Blue Goat CyberBlue Goat CyberSMMedical Device Cybersecurity
    ⌘K
    Blog · Risk

    PATCH Act: Legacy Device Cyber Gaps

    The PATCH Act became section 524B and covers new cyber devices only. See what it requires, who is exempt, and how to secure legacy medical devices.

    Cybersecurity shield protecting legacy medical devices from digital threats and regulatory risks
    On this page
    Christian Espinosa, Founder & CEO at Blue Goat Cyber

    By Christian Espinosa, MBA, CISSP

    Founder & CEO · Blue Goat Cyber

    Published: July 13, 2025 · Last reviewed: May 1, 2026

    Key Takeaways

    • The PATCH Act's requirements now live in section 524B of the FD&C Act, added by the Consolidated Appropriations Act, 2023.
    • Section 524B only reaches cyber devices in premarket submissions filed after March 29, 2023, with refuse-to-accept enforcement starting October 1, 2023.
    • Devices cleared before that window have no statutory cybersecurity mandate, regardless of how connected they are today.
    • Legacy devices commonly lack an SBOM, a coordinated disclosure process, and a documented patching capability that 524B requires of new submissions.
    • Manufacturers can voluntarily backfill SBOMs and compensating controls for fielded products even though the law does not compel it.
    • Hospitals need inventory and network segmentation programs because regulation will not retroactively secure equipment already in service.

    Part of our Postmarket medical device cybersecurity series (surveillance, vuln handling, PATCH Act). For the full overview, start with FDA Postmarket Cybersecurity for Cleared.

    Direct Answer

    The PATCH Act became section 524B of the FD&C Act through the Consolidated Appropriations Act, 2023, and it applies only to cyber devices in premarket submissions filed after March 29, 2023, with refuse-to-accept enforcement starting October 1, 2023. Devices cleared before that date carry no comparable mandate for SBOMs, vulnerability handling, or patching plans. Millions of fielded legacy devices sit outside the law's reach even though they run for a decade or longer with weaker security controls than anything a current submission would allow.

    Reviewed September 17, 2026

    Hospitals run infusion pumps, imaging systems, and patient monitors that were cleared long before Congress wrote a single word of cybersecurity law into the FD&C Act. Those devices keep functioning for years, sometimes decades, and none of them were ever required to include a software bill of materials or a documented vulnerability handling process. The PATCH Act closed that gap for new submissions, but it left the installed base of legacy devices exactly where it found them. Manufacturers and hospitals that assume the law protects everything on their network are wrong, and that assumption carries clinical and financial risk.

    Why This Matters

    The FDA's Cybersecurity in Medical Devices: Quality Management System Considerations and Content of Premarket Submissions guidance, first issued in September 2023, updated June 27, 2025, and finalized again February 3, 2026, describes what section 524B requires of a premarket submission. None of those three guidance versions reach back to devices already cleared. That is a statutory limit, not a policy choice the FDA can waive, because section 524B itself defines its scope by submission date rather than by a device's current risk profile.

    The result is a two-tier fleet inside most health systems. Newer connected devices arrive with SBOMs, vulnerability disclosure commitments, and update mechanisms baked into their design controls. Older devices, some still under active service contracts, were built and cleared under premarket review that never asked those questions. A hospital's biomedical engineering team can be fully compliant with every purchase order it signs today and still operate a fleet where a majority of devices predate any cybersecurity submission requirement at all.

    This gap matters because attackers do not care when a device was cleared. A ventilator cleared in 2015 and a ventilator cleared in 2025 present the same attack surface to a threat actor scanning a hospital network, but only one of them has a documented vulnerability response path. Treating section 524B as a complete cybersecurity solution for a hospital fleet misreads what the law actually covers.

    What Was the PATCH Act and How Did It Become Section 524B?

    The PATCH Act, short for the Protecting and Transforming Cyber Healthcare Act, was proposed legislation that set out premarket cybersecurity requirements for medical devices. Its substantive language did not pass as a standalone bill. Congress instead folded that language into the Consolidated Appropriations Act, 2023, which added section 524B to the Federal Food, Drug, and Cosmetic Act.

    Section 524B requires manufacturers of "cyber devices" to submit a plan for identifying and addressing vulnerabilities, to maintain processes for providing reasonable assurance of device security throughout its lifecycle, and to provide an SBOM. A cyber device under the statute is one that can connect to the internet, contains software, and has technological characteristics that could be vulnerable to cybersecurity threats. That definition is broad enough to catch most connected devices going through premarket review today.

    [KEY REQUIREMENT] A submission for a cyber device must include a plan to monitor, identify, and address postmarket cybersecurity vulnerabilities, a process that provides reasonable assurance the device and related systems are cybersecure, and a software bill of materials, or the FDA can refuse to accept the submission for review.

    Section 524B origin Detail
    Source legislation Consolidated Appropriations Act, 2023 (PATCH Act language)
    Codified as Section 524B of the FD&C Act
    Applies to submissions filed On or after March 29, 2023
    Enforcement mechanism begins October 1, 2023, via refuse-to-accept review
    Governing guidance chain September 27, 2023 final, June 27, 2025 update, February 3, 2026 final

    Which Devices Does Section 524B Actually Reach?

    Section 524B reaches only cyber devices included in premarket submissions filed on or after March 29, 2023. The FDA began enforcing this through refuse-to-accept checks on October 1, 2023, meaning submissions missing the required SBOM or vulnerability management plan can be bounced before substantive review even starts. Anything cleared, approved, or de novo granted before that date falls entirely outside the statute's reach, no matter how connected or clinically critical the device is.

    This creates a hard line rather than a gradient. A device cleared on March 28, 2023 has no statutory cybersecurity obligation under 524B. A device cleared one year later, built on the same platform with the same connectivity, must meet the full set of requirements. Manufacturers sometimes assume a "substantial equivalence" update to an older device pulls it into scope, and that can be true if the update itself constitutes a new premarket submission, but simply continuing to sell or support an already-cleared device does not trigger 524B on its own.

    For more detail on how the statute treats devices that fall right on that line, see does section 524B apply to legacy medical devices and the breakdown of the statute's individual subsections in FDA section 524B subsections explained.

    What Gap Does This Leave for Legacy Devices?

    The gap is straightforward: legacy devices were never asked to produce the artifacts section 524B now requires, so most of them do not have them. Infusion pumps, imaging workstations, and monitors cleared years ago typically shipped without an SBOM, without a documented vulnerability disclosure process, and without a supported patching mechanism. Replacing that entire installed base is neither fast nor affordable for most health systems, so these devices stay in service well past the point their manufacturers stop actively supporting them.

    See also: Legacy Medical Device Cybersecurity Risks in Hospitals, NeuroTech Cybersecurity Risks, and Medical Device Safety vs Security Risks.

    What section 524B requires of new submissions What legacy devices typically have
    Software bill of materials No SBOM, or an incomplete one assembled after the fact
    Documented vulnerability monitoring and disclosure plan No formal process, vulnerabilities surface through ad hoc reports
    Postmarket patching capability Limited or no remote update mechanism
    Security risk management aligned to premarket guidance Risk analysis done under older, less specific frameworks
    Labeling describing cybersecurity controls Labeling silent on cybersecurity

    The 2022 FBI alert on networked medical devices and the Internet of Things found that over half of scanned devices carried at least one known vulnerability, a finding from before section 524B existed. Nothing in the statute retroactively patches those devices or forces a manufacturer to produce an SBOM for a product cleared a decade ago.

    What Should Manufacturers Do About Fielded Devices?

    Manufacturers should treat legacy SBOM and vulnerability management work as a voluntary but necessary extension of their premarket obligations, not as a compliance exercise the law demands. Building an SBOM for an already-cleared product, even informally, gives a manufacturer the ability to answer a hospital's vulnerability question quickly instead of scrambling through old engineering records. It also positions the company well if that product line is ever updated in a way that triggers a new submission.

    [KEY REQUIREMENT] Manufacturers should document, for every legacy product still in active service, whether a coordinated vulnerability disclosure path exists, whether patches can still be issued, and what compensating controls hospitals can apply if the answer to either question is no.

    Hospitals that assume their procurement policy alone satisfies cybersecurity obligations under section 524B are also mistaken, since procurement contracts cannot retroactively change what a manufacturer submitted to the FDA years earlier. The right frame is to treat section 524B compliance for new purchases and legacy device risk management as two separate programs that both need active attention, rather than assuming one solves the other.

    What Should Hospitals Do About Devices Outside 524B's Scope?

    Hospitals should build their own inventory and segmentation program because regulation will not retroactively secure equipment already purchased. Knowing which devices predate March 29, 2023 versus which were cleared under full 524B requirements lets a security team prioritize which parts of the fleet need network-level compensating controls, such as segmentation, monitoring, and restricted access, rather than relying on the device itself to enforce security.

    Procurement teams should also ask vendors directly whether a legacy product has any SBOM or vulnerability disclosure commitment, even an informal one, since the absence of a legal requirement does not mean the manufacturer has nothing to offer.

    How Blue Goat Cyber Approaches This

    Blue Goat Cyber works with manufacturers on both sides of the March 29, 2023 line: new submissions that must satisfy section 524B in full, and legacy product lines where a manufacturer wants to build an SBOM and vulnerability management process voluntarily. Our engineers treat both efforts the same way, as design-controlled documentation tied to a verifiable engineering artifact rather than a paperwork exercise assembled after the fact. For submissions currently in progress, our FDA premarket cybersecurity services build the SBOM, threat model, and vulnerability management plan section 524B requires, scoped to the device's actual architecture and risk profile.

    Frequently Asked Questions

    Does the PATCH Act apply to devices cleared before 2023?

    No. Section 524B, which carries the PATCH Act's requirements, applies only to premarket submissions filed on or after March 29, 2023. Devices cleared before that date have no statutory cybersecurity obligation under this specific law, regardless of their current connectivity or clinical use.

    What is the difference between the PATCH Act and section 524B?

    The PATCH Act was proposed legislation describing premarket cybersecurity requirements for medical devices. Its language was never enacted as a standalone bill; instead, Congress added it to the Consolidated Appropriations Act, 2023, which created section 524B of the FD&C Act. Section 524B is the enforceable statute; the PATCH Act name refers to its legislative origin.

    Can a legacy device become subject to section 524B later?

    Yes, if the manufacturer files a new premarket submission for that device, such as a significant design change requiring a new 510(k) or PMA supplement, that submission must meet section 524B requirements. Simply continuing to sell, service, or support an already-cleared device without a new submission does not trigger the statute.

    What should hospitals do with medical devices that predate the PATCH Act?

    Hospitals should inventory these devices, confirm whether the manufacturer offers any vulnerability disclosure or patching support, and apply network-level compensating controls such as segmentation and monitoring. Since these devices have no statutory cybersecurity mandate, the hospital's own security architecture becomes the primary defense.

    CTA

    Legacy devices and current submissions both need a documented cybersecurity story, even if only one of them is legally required to have one. Contact Blue Goat Cyber to talk through where your fleet or your submission pipeline stands against section 524B.

    About the author

    Christian Espinosa, Founder & CEO at Blue Goat Cyber

    Christian Espinosa, MBA, CISSP · Founder & CEO, Blue Goat Cyber

    U.S. Air Force Academy graduate and veteran with 30+ years in cybersecurity. Founded Alpine Security in 2014 (acquired 2020), then Blue Goat Cyber in 2022. Has supported 275+ FDA medical device submissions; no client has failed to clear due to cybersecurity. Author of three books including The Smartest Person in the Room. Ironman triathlete and mountaineer.

    Read more about ChristianLinkedIn

    More in this category

    More Risk articles

    Browse all
    Related 524B & eSTAR resources

    Keep going: the 524B and eSTAR working set

    Start with the walkthrough hub, then drill into the statute, the eSTAR field map, SBOM monitoring, postmarket planning, and deficiency response. Use these as the playbook behind every cyber device submission.

    Hub
    FDA Section 524B & eSTAR Cybersecurity Walkthrough

    Start here: the hub that ties the statute, the February 2026 guidance, and the eSTAR fields together in the order a submission team works through them.

    Related services

    Put this into practice on your device

    Every Blue Goat Cyber engagement maps directly to FDA Section 524B and the SPDF - so the evidence you need lands in your submission, not in a separate report.

    Ready when you are

    Get FDA cleared without the cybersecurity headaches.

    30-minute strategy session. No cost, no commitment - just answers from people who've shipped 275+ FDA submissions.