Over-the-Air Updates
Remote, network-delivered software or firmware updates to a fielded medical device.
Definition
Over-the-Air (OTA) updates are software or firmware updates delivered to a fielded medical device over a network - Wi-Fi, cellular, or hospital-managed channel - rather than via local USB, service visit, or operator manual upgrade. A robust OTA system includes cryptographic signing of update packages, integrity verification on the device, secure boot validation, A/B (or dual-bank) partitioning to support rollback, audit logging, and version reporting back to the manufacturer.What this means in practice
OTA is the operational backbone of patchability. Most MedTech failures in this area are not in the cryptographic primitives but in the operational details - handling power loss mid-update, recovering from a corrupted partition, communicating status to clinicians, and giving hospitals control over the maintenance window.- •No rollback path - a single bad update bricks the fleet.
- •Updates that require clinical downtime without a hospital-controlled maintenance window.
- •Skipping signature verification 'because we control the update server' - trust the signature, not the server.
Frequently asked questions
Related terms
Grouped by themeEditor's picks
· Hand-selected related conceptsThe designed-in ability to deploy security updates to a fielded medical device in a timely, controlled, and verifiable manner.
The bundle of cybersecurity artifacts a sponsor includes in a 510(k), De Novo, PMA, or HDE submission for a cyber device.
The federal statute that gives FDA explicit premarket authority over cybersecurity for cyber devices.
A chain-of-trust mechanism that ensures only cryptographically signed firmware and software can run on a device.
More in Cybersecurity
· Same categoryAAMI/ANSI standard establishing requirements for medical-device cybersecurity activities throughout the lifecycle.
AAMI Technical Information Report providing MedTech-specific guidance on cybersecurity risk management.
AAMI Technical Information Report on post-market security risk management for medical device manufacturers, the operational companion to TIR57.
Unauthorized remote control of an implanted neurostimulator (e.g., DBS) to alter stimulation parameters and harm a patient.
Primary references
3 sources- 1
FDA Cybersecurity Guidance (Sept 2023)VerifiedFDAfda.gov
- 2
NIST SP 800-193 Platform Firmware Resiliency GuidelinesVerifiedNISTcsrc.nist.gov
- 3
MDCG Cybersecurity GuidanceVerifiedMDCGhealth.ec.europa.eu
Inline markers like [1] jump to the matching reference above.