Blue Goat CyberBlue Goat CyberSMMedical Device Cybersecurity
    K
    Blog · Risk

    PATCH Act & Legacy Medical Devices

    With the Food and Drug Administration’s (FDA’s) 2023 requirements for medical device cybersecurity and the PATCH Act, regulators focused on reducing risk.

    Cybersecurity shield protecting legacy medical devices from digital threats and regulatory risks
    On this page
    Christian Espinosa, Founder & CEO at Blue Goat Cyber

    By Christian Espinosa, MBA, CISSP

    Founder & CEO · Blue Goat Cyber

    Published: July 13, 2025 · Last reviewed: May 1, 2026

    Key Takeaways

    • PATCH Act applies only to new medical devices.
    • Legacy devices lack modern cybersecurity checks.
    • Pre-market submissions require SBOMs and patching plans.
    • Older devices can remain in use for decades.
    • Vulnerabilities in legacy devices pose significant risks.
    • Industry collaboration is vital for legacy device security.

    Part of our Postmarket medical device cybersecurity series (surveillance, vuln handling, PATCH Act). For the full overview, start with FDA Postmarket Cybersecurity for Cleared.

    Direct Answer

    The PATCH Act only applies to new medical devices. Legacy medical devices pose significant cybersecurity risks because they lack modern protections.

    With the Food and Drug Administration’s (FDA’s) 2023 requirements for medical device cybersecurity and the PATCH Act, regulators focused on reducing risk. However, the Patch Act only applies to new medical devices manufactured after March 2023. As a result, legacy systems have few checks around vulnerabilities.

    Manufacturers tend to focus on the development and launch of products. Sometimes, that means sunsetting ones on the market or no longer updating them as often. Yet, my providers and patients are still using these devices every day.

    Let’s look at the PATCH Act and the continued concern over legacy medical devices.

    Table of Contents

    Why this matters

    The FDA's Cybersecurity in Medical Devices: Quality Management System Considerations and Content of Premarket Submissions (Feb 3, 2026 final guidance) made cybersecurity documentation a gating criterion for clearance under Section 524B of the FD&C Act. Reviewers now apply this guidance to patch act only applies to new medical devices, leaves legacy systems a risk the same way they apply software lifecycle expectations from IEC 62304 and security risk-management expectations from AAMI TIR57 and ANSI/AAMI SW96:2023.

    Gaps in this area are the single most common driver of first-cycle cybersecurity Additional Information (AI) requests. The FDA's FY2024 CDRH performance reports show cybersecurity is among the top deficiency categories cited in 510(k) and PMA AI letters, behind only software documentation and clinical evidence. Treating it as a checklist exercise rather than a design-controlled engineering artifact is what creates the gap.

    What Is the PATCH Act?

    The PATCH Act refers to the Protecting and Transforming Cyber Healthcare Act. Its requirements include:

    • Pre-market submissions that demonstrate the company’s commitment to cybersecurity and safety, including a software bill of materials (SBOM)
    • Vulnerability prevention concerning exploitation by cybercriminals
    • Development and implementation of security patching to address any cybersecurity issues

    The law follows the guidance of the FDA.

    Why Doesn’t the Patch Act Cover Legacy Devices?

    The law leaves out the designation of legacy devices to adhere to the new rules. Most regulations don’t backdate to previous products, even in cybersecurity.

    There may have been little awareness that medical devices can remain functional for 10 to 30 years. They aren’t necessarily something you update as often as consumer electronics like smartphones.

    Problems with managing legacy devices and holding them to the same standard have challenges. Most healthcare organizations don’t track devices at a national or regional level. It would be difficult to understand the scale of legacy devices, as the industry doesn’t even know how many are in use.

    What Are the Biggest Threats of Legacy Medical Devices?

    In 2022, before the PATCH Act, the FBI issued an alert that 53% of networked medical devices and the Internet of Things (IoT) have at least one vulnerability.

    There are several high risks associated with these products, including:

    • Backdoors can be present and operating without anyone’s knowledge. This actually happened with patient monitors from Contec.
    • A lapse in updates and patches is common. There’s also no SBOM for most legacy systems, so there’s no source of truth identifying the code in use. Patching may also no longer be available from manufacturers.
    • There’s often a lack of modern security features in these older models.
    • Hard-coded passwords are another common legacy characteristic.
    • Legacy systems still rely on default settings for network configurations, which are easily exploitable.

    What Other Factors Impact Legacy Management?

    See also: Legacy Medical Device Risks | Hospitals, NeuroTech Cybersecurity Risks, and The Overlooked Threat in MedTech.

    The laws and rules don’t apply to this older equipment, but agencies, manufacturers, the healthcare industry, and other stakeholders continue to try to address issues. However, the body regulating medical devices has taken severe hits to their staffing numbers.

    Those cuts mostly impact new devices coming to market, but they could also impede overall oversight. When there’s any lapse, cybercriminals will take note. In fact, there’s been discussion by some experts that the FDA would have trouble managing concurrent cyber attacks.

    What Can the Industry Do to Reduce Legacy Device Risk?

    The industry could use the PATCH Act and FDA guidance for legacy devices. One of the best things to do is to have an SBOM to define all software in use, as that’s where attacks would likely target.

    Manufacturers can also work with healthcare organizations to develop stronger controls and smoother patching of these devices. If they are sunset, the manufacturer should advise of this and provide alternatives for further use.

    In the end, all parties should move cohesively to ensure the PATCH Act protects new devices while also addressing legacy systems.

    Have questions about legacy device cybersecurity? We can help. Contact our experts today.

    How Blue Goat approaches this

    Blue Goat Cyber's medical device practice is led by engineers with CISSP, OSCP, and prior military red-team backgrounds. We treat cybersecurity documentation as design-controlled engineering output, not a submission template, every artifact (threat model, SBOM, security risk assessment, penetration test, labeling) traces back to a controlled requirement and a verified result.

    Our engagements deliver the full Feb 3, 2026 guidance documentation set scoped to the device's risk profile, integrated with the existing IEC 62304 software lifecycle and ISO 14971 risk file. See our medical device cybersecurity services for the full scope. If the FDA raises cybersecurity deficiencies after our submission, we resolve them at no additional cost.

    FAQ

    What is the PATCH Act?

    The PATCH Act requires medical device manufacturers to submit cybersecurity documentation to the FDA for new devices. This includes a software bill of materials, plans for vulnerability management, and strong security patching processes.

    Why doesn't the PATCH Act cover legacy devices?

    The PATCH Act primarily focuses on new medical devices entering the market, a common approach for regulations. Retroactively applying these requirements to the vast and often untracked landscape of legacy devices presents significant logistical challenges for manufacturers and healthcare organizations.

    What are the biggest threats from legacy medical devices?

    Legacy medical devices often lack modern security features, such as strong authentication, and may contain vulnerabilities like hard-coded passwords or unpatched software. The absence of a software bill of materials for these devices also complicates vulnerability management.

    Does the FDA premarket guidance apply to legacy devices?

    The February 3, 2026 FDA premarket cybersecurity guidance primarily applies to new medical device submissions. While its principles offer valuable insights for improving the security posture of legacy devices, the guidance does not mandate compliance for devices already on the market.

    Related: Postmarket Cybersecurity for Medical Devices: The FDA Roadmap

    About the author

    Christian Espinosa, CISSP, Founder, Blue Goat Cyber. Christian leads a team focused exclusively on medical device cybersecurity for FDA premarket submissions and postmarket compliance. Read more about Christian.


    More on this topic

    Sources & references

    Primary sources cited in this article. Links open in a new tab.

    1. Food and Drug Administration’s (FDA’s) 2023 requirements- U.S. FDA
    2. patient monitors from Contec- CISA
    Related 524B & eSTAR resources

    Keep going: the 524B and eSTAR working set

    Start with the walkthrough hub, then drill into the statute, the eSTAR field map, SBOM monitoring, postmarket planning, and deficiency response. Use these as the playbook behind every cyber device submission.

    Hub
    FDA Section 524B & eSTAR Cybersecurity Walkthrough

    Start here: the hub that ties the statute, the February 2026 guidance, and the eSTAR fields together in the order a submission team works through them.

    Related services

    Put this into practice on your device

    Every Blue Goat Cyber engagement maps directly to FDA Section 524B and the SPDF - so the evidence you need lands in your submission, not in a separate report.

    Ready when you are

    Get FDA cleared without the cybersecurity headaches.

    30-minute strategy session. No cost, no commitment - just answers from people who've shipped 250+ FDA submissions.