Mind the Gap: The Biggest Threat in MedTech Cybersecurity That No One Is Talking About
MedTech Leading Voice - Webinars
0:00 / 0:00
Mind the Gap: The Biggest Threat in MedTech Cybersecurity That No One Is Talking About
17 просмотров · 10 дней назад
MedTech Leading Voice - Webinars
266 подписчиков
17 просмотров · 10 дней назад
Nobody on the call argued that advisories should not be sent. The argument was about confirmation. When Michelle Jump asked attendees when they had last confirmed that a security advisory they sent actually reached the hospitals that own the device, half of those it applied to could not say they ever had. Of 10 respondents who send advisories, 3 had never been able to confirm delivery and 2 do not send advisories directly. That is the gap in one number. Manufacturers have spent a decade getting better at producing security information, and almost no time making sure it arrives, so what hospitals receive is what they happen to find: a portal visit, an email that survived the corporate firewall, or a public site someone remembers to check. Michelle calls it the great big Easter egg hunt, and this session is about closing it.
In this Friday In-Focus session, Michelle Jump (Chief Executive Officer of MedSec), Matthew Hazelett (COO and CQO at MedSec) and Debra Bruemmer (Senior Director, Clinical Security at MedSec) break down the distance between what device manufacturers know about their security posture and what the hospitals running their devices can actually see, then walk through Bridge, the platform MedSec built to close it, shown publicly for the first time.
What you'll learn:
• Why the gap is confirmation and not awareness, and the poll number that proves it
• Why a manufacturer portal serving thousands of customers measured about 100 users a month
• What the Easter egg hunt costs hospitals: duplicate scanning, false positives, and re-asking questions the manufacturer closed six months ago
• What the MDS2 form discloses, why hospitals want it before procurement rather than after, and who owns it today
• How a hospital's healthcare technology management team decides whether an advisory applies to them, on a device list nobody can fully trust
• What FDA has been tightening since 2014, what the 524B requirements changed in 2023, and why the post-market guidance is still being rewritten
• Why recall-level traceability is the only thing today that proves a communication or a patch reached the field
• The iceberg below the waterline: devices past end of support that can no longer be patched and are still in use, and who owns the risk they carry
• What Bridge does differently, push instead of pull, hospitals at no cost, and a record that the information arrived
Speakers:
• Michelle Jump - Chief Executive Officer, MedSec
• Matthew Hazelett - COO and CQO, MedSec
• Debra Bruemmer - Senior Director, Clinical Security, MedSec
(Replay + chapters below)
00:00 - Welcome and introductions
00:04 - Why this gap runs under every cyber headline
01:04 - The Easter egg hunt: why posting to your portal is not delivery
03:00 - The channels manufacturers use today, and where each one breaks
05:53 - What the gap costs hospitals: duplicate scanning, false positives, repeat questions
07:49 - Poll: when did you last confirm your advisory reached the hospital that owns the device?
09:36 - Why this is a QMSR and post-market problem, not only a security problem
11:03 - What a portal actually delivers: 100 users a month against thousands of customers
13:01 - What the MDS2 form is, and why hospitals want it before procurement
13:43 - Debra Bruemmer on 24 years at Mayo Clinic and the view from the hospital side
14:39 - Inside the hospital: the healthcare technology management team
18:28 - Poll: could you list every hospital that owns your highest-volume product?
19:54 - You have a customer list. The question is how accurate it is
22:41 - What hospitals want: one view instead of 150 portals
26:49 - Matthew Hazelett on 524B and what FDA expects after the device ships
28:42 - Why only recall-level traceability proves your communication arrived
30:28 - A decade of tightening expectations, and the post-market guidance still to come
32:40 - Poll: how many of your in-field devices have an established end-of-support date?
34:06 - The iceberg: devices that can no longer be patched but are still in use
36:12 - What this looks like when the loop is closed
38:11 - Bridge: push instead of pull, with receipts on both sides
41:02 - One dashboard for hospitals and manufacturers
42:57 - Poll: what matters most when there is only one place to look?
43:58 - Onboarding: hospitals join at no cost, manufacturers start with their most mature lines
46:35 - Q&A: the machines nobody can find
50:43 - Who owns the risk when a device is past end of life?
52:37 - How many manufacturers and hospitals are on Bridge today?
54:29 - Close