Why Medical Devices are the New OT Security Battleground
In a 700-bed regional medical center, the security team ran a network discovery exercise to understand what was actually connected to their environment. They expected to find the usual mix: workstations, servers, printers, mobile devices. What they found was closer to 10,000 connected endpoints, roughly three times what their asset inventory showed.
The difference was medical devices. Infusion pumps. Patient monitors. Imaging systems. Ventilators. Nurse call systems. Connected diagnostic equipment from a dozen different vendors, running firmware that had not been updated in years, sitting on the same network segment as general IT infrastructure.
This is not an unusual finding. It is the norm in modern healthcare, and it represents one of the most complex and under-appreciated security challenges in the industry.
Related Read: Why Operators Don't Trust Your OT Asset Inventory and How to Fix It in 30 Days
What makes clinical OT different
Operational technology (OT) security, originally a concern for industrial environments like power grids and manufacturing facilities, has arrived in healthcare in the form of connected medical devices, often called the Internet of Medical Things (IoMT). The security challenges are structurally similar to industrial OT, with one critical difference: the assets in question are directly connected to patient care. (We explained why OT environments can't simply be secured like IT in The Path to OT Resiliency: Why OT Cannot Mirror IT and What to Do Instead.)
That distinction changes the risk calculus entirely. You cannot patch an infusion pump mid-infusion. You cannot take an ICU ventilator offline for a firmware update without a clinical plan. Many devices run on operating systems so old that the vendor no longer releases patches at all. Windows 7, Windows XP, and even older systems power devices that are still in active clinical use because the cost and disruption of replacement is prohibitive.
The result is a growing inventory of network-connected devices that cannot be updated, cannot be easily monitored, and cannot be taken offline for remediation on a security team's timeline. Attackers have noticed.
Related Read: The 4 Reasons Cyber and Safety Collide in OT — including why aggressive scanning can crash fragile legacy devices.
The threat is not theoretical
The FDA has issued multiple advisories on medical device cybersecurity vulnerabilities, including flaws in infusion pump communication protocols and patient monitoring systems that could allow unauthorized remote access. In 2022, the Cybersecurity and Infrastructure Security Agency (CISA) published an advisory on vulnerabilities affecting widely-deployed medical devices — specifically noting that exploitation could allow attackers to alter device function or access sensitive data. And healthcare's exposure is now being named at the highest levels: we covered why hospitals were singled out alongside water utilities in Called Out: Utilities and Healthcare Named in Critical Infrastructure AI Attack Warning.
The concern is not abstract. A compromised infusion pump, a manipulated patient monitor, or a ransomware-encrypted imaging system during a trauma case represents a patient safety incident, not just a security incident. Healthcare organizations that treat clinical OT as a pure IT problem — to be addressed on IT timelines and with IT tools — are misunderstanding the risk.
Related Read: 72 Hours to Recover: Why Cyber Resilience Is Becoming a HIPAA Requirement
Why segmentation is the most important control
When most security controls are unavailable, think no patch, no agent, no modern authentication, network segmentation becomes the primary defense. Isolating medical devices into dedicated, monitored network segments limits the blast radius of a breach. If ransomware enters through a general workstation, segmentation prevents it from reaching the imaging system. If a vulnerable infusion pump is exploited, segmentation prevents lateral movement to the EHR. That IT-to-OT pivot is the first path we break down in The Five Most Common Attack Paths in Operational Technology and How to Prevent Them.
We believe forthcoming HIPAA updates will make network segmentation mandatory. For healthcare organizations with substantial IoMT footprints, this is not a simple firewall change. Tt requires understanding what devices exist, what they communicate with, and what traffic patterns are normal versus anomalous. That requires discovery, mapping, and ongoing monitoring.
Related Read: Exposing Invisible Links: The 6 IT-OT Bridges That Could Compromise Your Operations
Microsoft Defender for IoT extends visibility into unmanaged and legacy devices, providing passive network monitoring without requiring agents on devices that cannot support them. For healthcare organizations already in the Microsoft ecosystem, this is often the most practical path to IoMT visibility. Many of those organizations already own more of the stack than they use, a point we make in Stop Paying for Security Twice: Operationalizing the Microsoft Security Stack for Modern SOC, MDR, and Zero Trust.
The vendor patch problem
One of the most frustrating aspects of clinical OT security is vendor dependency. A hospital cannot patch a medical device without the manufacturer's involvement — and manufacturer response times on security vulnerabilities vary widely. Some vendors are responsive. Others take months or longer to release patches, leaving organizations aware of a vulnerability they cannot remediate unilaterally. As we put it in Vendor Risk Is Your Risk, a vendor's gap quickly becomes your exposure.
The practical response is layered: compensating controls around the device, active monitoring for anomalous behavior, and formal vendor management processes that include security patch timelines in procurement decisions going forward. The same discipline applies to the remote support connections many device manufacturers maintain into hospital networks. It is not a perfect answer, but it is the realistic one.
Related Read: Killing Always-On Vendor Access: A Key to Secure Remote OT
A different kind of expertise
Bridging healthcare operations, clinical OT, and cybersecurity requires a different combination of expertise than traditional enterprise security. Most cybersecurity firms are not equipped to navigate the clinical implications of a network change that affects patient monitoring systems. (That's why disciplined change control matters so much in these environments; see Why OT Change Management Is Your Most Important Cyber Control.) Healthcare IT teams are not typically equipped to think through threat modeling for embedded device firmware.
This is a gap that matters as the likely HIPAA Security changes push organizations toward more explicit technical controls across all systems that process ePHI, and medical devices are squarely in that scope.
Our HIPAA 2026 Regulation Update guide covers the technical safeguard requirements that apply to all ePHI-touching systems, including the network segmentation and asset inventory requirements most relevant to clinical OT environments.
Find the content useful? Subscribe to The Catch,our exclusive weekly LinkedIn newsletterfocused on real-life experiences doing cyber right in the most highly regulated industries.


