Medhacking
Umbrella term for hacking activity directed at medical devices, ranging from criminal attack to coordinated security research and patient-led modification.
Definition
Medhacking is an informal umbrella term for hacking activity directed at medical devices and clinical systems. It covers three overlapping populations: (1) malicious actors attacking devices to harm patients, extort hospitals, or pivot into healthcare networks (overlapping with medjacking); (2) security researchers performing coordinated vulnerability disclosure under programs aligned with the FDA-recognized ISO/IEC 29147 and 30111 standards; and (3) patient and DIY communities modifying their own devices for clinical benefit - most visibly the #WeAreNotWaiting movement that built open-source automated insulin delivery systems (OpenAPS, Loop, AndroidAPS) on top of commercial insulin pumps and CGMs. The term is not a regulatory category; it is a shorthand the press, conference circuit (DEF CON Biohacking Village), and patient communities use to describe the broader phenomenon of technical intervention into medical devices outside the manufacturer's intended pathway.What this means in practice
For manufacturers, the practical implication is to plan for all three populations: a hardened device, a published coordinated vulnerability disclosure policy and security.txt, an active relationship with the security research community (Biohacking Village, ICS-CERT, MDIC), and clear labeling and human-factors design that anticipate motivated patient modification - especially in chronic-disease devices like insulin pumps and CGMs.- •Treating all medhackers as adversaries and lacking a coordinated vulnerability disclosure channel.
- •Threatening security researchers with legal action instead of triaging their findings - a known reputational disaster in MedTech.
- •Ignoring patient-driven modification trends until they become a safety communication.
- •Conflating medhacking, medjacking, and brainjacking in internal risk documentation - regulators expect precise language.
Frequently asked questions
Related terms
Grouped by themeEditor's picks
· Hand-selected related conceptsUnauthorized remote control of an implanted neurostimulator (e.g., DBS) to alter stimulation parameters and harm a patient.
A documented process for receiving, triaging, and responsibly disclosing security vulnerabilities reported by external researchers.
Compromise of a networked medical device to use it as a foothold inside a hospital network or to manipulate clinical function.
The bundle of cybersecurity artifacts a sponsor includes in a 510(k), De Novo, PMA, or HDE submission for a cyber device.
More in Cybersecurity
· Same categoryThe federal statute that gives FDA explicit premarket authority over cybersecurity for cyber devices.
AAMI/ANSI standard establishing requirements for medical-device cybersecurity activities throughout the lifecycle.
AAMI Technical Information Report providing MedTech-specific guidance on cybersecurity risk management.
AAMI Technical Information Report on post-market security risk management for medical device manufacturers, the operational companion to TIR57.
Primary references
6 sources- 1
FDA Cybersecurity Guidance (Sept 2023)VerifiedFDAfda.gov
- 2
ISO/IEC 29147:2018 Vulnerability DisclosureVerifiedISO/IECiso.org
- 3
ISO/IEC 30111:2019 Vulnerability Handling ProcessesVerifiedISO/IECiso.org
- 4
DEF CON Biohacking Village Device LabVerifiedBiohacking Villagevillageb.io
- 5
FDA Safety Communication on Unauthorized Automated Insulin Dosing Systems (2019)VerifiedFDAfda.gov
- 6
HSCC Medical Device and Health IT Joint Security PlanVerifiedHSCChealthsectorcouncil.org
Inline markers like [1] jump to the matching reference above.