Перейти к содержимому

Mind the Gap: The Biggest Threat in MedTech Cybersecurity That No One Is Talking About

MedTech Leading Voice - Webinars

0:00 / 0:00

Mind the Gap: The Biggest Threat in MedTech Cybersecurity That No One Is Talking About

17 просмотров · 10 дней назад
MedTech Leading Voice - Webinars
266 подписчиков
17 просмотров · 10 дней назад
Nobody on the call argued that advisories should not be sent. The argument was about confirmation. When Michelle Jump asked attendees when they had last confirmed that a security advisory they sent actually reached the hospitals that own the device, half of those it applied to could not say they ever had. Of 10 respondents who send advisories, 3 had never been able to confirm delivery and 2 do not send advisories directly. That is the gap in one number. Manufacturers have spent a decade getting better at producing security information, and almost no time making sure it arrives, so what hospitals receive is what they happen to find: a portal visit, an email that survived the corporate firewall, or a public site someone remembers to check. Michelle calls it the great big Easter egg hunt, and this session is about closing it. In this Friday In-Focus session, Michelle Jump (Chief Executive Officer of MedSec), Matthew Hazelett (COO and CQO at MedSec) and Debra Bruemmer (Senior Director, Clinical Security at MedSec) break down the distance between what device manufacturers know about their security posture and what the hospitals running their devices can actually see, then walk through Bridge, the platform MedSec built to close it, shown publicly for the first time. What you'll learn: • Why the gap is confirmation and not awareness, and the poll number that proves it • Why a manufacturer portal serving thousands of customers measured about 100 users a month • What the Easter egg hunt costs hospitals: duplicate scanning, false positives, and re-asking questions the manufacturer closed six months ago • What the MDS2 form discloses, why hospitals want it before procurement rather than after, and who owns it today • How a hospital's healthcare technology management team decides whether an advisory applies to them, on a device list nobody can fully trust • What FDA has been tightening since 2014, what the 524B requirements changed in 2023, and why the post-market guidance is still being rewritten • Why recall-level traceability is the only thing today that proves a communication or a patch reached the field • The iceberg below the waterline: devices past end of support that can no longer be patched and are still in use, and who owns the risk they carry • What Bridge does differently, push instead of pull, hospitals at no cost, and a record that the information arrived Speakers: • Michelle Jump - Chief Executive Officer, MedSec • Matthew Hazelett - COO and CQO, MedSec • Debra Bruemmer - Senior Director, Clinical Security, MedSec (Replay + chapters below) 00:00 - Welcome and introductions 00:04 - Why this gap runs under every cyber headline 01:04 - The Easter egg hunt: why posting to your portal is not delivery 03:00 - The channels manufacturers use today, and where each one breaks 05:53 - What the gap costs hospitals: duplicate scanning, false positives, repeat questions 07:49 - Poll: when did you last confirm your advisory reached the hospital that owns the device? 09:36 - Why this is a QMSR and post-market problem, not only a security problem 11:03 - What a portal actually delivers: 100 users a month against thousands of customers 13:01 - What the MDS2 form is, and why hospitals want it before procurement 13:43 - Debra Bruemmer on 24 years at Mayo Clinic and the view from the hospital side 14:39 - Inside the hospital: the healthcare technology management team 18:28 - Poll: could you list every hospital that owns your highest-volume product? 19:54 - You have a customer list. The question is how accurate it is 22:41 - What hospitals want: one view instead of 150 portals 26:49 - Matthew Hazelett on 524B and what FDA expects after the device ships 28:42 - Why only recall-level traceability proves your communication arrived 30:28 - A decade of tightening expectations, and the post-market guidance still to come 32:40 - Poll: how many of your in-field devices have an established end-of-support date? 34:06 - The iceberg: devices that can no longer be patched but are still in use 36:12 - What this looks like when the loop is closed 38:11 - Bridge: push instead of pull, with receipts on both sides 41:02 - One dashboard for hospitals and manufacturers 42:57 - Poll: what matters most when there is only one place to look? 43:58 - Onboarding: hospitals join at no cost, manufacturers start with their most mature lines 46:35 - Q&A: the machines nobody can find 50:43 - Who owns the risk when a device is past end of life? 52:37 - How many manufacturers and hospitals are on Bridge today? 54:29 - Close