Blue Goat CyberSMMedical Device Cybersecurity
    K
    Podcast · Episode 20

    The Human Factor in MedTech Design with Dylan Horvath

    With Dylan Horvath - How can human-centered design influence medical device cybersecurity? In this episode, Christian Espinosa chats with Dylan Horvath of Cortex Design about the powerful intersection of human-centered design and medical device cybersecurity.

    Christian Espinosa, Founder & CEO at Blue Goat Cyber

    By Christian Espinosa, MBA, CISSP

    Founder & CEO · Blue Goat Cyber

    Listen now

    Key takeaways

    • Human-centered design and human factors engineering must be integrated into medical device development from the outset, not as an afterthought.
    • A medical device being "safe and effective" for regulatory approval does not guarantee commercial success; market adoption depends on usability and user desirability.
    • Understanding all stakeholders, including end-users, purchasers, and reimbursement decision-makers, is crucial for successful medical device design.
    • Changing design, hardware, or firmware late in the development process is costly and causes significant delays, emphasizing the need for early planning.
    • Industrial design and human factors engineering should be viewed as a cohesive process to create a seamless and effective user experience.
    • The FDA is increasingly focused on cybersecurity in medical devices, and submissions must be thorough and buttoned-up from the beginning to avoid delays.
    • High-quality, complete market submissions are critical to navigate the current FDA landscape, which is characterized by resource constraints and increased uncertainty.

    How can human-centered design influence medical device cybersecurity?

    In this episode, Christian Espinosa chats with Dylan Horvath of Cortex Design about the powerful intersection of human-centered design and medical device cybersecurity. They explore how usability, trust, and empathy can shape safer, smarter devices from the start. Dylan also shares valuable insights into building design teams, learning from failure, and driving innovation in regulated industries.

    Dylan Horvath is a passionate industrial designer who’s spent decades shaping how people interact with technology. As the founder and CEO of Cortex Design, he’s all about blending creativity and engineering to build medical devices that actually work for people.

    (00:30) Design Thinking in MedTech

    • Christian and Dylan discuss the similarities between design and cybersecurity.

    (07:08) The Design Process

    • How psychological safety and curiosity are foundations for team success.

    • Cortex’s lean, iterative process and fast prototyping.

    (14:18) Lessons Learned

    • Dylan reflects on design failures and what they taught him.

    • The balance between regulation and innovation in MedTech.

    (21:26) Security and Usability

    • Dylan’s thoughts on how threat modeling could better include design teams.

    • The trade-offs between usability and strong security in med devices.

    (26:36) Design Challenges

    • User experience is critical, and overlooking it can lead to products that are difficult to use and unappealing to the market.

    Notable quotes

    “Safe and effective is core to all medical devices, but that doesn't mean they're commercially successful. Commercial success really means about market adoption, making sure you're designing a product that people want, people that people understand how to use, and can resonate with.”
    - Dylan Horvath
    “If you consider some of these constraints too late in the game, it's very expensive to change. So that includes cybersecurity and access to microcontrollers or computing devices on the device, making sure that they're hardened or protected.”
    - Dylan Horvath
    “The FDA is under-resourced right now. Hopefully, that won't continue to be the case, but making sure that your market submissions are buttoned up from A to Z, and that certainly includes cybersecurity, it's going to be increasingly difficult to go back and forth with the FDA.”
    - Dylan Horvath

    Frequently asked questions

    Bring this work to your device

    Need help with threat modeling?

    Blue Goat Cyber delivers medical device threat modeling for medical device manufacturers - from threat modeling to FDA-ready reports.

    Medical Device Threat Modeling

    More on Threat Modeling

    Ready when you are

    Get FDA cleared without the cybersecurity headaches.

    30-minute strategy session. No cost, no commitment - just answers from people who've shipped 250+ FDA submissions.