• Skip to main content
  • Skip to secondary menu
  • Skip to primary sidebar
  • Skip to secondary sidebar
  • Skip to footer

  • Opinion
  • Health IT
    • Behavioral Health
    • Care Coordination
    • EMR/EHR
    • Interoperability
    • Patient Engagement
    • Population Health Management
    • Revenue Cycle Management
    • Social Determinants of Health
  • Digital Health
    • AI
    • Blockchain
    • Precision Medicine
    • Telehealth
    • Wearables
  • Life Sciences
  • Investments
  • M&A
  • Value-based Care
    • Accountable Care (ACOs)
    • Medicare Advantage

IoMT: Why Healthcare Organizations Should Pay Attention to the New U.S. Cyber Trust Mark

by Shankar Somasundaram, CEO of Asimily 11/07/2023 Leave a Comment

  • LinkedIn
  • Twitter
  • Facebook
  • Email
  • Print
Shankar Somasundaram, CEO of Asimily

The recently proposed U.S. Cyber Trust Mark is a voluntary cybersecurity labeling program operated by the FCC. It will initially provide IoT manufacturers with a certification label that signifies their compliance with cybersecurity guidelines and best practices—while providing consumers with more confidence when purchasing internet-connected devices. While the program won’t be implemented until the end of 2024 at the earliest and, as currently proposed, will cover only consumer-grade IoT devices, the government taking an active stance in establishing IoT security standards is significant. This development also undoes some of the disappointment that proponents of medical device security standards felt a year ago when IoMT cybersecurity requirements were stripped out of the FDA appropriations bill.

Enforcing recognized benchmarks within the relative Wild West of IoMT devices is a huge positive for the industry that will pay dividends down the road. Beginning with consumer healthcare devices that individuals use in their own homes will make the Cyber Trust Mark a competitive differentiator among device manufacturers, one that should quickly usher in better cybersecurity features. With these standards will come greater market trust and confidence in IoMT devices, as well as stronger safeguards and clearer expectations for what’s acceptable and what isn’t. I expect that as the ball gets rolling on the details of the Cyber Trust Mark program, the need to expand the certification program to include the IoMT will become clear, and new government action will result.

The IoMT remains rife with vulnerabilities, even as telehealth blurs the line between consumer and professional devices


Another trending development comes into play here: healthcare delivery organizations (HDOs) increasingly deliver care to patients at home, outside of a traditional hospital or medical facility. HDOs are also unique among IoT technology users in that they have massive fleets of heterogeneous IoMT devices from myriad manufacturers—because that’s what’s necessary for modern care with specialized healthcare functions. Patients love telehealth services, which are often enabled by connected IoMT devices providing health monitoring and more.

That said, attackers know IoMT devices have been among the most lucrative and easy-to-exploit targets; the average IoMT device has 6.2 vulnerabilities. Overwhelmed IoMT manufacturers can patch only a fraction of these flaws. Meanwhile, attackers targeting the IoMT have the possibility to breach highly sensitive personal data, and conduct ransomware attacks with the added threat that interrupted systems could put patients in peril.

This is why such government initiatives are so welcome. In a future where HDOs can easily vet new IoMT devices by looking for the Cyber Trust Mark, the speed of procurement and confidence cybersecurity teams can take in those devices will provide cascading benefits.

Sooner or later, IoMT certification or regulation is coming


Medical device manufacturers should anticipate more government mandates designed to enforce uniform and effective cybersecurity standards across consumer and hospital-grade IoMT solutions. HDOs—too many of which operate under the false notion that they hold no responsibility for security vulnerabilities they aren’t aware of—also need to refine their understanding of IoMT devices and their specific cybersecurity needs.

Even while IoMT devices have become a backbone of modern healthcare, HDOs, in general, have yet to develop a particularly deep and intuitive knowledge of what utilizing these solutions safely means for their organizations. This has to change: the consequences are too severe not to, and it will force HDOs’ hands. Government action to enforce IoMT device security standards will certainly help HDOs open their eyes to the importance of their cybersecurity postures and the measures they should take to protect their environments. Government goalposts and certifications will also add structure to conversations among HDOs, IoMT device manufacturers, and device suppliers, making cybersecurity responsibilities and expectations that much clearer.

IoMT manufacturers and HDOs should be active in the government process

The U.S. Cyber Trust Mark proposal will become open to public comment on its path to implementation, as will other potential and evolving government requirements. IoMT manufacturers and HDOs should remain attuned to those developments and make their voices heard in those processes. Going forward, certification criteria will need to ensure cybersecurity across the spectrum of IoMT devices, from low-complexity devices with only simple firmware, all the way up to high-end devices that include an operating system and their own data storage. 

Being part of the process will help ensure that future certification or regulatory rules are workable and effective; for example, the certification process must allow manufacturers to bring secure devices to market without undue obstacles or slowdowns. Communication and collaboration will be essential as the government, manufacturers, and HDOs work together to shape a more secure IoMT.


About Shankar Somasundaram

Shankar Somasundaram is the CEO of Asimily, a risk management platform that secures IoT devices for medical, diagnostic, life sciences, pharmaceutical, and enterprise companies. Previously, he worked on IoT analytics and security solutions at Symantec.

  • LinkedIn
  • Twitter
  • Facebook
  • Email
  • Print

Tap Native

Get in-depth healthcare technology analysis and commentary delivered straight to your email weekly

Reader Interactions

Primary Sidebar

Subscribe to HIT Consultant

Latest insightful articles delivered straight to your inbox weekly.

Submit a Tip or Pitch

Featured Interview

Reach7 Diabetes Studios Founder Chun Yong on Reimagining Chronic Care with a Concierge Medical Model

Most-Read

HHS Finalizes HTI-4 Rule: Prior Authorization & E-Prescribing Interoperability

HHS Finalizes HTI-4 Rule: Prior Authorization & E-Prescribing Interoperability

Meaningful Use Penalties_Meaningful Use_Partial Code Free_Senators Urge CMS to Establish Clear Metrics for ICD-10 Testing

CMS Finalizes TEAM Model: A New Era of Value-Based Surgical Care

White House Event Unveils CMS Health Tech Ecosystem Initiative

White House Event Unveils CMS Health Tech Ecosystem Initiative

Digital Health Faces Q2'25 Pullback: Funding Falls to 5-Year Low, But AI Dominates and $1B+ IPOs Emerge

Healthcare Investment Shifts in 1H 2025: AI Remains a Bright Spot Amidst Fundraising Decline

Digital Health Faces Q2'25 Pullback: Funding Falls to 5-Year Low

Digital Health Faces Q2’25 Pullback: Funding Falls to 5-Year Low

Beyond the Hype: Building AI Systems in Healthcare Where Hallucinations Are Not an Option

Beyond the Hype: Building AI Systems in Healthcare Where Hallucinations Are Not an Option

Health IT Sector Navigates Policy Turbulence with Resilient M&A

Health IT’s New Chapter: IPOs Return, Resilient M&A, Valuations Rise in 1H 2025

PwC Report: US Medical Cost Trend to Remain Elevated at 8.5% in 2026

PwC Report: US Medical Cost Trend to Remain Elevated at 8.5% in 2026

Philips Launches ECG AI Marketplace, Partnering with Anumana to Enhance Cardiac Care with AI-Powered Diagnostics

Philips Launches ECG AI Marketplace, Partnering with Anumana to Enhance Cardiac Care with AI-Powered Diagnostics

WeightWatchers Emerges from Bankruptcy, Launches New Menopause Program

WeightWatchers Emerges from Bankruptcy, Launches New Menopause Program

Secondary Sidebar

Footer

Company

  • About Us
  • Advertise with Us
  • Reprints and Permissions
  • Submit An Op-Ed
  • Contact
  • Subscribe

Editorial Coverage

  • Opinion
  • Health IT
    • Care Coordination
    • EMR/EHR
    • Interoperability
    • Population Health Management
    • Revenue Cycle Management
  • Digital Health
    • Artificial Intelligence
    • Blockchain Tech
    • Precision Medicine
    • Telehealth
    • Wearables
  • Startups
  • Value-Based Care
    • Accountable Care
    • Medicare Advantage

Connect

Subscribe to HIT Consultant Media

Latest insightful articles delivered straight to your inbox weekly

Copyright © 2025. HIT Consultant Media. All Rights Reserved. Privacy Policy |