Financial & Business

Survey Reveals Scope of Medical Device Cybersecurity Risk

Nearly half of surveyed hospitals rely on unsupported operating systems

Photo: NicoElNino/Shutterstock.

Think medical devices are safe from cybercriminals?

Think again. More than 1 million internet-connected devices—from MRI scanners to blood analyzers—are misconfigured, weakly protected, or directly exposed online, quietly leaking patient information and creating fertile ground for cybercriminal exploitation, according to a new Black Book Research flash survey of hospital technology leaders.

Conducted between July and September, the survey collected insights from 312 hospital CIOs, CISOs, radiology directors, and biomedical engineers in eight countries (United States, United Kingdom, Germany, Australia, South Africa, Brazil, India, and Singapore). Respondents highlighted systemic weaknesses in biomedical IT governance that compromise patient privacy, regulatory compliance, and healthcare resilience.

Key Findings

  • Global Scale, Uneven Protections: Survey data suggests more than 1.4 million medical devices are at risk worldwide, with the United States accounting for an estimated 200,000 devices (14.2%) , followed by South Africa, Australia, Brazil, and Germany.
  • Default Credentials Remain Common: 33% of surveyed hospitals admitted at least some connected devices still run on factory-set usernames or passwords, a figure that climbs to nearly 75% in facilities under 250 beds.
  • Legacy Technology Dependency: 48% of respondents acknowledged continued reliance on unsupported operating systems (e.g., Windows 7/XP), with patching cycles averaging 18 months.
  • Direct Internet Exposure: 30% of hospitals reported at least one imaging workstation or PACS node accessible online without VPN or zero-trust safeguards.
  • Silent Incidents: 14% of hospitals reported unexplained or anomalous biomedical network traffic in the past year, with two facilities disclosing confirmed data exfiltration of DICOM imaging files.
  • Analog Backstops Still Common: Nearly 87% of hospitals reported reverting to fax or paper requisitions for imaging orders during cyber incidents.

“Biomedical IT misconfigurations are systemic,” Black Book Research Founder Doug Brown said. “Unlike ransomware that shuts down an ER, these exposures are more insidious: patient scans and identifiers sitting online in plain view. This hidden crisis undermines both patient trust and healthcare resilience.”

Related: Cybersecurity for Medtech Software: A Look at IEC 81001-5-1—A Medtech Makers Q&A

Strategic 2026 Implications

For vendors: Hospitals are demanding “secure by default” design, eliminating factory credentials, supporting certificate rotation, and ensuring long-term OS support.

For hospitals: Governance boards must treat biomedical IT as critical infrastructure, not peripheral equipment.

For policymakers: Regulatory tightening is inevitable; frameworks like HIPAA/HITRUST in the United States and EHDS in Europe will push enforceable baselines.

Since 2011, Black Book has been healthcare’s independent benchmark source, surveying millions of technology users worldwide to measure vendor performance across 18 key indicators. In addition to recognizing top performers, Black Book research uncovers hidden risks and blind spots that threaten care delivery, patient safety, and organizational trust. With a global focus on healthcare technology, services, and capital equipment including cybersecurity and patient privacy governance, Black Book provides insights for providers, payers, vendors, and policymakers to strengthen healthcare through smarter, safer technology.

Each year, Black Book publishes The State of Healthcare Cybersecurity, an extensive industry research report available free at https://blackbookmarketresearch.com/the-2025-black-book-of-healthcare-cybersecurity.

Keep Up With Our Content. Subscribe To Medical Product Outsourcing Newsletters