* [![perspectives](https://origin-www.paloaltonetworks.com.au/perspectives/wp-content/uploads/2025/02/prespective-icon.png)](https://origin-www.paloaltonetworks.com.au/perspectives)
* IoT Adoption in Healthcare Brings Security Opportunities

English

* [English](https://develop.paloaltonetworks.com/perspectives/iot-adoption-in-healthcare)
* [Français (French)](https://www.paloaltonetworks.fr/perspectives/iot-adoption-in-healthcare/)
* [日本語 (Japanese)](https://www.paloaltonetworks.jp/perspectives/iot-adoption-in-healthcare/)
* [简体中文 (Chinese -Simplified)](https://www.paloaltonetworks.cn/perspectives/iot-adoption-in-healthcare/)
* [繁體中文 (Chinese -Traditional)](https://www.paloaltonetworks.tw/perspectives/iot-adoption-in-healthcare/)
* [Deutsch (German)](https://www.paloaltonetworks.de/perspectives/iot-adoption-in-healthcare/)
* [한국어 (Korean)](https://www.paloaltonetworks.co.kr/perspectives/iot-adoption-in-healthcare/)
* [Español (Spanish)](https://www.paloaltonetworks.es/perspectives/iot-adoption-in-healthcare/)

# IoT Adoption in Healthcare Brings Security Opportunities

![IoT Adoption in Healthcare Brings Security Opportunities](https://origin-www.paloaltonetworks.com.au/perspectives/wp-content/uploads/2023/09/iot-894x320-1.png)  
**By [Anand Oswal](https://origin-www.paloaltonetworks.com.au/perspectives/author/anand-oswal/ "Posts by Anand Oswal")** | **7 min read** |  
![share icon](https://paloaltonetworks.com/content/dam/pan/en_US/cxo-perspectives/images/cxo-share.svg)

* LinkedIn button ![linkedin-icon](https://www.paloaltonetworks.com/content/dam/pan/en_US/microsite/cortex/images/share-linkedin.svg)
* Twitter share button ![twitter-icon](https://www.paloaltonetworks.com/content/dam/pan/en_US/microsite/cortex/images/share-twitter-x-black.svg)
* \[Email share button ![email-icon](https://www.paloaltonetworks.com/content/dam/pan/en_US/microsite/cortex/images/share-email.svg)\](mailto:?subject=IoT Adoption in Healthcare Brings Security Opportunities\&body=Check out this article https%3A%2F%2Forigin-www.paloaltonetworks.com.au%2Fperspectives%2Fiot-adoption-in-healthcare%2F "Share in Email")
* ![copy-icon](https://origin-www.paloaltonetworks.com.au/perspectives/wp-content/themes/csp2025/dist/images/icons/icon-share.svg)
  [](https://origin-www.paloaltonetworks.com.au/perspectives/iot-adoption-in-healthcare/?pdf=download&lg=en&_wpnonce=83197ae001 "Click here to download") MEET THE AUTHOR  
  ![](https://origin-www.paloaltonetworks.com.au/perspectives/wp-content/uploads/2025/01/anand-oswal.jpg)  
  Anand Oswal is the Executive Vice President of Network Security at cybersecurity leader Palo Alto Networks. His team of product managers, engineers and researchers deliver best-in-class enterprise security products and services to help to protect users, applications and infrastructure from cybersecurity threats. An innovation-driven technology leader who holds over 100 U.S. patents, Anand leads the AI transformation of the Network Security business. His team has developed a range of advanced security capabilities including: Prisma AIRS, a comprehensive AI security platform; Strata, an AI-powered platform; Cloud Delivered Security Services (CDSS); Secure Access Service Edge (SASE); Next Generation Firewalls (NGFW); and Zero Trust solutions. As a dynamic leader, Anand is dedicated to building strong, diverse and motivated teams focused on creating innovative security products and solutions for some of the world's biggest enterprise customers. Before joining Palo Alto Networks, Anand was SVP of Engineering for Cisco's Intent-Based Networking Group. At Cisco he was responsible for building the complete set of platforms and solutions for the Cisco enterprise networking portfolio. The portfolio spans enterprise products across routing, access switching, IoT connectivity, wireless, and network and cloud services deployed for customers worldwide. He joined Cisco through the acquisition of Starent Networks, and earlier in his career, held leadership roles at Siara Systems, Sun Microsystems and Ericsson. Anand holds a bachelor's degree in telecommunications from the College of Engineering, Pune, India and a master's degree in computer networking from the University of Southern California....

[Learn more](https://origin-www.paloaltonetworks.com.au/perspectives/author/anand-oswal/)

## IN THIS ARTICLE

Connected medical devices, also known as the Internet of Medical Things or  
IoMT, are revolutionizing healthcare, not only from an operational standpoint  
but related to patient care. In hospital and healthcare settings around the world,  
connected medical devices support critical patient care delivery and a wide  
variety of clinical functions, from medical infusion pumps and surgical robots to  
vital sign monitors, ambulance equipment, and so much more. At the end of the  
day, it's all about patient outcomes and how to improve the delivery of care, so  
this kind of IoT adoption in healthcare brings opportunities that can be  
life-changing, as well as simply being operationally sound.

Yet, enabling these amazing patient outcomes through IoT technology brings with it an associated set  
of security risks to hospitals and patients that are in the news far too often. Ransomware, for example,  
is a particularly prevalent threat to healthcare providers around the world. In August 2022, the French  
hospital Centre Hospitalier Sud Francilien (CHSF) was the victim of a ransomware attack that disabled  
medical imaging and patient admission systems. And in October 2022, [CISA issued an advisory](https://www.cisa.gov/uscert/ncas/alerts/aa22-294a) to healthcare providers warning of a ransomware and data extortion group targeting the healthcare and  
public health sector with a particular interest in accessing database, imaging, and diagnostics systems  
within networks. But ransomware isn't the only risk. In fact, according to a report in HIPAA Journal,  
there has been an 60% increase in cyberattacks of all varieties in healthcare in 2022,^1^  
making it an unfortunately routine aspect of delivering care that the industry must be prepared to address.

## Why Medical IoT Devices Are at Risk

There are a number of reasons why medical IoT devices are at risk. Among the most common reasons  
is the fact that many of these devices are not designed with security in mind.

Many connected devices ship with inherent vulnerabilities. For example, according to research  
from Unit 42^®^, 75% of infusion pumps have unpatched vulnerabilities.^2^ Over half (51%) of all X-Ray  
machines had a high severity CVE (CVE-2019-11687), with around 20% running an unsupported  
version of Windows.^3^

Unit 42 research also found that 83% of ultrasound, MRI, and CT scanners run on an end-of-life  
operating system.4 Those operating systems have known vulnerabilities that can potentially be  
exploited. Attackers are known to target vulnerable devices and then move laterally across the  
organization's network to infect and damage the rest of a hospital network.

The impact of medical IoT device vulnerabilities is serious and potentially life-threatening. It's not  
always easy and sometimes not even possible to update or patch some of these devices, either because  
doing so requires operational disruption of care delivery or due to a lack of computing capability of  
many types of devices. As a result, we've seen patient data exposed. We've seen hospital operations  
halted. While the attack potential is widespread, healthcare providers can take proactive steps to help  
minimize the vast majority of device-related security risks.

## Four Necessary Steps to Improve Medical IoT Security

Among the challenges that medical facilities and health providers face is actually being aware of all the  
connected devices that are present. Visibility, however, isn't the only thing that is needed to improve  
medical device security. In fact, there are four steps that can be taken to secure devices and reduce risk:

* **Ensure visibility and risk assessment of all connected medical and operational devices.** The first  
  step in securing IoT in healthcare is to know what's there; you can't secure what you can't see.  
  Device visibility isn't enough---you have to be able to continuously assess the risk the devices and  
  their evolving vulnerabilities pose to the network.
* **Apply contextual network segmentation and least-privileged access controls.** Knowing a device  
  is present is useful. What's more useful is understanding what network resources or information  
  can be accessed by the device. That's where network segmentation comes into play, creating and  
  enforcing policies that limit device access to only the resources necessary for its intended use and  
  nothing more.
* **Continuously monitor device behavior and prevent known and unknown threats.** As these  
  devices communicate across clinical environments and with external networks and services, they  
  ensure that you establish baseline behavior, monitor devices for anomalous behavior, and protect  
  network-connected devices against threats such as malware.
* **Simplify operations.** In order to effectively manage and secure the sheer volume of devices on  
  a healthcare network, providers require a solution that integrates with existing IT and security  
  solutions to eliminate network blind spots, automate workflows, and reduce the burden of  
  tedious manual processes for network administrators.

## Better IoT Security Helps Ease Regulatory Compliance Challenges

Understandably, there are a lot of compliance requirements in healthcare. Healthcare compliance  
covers numerous areas like patient care, managed care contracting, Occupational Safety and Health  
Administration (OSHA), and Health Insurance Portability and Accountability Act (HIPAA) privacy and  
security, to name a few. Any attack that involves a patient system or medical IoT device is most likely a  
compliance breach, resulting in the loss of sensitive data or access to sensitive data from unauthorized  
entities. Limited IoMT visibility and risk assessment make it difficult to meet regulatory, audit, and  
HIPAA requirements. Having complete visibility into all devices and their utilization data reduces the  
burden of preparing for compliance audits and compiling compliance reports.

## Implementing Zero Trust for Medical IoT

Humans place their trust in medical professionals to improve and sustain human health. Medical  
facilities rely on their technology to do the same. But trust should not be granted by default. It needs to  
be continuously monitored and validated. That's where a Zero Trust approach comes into play.

Zero Trust, in very straightforward terms, is a cybersecurity strategy that seeks to eliminate implicit  
trust for any user, application, or device accessing an organization's network. Zero Trust is not a  
product. For many customers, Zero Trust is a journey. For medical IoT security, Zero Trust starts from  
understanding several key things:

*Who is the user of the device?
What is the device?
What is the device supposed to do?
Is the device doing what it is designed for?*

On a continuous basis, Zero Trust means monitoring devices and their behavior for threats, malware,  
and policy violations to help reduce the risk by validating every interaction.

## Take the Zero Trust Path of Least Resistance to Improve Healthcare IoT

Healthcare IT and security teams are overburdened, so security implementation shouldn't be  
onerous. Improving security for medical IoT devices shouldn't require a forklift upgrade of hospital  
networks either.

Most healthcare providers already have network firewalls that act as enforcement points for Zero Trust  
device security. When you want to enable visibility, risk assessment, segmentation, least privilege  
policies, and threat prevention on the journey toward Zero Trust, it should be done with as little friction  
as possible. Machine learning (ML) can also dramatically accelerate policy configuration, which can be  
automated. If security becomes another big project that requires significant human effort, it has less  
chance of being successful. Security needs to be integrated, easy to deploy, and as automated as possible.

Medical IoT devices help to improve human healthcare every day. Just like humans need to do the  
right things to stay healthy, it's essential for medical IoT devices to remain healthy too. Lives literally  
depend on it.

* [Business Transformation](https://origin-www.paloaltonetworks.com.au/perspectives/all-articles/?cat=business-transformation)
* [Staying Ahead of Evolving Threats](https://origin-www.paloaltonetworks.com.au/perspectives/all-articles/?cat=staying-ahead-of-evolving-threats)

## Related Content

![](https://origin-www.paloaltonetworks.com.au/perspectives/wp-content/uploads/2026/03/Securing-the-Wrong-Layer-featured.jpg) BLOG

### Staying Ahead of Evolving Threats

**Cybersecurity in 2026: What we predicted, what surprised us, and what's next**

At Palo Alto Networks, we are privileged to sit at the intersection of cybe...

[Haider Pasha](https://origin-www.paloaltonetworks.com.au/perspectives/author/haider-pasha/ "Posts by Haider Pasha")
[](https://origin-www.paloaltonetworks.com.au/perspectives/cybersecurity-in-2026-what-we-predicted-what-surprised-us-and-whats-next/)  
![](https://origin-www.paloaltonetworks.com.au/perspectives/wp-content/uploads/2026/03/Why-Cybersecurity-KPIs-Are-Changing-featured.jpg) BLOG

### AI

**Why Cybersecurity KPIs Are Changing (And What This Means for Security Leaders)**

True cyber resilience is impossible to achieve without strategic and tactic...

[Helmut Reisinger](https://origin-www.paloaltonetworks.com.au/perspectives/author/helmut-reisinger/ "Posts by Helmut Reisinger")
[](https://origin-www.paloaltonetworks.com.au/perspectives/why-cybersecurity-kpis-are-changing-and-what-this-means-for-security-leaders/)  
![](https://origin-www.paloaltonetworks.com.au/perspectives/wp-content/uploads/2026/03/RFP-Bottleneck-featured.jpg) BLOG

### AI

**From Weeks to Minutes: How We Applied an AI-First Transformation to the RFP Bottleneck**

Understanding why manual efforts burn hundreds of hours and are bottlenecki...

[Sandeep Uttamchandani](https://origin-www.paloaltonetworks.com.au/perspectives/author/sandeep-uttamchandani/ "Posts by Sandeep Uttamchandani")
[](https://origin-www.paloaltonetworks.com.au/perspectives/from-weeks-to-minutes-how-we-applied-an-ai-first-transformation-to-the-rfp-bottleneck/)  
STAY CONNECTED

## Connect with our team today

Job Level  
Sign me up to receive news, product updates, sales outreach, event information and special offers about Palo Alto Networks and its partners.  
By submitting this form, I understand my personal data will be processed in accordance with Palo Alto Networks [Privacy Statement](https://www.paloaltonetworks.com/legal-notices/privacy?ts=markdown) and [Terms of Use](https://www.paloaltonetworks.com/legal-notices/terms-of-use?ts=markdown).  
This site is protected by reCAPTCHA and the Google [Privacy Policy](https://policies.google.com/privacy) and [Terms of Service](https://policies.google.com/terms) apply.
Reach out  
{#footer} Products and Services

* [AI-Powered Network Security Platform](https://www.paloaltonetworks.com/network-security?ts=markdown)

* [Secure AI by Design](https://www.paloaltonetworks.com/ai-security?ts=markdown)

* [Prisma AIRS](https://www.paloaltonetworks.com/ai-security/prisma-airs?ts=markdown)

* [AI Access Security](https://www.paloaltonetworks.com/sase/ai-access-security?ts=markdown)

* [Cloud Delivered Security Services](https://www.paloaltonetworks.com/network-security/security-subscriptions?ts=markdown)

* [Advanced Threat Prevention](https://www.paloaltonetworks.com/network-security/advanced-threat-prevention?ts=markdown)

* [Advanced URL Filtering](https://www.paloaltonetworks.com/network-security/advanced-url-filtering?ts=markdown)

* [Advanced WildFire](https://www.paloaltonetworks.com/network-security/advanced-wildfire?ts=markdown)

* [Advanced DNS Security](https://www.paloaltonetworks.com/network-security/advanced-dns-security?ts=markdown)

* [Enterprise Data Loss Prevention](https://www.paloaltonetworks.com/sase/enterprise-data-loss-prevention?ts=markdown)

* [Enterprise IoT Security](https://www.paloaltonetworks.com/network-security/enterprise-device-security?ts=markdown)

* [Medical IoT Security](https://www.paloaltonetworks.com/network-security/medical-device-security?ts=markdown)

* [Industrial OT Security](https://www.paloaltonetworks.com/network-security/medical-device-security?ts=markdown)

* [SaaS Security](https://www.paloaltonetworks.com/sase/saas-security?ts=markdown)

* [Next-Generation Firewalls](https://www.paloaltonetworks.com/network-security/next-generation-firewall?ts=markdown)

* [Hardware Firewalls](https://www.paloaltonetworks.com/network-security/hardware-firewall-innovations?ts=markdown)

* [Software Firewalls](https://www.paloaltonetworks.com/network-security/software-firewalls?ts=markdown)

* [Strata Cloud Manager](https://www.paloaltonetworks.com/network-security/strata-cloud-manager?ts=markdown)

* [SD-WAN for NGFW](https://www.paloaltonetworks.com/network-security/sd-wan-subscription?ts=markdown)

* [PAN-OS](https://www.paloaltonetworks.com/network-security/pan-os?ts=markdown)

* [Panorama](https://www.paloaltonetworks.com/network-security/panorama?ts=markdown)

* [Secure Access Service Edge](https://www.paloaltonetworks.com/sase?ts=markdown)

* [Prisma SASE](https://www.paloaltonetworks.com/sase?ts=markdown)

* [Application Acceleration](https://www.paloaltonetworks.com/sase/app-acceleration?ts=markdown)

* [Autonomous Digital Experience Management](https://www.paloaltonetworks.com/sase/adem?ts=markdown)

* [Enterprise DLP](https://www.paloaltonetworks.com/sase/enterprise-data-loss-prevention?ts=markdown)

* [Prisma Access](https://www.paloaltonetworks.com/sase/access?ts=markdown)

* [Prisma Browser](https://www.paloaltonetworks.com/sase/prisma-browser?ts=markdown)

* [Prisma SD-WAN](https://www.paloaltonetworks.com/sase/sd-wan?ts=markdown)

* [Remote Browser Isolation](https://www.paloaltonetworks.com/sase/remote-browser-isolation?ts=markdown)

* [SaaS Security](https://www.paloaltonetworks.com/sase/saas-security?ts=markdown)

* [AI-Driven Security Operations Platform](https://www.paloaltonetworks.com/cortex?ts=markdown)

* [Cloud Security](https://www.paloaltonetworks.com/cortex/cloud?ts=markdown)

* [Cortex Cloud](https://www.paloaltonetworks.com/cortex/cloud?ts=markdown)

* [Application Security](https://www.paloaltonetworks.com/cortex/cloud/application-security?ts=markdown)

* [Cloud Posture Security](https://www.paloaltonetworks.com/cortex/cloud/cloud-posture-security?ts=markdown)

* [Cloud Runtime Security](https://www.paloaltonetworks.com/cortex/cloud/runtime-security?ts=markdown)

* [Prisma Cloud](https://www.paloaltonetworks.com/prisma/cloud?ts=markdown)

* [AI-Driven SOC](https://www.paloaltonetworks.com/cortex?ts=markdown)

* [Cortex XSIAM](https://www.paloaltonetworks.com/cortex/cortex-xsiam?ts=markdown)

* [Cortex XDR](https://www.paloaltonetworks.com/cortex/cortex-xdr?ts=markdown)

* [Cortex XSOAR](https://www.paloaltonetworks.com/cortex/cortex-xsoar?ts=markdown)

* [Cortex Xpanse](https://www.paloaltonetworks.com/cortex/cortex-xpanse?ts=markdown)

* [Unit 42 Managed Detection \& Response](https://www.paloaltonetworks.com/cortex/managed-detection-and-response?ts=markdown)

* [Managed XSIAM](https://www.paloaltonetworks.com/cortex/managed-xsiam?ts=markdown)

* [Next-Generation Identity Security](https://www.paloaltonetworks.com/idira?ts=markdown)

* [Privileged Access Management](https://www.paloaltonetworks.com/idira/human/privileged-access-management?ts=markdown)

* [Identity and Access Management](https://www.paloaltonetworks.com/idira/human/identity-and-access-management?ts=markdown)

* [Endpoint Privilege Manager](https://www.paloaltonetworks.com/idira/human/endpoint-privilege-manager?ts=markdown)

* [Identity Governance](https://www.paloaltonetworks.com/idira/human/identity-governance?ts=markdown)

* [Workforce Password Management](https://www.paloaltonetworks.com/idira/human/workforce-password-management?ts=markdown)

* [Agentic Identities](https://www.paloaltonetworks.com/idira/agentic?ts=markdown)

* [Secrets Management](https://www.paloaltonetworks.com/idira/machine/secrets-management?ts=markdown)

* [Unified Secrets Governance](https://www.paloaltonetworks.com/idira/machine/unified-secrets-governance?ts=markdown)

* [Application Credentials Delivery](https://www.paloaltonetworks.com/idira/machine/application-credentials-delivery?ts=markdown)

* [Vendor Privileged Access](https://www.paloaltonetworks.com/idira/human/vendor-privileged-access?ts=markdown)

* [Threat Intel and Incident Response Services](https://www.paloaltonetworks.com/unit42?ts=markdown)

* [Proactive Assessments](https://www.paloaltonetworks.com/unit42/assess?ts=markdown)

* [Incident Response](https://www.paloaltonetworks.com/unit42/respond?ts=markdown)

* [Transform Your Security Strategy](https://www.paloaltonetworks.com/unit42/transform?ts=markdown)

* [Discover Threat Intelligence](https://www.paloaltonetworks.com/unit42/threat-intelligence-partners?ts=markdown)  
  Company

* [About Us](https://www.paloaltonetworks.com/about-us?ts=markdown)

* [Careers](https://jobs.paloaltonetworks.com/en/)

* [Contact Us](https://www.paloaltonetworks.com/company/contact-sales?ts=markdown)

* [Corporate Responsibility](https://www.paloaltonetworks.com/about-us/corporate-responsibility?ts=markdown)

* [Customers](https://www.paloaltonetworks.com/customers?ts=markdown)

* [Investor Relations](https://investors.paloaltonetworks.com/)

* [Location](https://www.paloaltonetworks.com/about-us/locations?ts=markdown)

* [Newsroom](https://www.paloaltonetworks.com/company/newsroom?ts=markdown)  
  Popular Links

* [Blog](https://www.paloaltonetworks.com/blog/?ts=markdown)

* [Communities](https://www.paloaltonetworks.com/communities?ts=markdown)

* [Content Library](https://www.paloaltonetworks.com/resources?ts=markdown)

* [Cyberpedia](https://www.paloaltonetworks.com/cyberpedia?ts=markdown)

* [Event Center](https://events.paloaltonetworks.com/)

* [Manage Email Preferences](https://start.paloaltonetworks.com/preference-center)

* [Products A-Z](https://www.paloaltonetworks.com/products/products-a-z?ts=markdown)

* [Product Certifications](https://www.paloaltonetworks.com/legal-notices/trust-center/compliance?ts=markdown)

* [Report a Vulnerability](https://www.paloaltonetworks.com/security-disclosure?ts=markdown)

* [Sitemap](https://www.paloaltonetworks.com/sitemap?ts=markdown)

* [Tech Docs](https://docs.paloaltonetworks.com/)

* [Unit 42](https://unit42.paloaltonetworks.com/)

* [Do Not Sell or Share My Personal Information](https://panwedd.exterro.net/portal/dsar.htm?target=panwedd)
  ![Palo Alto Networks Logo](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/pan-logo-dark.svg)

* [Privacy](https://www.paloaltonetworks.com/legal-notices/privacy?ts=markdown)

* [Trust Center](https://www.paloaltonetworks.com/legal-notices/trust-center?ts=markdown)

* [Terms of Use](https://www.paloaltonetworks.com/legal-notices/terms-of-use?ts=markdown)

* [Documents](https://www.paloaltonetworks.com/legal?ts=markdown)

Copyright © 2026 Palo Alto Networks. All Rights Reserved

* [![Youtube](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/youtube-black.svg)](https://www.youtube.com/user/paloaltonetworks)
* [![Podcast](https://www.paloaltonetworks.com/content/dam/pan/en_US/images/icons/podcast.svg)](https://www.paloaltonetworks.com/podcasts/threat-vector?ts=markdown)
* [![Facebook](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/facebook-black.svg)](https://www.facebook.com/PaloAltoNetworks/)
* [![LinkedIn](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/linkedin-black.svg)](https://www.linkedin.com/company/palo-alto-networks)
* [![Twitter](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/twitter-x-black.svg)](https://twitter.com/PaloAltoNtwks)
* AU  
  Select your language
