The expanding attack surface of networked and implantable devices, FDA premarket cybersecurity guidance, and secure design principles.
A modern medical device is rarely an electrically isolated island the way earlier generations of equipment were — networked infusion pumps, PACS servers, and physiological monitors that integrate with electronic health records are all clinical conveniences that are simultaneously attack surfaces — and this module builds that expanding attack-surface picture before covering FDA's premarket cybersecurity guidance, which now requires a Software Bill of Materials and a documented threat model as part of most connected-device submissions.
It then covers secure design principles for connected and implantable devices specifically, including a real-world vulnerability class — implantable cardiac device telemetry — that illustrates why cybersecurity is treated as an extension of the IEC 62304 software lifecycle management covered in Module 10, not a separate bolt-on discipline handled at the end of development.