← Back to portfolio

🩺 Medical Device & IoMT Security Dashboard

Connected Medical Device Risk · Vulnerability Exposure · FDA Recalls · CISA Advisories · NIST CSF Controls Mapping

Built by El’Azar Ferrer · Google Data Analytics & Google Cybersecurity Certified · Real FDA, CISA & industry IoMT data

53%
Networked Devices w/ a Known Critical Vuln
▲ FBI Cyber Division estimate
1 in 5
Devices on Unsupported / Legacy OS
▲ ~20% run end-of-life software
75%
Infusion Pumps w/ Security Weaknesses
▲ Analysis of 200,000+ pumps
13%
Devices That Support Endpoint Protection
▼ The core defensive gap

Known Vulnerabilities by Device Category

So what: Infusion/IV pumps are the single largest attack surface in a hospital — the most numerous connected device and the most vulnerable, with ~75% carrying identifiable cybersecurity weaknesses. They are the highest-leverage place to start network segmentation and patch governance.

FDA Device Recalls by Risk Class (FY2020–2024)

So what: Of 3,934 FDA device recalls in FY2020–2024, ~88% were Class II and ~9% Class I (highest risk). Class I recalls rose from 7.7% of events in 2023 to 10.8% in 2024 — a signal that the most dangerous device defects, increasingly including software/cyber faults, are trending up.

IoMT Risk Scorecard by Device Class

Infusion / IV pumps
92
Patient monitors
86
Imaging / PACS (DICOM)
80
Legacy Windows hosts
78
Pneumatic tube systems
68
Patient portals / wearables
58
Scoring: composite of vulnerability prevalence, exploitability, network exposure, and patient-safety impact. Highest scores combine high vulnerability rates with direct patient contact — where a compromise can affect care, not just data.

Recent CISA ICS Medical Advisories (ICSMA)

DeviceAdvisoryIssueSeverity
Contec CMS8000 Patient MonitorICSMA-25-030-01Hard-coded backdoor / data exfiltrationCritical
Philips Vue PACSICSMA-24-200-01Remote code execution, info disclosureHigh
Baxter Connex Health PortalICSMA-24-249-01Improper access controlHigh
OHIF DICOM ViewersICSMA-26-176-02Cross-site scripting / data exposureMedium
pydicom / pynetdicom LibraryICSMA-26-176-01Path traversal in imaging libraryMedium
Fourth Frontier Frontier XICSMA-26-148-01Cleartext transmission / auth weaknessMedium
So what: The Contec CMS8000 advisory is the textbook case — a patient monitor shipping with a hidden function that sent data to a hard-coded external IP. Inventory and continuous monitoring (NIST CSF Identify + Detect) are the only way these are caught before they reach a bedside.

NIST CSF 2.0 Controls Mapped to IoMT Risk

Identify
Complete IoMT asset inventory & software bill of materials (SBOM)
Counters: unknown legacy/EOL devices, shadow IoMT
Protect
Network segmentation / VLANs, least-privilege access, patch & firmware governance
Counters: flat networks, unpatched pumps & monitors
Detect
Passive network monitoring & anomaly detection for device traffic
Counters: backdoors, exfiltration (e.g., CMS8000)
Respond
Device-specific incident playbooks; clinical-engineering escalation
Counters: slow containment, patient-safety impact
Recover
Validated device re-imaging & safe fail-over to manual care
Counters: care disruption during incidents
Govern
Procurement security requirements & FDA premarket cyber alignment
Counters: insecure-by-design devices entering the fleet