By NHI Mgmt Group Editorial TeamDomain: Cyber SecuritySource: Sprocket SecurityPublished March 6, 2026

TL;DR: Hospital networks now contain 10,000 to 15,000 connected medical devices on average, while 53% of those devices have at least one critical vulnerability and 75% of infusion pumps have known unpatched flaws, according to Sprocket Security's analysis of healthcare IoT risk. The security problem is no longer perimeter protection, but visibility, segmentation, and safe testing for unmanaged devices that attackers can use as pivot points.


At a glance

What this is: This analysis shows that connected medical devices have become a large, under-defended attack surface in hospital networks, with outdated systems, default credentials, and weak telemetry creating easy pivot points for attackers.

Why it matters: It matters because healthcare security, IAM, and resilience teams must treat unmanaged clinical devices as part of the security perimeter, not as isolated operational assets outside identity, monitoring, and containment controls.

By the numbers:

👉 Read Sprocket Security's analysis of medical device attack surface risk in hospitals


Context

Healthcare networks no longer end at the firewall or VPN boundary. The primary security gap is that large numbers of connected medical devices operate with outdated operating systems, default credentials, and limited telemetry, which leaves clinical infrastructure exposed to lateral movement and difficult-to-detect persistence.

For IAM and PAM teams, the issue is not user authentication alone. These devices function as unmanaged assets with embedded access assumptions, and that makes segmentation, inventory accuracy, and trusted network paths part of identity governance for the wider clinical environment.

The hospital described in the source is not atypical. It reflects a common pattern across healthcare, where legacy devices remain in production long after modern security controls would normally be expected.


Key questions

Q: What breaks when medical devices are left outside normal security controls?

A: The main failure is not just device compromise. Once a medical device sits outside inventory, monitoring, and segmentation controls, attackers can use it as a quiet foothold into clinical systems, identity services, and backup infrastructure. The result is a small unmanaged asset becoming a hospital-wide incident path.

Q: Why do connected medical devices increase lateral movement risk in hospitals?

A: They often sit on networks that connect to EHR, directory services, and other high-value systems, yet they lack EDR, strong logging, and routine patchability. That combination gives attackers a low-noise route to move from an exposed device into core clinical systems without immediate detection.

Q: How do security teams know whether medical device segmentation is working?

A: A good test is whether a compromised device can reach patient records, directory services, or backup systems without an explicit, monitored control point. If the answer is yes, segmentation is only administrative on paper. Effective segmentation limits the blast radius of a device compromise and makes lateral movement visible.

Q: Who is accountable when a medical device cyber issue affects patient safety?

A: Accountability sits with the manufacturer for ensuring cybersecurity does not compromise clinical performance, but healthcare operators also need ownership for deployment, monitoring, and maintenance. The practical question is not who caused the weakness alone, but who controls the patch path, the risk decision, and the response when patient harm becomes plausible.


Technical breakdown

Why medical device networks become invisible attack paths

Medical devices often cannot support endpoint agents, modern logging, or routine vulnerability tooling, which leaves security teams with partial inventory and weak behavioural telemetry. That creates a blind spot: devices may be present on the network, but they are not observable in the same way as servers or laptops. Attackers exploit that asymmetry by using the device network as a low-noise foothold, then moving into adjacent systems that do have business value. In practice, the problem is less about a single vulnerable device than about an unmanaged population that sits outside normal control loops.

Practical implication: build dedicated discovery and monitoring for OT and IoT assets before assuming your SIEM or EDR stack covers them.

Default credentials, legacy firmware, and unsafe management interfaces

The article highlights three recurring failure modes: unchanged manufacturer credentials, exploitable firmware flaws, and exposed management services on internal networks. Together they collapse the distance between reconnaissance and access. Because many devices are old, they may run unsupported operating systems and firmware that cannot be patched quickly, if at all. That means vulnerability management alone is not enough. The security model has to combine asset knowledge, exposure reduction, and containment controls that assume some devices will remain vulnerable for long periods.

Practical implication: identify devices that cannot be remediated quickly and place them behind tighter network boundaries and compensating controls.

How attackers pivot from medical devices to core clinical systems

Once a device is compromised, the attacker’s next step is usually lateral movement toward clinical workstations, directory services, EHR platforms, or backup infrastructure. That progression matters because the device itself may not hold the desired data, but it often sits on a network route to it. The article’s attack chain maps to established ICS and hospital intrusion patterns where the initial foothold is operational, but the impact is enterprise-wide. Without segmentation and anomaly detection on the device segment, the compromise can persist for weeks before discovery.

Practical implication: validate that the device VLAN cannot reach EHR, identity, or backup systems except through explicitly controlled paths.


Threat narrative

Attacker objective: The attacker aims to establish quiet persistence inside the hospital network and reach systems that support patient care, records access, or ransomware deployment.

  1. Entry begins with reconnaissance against internet-exposed or internally reachable medical devices, where attackers identify model types, firmware versions, and open services.
  2. Escalation occurs through default credentials, known firmware flaws, or exposed management interfaces, allowing the attacker to gain a foothold without triggering normal security tooling.
  3. Impact follows when the compromised device is used to pivot into clinical workstations, Active Directory, EHR systems, or backup infrastructure, extending a device issue into a hospital-wide incident.

NHI Mgmt Group analysis

Connected medical devices are now part of identity-adjacent governance, not just clinical engineering. Once a device can be used as a pivot point, it becomes a security-controlled asset even if it is not a person, workload, or conventional endpoint. That puts inventory accuracy, network trust boundaries, and lifecycle ownership into the same governance conversation as access review. Practitioners should treat unmanaged clinical devices as a governed population, not a separate exception set.

Default credentials and unmanaged firmware create a standing access problem, not a patching problem alone. The article shows that attackers benefit most when a device remains reachable and unchanged for years. That is the same governance failure pattern seen in NHI sprawl: credentials and access paths persist longer than the control plane can track them. The practical conclusion is that exposure reduction must be designed around persistent device risk, not just patch cadence.

Medical device segmentation is the hospital equivalent of blast-radius control. If a compromised infusion pump can reach EHR systems or backup infrastructure, the environment has already failed at containment. This is where NIST CSF and NIST SP 800-53 thinking matters most: the control objective is not perfect prevention, but enforced separation and monitored routes between high-risk device zones and critical systems. Practitioners should measure whether a device compromise can cross the first boundary at all.

Device telemetry gaps are a governance signal, not only an operational inconvenience. When assets cannot log, alert, or support standard scanning, security teams lose the evidence needed for detection and investigation. That means programme maturity must be judged by the quality of compensating controls, not by the fiction that all assets can be managed the same way. For healthcare security teams, the question is whether visibility exists where the risk actually lives.

Clinical OT security needs a named concept: unmanaged device pivot risk. This is the condition where a vulnerable medical device becomes the entry point into broader identity, data, and resilience failures. The term matters because it captures the real governance issue. The device is not the endpoint of the attack, it is the route. Practitioners should use that framing when setting scope for monitoring, segmentation, and penetration testing.

What this signals

Unmanaged clinical devices create the same governance problem as hidden non-human identities. If you cannot enumerate, classify, and constrain the asset, you cannot trust the access path it creates. For programmes that already struggle with shadow access and service account sprawl, the hospital device problem is a reminder that visibility is the first control, not the last.

Medical-device segmentation should be measured as blast-radius reduction, not network tidy-up. Healthcare teams need to know whether a compromised pump can reach identity, record, or backup systems, and they should test that boundary routinely. NIST SP 800-207 Zero Trust Architecture and the OWASP Non-Human Identity Top 10 both reinforce the same principle: trust must be explicit, not inherited from network location.

Device telemetry gaps will increasingly drive resilience decisions. Where logging, scanning, and patching are constrained by patient safety, security leaders need compensating controls, documented exceptions, and stronger ownership models. That is where programmes move from theoretical coverage to operational governance.


For practitioners

  • Map the medical device attack surface Inventory every connected clinical device, including firmware, network path, owner, and patchability, so exposure is visible before an incident exposes it for you.
  • Segment device traffic from identity and record systems Place infusion pumps, monitors, and other high-risk devices in tightly controlled network zones that cannot directly reach EHR, Active Directory, or backup infrastructure.
  • Test pivot paths, not just device exploits Include the device VLAN in penetration tests and validate whether a compromised device can reach higher-value systems through allowed routes or weak trust relationships.
  • Apply compensating controls where patching is not realistic Use access restrictions, anomaly monitoring, and compensating network controls for devices that cannot be patched quickly because of vendor limits or clinical safety constraints.

Key takeaways

  • Connected medical devices are no longer peripheral assets, because they can serve as the first step in a hospital-wide intrusion.
  • The evidence points to a large exposure problem, with thousands of devices, high vulnerability rates, and long-lived unsupported technology.
  • The most effective control is containment through visibility, segmentation, and tested pivot-path blocking, not reliance on patching alone.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

MITRE ATT&CK address the attack and risk surface, while NIST CSF 2.0 and NIST SP 800-53 Rev 5 set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
NIST CSF 2.0PR.AC-4Network access control and segmentation are central to containing risky device paths.
NIST SP 800-53 Rev 5AC-4Information flow enforcement fits the need to separate device zones from EHR and backup systems.
MITRE ATT&CKTA0006 , Credential Access; TA0008 , Lateral MovementDefault credentials and pivoting from devices align to credential access and lateral movement.

Map device compromise scenarios to TA0006 and TA0008 when testing containment and detection.


Key terms

  • Medical Device Attack Surface: The full set of connected clinical devices that can be discovered, reached, or abused on a hospital network. It includes infusion pumps, monitors, ventilators, and other assets that may not support standard security tooling but still create real exposure and lateral movement paths.
  • Pivot Path: A pivot path is a sequence of systems, services, or identities an attacker can traverse to reach a target. It is useful for security analysis because it makes blast radius measurable and shows where segmentation or privilege reduction will have the biggest effect.
  • Compensating Control: A compensating control is a measure that reduces risk when the ideal fix, such as immediate patching or redesign, is not possible. In OT, compensating controls often include session recording, access restriction, and tighter monitoring. They do not eliminate the underlying issue, but they narrow exposure until safer remediation can happen.

What's in the full article

Sprocket Security's full analysis covers the operational detail this post intentionally leaves for the source:

  • Device-network penetration testing methods that account for clinical safety constraints and realistic pivot paths
  • Attack surface monitoring approaches for OT and IoT assets with limited agent support
  • Examples of how hospitals can segment medical device VLANs without breaking care delivery
  • Practical guidance on validating whether an infected device can reach EHR or backup systems

👉 The full Sprocket Security post covers device compromise paths, containment strategy, and testing scope in more operational detail.

Deepen your knowledge

NHI Foundation Level course, the industry's only accredited NHI security programme, covers NHI governance, workload identity, and secrets management for practitioners who need stronger control over access paths and lifecycle risk. It helps security teams build the governance discipline needed to manage identities, credentials, and trust boundaries across modern programmes.
NHIMG Editorial Note
Published by the NHIMG editorial team on August 19, 2026.
NHI Mgmt Group — the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org