Secure communication between medical devices and health information systems is now a regulatory expectation — but in practice, adoption of secure standards like HL7, DICOM, and ASTM remains inconsistent. This whitepaper explains the disconnect between regulatory guidance and real-world deployment, showing how infrastructure limitations, legacy systems, and divided regulatory responsibilities contribute to insecure implementations. Drawing on real examples and audits, it identifies systemic barriers to secure connectivity and provides actionable recommendations for device manufacturers, healthcare organizations, and regulators to bridge the gap.