Executive summary
What this whitepaper covers
Secure communication between medical devices and health information systems is now a regulatory expectation — but in practice, adoption of secure standards like HL7, DICOM, and ASTM remains inconsistent. This whitepaper explains the disconnect between regulatory guidance and real-world deployment, showing how infrastructure limitations, legacy systems, and divided regulatory responsibilities contribute to insecure implementations. Drawing on real examples and audits, it identifies systemic barriers to secure connectivity and provides actionable recommendations for device manufacturers, healthcare organizations, and regulators to bridge the gap.
Why it matters
The regulatory and product context
The FDA requires manufacturers to support secure connectivity as part of device cybersecurity, yet most hospitals operate on infrastructures that can’t, or don’t, enforce it. While device manufacturers fall under FDA oversight, healthcare delivery organizations (HDOs) are governed by HIPAA, creating a regulatory blind spot where secure system integration is no one’s responsibility. This paper outlines how that gap undermines both patient safety and compliance, and what all parties can do to drive progress toward true system-level security and interoperability.
Key insights
What you’ll take away
- Device-side secure protocol support does not guarantee secure deployment.
- Regulatory oversight gaps between FDA and HIPAA create systemic weaknesses.
- Most hospitals still operate on outdated HL7/DICOM configurations due to complexity and cost.
- Real-world breaches demonstrate that lack of interoperability coordination leads to real patient-care disruption.
- Cross-industry collaboration and secure-by-default configurations are essential to closing the gap.
Who should read this
- Medical Device Manufacturers (MDMs): regulatory, engineering, and product security teams demonstrating secure interoperability in FDA submissions.
- Healthcare Delivery Organizations (HDOs): IT, clinical engineering, and security teams maintaining HIS/LIS/PACS/RIS infrastructures.
- Regulators and Policymakers: professionals working across FDA, OCR, or international equivalents on coordinated oversight.
- System Integrators and Vendors: interoperability specialists and network engineers designing mixed legacy-modern healthcare environments.

