Legacy Device Cybersecurity
Cybersecurity considerations for medical devices that cannot be reasonably protected against current threats.
Definition
A legacy medical device is one that cannot be reasonably protected against current cybersecurity threats - typically because the underlying OS or platform is unsupported (e.g., Windows XP/7, embedded RTOS without update path), the device cannot accept patches, or the manufacturer has ended support. IMDRF/CYBER WG/N73 (2023) defines the term and frames a shared-responsibility model among manufacturers, healthcare delivery organizations (HDOs), and other stakeholders.What this means in practice
Legacy devices are ubiquitous in hospitals - imaging systems, infusion pumps, lab analyzers - and are repeatedly implicated in ransomware incidents. The right response is a documented end-of-life plan, transparent communication to operators, and a path to a supported replacement, not silent obsolescence.- •Letting devices age into legacy status without notifying operators or providing compensating-control guidance.
- •Assuming HDO network segmentation alone substitutes for manufacturer responsibility.
- •Continuing to sell new units of a device that can no longer be patched.
Frequently asked questions
Cross-references
See also
Closely related context worth reading.
Related terms
Grouped by themeEditor's picks
· Hand-selected related conceptsAn industry-developed reference framework from the Healthcare Sector Coordinating Council for end-to-end MedTech cybersecurity.
International harmonized guidance on medical-device cybersecurity from the IMDRF Cybersecurity Working Group.
The designed-in ability to deploy security updates to a fielded medical device in a timely, controlled, and verifiable manner.
More in Cybersecurity
· Same categoryAAMI/ANSI standard establishing requirements for medical-device cybersecurity activities throughout the lifecycle.
AAMI Technical Information Report providing MedTech-specific guidance on cybersecurity risk management.
AAMI Technical Information Report on post-market security risk management for medical device manufacturers, the operational companion to TIR57.
Unauthorized remote control of an implanted neurostimulator (e.g., DBS) to alter stimulation parameters and harm a patient.
Where this term appears across MedTech Terms.
Primary references
3 sources- 1
IMDRF/CYBER WG/N73 (2023)VerifiedIMDRFimdrf.org
- 2
FDA Cybersecurity Guidance (Sept 2023)VerifiedFDAfda.gov
- 3
HSCC - Health Sector Coordinating CouncilVerifiedHSCChealthsectorcouncil.org
Inline markers like [1] jump to the matching reference above.