---
title: "Legacy Device Cybersecurity, Definition | MedTech Terms"
description: "Cybersecurity considerations for medical devices that cannot be reasonably protected against current threats. Plain-English Cybersecurity definition for MedTech"
lang: en
json-ld: |
  {
    "@context": "https://schema.org",
    "@graph": [
      {
        "@type": "DefinedTerm",
        "@id": "https://medtechterms.com/terms/legacy-device-cyber#term",
        "name": "Legacy Device Cybersecurity",
        "description": "A legacy medical device is one that cannot be reasonably protected against current cybersecurity threats - typically because the underlying OS or platform is unsupported (e.g., Windows XP/7, embedded RTOS without update path), the device cannot accept patches, or the manufacturer has ended support. IMDRF/CYBER WG/N73 (2023) defines the term and frames a shared-responsibility model among manufacturers, healthcare delivery organizations (HDOs), and other stakeholders.",
        "url": "https://medtechterms.com/terms/legacy-device-cyber",
        "termCode": "legacy-device-cyber",
        "inDefinedTermSet": {
          "@type": "DefinedTermSet",
          "name": "MedTech Terms",
          "url": "https://medtechterms.com/terms"
        }
      },
      {
        "@type": "Article",
        "@id": "https://medtechterms.com/terms/legacy-device-cyber#article",
        "headline": "Legacy Device Cybersecurity",
        "description": "Cybersecurity considerations for medical devices that cannot be reasonably protected against current threats.",
        "url": "https://medtechterms.com/terms/legacy-device-cyber",
        "mainEntityOfPage": {
          "@type": "WebPage",
          "@id": "https://medtechterms.com/terms/legacy-device-cyber"
        },
        "about": {
          "@id": "https://medtechterms.com/terms/legacy-device-cyber#term"
        },
        "articleSection": "Cybersecurity",
        "inLanguage": "en",
        "keywords": "Legacy Device Cybersecurity, Cybersecurity, medical device, MedTech",
        "author": {
          "@type": "Person",
          "name": "Christian Espinosa",
          "jobTitle": "Founder, Blue Goat Cyber",
          "url": "https://bluegoatcyber.com"
        },
        "publisher": {
          "@type": "Organization",
          "name": "MedTech Terms",
          "url": "https://medtechterms.com"
        },
        "isPartOf": {
          "@type": "WebSite",
          "name": "MedTech Terms",
          "url": "https://medtechterms.com"
        },
        "datePublished": "2026-05-05",
        "dateModified": "2026-05-05",
        "citation": [
          {
            "@type": "CreativeWork",
            "name": "IMDRF/CYBER WG/N73 (2023)",
            "url": "https://www.imdrf.org/documents/principles-and-practices-cybersecurity-legacy-medical-devices",
            "publisher": {
              "@type": "Organization",
              "name": "IMDRF"
            }
          },
          {
            "@type": "CreativeWork",
            "name": "FDA Cybersecurity Guidance (Sept 2023)",
            "url": "https://www.fda.gov/regulatory-information/search-fda-guidance-documents/cybersecurity-medical-devices-quality-system-considerations-and-content-premarket-submissions",
            "publisher": {
              "@type": "Organization",
              "name": "FDA"
            }
          },
          {
            "@type": "CreativeWork",
            "name": "HSCC - Health Sector Coordinating Council",
            "url": "https://healthsectorcouncil.org/",
            "publisher": {
              "@type": "Organization",
              "name": "HSCC"
            }
          }
        ],
        "mentions": [
          {
            "@type": "DefinedTerm",
            "@id": "https://medtechterms.com/terms/imdrf-cyber-principles#term",
            "name": "IMDRF Principles and Practices for Medical Device Cybersecurity",
            "url": "https://medtechterms.com/terms/imdrf-cyber-principles"
          },
          {
            "@type": "DefinedTerm",
            "@id": "https://medtechterms.com/terms/patchability#term",
            "name": "Patchability",
            "url": "https://medtechterms.com/terms/patchability"
          },
          {
            "@type": "DefinedTerm",
            "@id": "https://medtechterms.com/terms/hscc-jsp#term",
            "name": "HSCC Joint Security Plan",
            "alternateName": "HSCC JSP",
            "url": "https://medtechterms.com/terms/hscc-jsp"
          }
        ]
      },
      {
        "@type": "BreadcrumbList",
        "itemListElement": [
          {
            "@type": "ListItem",
            "position": 1,
            "name": "Home",
            "item": "https://medtechterms.com/"
          },
          {
            "@type": "ListItem",
            "position": 2,
            "name": "Terms",
            "item": "https://medtechterms.com/terms"
          },
          {
            "@type": "ListItem",
            "position": 3,
            "name": "Cybersecurity",
            "item": "https://medtechterms.com/terms?cat=Cybersecurity"
          },
          {
            "@type": "ListItem",
            "position": 4,
            "name": "Legacy Device Cybersecurity",
            "item": "https://medtechterms.com/terms/legacy-device-cyber"
          }
        ]
      },
      {
        "@type": "FAQPage",
        "@id": "https://medtechterms.com/terms/legacy-device-cyber#faq",
        "mainEntity": [
          {
            "@type": "Question",
            "name": "When does a device become 'legacy'?",
            "acceptedAnswer": {
              "@type": "Answer",
              "text": "Per IMDRF N73, when it can no longer be reasonably protected against current threats - typically tied to the end of OS/platform support. The manufacturer should declare and communicate the date."
            }
          },
          {
            "@type": "Question",
            "name": "Can we keep selling a legacy device?",
            "acceptedAnswer": {
              "@type": "Answer",
              "text": "FDA expects manufacturers to act in the interest of patient safety. Continuing to ship new units of an unpatchable device invites enforcement and reputational risk; most manufacturers transition to a successor product instead."
            }
          },
          {
            "@type": "Question",
            "name": "What's the HDO's responsibility?",
            "acceptedAnswer": {
              "@type": "Answer",
              "text": "Per IMDRF N73 and HSCC guidance, HDOs apply compensating controls (segmentation, monitoring, restricted access) and prioritize replacement. Manufacturers must enable that work with clear communication and configuration guidance."
            }
          }
        ]
      }
    ]
  }
---

[

MedTech Terms

The authoritative reference



](/)

Browse

Learn

[Latest](/latest)

About

1.  [Home](/)
2.  /
3.  [Terms](/terms)
4.  /
5.  [Cybersecurity](/terms?cat=Cybersecurity)
6.  /
7.  Legacy Device Cybersecurity

[All terms](/terms)

Cybersecurity [Connected & Cyber-Physical Devices](/ecosystems/connected-devices)

# Legacy Device Cybersecurity

Cybersecurity considerations for medical devices that cannot be reasonably protected against current threats.

Reviewed by [Christian Espinosa, Founder, Blue Goat Cyber](/authors/christian-espinosa) Last reviewed May 5, 2026 

## Definition

A legacy medical device is one that cannot be reasonably protected against current cybersecurity threats - typically because the underlying OS or platform is unsupported (e.g., Windows XP/7, embedded RTOS without update path), the device cannot accept patches, or the manufacturer has ended support.  [IMDRF](/terms/imdrf)/CYBER WG/N73 (2023) defines the term and frames a shared-responsibility model among manufacturers, healthcare delivery organizations (HDOs), and other stakeholders. 

What the regulation says

FDA's 2023 guidance and  [IMDRF](/terms/imdrf) N73 both expect manufacturers to publish end-of-support timelines and to communicate clearly to operators when a device transitions to legacy status. HDOs are expected to apply compensating controls (network segmentation, monitoring) for legacy devices that remain in clinical use. 

## What this means in practice

Legacy devices are ubiquitous in hospitals - imaging systems, infusion pumps, lab analyzers - and are repeatedly implicated in ransomware incidents. The right response is a documented end-of-life plan, transparent communication to operators, and a path to a supported replacement, not silent obsolescence. 

Common pitfalls

-   • Letting devices age into legacy status without notifying operators or providing compensating-control guidance. 
-   • Assuming HDO network segmentation alone substitutes for manufacturer responsibility. 
-   • Continuing to sell new units of a device that can no longer be patched. 

## Frequently asked questions

When does a device become 'legacy'? 

Per  [IMDRF](/terms/imdrf) N73, when it can no longer be reasonably protected against current threats - typically tied to the end of OS/platform support. The manufacturer should declare and communicate the date. 

Can we keep selling a legacy device? 

What's the HDO's responsibility? 

## Cross-references

### See also

Closely related context worth reading.

-   [
    
    Patchability
    
    
    
    ](/terms/patchability)

## Related terms

Grouped by theme 

### Editor's picks

· Hand-selected related concepts 

[

Cybersecurity

HSCC Joint Security Plan(HSCC JSP) 

An industry-developed reference framework from the Healthcare Sector Coordinating Council for end-to-end MedTech cybersecurity.





](/terms/hscc-jsp)[

Cybersecurity

IMDRF Principles and Practices for Medical Device Cybersecurity

International harmonized guidance on medical-device cybersecurity from the IMDRF Cybersecurity Working Group.





](/terms/imdrf-cyber-principles)[

Cybersecurity

Patchability

The designed-in ability to deploy security updates to a fielded medical device in a timely, controlled, and verifiable manner.





](/terms/patchability)

### More in Cybersecurity

· Same category 

[

Cybersecurity

AAMI SW96

AAMI/ANSI standard establishing requirements for medical-device cybersecurity activities throughout the lifecycle.





](/terms/aami-sw96)[

Cybersecurity

AAMI TIR57

AAMI Technical Information Report providing MedTech-specific guidance on cybersecurity risk management.





](/terms/aami-tir57)[

Cybersecurity

AAMI TIR97(TIR97) 

AAMI Technical Information Report on post-market security risk management for medical device manufacturers, the operational companion to TIR57.





](/terms/aami-tir97)[

Cybersecurity

Brainjacking

Unauthorized remote control of an implanted neurostimulator (e.g., DBS) to alter stimulation parameters and harm a patient.





](/terms/brainjacking)

Cited by

Where this term appears across MedTech Terms.

Ecosystems (1)

-   [Connected & Cyber-Physical Devices](/ecosystems/connected-devices)

## Primary references

3 sources 

Link health:  3 verified · last checked 2026-06-20 

IMDRF· 1 FDA· 1 HSCC· 1 

1.  [1 
    
    IMDRF/CYBER WG/N73 (2023)
    
    Verified 
    
    IMDRF · imdrf.org 
    
    
    
    ](https://www.imdrf.org/documents/principles-and-practices-cybersecurity-legacy-medical-devices)
2.  [2 
    
    FDA Cybersecurity Guidance (Sept 2023)
    
    Verified 
    
    FDA · fda.gov 
    
    
    
    ](https://www.fda.gov/regulatory-information/search-fda-guidance-documents/cybersecurity-medical-devices-quality-system-considerations-and-content-premarket-submissions)
3.  [3 
    
    HSCC - Health Sector Coordinating Council
    
    Verified 
    
    HSCC · healthsectorcouncil.org 
    
    
    
    ](https://healthsectorcouncil.org/)

Inline markers like \[1\]  jump to the matching reference above.

Sponsor note

### Working on medical device cybersecurity?

Blue Goat Cyber specializes in MedTech cybersecurity - threat modeling, SBOMs, penetration testing, and FDA premarket submissions.

[Book a 30-minute discovery session](https://go.bluegoatcyber.com/meetings/blue-goat-cyber/discovery-session)

-   No obligation
-   Expert-led from minute one
-   NDA available on request

MedTech Terms is a community resource sponsored by [Blue Goat Cyber](https://bluegoatcyber.com). Definitions are independent of any vendor.

On this term

Category

Cybersecurity

Sources

3

Updated

5/5/2026

[Compare with another term](/compare?a=legacy-device-cyber)

Learn in 60 seconds

Card Lesson Quiz

Cybersecurity considerations for medical devices that cannot be reasonably protected against current threats.

-   · Legacy devices are ubiquitous in hospitals - imaging systems, infusion pumps, lab analyzers - and are repeatedly implicated in ransomware incidents. 
-   · The right response is a documented end-of-life plan, transparent communication to operators, and a path to a supported replacement, not silent obsolescence. 
-   · IMDRF/CYBER WG/N73 (2023) defines the term and frames a shared-responsibility model among manufacturers, healthcare delivery organizations (HDOs), and other stakeholders. 

Remember this

Watch out: Letting devices age into legacy status without notifying operators or providing compensating-control guidance.

Related terms

-   [IMDRF Principles and Practices for Medical Device Cybersecurity ](/terms/imdrf-cyber-principles)
-   [Patchability ](/terms/patchability)
-   [HSCC Joint Security Plan(HSCC JSP) ](/terms/hscc-jsp)

You may also need

Auto-suggested from Cybersecurity and shared keywords.

-   [IEC 80001-1 ](/terms/iec-80001)
-   [Hardware Root of Trust(HRoT) ](/terms/hardware-root-of-trust)
-   [Health Industry Cybersecurity Practices(HICP) ](/terms/hicp)
-   [Healthcare and Public Health Cybersecurity Performance Goals(HPH-CPG) ](/terms/hph-cpg)
-   [Manufacturer Disclosure Statement for Medical Device Security(MDS2) ](/terms/mds2)
-   [NIST Cybersecurity Framework(NIST CSF) ](/terms/nist-csf)

[All Cybersecurity terms](/terms?cat=Cybersecurity)

From the Blue Goat network

Related resources and services on this topic.

-   [
    
    MedTech Cybersecurity Standards 
    
    Authoritative reference for the standards and guidances behind medical device cybersecurity.
    
    ](https://medtechcyberstandards.com)
-   [
    
    MedTech Cyber Tips 
    
    Practical, organized tips for medical device cybersecurity teams.
    
    ](https://medtechcybertips.com)
-   [
    
    MedTech Cybersecurity Crosswalk 
    
    International crosswalk of medical device cybersecurity requirements across regulators.
    
    ](https://mdccrosswalk.com)
-   [
    
    Code Blue 
    
    Real medical device cybersecurity incidents and their lessons.
    
    ](https://codebluechart.com)

MedTech Terms 

An authoritative, plain-language reference for the regulatory, quality, cybersecurity, and software terms that shape modern medical devices.

Browse

-   [All terms](/terms)
-   [A–Z index](/a-z)
-   [Categories](/categories)
-   [Ecosystems](/ecosystems)
-   [Learning paths](/paths)
-   [Compare terms](/compare)
-   [Quiz](/quiz)

Resources

-   [FDA Medical Devices](https://www.fda.gov/medical-devices)
-   [EU MDR](https://eur-lex.europa.eu/eli/reg/2017/745/oj)
-   [IMDRF](https://www.imdrf.org/)
-   [Methodology](/methodology)
-   [Changelog](/changelog)
-   [Editor: Christian Espinosa](/authors/christian-espinosa)
-   [About this site](/about)

© 2026 MedTech Terms. Reference content for educational purposes - not regulatory advice. A community resource sponsored by [Blue Goat Cyber](https://bluegoatcyber.com)