
On this page
Published: · Updated:
Key Takeaways
- IoT connects everyday objects for general use cases.
- IoMT connects medical devices specifically for healthcare applications.
- IoMT faces strict regulatory oversight, unlike general IoT.
- Data security and patient safety are the highest priorities in IoMT.
- IoMT aims to improve patient monitoring and healthcare delivery.
- IoT focuses on convenience and automation across many sectors.
IoMT is the healthcare subset of IoT: connected medical devices and systems that exchange data for monitoring, diagnosis, and treatment. Both need security, but IoMT adds clinical consequences and medical device regulatory obligations. We assess not only whether an attacker can access data, but whether altered readings, unavailable services, or unauthorized commands could affect patient care. Requirements depend on intended use, device classification, and market.
Updated November 16, 2024
A connected thermostat and a connected patient monitor can use similar radios, cloud services, and software libraries. That does not make their security requirements interchangeable. For the patient monitor, we need to trace a compromised connection through to its effect on clinical decisions and patient safety.
IoMT is not a separate networking technology. It is an application of connected technology to healthcare, with different consequences when the technology fails. That distinction should shape the architecture, security tests, submission evidence, and postmarket support plan.
Why this matters
An IoMT vulnerability can expose Protected Health Information (PHI), interrupt care, or change the information a clinician uses to make a decision. Manufacturers also face financial and reputational consequences. We therefore assess confidentiality, integrity, and availability together, rather than treating cybersecurity as a privacy exercise.
The FDA's “Cybersecurity in Medical Devices” final guidance, dated February 3, 2026, sets expectations for threat modeling, secure design, and vulnerability management across the total product lifecycle, from premarket submissions through postmarket activities. Binding statutory obligations and guidance recommendations are not the same thing. Manufacturers need to identify which requirements apply to their device.
Relevant standards include IEC 81001-5-1, ISO 27001, and AAMI TIR57 / ANSI/AAMI SW96:2023. They address different parts of secure development, information security management, and medical device security risk management. We do not treat them as interchangeable or assume that every device must use every standard.
General IoT is not harmless by comparison. Industrial equipment and autonomous systems can also create direct physical hazards. The practical distinction is the intended use and the resulting safety and regulatory obligations, not simply whether the product has a wireless connection.
At a glance
| Dimension | IoT (Internet of Things) | IoMT (Internet of Medical Things) |
|---|---|---|
| Definition | A general network of consumer and industrial objects sharing data online. | A specialized network of medical devices and systems for healthcare. |
| Primary Goal | Operational efficiency, automation, and user convenience. | Patient monitoring, diagnostic accuracy, and improved clinical outcomes. |
| Safety Risk | Financial or privacy risk is high; physical danger is usually indirect. | Critical risk is high; device malfunction can cause patient injury or death. |
| Regulatory Scope | General consumer protections and industry standards (e.g., NIST). | Strict FDA/MDR oversight; requires clinical validation and Premarket Notification (510k). |
| Security Posture | Variable; often prioritizes cost and usability over security. | High-intensity; requires encrypted data and multi-layered authentication. |
| Common Attacks | Botnet recruitment (DDoS), data privacy breaches, unauthorized remote access. | Ransomware, telemetry spoofing, life-critical command injection. |
| Key Tradeoff | Convenience vs. data privacy and peripheral network security. | Clinical innovation vs. heavy regulatory burden and patient safety risks. |
We use this comparison as a starting point, not a classification rule. Not every IoMT product follows the 510(k) pathway or needs the same clinical evidence. Encryption and authentication controls must fit the device's interfaces and risks. NIST guidance is not itself consumer-protection law, and the EU MDR and FDA requirements apply in their respective markets.
Defining the Concepts: Internet of Things and Internet of Medical Things
Both terms describe connected systems that collect, exchange, and act on data. The useful distinction is what those systems do with that data and what happens when it becomes incorrect or unavailable.
An IoT environment can include sensors, embedded software, gateways, applications, and remote services. We scope the whole data path, not just the object wearing the “smart” label.
What is the Internet of Things (IoT)?
IoT connects physical objects through sensors, software, and communication interfaces. Home appliances, environmental sensors, and industrial machinery can send measurements or receive commands, often through a gateway rather than a direct internet connection. Smartphones may serve as controllers or gateways.
The purpose is usually automation, visibility, or operational efficiency. Security still matters: unauthorized remote access, data theft, and botnet recruitment can affect both the device owner and other networks.
What is the Internet of Medical Things (IoMT)?
IoMT connects medical devices, medical wearables, and healthcare IT systems to collect and exchange medical data. Applications include remote patient monitoring, diagnosis, and treatment support.
Within the Internet of Medical Things (IoMT), the device is only one part of the system. A companion app, home base station, hospital network, or cloud service can affect whether data reaches the right person intact and on time.
We also distinguish medical wearables from general wellness trackers. Similar hardware does not establish the same regulatory status. Intended use matters.
The Core Differences Between IoT and IoMT
The protocols may be familiar. The clinical context changes how we assess an attack.
IoT commonly supports smart homes, factory automation, and environmental monitoring. IoMT uses connected systems for improving patient outcomes, including remote monitoring and personalized care.
For medical devices, we ask what a successful attack could change: a measurement, an alert threshold, an update, or a treatment command. We then connect that effect to the safety assessment. “The connection is encrypted” does not answer those questions.
Purpose and Application
IoT often automates a task or makes an operation easier to observe. IoMT must also preserve the clinical meaning of the information it delivers. A plausible reading is not necessarily a trustworthy reading.
In our sanitized, representative Class II wearable case study, we tested a proprietary sub-GHz RF link carrying telemetry to a home base station. Its sequence number reset on power-cycle, and captured packets replayed successfully to the base station. The recommended fix was per-packet authentication using a session key derived during enrollment. A rolling nonce alone would not address the power-cycle weakness.
That is why strict security measures to protect patient privacy. are only part of the job. We also need evidence that a receiver can reject unauthorized or replayed medical data. Privacy controls do not establish telemetry integrity.
Regulatory Compliance
Medical devices must meet applicable regulatory requirements. The required evidence depends on classification, intended use, and the submission pathway. Following a security framework alone does not establish device safety or effectiveness.
In the FDA letters we reviewed for our September 2026 MTEC webinar, one submission received nine separate findings for controls described only at a high level. Recurring gaps included naming TLS 1.2 without cipher suites and citing ECDSA without the curve or hash function. These were findings in the reviewed letters, not a measure of all submissions.
The lesson is practical: document what the control actually does. We look for a traceable chain from threat to requirement, implementation, test case, and result. This is the part teams skip when they write the submission as a narrative about good intentions.
The Role of IoT and IoMT in Today’s World
IoT in Everyday Life
Smart lights, thermostats, and fitness trackers make connected technology familiar. They automate routine tasks and let users inspect or change settings remotely.
Those conveniences create dependencies. Accounts, mobile apps, network access, and vendor support become part of the product's operation. We assess those dependencies rather than assuming the physical device is the entire attack surface.
IoMT in Healthcare
Connected medical devices can support real-time monitoring, remote consultations, and faster access to patient information. These capabilities can reduce travel and help providers reach patients in remote areas. Their value depends on data quality and timely delivery, not connectivity alone.
See also: Implantable Device Cybersecurity: Risks, Controls, Evidence, The Dangers of Pacemaker Hacks, and Securing IoT-Enabled Medical Devices: 5 Essential Tips.
In the Class II wearable case study, denying the RF link caused the device to buffer telemetry silently. A clinician-visible alert did not appear until 30 minutes of continuous loss. We recommended documenting that failure mode in labeling and adding a configurable alert threshold for sustained connectivity loss.
No patient outcome was established by that test. It demonstrated a behavior that needed clinical risk assessment. For IoMT, testing what happens when communication stops is just as necessary as testing who can connect.
The Future of IoT and IoMT
Both fields are expanding through faster connectivity, local processing, and more capable analytics. We assess these changes by asking what new trust boundaries and failure modes they introduce.
Edge computing moves processing closer to the data source, reducing latency and network traffic. It can also move sensitive data and decision logic onto endpoints that need secure updates and access controls.
Emerging Trends in IoT
Smart cities use connected sensors for resource management and planning. Autonomous vehicles use sensors and connectivity to support operation. AI can help connected systems detect patterns and adapt to user behavior.
5G technology supports faster connectivity and new applications in industrial automation, healthcare, and agriculture. It does not remove the need to authenticate endpoints or protect commands. We keep transport performance and application security separate in the assessment.
Advancements in IoMT
AI and machine learning can support earlier detection, diagnosis, and treatment planning. Connected wearables and robotic surgery also extend the places where medical data and control signals travel. Wider adoption depends on clinical evidence, safe failure behavior, and workable operational support.
Blockchain continues to attract interest for medical data integrity and auditability. It does not, by itself, secure a compromised endpoint or establish that a measurement was correct when recorded.
Personalized medicine benefits from more patient-specific data. We still need to establish who generated that data, whether it changed in transit, and whether the system can identify missing or stale information.
Challenges and Opportunities in IoT and IoMT
Overcoming IoT Challenges
Interoperability remains difficult across manufacturers, protocols, and software versions. A working connection is not necessarily a secure connection. Teams need to define authentication, authorization, and data handling at each integration point.
Connected systems also produce large volumes of data. Processing and storage decisions affect performance, privacy, and retention obligations. We recommend deciding what data is needed and where it must be processed before adding storage simply because it is available.
Long-term support deserves equal attention. A device can remain physically functional after its software components stop receiving security updates.
Capitalizing on IoMT Opportunities
Remote monitoring and connected care need more than device deployment. Healthcare organizations need infrastructure, training, secure configuration instructions, and a clear response when data stops arriving.
Integrating artificial intelligence and machine learning can support predictive analytics and tailored treatment plans. Potential improvements in outcomes and costs must be demonstrated, not assumed from the presence of an algorithm.
We advise manufacturers to design for postmarket support before release. Maintain a component inventory, monitor vulnerabilities, publish a disclosure process, and build a way to deliver authenticated updates. A patch plan is not useful if the deployed device cannot receive the patch.
Conclusion
IoMT uses many of the same technologies as other IoT systems. Its distinguishing feature is the connection to medical use, patient safety, and medical device oversight. That changes the evidence needed to defend the design.
We focus on the complete system: device, application, gateway, cloud services, and the people relying on them. Security testing should show whether controls work across those boundaries and explain what a failure could mean for care.
Blue Goat Cyber is a Service-Disabled Veteran-Owned Small Business focused exclusively on medical device cybersecurity. We provide penetration testing, threat modeling, security risk management, and premarket and postmarket cybersecurity support. Contact us today for cybersecurity help to discuss your connected medical device and its testing scope.
Check out our medical device cybersecurity compliance package.
How Blue Goat approaches this
We start with the device's intended use, architecture, and threat model. That establishes which interfaces, dependencies, and attack paths security testing needs to cover.
Our penetration testing examines whether an attacker can cross those boundaries and what happens if they do. Reports document scope, methodology, reproduction steps, risk-rated findings, and traceability to the threat model and patient safety assessment. We distinguish vulnerability scanning from penetration testing: finding a known weakness is not the same as demonstrating its impact.
For premarket work, we help manufacturers connect security requirements, test evidence, and residual risk conclusions. Postmarket services support vulnerability management and security maintenance. Our role is security testing and cybersecurity support, not device verification and validation or a guarantee of regulatory clearance.
Learn more about specialized offerings at FDA premarket cybersecurity services.
To turn these risks into submission-ready evidence, see our medical device threat modeling service.
FAQ
What is the primary difference between IoT and IoMT?
IoMT is the healthcare subset of IoT. It connects medical devices and systems for monitoring, diagnosis, and treatment support. Medical device intended use brings safety considerations and regulatory obligations that differ from those of general connected products.
Why is security more critical for IoMT than general IoT?
An IoMT compromise can expose patient data, alter clinical information, or interrupt care. Some failures can cause serious harm or death. Industrial IoT can also create direct safety risks, so we assess consequences rather than assuming every nonmedical device is low risk.
Does the FDA regulate all IoT devices?
No. The FDA regulates products that meet the applicable medical device definition, including connected medical devices. Connectivity alone does not place a consumer or industrial product under FDA medical device oversight.
How does IoMT improve healthcare?
IoMT can enable real-time monitoring, remote care, and access to data for diagnosis and personalized treatment. Better outcomes depend on clinical use, reliable data, and an effective response to the information collected.
What are common security concerns for IoMT devices?
Common concerns include ransomware, unauthorized access to patient data, telemetry spoofing, and unauthorized commands. Weak update mechanisms and unavailable communication links also need assessment because they can affect device operation and patient safety.
What guidance does the FDA offer for IoMT cybersecurity?
The FDA's February 3, 2026, final cybersecurity guidance describes expectations for medical device cybersecurity across the product lifecycle. We use it alongside applicable statutory requirements and device-specific risk assessments when preparing cybersecurity evidence.
Related: The Rising Tide of Cyber Threats in Medical Devices: Understanding the Risks
About the author

Christian Espinosa, MBA · Founder & CEO, Blue Goat Cyber
U.S. Air Force Academy graduate and veteran with 30+ years in cybersecurity. Founded Alpine Security in 2014 (acquired 2020), then Blue Goat Cyber in 2022. Has supported 275+ medical devices, with no cybersecurity-related rejections to date. Author of three books including The Smartest Person in the Room. Ironman triathlete and mountaineer.
Sources & references
Primary sources cited in this article. Links open in a new tab.
- applicable regulatory requirements.- U.S. FDA
