Blog · Compliance

    CLIA-Waived Test Cybersecurity: Point-of-Care Risks

    CLIA-waived test cybersecurity: why point-of-care devices used by untrained staff need strong security, and what the FDA expects in the premarket submission.

    Hero illustration for the Compliance article: CLIA-Waived Test Cybersecurity: Point-of-Care Risks
    On this page
    Christian Espinosa, Founder & CEO at Blue Goat Cyber

    By Christian Espinosa, MBA

    Founder & CEO · Blue Goat Cyber

    Published:

    Direct Answer

    A CLIA-waived test is simple enough, and carries a low enough risk of a wrong result, that it can run outside a traditional lab. That puts connected readers in pharmacies, clinics and homes run by people with no lab or IT training. If the device sends results to an EHR, LIS or app, it is likely a cyber device under FDA Section 524B, and its submission needs a full cybersecurity package.

    Waived tests are where diagnostics meet everyday care. A strep test at urgent care, a glucose or INR check in a physician office, a respiratory panel in a retail pharmacy. The person running the test may be a medical assistant or a pharmacy technician, not a laboratory scientist.

    That convenience is the whole point of a waiver. It is also why security matters more, not less. Nobody in that room is checking whether the reader's firmware is current or whether its Wi-Fi link is encrypted. A result that has been altered in transit can be acted on within minutes, with no pathologist reviewing it first. For manufacturers building connected point-of-care devices, cybersecurity is part of what makes the product safe to use in those settings, and part of what the FDA will look for in the submission.

    Why this matters

    CLIA, the Clinical Laboratory Improvement Amendments of 1988, sets quality standards for any laboratory that tests human specimens for patient care. CMS runs the program, and the FDA assigns each test a complexity category. Sites that run only waived tests hold a Certificate of Waiver, which brings far lighter oversight than a moderate or high complexity lab.

    Lighter lab oversight does not change what the manufacturer owes the FDA. Section 524B of the FD&C Act applies to any cyber device: one that includes software, can connect to the internet, and could be vulnerable to cybersecurity threats. A waived reader with Bluetooth, Wi-Fi, cellular or a cloud app usually meets that definition.

    The FDA's February 3, 2026 final premarket cybersecurity guidance explains what a cyber device submission should contain: threat modeling, cybersecurity risk assessment, SBOM, security architecture views, testing evidence and a postmarket vulnerability plan. None of that is reduced because the test is waived.

    The user environment actually raises the stakes. The guidance asks manufacturers to consider the intended use environment and users. For a waived test, that means assuming shared devices, consumer-grade networks, no dedicated IT staff and users who will not notice subtle tampering. Your threat model and labeling have to reflect that reality.

    What does CLIA waived actually mean?

    CLIA places tests into three tiers:

    TierTypical settingWho runs it
    WaivedPhysician offices, urgent care, pharmacies, homesStaff or patients with minimal training
    Moderate complexityHospital and clinic labsTrained laboratory personnel
    High complexityHospital, reference and specialty labsHighly qualified laboratory scientists

    A waived test is simple to perform and has a low risk of an erroneous result when the instructions are followed. Manufacturers usually reach waived status through a CLIA waiver by application or a dual 510(k) and CLIA waiver submission, showing that untrained users get accurate results.

    Notice what that review covers: analytical accuracy in untrained hands. It does not assess whether the result stays accurate once it leaves the reader and crosses a network. That gap is the cybersecurity problem.

    Is a connected waived test a cyber device?

    Usually, yes. If the reader has software and any path to the internet, directly or through a phone, gateway or hub, it fits the Section 524B definition. Common examples:

    • A reader that pairs with a smartphone app over Bluetooth Low Energy
    • A benchtop analyzer that posts results to an LIS or EHR over the clinic network
    • A home test that uploads results to a cloud dashboard for a telehealth provider
    • A device that receives firmware or assay updates over the air
    Key requirement

    Section 524B requires cyber device submissions to include a plan to monitor and address postmarket vulnerabilities, processes that provide reasonable assurance the device is cybersecure, and a software bill of materials.

    Even a reader with no network connection can carry risk through USB ports, removable media or service tools. Document why the device is or is not a cyber device, and expect the FDA to question a "not connected" claim if any data path exists.

    What threats are specific to point-of-care settings?

    Waived devices face the same attacks as any connected device, but the setting changes which ones matter most.

    Result tampering. An attacker who can change a value between the reader and the EHR can cause a missed diagnosis or the wrong treatment. Because waived results are often acted on immediately, there may be no expert review to catch an implausible number. Integrity protection on results, end to end, is the top control.

    Shared and unmanaged devices. Readers sit on counters, get borrowed between rooms and go home with patients. Expect weak physical security, shared logins and lost devices. Design for safe defaults, short sessions and remote disable where it makes sense.

    See also: CLIA Lab Cybersecurity: HIPAA & 21 CFR Part 11 (2026), Breakthrough Device Designation and Cybersecurity, and Q-Sub vs Pre-Sub: FDA Cybersecurity Guide.

    Consumer networks and phones. Home and pharmacy devices often depend on a patient's own phone or a public Wi-Fi network. Pairing, encryption and app security become part of the device's security boundary.

    Silent update failures. Clinics without IT staff will not chase firmware updates. Plan for signed, automatic or prompted updates, and for devices that stay offline for months.

    Privacy exposure. Results tied to patient identity in a cloud app bring HIPAA and state privacy duties for the companies handling them.

    What should the premarket package include?

    For a connected waived test, the cybersecurity section of the submission should cover:

    • A threat model that names the real use environments: retail pharmacy, urgent care, home
    • A cybersecurity risk assessment that links result tampering to patient harm in your safety risk file
    • Security architecture views showing every data path from reader to app, cloud and EHR
    • An SBOM with vulnerability analysis for the reader firmware and companion app
    • Penetration testing of the reader, wireless interfaces, mobile app and cloud services
    • Labeling written for non-technical users: how to update, what to do if the device is lost, what network it needs
    • A postmarket plan for monitoring and fixing vulnerabilities in devices you cannot easily reach

    The same evidence supports the waiver story. If you can show that results cannot be silently altered, you strengthen the claim that untrained users get results they can trust.

    How Blue Goat Cyber approaches this

    We treat a waived device's use environment as the starting point. During scoping we map who handles the device, which networks it touches and where results go, then build the threat model around those facts instead of a hospital network template.

    From there the work follows our standard premarket process. You get a project manager, a shared Slack channel and secure file sharing. We collect your intake documents, then produce the threat model, risk assessment, architecture views and SBOM analysis. Our in-house team penetration tests the reader, the wireless links, the mobile app and the cloud services, and we document findings in a report written for the FDA reviewer. Retests are unlimited until findings are closed.

    If the FDA raises a cybersecurity question, we answer it at no extra cost until the cybersecurity portion is closed. Your regulatory team owns the waiver and 510(k) strategy; we supply the cybersecurity evidence that supports it.

    FAQ

    Does a CLIA waiver reduce FDA cybersecurity requirements?

    No. CLIA waiver status describes how simple the test is to perform and how lightly the testing site is overseen. Cybersecurity obligations come from Section 524B and the FDA's premarket cybersecurity guidance, which apply to any cyber device regardless of its CLIA category. A connected waived test needs the same cybersecurity package as any other connected device, with a threat model tuned to untrained users.

    Who is responsible for security at the testing site?

    The site is responsible for its own network and HIPAA duties, but most waived sites have no IT staff to lean on. That shifts practical responsibility to the manufacturer's design. Secure defaults, signed updates, encrypted links and plain-language labeling do the work that a hospital security team would do in a high complexity lab.

    Is a home-use waived test treated differently?

    The use environment changes, but the obligations do not. A home test that syncs to an app or cloud service is usually a cyber device. Your threat model should cover the patient's phone, home Wi-Fi and lost or shared devices, and your labeling should tell lay users what they need to do to keep the device secure.

    Why does cybersecurity matter for an investor story?

    Investors in point-of-care diagnostics want to know the device can clear the FDA and be trusted in settings without lab oversight. Showing that results cannot be silently altered, and that the cybersecurity package is planned from the start, reduces submission risk and supports adoption by health systems that review vendor security before purchase.

    CTA

    Building a connected CLIA-waived test? Book a discovery session and we will map your device's real use settings, scope the cybersecurity package for your submission and give you a fixed fee before work begins.

    Related reading on this site

    About the author

    Christian Espinosa, Founder & CEO at Blue Goat Cyber

    Christian Espinosa, MBA · Founder & CEO, Blue Goat Cyber

    U.S. Air Force Academy graduate and veteran with 30+ years in cybersecurity. Founded Alpine Security in 2014 (acquired 2020), then Blue Goat Cyber in 2022. Has supported 275+ medical devices, with no cybersecurity-related rejections to date. Author of three books including The Smartest Person in the Room. Ironman triathlete and mountaineer.

    Read more about ChristianLinkedIn

    Where your device stands

    Find your stage in the FDA cybersecurity journey

    Answer one question about where your device is today. You get your stage, the next action to take, and the support that fits it.

    Find where my device stands

    Free readiness check

    How ready is your cybersecurity package for FDA review?

    Seven questions mapped to the FDA's February 3, 2026 premarket cybersecurity guidance. You get a score, a gap list by area, and the fastest next move. Takes about three minutes.

    Related services

    Put this into practice on your device

    Every Blue Goat Cyber engagement maps directly to FDA Section 524B and the SPDF - so the evidence you need lands in your submission, not in a separate report.

    Ready when you are

    Get FDA cleared without the cybersecurity headaches.

    30-minute strategy session. No cost, no commitment - just answers from people who've shipped 275+ devices supported.