A Compass Healthcare Company

Tuesday, 14 July 2026

Why legacy medical devices remain a critical cybersecurity risk

Capital Planning

Legacy medical devices remain one of the most persistent cybersecurity risks in healthcare


 

Cybersecurity has long been framed as an IT problem. In healthcare, that framing is no longer sufficient.

Cyber risk is clinical risk. It is operational risk. It is financial risk. And increasingly, it is being driven by something most organizations cannot easily eliminate: legacy medical devices.

ECRI recognized this reality in its Top 10 Health Technology Hazards for 2026, identifying cybersecurity risks from legacy medical devices as a top concern for the year ahead.

That concern is well founded.

These devices often run outdated operating systems or unsupported software, creating persistent vulnerabilities in environments where uptime, patient safety, and data integrity are non-negotiable.

The inescapable reality of legacy infrastructure


 

Virtually every hospital operates with some level of legacy technology. In many cases, critical devices still run on outdated platforms like Windows XP or other unsupported systems. Replacing them outright is rarely feasible from a cost perspective.

This creates a structural challenge for health systems. A successful cyberattack in healthcare does not stop at the network. It can interrupt care delivery, force clinicians into downtime workflows, delay diagnosis, and place additional strain on already stretched teams.

When legacy devices are compromised, the consequences often extend well beyond the device itself:

  • Loss of access to patient data
  • Disruption of clinical workflows
  • Device downtime or system unavailability
  • Delays in diagnosis or treatment

In smaller or resource-constrained facilities, the impact can be even more acute. A single compromised device, such as a CT scanner, can take an entire service line offline, forcing diversion and delaying care.

These are not theoretical scenarios. They are already happening.

Why medical device cyber risk often hides in plain sight


 

One of the most consistent findings across healthcare environments is a lack of visibility.

That creates a dangerous false sense of readiness. Many health systems believe they understand their cyber exposure, but legacy medical devices often sit outside the processes used to identify and manage enterprise risk.

This lack of visibility creates blind spots that attackers can exploit.

At the same time, responsibility for these systems is often fragmented. Clinical engineering, IT, and cybersecurity teams often times operate in silos, each with partial ownership but no unified strategy.

That gap is where many cybersecurity strategies break down. The issue is not simply whether a device is vulnerable. It is whether the organization has a coordinated way to see that risk, prioritize it, and act on it without disrupting care.

A practical approach to managing legacy medical device risk


 

Given the financial constraints, the path forward is often not immediate replacement of legacy systems. It is mitigation.

For most health systems, this shifts the focus from elimination of risk to management of risk.

Effective organizations are focusing on three core strategies:

  • Network segmentation
    Isolating legacy devices and limiting their communication pathways is the single most impactful step. By reducing what a device can access, organizations can contain potential threats.
  • Visibility and vulnerability management
    Understanding what exists on the network is foundational. Advanced monitoring tools can identify device profiles, detect anomalies, and surface vulnerabilities that would otherwise remain hidden.
  • Lifecycle planning
    While immediate replacement may not be possible, organizations must prioritize and plan for phased upgrades based on risk exposure.

The role of integrated cybersecurity programs

The most effective healthcare systems are moving toward comprehensive cybersecurity programs that integrate across disciplines. This shift reflects a broader recognition that cybersecurity can no longer operate as a standalone function.

This includes:

    • Continuous monitoring of network activity

    • Centralized visibility into connected devices

    • Coordinated response between IT, cybersecurity, and clinical engineering

    • Structured plans for both mitigation and eventual replacement

Solutions that provide this level of visibility and coordination have become increasingly important because they allow organizations to move from reactive defense to proactive risk management.

In many cases, the greatest value is not just in protecting systems, but in revealing what organizations didn’t know they had.

The road ahead for medical device cybersecurity


 

Cyber threats are not slowing down. In fact, AI is accelerating both attack sophistication and the tools available to defend against it.

The focus can no longer be limited to preventing attacks. It also must include how care and operations will continue if systems are affected.

Against that backdrop, legacy medical devices represent one of the most persistent and complex vulnerabilities in the healthcare environment.

Addressing them requires a shift in mindset. From siloed teams to integrated operations. From limited visibility to continuous awareness. Most importantly, it requires recognizing that cybersecurity is not separate from care delivery. It is embedded within it.

To respond, many organizations are moving toward more connected approaches to medical device cybersecurity, where lifecycle visibility, vulnerability insight, and operational context are brought together. Intelas’ CyberHUB supports this shift, delivering continuous visibility into connected medical devices and helping teams identify risk, respond in real time, and manage vulnerabilities through a closed-loop process that drives accountability from detection through confirmed resolution.

When systems fail, care is disrupted. And when care is disrupted, patients feel the impact. That is what makes this issue urgent for health systems and IT leaders alike.

Written by: Edward Myers, National Director of Cyber Security, Intelas

Healthcare Technology Management (HTM) FAQs

How can hospitals secure legacy medical devices that cannot be replaced?

Many hospitals continue to rely on legacy medical devices because replacing them immediately is not financially feasible. The most effective strategy is to reduce risk through network segmentation, continuous device monitoring, vulnerability management, and coordinated remediation. By prioritizing high-risk devices and integrating cybersecurity into healthcare technology management (HTM) workflows, organizations can strengthen security while maintaining clinical operations.

Legacy medical devices often run unsupported operating systems or outdated software that no longer receive security updates. These vulnerabilities can make devices attractive targets for cyberattacks, potentially disrupting clinical workflows, delaying patient care, exposing sensitive data, and increasing operational and financial risk. Managing these devices requires ongoing visibility, risk assessment, and coordinated response.

Medical device cybersecurity risk management is the ongoing process of identifying, assessing, prioritizing, and mitigating cyber risks across connected medical devices throughout their lifecycle. It combines asset inventory, vulnerability management, continuous monitoring, incident response, and lifecycle planning to help healthcare organizations reduce cyber risk while supporting patient safety and regulatory compliance.

Intelas strengthens medical device cybersecurity through its award-winning CyberHUB platform and integrated Cyber Defense Team (CDT).

Recipient of the 2026 Fortress Cybersecurity Award for Healthcare, CyberHUB combines continuous visibility into connected medical devices with expert-led vulnerability management, risk prioritization, and coordinated remediation across HTM, IT, and cybersecurity teams. In the last 12 months, the solution has helped healthcare organizations identify and mitigate more than 670,000 potential vulnerabilities across 82,000+ connected medical devices, while moving 10,400+ devices from high-risk to low-risk status.

Unlike solutions that stop at identifying vulnerabilities, CyberHUB’s closed-loop remediation process ensures identified risks progress from discovery through remediation and documented resolution, providing greater accountability, operational visibility, and resilience.