TL;DR: Legacy medical devices remain a governance problem because they often outlive support periods, depend on older codebases, and can expose patient safety to security failures, according to Kusari. The practical lesson is that inventory, segmentation, vulnerability sharing, and continuity planning matter more than waiting for perfect patching.
NHIMG editorial — based on content published by Kusari: securing legacy medical devices in the field
By the numbers:
- The average ransomware incident requires 30 days to recover.
- Medical device regulations include section 524B of the Federal Food, Drug, and Cosmetic Act.
Questions worth separating out
Q: What breaks when legacy medical devices are not inventoried and segmented properly?
A: Without inventory and segmentation, security teams cannot identify where old devices sit, what they can reach, or how to contain a compromise.
Q: Why do legacy medical devices create a different risk model from ordinary IT assets?
A: Legacy medical devices can affect patient safety directly, remain in use long after vendor support ends, and may be difficult or impossible to patch.
Q: How do you know whether medical device security controls are actually working?
A: Look for a current inventory, verified network segmentation, documented end-of-life status, and tested fallback procedures.
Practitioner guidance
- Build a complete device inventory Record every medical device’s location, network dependencies, support status, and end-of-life date so containment decisions can be made before an incident forces emergency isolation.
- Segment legacy devices by clinical function Place older devices into restricted network zones and limit east-west connectivity so a compromise does not spread into EHR systems, imaging systems, or broader hospital infrastructure.
- Restrict removable media where it is unnecessary Apply policies that block USB mounting on devices that do not require external storage, because removable media often becomes a bypass path around network protections.
What's in the full article
Kusari's full article covers the operational detail this post intentionally leaves for the source:
- Manufacturer-side guidance on sharing newly discovered vulnerabilities with device owners and health delivery organisations
- Criteria for deciding when an end-of-life device still deserves exceptional patch support
- Trade-in incentive considerations for retiring unsupported medical devices from the field
- Practical examples of how inventory, segmentation, and information-sharing groups can be used together
👉 Read Kusari's analysis of legacy medical device security and lifecycle risk →
Legacy medical devices: what security teams need to do now?
Explore further
Legacy medical device security is a lifecycle governance problem, not a patching problem. The article shows that the hardest part is not identifying a vulnerability, but governing equipment that may remain in service long after support ends. That is a lifecycle issue shared with identity and access systems: unmanaged longevity creates unmanaged risk. Practitioners should treat end-of-life visibility as a security control, not an asset-management nicety.
A question worth separating out:
Q: Who is accountable when a medical device cyber issue affects patient safety?
A: Accountability sits with the manufacturer for ensuring cybersecurity does not compromise clinical performance, but healthcare operators also need ownership for deployment, monitoring, and maintenance. The practical question is not who caused the weakness alone, but who controls the patch path, the risk decision, and the response when patient harm becomes plausible.
👉 Read our full editorial: Legacy medical device security still depends on inventory and isolation