forumNew topic

An information security audit was requested for our medical devices — what are they looking for exactly?

ÖÖmer Ö***Member
Job title
Social media manager
Sector
Textile
Organization type
workshop
Joined
Feb 2022
Message
76
#1

We are an 18-person medtech company based in Munich manufacturing wireless patient monitoring sensors and data gateways for hemodialysis units and intensive care clinics. Our devices are Class IIa certified under the MDR (Medical Device Regulation) and we passed all hardware-level testing. Last month we bid on a 350.000 EUR patient monitoring tender from a nationwide hospital group in Germany.

The tender committee approved clinical compliance but the hospital's IT security team stepped in, demanding a comprehensive cybersecurity audit before contract signing and handing us a 45-item list of requirements. Our technical team tried to write secure code internally, but we can't fully tell what evidence test reports, and process documentation the hospital auditor expects to see. What areas get prioritized during audits like this?

KKader B***Expert
Job title
Social media manager
Sector
Sports and fitness
Organization type
boutique agency
Joined
Nov 2024
Message
56
Most Helpful#2

Short answer: Hospital IT security auditors don't care about the clinical performance of the device; they care about whether it provides an entry point into the hospital network and whether patient data integrity is preserved. Even with your MDR certification, the audit primarily focuses on your threat model, Software Bill of Materials (SBOM) patch management procedures, and local network isolation capabilities.

The first major item you need to put on the table is a Threat Model document compliant with MDCG 2019-16 guidance. It should analyze which network ports the device uses over hospital Wi-Fi or Ethernet, encryption algorithms (at least TLS 1.3 or modern AES standards) and whether unauthorized users could access device memory via physical USB or serial console ports.

The second critical area is the Software Bill of Materials (SBOM). You must prove that all open-source libraries and embedded OS components have been scanned for known vulnerabilities (CVEs). Auditors want to see a written commitment outlining how many days it takes you to patch newly disclosed vulnerabilities and how you report security advisories to the hospital (Coordinated Vulnerability Disclosure).

Finally support for centralized user management (LDAP or RADIUS integration), role-based access control and the ability to forward tamper-proof audit logs to a central SIEM system are typically mandatory in hospital environments. Once you provide these documents alongside a recent penetration test report, the process usually moves along quickly.

GGamze U***Member
Job title
Technical service technician
Sector
Furniture manufacturing
Organization type
family business
Joined
May 2024
Message
255
#3

One of the top items on that list will be a machine-readable SBOM in CycloneDX or SPDX format. If the gateway runs a Linux kernel, every open-source package version and its corresponding CVE scan output needs to be documented. If you didn't leave telnet open or use unencrypted HTTP on the gateway, you're halfway there.

ÜÜlkü K***Member
Job title
Board member
Sector
Agriculture
Organization type
cooperative
Joined
Jan 2025
Message
19

Doki · Infrastructure migration · 2025

#4

Two years ago in a similar tender, we paid 11.500 EUR to an independent lab for a device penetration test and a B3S hospital standard compliance report. Once we attached that report to the tender file, the hospital IT team signed off on the 45-point checklist with barely any pushback.

GGürkan A***Member
Job title
Studio Founder
Sector
Software
Organization type
chain store
Joined
Jul 2024
Message
139
#5

Ask the hospital IT team if they are basing requirements on BSI IT-Grundschutz or the B3S Medizinische Versorgung profile. Most hospitals don't write checklists from scratch; they copy existing forms from federal standards. Knowing the exact framework makes answering them much easier.

SSinan Y***Member
Job title
Graphic Designer
Sector
IT services
Organization type
early-stage startup
Joined
Dec 2023
Message
25
#6

Hospital IT teams usually don't understand the internal logic of medical software, so they treat it like a standard server. They might tell you to "install an antivirus on the device." You need to patiently explain why traditional antivirus software can't run on embedded devices and that you use hardware-level integrity checks (Secure Boot) instead.

AAhmet O***MemberCommunity member
Joined
Feb 2025
Message
142
#7

We got caught in a similar audit back in 2021 during a university clinic tender. Our devices were top-notch, but our remote software update mechanism lacked cryptographic signature verification. The auditor flagged it under a single clause and suspended the contract for 5 months until we set up the signature infrastructure.

BBurak A***Member
Job title
IT manager
Sector
E-commerce
Organization type
early-stage startup
Joined
May 2023
Message
126
#8

as long as you haven't left default credentials like "admin/admin" on the devices and you force a password change on first login, you've already cleared the primary hurdle auditors look at.

HHüseyin T***MemberCommunity member
Joined
Jun 2025
Message
292
#9

Information security is already an essential legal requirement under MDR Annex I, Section 17.2. Presenting the documentation to the auditor as integrated parts of your medical device technical file (Post-Market Surveillance and Risk Management) will demonstrate your corporate professionalism.

edit: I wrote something wrong above, sorry about that.

BBeyza D***Member
Job title
Sales Manager
Sector
E-commerce
Organization type
a company within a holding
Joined
Jul 2023
Message
197
#10

The 4 documents you need to submit right off the bat are: 1) An MDCG-compliant threat analysis report, 2) A network architecture document listing all open ports and services, 3) A vulnerability disclosure and patch management policy document, 4) Proof of hardware-level secure boot (Secure Boot) on the device.

OOkan U***ExpertCommunity member
Joined
Apr 2023
Message
286
#11

Let me speak from the other side; I'm on the supplier side. Any unwritten clause becomes a point of disagreement later, as both sides remember it differently.

Of course, it varies if your situation is different.

FFurkan K***New member
Job title
QA Tester
Sector
Catering
Organization type
120-person company
Joined
Sep 2026
Message
258
#12

I have a question. An untested backup is not a backup.

Good luck with that.

HHasan E***MemberCommunity member
Joined
Aug 2022
Message
333
#13

I didn't know that.

KKemal U***VeteranCommunity member
Joined
Nov 2025
Message
1
#14

I agree with this. The biggest time-waster for us was not knowing who had the final say.

Just leaving this note, it might be useful.

HHilal B***Veteran
Job title
Graphic Designer
Sector
Electrical-electronics
Organization type
regional distributor
Joined
Dec 2023
Message
17
#15

Here's how it went for us. If permission and scope aren't in writing, don't start that test.

Proven by experience.

ZZeynep A***MemberCommunity member
Joined
Aug 2024
Message
31
#16

I disagree with you on this point. The answer varies greatly by industry; there is no one-size-fits-all rule.

An untested backup is not a backup.

KKader T***Expert
Job title
Accounting clerk
Sector
E-commerce
Organization type
40-person manufacturing company
Joined
Jul 2023
Message
219
#17

I'm in the same situation that's why I'm asking. The real issue isn't the number but what it's based on.

NNazlıMember
Job title
Local marketing
Organization type
boutique agency
Joined
Aug 2024
Message
126
#18

I agree and I'd like to emphasize that. An automated scan report is not the same as a penetration test.

If you post the result here, it will help others too.

GGizem Y***Member
Job title
Board member
Sector
Livestock
Organization type
a company within a holding
Joined
Jan 2024
Message
209

Doki · Server maintenance contract · 2025

#19

I've been down this road, let me tell you. Don't hesitate to ask; those who don't ask always pay more.

ZZerrin G***MemberCommunity member
Joined
Jul 2023
Message
260
#20

I'm writing this so you don't make the same mistake. The harder it is to reverse a decision, the slower you should make it.

This is my opinion, I'm not claiming it's absolute truth.

Reply