MedTech Terms
    The authoritative reference
    Glossary

    All MedTech Terms

    380 sourced definitions covering the regulatory, quality, software, and cybersecurity vocabulary of modern medical devices.

    Showing 1–24 of 39

    Cybersecurity

    AAMI SW96

    aka Standard for medical device security

    AAMI/ANSI standard establishing requirements for medical-device cybersecurity activities throughout the lifecycle.

    Cybersecurity

    AAMI TIR57

    aka Principles for Medical Device Security - Risk Management

    AAMI Technical Information Report providing MedTech-specific guidance on cybersecurity risk management.

    Cybersecurity

    Common Vulnerabilities and Exposures(CVE)

    A globally unique identifier for a publicly disclosed cybersecurity vulnerability.

    Cybersecurity

    Common Vulnerability Scoring System(CVSS)

    An industry-standard 0–10 score that quantifies the severity of a software vulnerability.

    Cybersecurity

    Coordinated Vulnerability Disclosure(CVD)

    A documented process for receiving, triaging, and responsibly disclosing security vulnerabilities reported by external researchers.

    Cybersecurity

    Cryptographic Agility

    The designed-in ability to replace cryptographic primitives over a device's supported lifetime.

    Cybersecurity

    CycloneDX

    A lightweight, OWASP-maintained SBOM format designed for application security and supply-chain use cases.

    Cybersecurity

    De-Identification of Health Data

    The HIPAA-defined process of removing identifiers from PHI so the resulting data is no longer subject to the Privacy Rule.

    Cybersecurity

    Hardcoded Credentials

    Secrets - passwords, API keys, certificates - embedded in firmware or source code shipped on every device.

    Cybersecurity

    HIPAA(HIPAA)

    aka Health Insurance Portability and Accountability Act

    U.S. federal law governing the privacy and security of protected health information.

    Cybersecurity

    HITECH Act(HITECH)

    U.S. law that strengthened HIPAA enforcement and introduced breach-notification requirements.

    Cybersecurity

    HSCC Joint Security Plan(HSCC JSP)

    An industry-developed reference framework from the Healthcare Sector Coordinating Council for end-to-end MedTech cybersecurity.

    Cybersecurity

    IEC 80001-1

    aka Application of risk management for IT-networks incorporating medical devices

    International standard for risk management of IT networks that incorporate medical devices.

    Cybersecurity

    IEC 81001-5-1

    aka Health software security activities

    International standard defining secure-product-lifecycle activities for health software, including medical devices.

    Cybersecurity

    IMDRF Principles and Practices for Medical Device Cybersecurity

    aka IMDRF/CYBER WG/N60

    International harmonized guidance on medical-device cybersecurity from the IMDRF Cybersecurity Working Group.

    Cybersecurity

    ISO/IEC 27001(ISO 27001)

    International standard for information security management systems (ISMS), often required of MedTech vendors by enterprise customers.

    Cybersecurity

    Legacy Device Cybersecurity

    Cybersecurity considerations for medical devices that cannot be reasonably protected against current threats.

    Cybersecurity

    Manufacturer Disclosure Statement for Medical Device Security(MDS2)

    A standardized form by which device manufacturers disclose security characteristics to healthcare delivery organizations.

    Cybersecurity

    NIST Cybersecurity Framework(NIST CSF)

    A risk-based framework of cybersecurity functions and outcomes published by NIST and widely used to organize MedTech security programs.

    Cybersecurity

    NIST SP 800-53 / 800-171(NIST 800-53/171)

    Federal control catalogs (800-53) and CUI-handling requirements (800-171) often referenced in MedTech contracts.

    Cybersecurity

    Over-the-Air Updates(OTA)

    Remote, network-delivered software or firmware updates to a fielded medical device.

    Cybersecurity

    OWASP IoT and Embedded Application Security

    OWASP project resources for securing IoT, embedded, and connected medical devices.

    Cybersecurity

    Patchability

    The designed-in ability to deploy security updates to a fielded medical device in a timely, controlled, and verifiable manner.

    Cybersecurity

    Penetration Testing

    aka Pen test · Pentest

    Hands-on adversarial testing in which qualified independent testers attempt to exploit a device's security controls.