Products Intelligence Pricing Methodology Contact
FINANCIAL & CAPITAL MARKETS

Medical device cybersecurity

Financial and capital markets firms are not the primary target of medical device cybersecurity regulation, but third-party vendor exposure is pulling them in. The U.S. Food and Drug Administration's 2023 cybersecurity guidance for premarket submissions and the U.S. Department of Health and Human Services Office for Civil Rights enforcement posture on connected health devices create indirect obligations for any capital markets firm that finances, insures, or services healthcare technology. Compliance teams with healthcare sector clients or fintech partnerships involving patient-adjacent devices are now reviewing vendor due diligence frameworks against these requirements.

Watch

  • FDA's 2023 premarket cybersecurity guidance: vendor contract obligations for financed devices
  • HHS OCR enforcement actions tied to networked medical device breaches involving financial data flows
  • EU Cyber Resilience Act provisions covering medical-grade connected products sold into European markets
  • NIST SP 800-82 Rev. 3 adoption by federal contractors with capital markets clearing relationships
  • Third-party risk disclosure requirements where medical device vendors touch firm infrastructure

Recent material activity in Financial & Capital Markets

Active monitoring in place across Financial & Capital Markets. Material developments related to medical device cybersecurity will appear here as they are published.