1 Independent Researcher, Ann Arbor, USA.
2 Department of Electrical Engineering and Computer Science, University of Michigan, Ann Arbor, USA.
International Journal of Science and Research Archive, 2026, 19(02), 1178-1195
Article DOI: 10.30574/ijsra.2026.19.2.1164
Received on 11 April 2026; revised on 16 May 2026; accepted on 19 May 2026
Legacy medical devices that cannot support standard cybersecurity controls present persistent risk to patient safety, care availability, and protected health information. Existing frameworks address network-borne threats but underserve two profiles: irreversible-consequence risk for life-sustaining devices, and the physical or insider attacker with legitimate device proximity. This paper presents five integrated, practitioner-oriented frameworks grounded in international risk-management standards: a constraint-indexed compensating controls playbook; STRIDE-HC (STRIDE for Healthcare), a clinical adaptation of the STRIDE threat model; a Medical Device Risk Score with an irreversibility-driven tier floor; a five-zone clinical network segmentation model; and a behavioral monitoring framework operationalizing detection-as-control. The frameworks address both healthcare delivery organizations and medical device manufacturers, align with major regulatory and industry standards, and are supported by a companion open-source artifact suite to enable practitioner adoption and empirical validation.
Legacy medical devices; Healthcare cybersecurity; Compensating controls; Threat modeling; STRIDE-HC; Medical device risk score; MDRS; Network segmentation; Behavioral monitoring; Physical attackers; Insider threats; ISO 14971; HIPAA; FDA; Food and Drug Administration
Preview Article PDF
Khaja T Mohiuddin, Bradley Bernia and Wenbo Gong. A practical cybersecurity framework for legacy medical devices. International Journal of Science and Research Archive, 2026, 19(02), 1178-1195. Article DOI: https://doi.org/10.30574/ijsra.2026.19.2.1164.






