Why a Medical Device Cannot Simply Be Patched
A connected medical device cannot simply be patched because the software is part of a regulated product. Changing it can require the manufacturer to revalidate, and a hospital that patches one device unilaterally may void support or certification. The result is equipment running known-vulnerable software for years, legitimately.
That constraint is why the mitigation strategy in this area looks nothing like the one used for laptops. The device cannot be fixed, so the network around it has to change instead, and every control has to be chosen without disrupting a clinical workflow that people depend on. The one thing to withhold is device-level detail: model numbers, firmware versions, and which units are known to be unpatched form a targeting list if published.
The template explains it across seven scenes: one on why the device is frozen, one on what an attacker gains from reaching it, two on segmentation and controlling what can talk to what, one on monitoring rather than patching, one on what clinical staff should and should not do, and one on the questions to ask before the next device is bought.

