All whitepapers

Whitepaper · August 13, 2026

Cybersecurity LeadershipThought Leadership

Five years later, the same six problems

New whitepaper: 4 of 6 healthcare cybersecurity constraints just got worse

Open whitepaper PDF
Thumbnail for Five years later, the same six problems

Executive summary

What this whitepaper covers

In March 2021, Medcrypt published "Why Healthcare Cybersecurity Is Hard," naming six structural constraints that no amount of security spending could fix on its own. Five years later, we went back and checked each one against the record: new breaches, new regulation, and a materially different vendor landscape. Four of the six constraints haven't just persisted, they've intensified. Two have genuinely changed, largely because regulation forced it. None have gone away.

Why it matters

The regulatory and product context

Healthcare has now ranked as the costliest industry for a data breach for 14 consecutive years running. The 2024 Change Healthcare/UnitedHealth breach alone affected 192.7 million people, the largest healthcare breach on record. At the same time, new FDA authority (Section 524B's postmarket mandates, Section 515C's change-control provisions, and the QMSR effective February 2026) has genuinely reshaped two of the original six constraints. Understanding which problems are structural and durable, and which are actually solvable through regulation, is the difference between a security program that treats symptoms and one that addresses root causes.

Key insights

What you’ll take away

  • Healthcare has ranked as the costliest industry for a data breach for 14 straight years, averaging $7.42M per incident. The 2024 Change Healthcare breach affected 192.7 million people, the largest healthcare breach on record. Section 524B (2023) created the first statutory mandate for continuous postmarket risk management, including SBOMs and a 60-day vulnerability remediation clock. The QMSR, effective February 2026, replaced the 1996-era Quality System Regulation. Four of six constraints named in 2021 have intensified; two changed, both because regulation forced it, not market incentives.

Who should read this

  • VP/Director of Product Security (or CISO-equivalent) at a mid-to-large medical device manufacturer
  • Regulatory affairs and quality leads
Open PDF

Related resources

Go deeper on the topics in this whitepaper with Medcrypt analysis and real device programs.

Know where you are in 1 hour.

Run the free check or talk to a human. Either way, you’ll get a clearer view of readiness without a paywall or lengthy sales call.

Check readiness