Observed arrival · 2026-09-14
Medical Device Penetration Testing, Filed as Evidence
A regulatory reference for turning connected-device security testing into evidence for EU MDR, IVDR, and US FDA submissions.
Field notes
The reference organizes a test around a defined device build: firmware, companion application, backend release, accounts, and reachable interfaces. It distinguishes attack activity from the evidence package, describing findings that include scope, duration, method, results, and reproduction material. Coverage extends from Bluetooth, Wi-Fi, and hospital protocols such as DICOM and HL7 to field updates, patient-data storage, and manufacturer-hosted cloud systems. The page maps these outputs to EU technical documentation and US premarket submissions.
Observed signals
Read the marks
Editorial observations of this landing page, not a rating.
One card from the complete issue