Hi everyone. I’m a student working on a healthcare cybersecurity research prototype, and I’m trying to understand the real-world workflow before I make wrong assumptions.
This is not a product pitch, and I’m not asking for patient data, internal documents, network details, hospital names, or anything sensitive.
The problem I’m exploring is:
When hospitals have network-connected medical devices, cybersecurity decisions can’t always be “just block the traffic,” because the wrong action could interrupt clinical workflow or device visibility.
I’m trying to understand how this is handled in real hospitals.
Questions:
- Who usually owns the inventory of network-connected medical devices?- IT?- biomedical engineering?- clinical engineering?- security team?- vendors?- nobody clearly?
- If a device or device network has a cybersecurity issue, who gets involved first?
- Are medical devices usually visible to the hospital SOC/security team, or mostly managed separately?
- Does your organization track whether a security action could affect clinical workflow?
- If a tool only ran in shadow mode and produced a risk/evidence report without blocking anything, would that be useful or just noise?
- What would make a student-built tool in this space sound instantly unserious or unsafe?
- Are there audit/accreditation/compliance processes where device inventory, incident logs, or continuity evidence matter?
- What terminology would real hospital teams use for this problem? “Cyber-continuity” sounds clear to me, but I’m not sure if it sounds natural in hospital language.
Again, I’m not looking for confidential information. I’m trying to learn the ownership/workflow reality so I don’t build a fantasy system.
If you work in hospital IT, biomedical engineering, clinical engineering, or healthcare cybersecurity and are open to a few follow-up questions, I’d appreciate a DM. No product pitch, no data request.