Legacy Ultrasound Cybersecurity Framework: 90% of Cleared Systems Predate US Cyber-Device Statute
核心洞察
An evidence-based framework from Rongtao Medical (搜索) finds 90.1% of all FDA 510(k)-cleared ultrasound systems predate Section 524B cyber-device requirements effective March 29, 2023.
All four CISA advisories naming ultrasound product lines had incomplete patch coverage, with remedies limited to network restriction, physical access control, or replacement.
Zero of 8,525 FDA ultrasound adverse-event reports since 2019 mention ransomware, malware, or hacking, a silence the report attributes to reporting pathways rather than risk level.
Guangzhou Rongtao Medical Technology Co., Ltd. (搜索) has published an evidence-based framework for deciding whether a legacy ultrasound system should be patched, segmented, isolated, or replaced, built from FDA clearance records, CISA advisories, adverse-event data, and OEM support notices. The report's central argument is that device age is the wrong decision variable: supportability is, measured across five "clocks" that expire at different times—clinical usefulness, OEM product support, software and component support, security-control supportability, and physical serviceability.
The anchor statistic draws on all 2,066 FDA 510(k) clearances for cart and console ultrasound systems from 1977 through mid-2026. According to the report, 90.1 percent were cleared before Section 524B's cyber-device requirements took effect on March 29, 2023—and every console cleared between 2006 and 2020, the vintage band that dominates working fleets, predates the statute without exception. With clearance volume flat at 55 to 83 systems a year, the report concludes the pre-statute population does not age out on any planning horizon.
The advisory record reinforces the case for dispositions beyond patching. Across 18 individually verified CISA medical advisories affecting imaging products, half left at least one named product with no software fix at publication. All four advisories naming ultrasound product lines had incomplete patch coverage, with stated remedies of network restriction, physical access control, or replacement. The federal Known Exploited Vulnerabilities catalog, meanwhile, runs on a 21-day median remediation clock that no validated medical device can meet, and names no diagnostic-imaging manufacturer among its 276 vendors.
The safety record is measurably silent. Zero of the 8,525 ultrasound adverse-event reports filed with the FDA since 2019 mention ransomware, malware, cybersecurity, hacking, or a virus, and the FDA's recall database holds exactly one ultrasound cybersecurity recall—from 2008. The report is careful about what that means: the silence measures a reporting pathway, not a risk level, and hospitals cannot wait for a safety signal before deciding a disposition.
"The most useful sentence in the whole record comes from an OEM end-of-support letter that stopped a product's software clock and kept its hardware clock running in the same document," said Frank Zhu, General Manager of Rongtao Medical (搜索). "That is the reality of legacy fleets: the clocks are separable. When the software clock stops, somebody still has to keep the hardware running—and that is the lane independent service occupies, inside the disposition framework, never as a substitute for it."
The report states the boundary of that lane plainly: a hardware repair does not create an OEM patch, validate an operating-system change, or make a device cybersecure. Rongtao Medical (搜索) is not a cybersecurity vendor and does not develop patches; it supplies the physical-serviceability evidence a disposition decision requires—board-level fault isolation, tested parts availability, and real-machine test documentation—under its ISO 13485:2016 and ISO 9001:2015 quality systems.
The full report includes the five-clock framework, four dispositions with evidence gates and stop conditions, an OEM disclosure survey, procurement clauses for future purchases, and 38 source citations. It covers the Olympus EU-ME2 end-of-support notice as its framing case, an analysis of the CISA Known Exploited Vulnerabilities catalog and ICS Medical Advisories series, a keyword analysis of 13,213 FDA MAUDE ultrasound reports, a ten-vendor OEM disclosure survey (zero of ten publish an ungated per-product operating-system or support-status document), the corrected WannaCry record from the UK National Audit Office and NHS England, and a two-axis serviceability-versus-supportability decision matrix.
