Aging Technology, Emerging Threats: Examining Cybersecurity Vulnerabilities in Legacy Medical Devices

Health Care Costs and Drug PricingHouse Energy and Commerce Subcommittee on Oversight and Investigations · 2025-04-01 · 119th Congress
The House Energy and Commerce Subcommittee on Oversight and Investigations held this hearing to examine cybersecurity vulnerabilities in aging "legacy" medical devices — patient monitors, infusion pumps, imaging systems, and implantables — that cannot be reasonably protected against current threats [0:18:57]. Begins at 0:18:57
Transcript
Highlights

Title

Cybersecurity risks of legacy medical devices amid FDA workforce cuts

Purpose

The House Energy and Commerce Subcommittee on Oversight and Investigations held this hearing to examine cybersecurity vulnerabilities in aging "legacy" medical devices — patient monitors, infusion pumps, imaging systems, and implantables — that cannot be reasonably protected against current threats0:18:57. Five witnesses testified on the scope of the problem, the 2022 PATCH Act's limits, and a January 2025 alert about a backdoor found in a Chinese-made Contec patient monitor. Much of the hearing was also dominated by Democrats' objections to concurrent HHS/FDA staffing cuts under the Trump administration and Secretary Kennedy. Begins at0:18:57

Who spoke

Chairman Morgan Griffith (subcommittee chair)0:18:57: Opened by describing legacy device risks, the 2022 PATCH Act, and the WannaCry ransomware attack as a wake-up call0:20:38; later questioned witnesses on ransomware/backdoor risk1:39:54.

Rep. Yvette Clarke (D-NY), Subcommittee Ranking Member0:22:59: Criticized HHS Secretary Kennedy's plan to cut 20,000 positions, including 3,500 at FDA0:23:15; cited Peter Marks's resignation letter alleging Kennedy wanted "subservient confirmation" of misinformation0:24:23; pressed witnesses on how staffing cuts would harm postmarket device review1:13:34.

Rep. Brett Guthrie (R-KY), Full Committee Chairman0:28:24: Cited a cybersecurity firm/FBI report that 53% of connected medical devices had known critical vulnerabilities as of January 20220:29:17; detailed the Contec patient monitor's hidden connection to a Beijing university IP address0:30:07; later asked witnesses about liability and Chinese-made device procurement1:19:10.

Rep. Frank Pallone (D-NJ), Full Committee Ranking Member0:33:02: Argued the hearing was "deeply divorced from reality" given HHS layoffs; cited 483 measles cases across 31 states and two deaths0:34:44; asked Dr. Fu about certainty for industry given FDA staff turnover1:24:39.

Dr. Christian Dameff, UC San Diego Center for Healthcare Cybersecurity0:40:39: Described himself as "a hacker" turned ER physician0:41:09; said no one knows how many Contec-type devices exist in U.S. hospitals0:42:33; cited a San Diego 2021 ransomware attack tied to a measured spike in cardiac-arrest mortality nearby1:43:22; recommended national healthcare dependency mapping and permanent DMCA exemptions for security research0:43:53.

Mr. Erik Decker, VP/CISO, Intermountain Health0:46:05: Identified nation-state actors and organized crime as the two main adversary groups, citing Volt Typhoon0:47:34; said only 55% of hospitals have implemented recommended HICP device-security practices0:49:02; urged reestablishing the 16 critical infrastructure advisory committees disbanded March 70:50:14.

Ms. Michelle Jump, CEO, MedSec0:51:31: Said her clients represent over 70% of the global medical device market0:52:23; explained that third-party software components in devices are often unsupported long before the device's clinical life ends0:54:29; called the issue "as much people and process as technical"0:54:03.

Mr. Greg Garcia, Executive Director, Health Sector Coordinating Council Cybersecurity Working Group0:56:48: Noted the healthcare sector is now the most-targeted critical infrastructure sector for both criminal and nation-state attacks0:58:03; described five HSCC-developed practices on device security, including model contract terms0:58:31; recommended a consultative process with HHS rather than one-way regulation1:00:35.

Dr. Kevin Fu, Professor, Northeastern University; former FDA acting director of medical device security1:02:17: Recounted co-leading a 2008 wireless exploit of an implantable defibrillator that could induce fatal heart rhythms1:03:34; described the first known patient-harm case from ransomware, a radiation therapy device down six weeks1:46:49; warned FDA "at present staffing levels" likely could not handle two simultaneous cyber incidents1:06:55; called legacy device security "spoiled milk not fine wine"1:07:20.

Rep. Morgan Griffith (as questioner)1:07:48: Asked Decker to estimate legacy device numbers, extrapolating roughly 10 million connected devices nationwide from ~913,000 hospital beds1:09:09.

Rep. H. Morgan Griffith / Rep. Randy Weber (R-TX)1:50:14: Asked all witnesses about manufacturer liability for cyber vulnerabilities1:50:43; Dameff described a shifting "chain of responsibility" and cited an alleged Alabama case linking a ransomware attack to a newborn's death1:52:28.

Rep. Kathy Castor / Rep. Kim Schrier — not present; not applicable

Rep. Robert Garcia (D-CA)1:55:42: Asked Decker and Fu how important in-house FDA cybersecurity expertise is to industry, warning cuts would slow innovation and increase safety risk1:58:05.

Rep. Neal Dunn (R-FL)1:59:19: Asked how the public and providers are notified of a device cyber threat; Dameff said he has personally never received such a notification as a clinician2:00:49.

Rep. Alexandria Ocasio-Cortez (D-NY)2:04:37: Noted Elon Musk's DOGE team fired roughly 700 FDA employees, including 200+ at CDRH, then moved to reinstate some, including reviewers of Musk's Neuralink device2:08:27.

Rep. Rick Allen (R-GA)2:10:19: Disputed characterizations of Musk's authority, stating he has no power to hire or fire federal employees2:10:19; pressed witnesses on interagency cybersecurity coordination with CISA and NSA2:11:43.

Rep. Diana DeGette (D-CO)2:14:23: Polled witnesses on whether reducing FDA cybersecurity expert staff could harm patient safety and innovation; four of five witnesses said yes2:17:00.

Rep. Bill Johnson / Rep. Troy Balderson (R-OH), Vice Chairman1:29:59: Asked about hospital device lifecycle challenges and patching delays1:31:48.

Rep. Kim Schrier / Rep. Debbie Dingell (D-MI)2:33:42: Raised NIH funding cuts' effect on device research and asked about electronic health record "information blocking"2:37:01.

Rep. John Joyce (R-PA), Vice Chairman of full committee2:38:57: Asked whether medical students/residents receive adequate cybersecurity training; Dameff said no standardized curriculum exists2:40:11; discussed Medicare reimbursement's link to hospitals' ability to upgrade vulnerable devices2:42:24.

Rep. Buddy Carter/Mariannette Miller-Meeks and other members asking brief questions — not confidently attributable by name from transcript cues; omitted per name-guard rule.

Key moments

Guthrie detailed the January 2025 CISA/FDA alert on a Contec CMS8000 patient monitor with a hidden backdoor connecting to a Beijing university IP address with no known manufacturer link, noting hackers from that network had targeted U.S. energy and communications firms and Alaska's state government in 20180:30:070:30:36.

Decker estimated roughly 10 million connected medical devices exist in U.S. hospitals, extrapolated from ~913,000 hospital beds with 10–15 devices each1:09:09.

Fu described his 2008 research demonstrating a wireless exploit of an implantable defibrillator that could induce fatal heart rhythms without physical contact, warning similarly insecure devices remain in hospitals today1:03:34.

Decker said it can take 30–60 days to certify and deploy a patch to a medical device versus about 3 days for a typical IT system patch1:32:16.

Jump testified only 55% of hospitals have implemented HICP-recommended medical device security practices, per a 2024 joint landscape analysis0:49:02.

Ocasio-Cortez said DOGE fired roughly 700 FDA employees including 200+ at CDRH in February, then moved to reinstate some — including reviewers assessing Musk's own Neuralink device — while Allen countered that Musk has no legal hiring/firing authority2:08:272:10:19.

Dameff cited a 2021 San Diego ransomware attack on five hospitals; a follow-up study found a measured decrease in cardiac-arrest patient survivability in the region attributable to the attack1:43:221:44:12.

Fu described FDA's first documented case of patient harm from ransomware — a radiation therapy device down for six weeks after its manufacturer's private cloud was infected1:46:49.

DeGette polled all five witnesses on whether reducing FDA cybersecurity expertise could harm patient safety/innovation; four answered yes and one (Decker) said it would need to be studied2:14:232:17:00.

Dameff testified he has never personally received a notification, as a practicing clinician, that a device he used had a cybersecurity vulnerability, citing the lack of a national system to track device locations and security status2:00:492:01:54.

Metadata

CommitteeHouse Energy and Commerce Subcommittee on Oversight and Investigations
Chamber / CongressHouse · 119th Congress
Date2025-04-01
TypeHearing
Witnesses
Mr. Greg Garcia — Executive Director, Healthcare Sector Coordinating Council Cybersecurity Working Group
Mr. Erik Decker — Vice President and Chief Information Security Officer
Dr. Christian Dameff, MD, MS, FACEP — Emergency Physician and Co-Director, Center for Healthcare Cybersecurity
Ms. Michelle Jump — Chief Executive Officer
Dr. Kevin Fu, PhD — Professor, Department of Electrical and Computer Engineering, Khoury College of Computer Sciences,
Videoyoutube
Transcript337 caption blocks · 23,643 words · 2:45:44 runtime
EventCongress.gov 118077