, a denial-of-service bug may be an inconvenience. On a modality a clinician needs in the next ten minutes, it can become a patient-safety issue.
Why “just patch it” does not work here
There are a few structural reasons this category resists standard IT remediation:
- Regulatory clearance and vendor validation can tie a device to a specific OS, firmware, or software configuration. Patching may require additional vendor review or validation, which may not be available for older hardware.
- Many devices cannot run endpoint agents or tolerate active vulnerability scanning without risking clinical function or triggering false alarms during care delivery.
- Replacement cycles can run 10 to 15 years or longer, often tied to capital budgets that do not move on a security team’s timeline.
- Visibility is often the first gap. Teams cannot compensate for devices they have not inventoried, and IoMT asset inventories remain incomplete in many organizations.
What the FDA and HHS are pushing toward
The FDA’s February 2026 update to its final guidance, Cybersecurity in Medical Devices: Quality Management System Considerations and Content of Premarket Submissions, reinforces cybersecurity as part of device safety and quality management. It also addresses FDA recommendations for premarket submissions involving devices with cybersecurity risk. The guidance continues the focus on software transparency, including machine-readable SBOMs and vulnerability-management planning. HHS’s 405(d) Health Industry Cybersecurity Practices takes a similar view by identifying attacks against network-connected medical devices as a top healthcare-sector threat area.
The practical implication is clear. Manufacturers and healthcare organizations need better visibility into cybersecurity risk and software components so they can improve vulnerability management planning before devices reach operational limits. That visibility only matters if the facility side is ready to act on it.
What practitioners can actually do this month
- Build a real inventory that includes legacy medical devices and IoMT. Use passive network discovery where possible to improve device visibility without disrupting clinical operations.
- Segment by risk, not just by device type. Place unsupported and unpatchable devices on isolated VLANs with explicit allow-lists for the traffic they actually need.
- Track end-of-support notices as a security input, not a procurement footnote. Route them to the security team the day they arrive.
- Use virtual patching or IPS signatures for known CVEs on devices that cannot be patched directly, especially for medical imaging software flaws like the ones CISA disclosed this year.
- Test monitoring for cyber-physical impact. An alert that fires ten minutes after a modality goes down may be too late when a procedure is in progress.
The takeaway
Cybersecurity Awareness Month tends to bring familiar advice, reminding organizations to use MFA, patch systems, and train staff. All of that matters, but it does not solve the device in the imaging suite that cannot be patched and cannot be replaced this fiscal year. For healthcare security teams, the priority is strengthening compensating controls around the fleet they cannot fully secure through conventional remediation. That fleet is not going away anytime soon.