How connected systems can leave healthcare operators exposed to cyber risk
An operating room, ICU or hospital ward depends on more than patient data and enterprise networks. Healthcare teams also rely on connected medical devices, nurse call systems, badge access controls, infection control systems, airflow management, pressure controls, temperature monitoring and other environmental systems to support safe, continuous patient care.
Many of these technologies are part of healthcare’s operational technology (OT) environment. Some fall under the Internet of Medical Things (IoMT). Others sit in facility, building or operational technology environments. Together, these medical cyber-physical systems (MCPS) help shape the conditions clinicians depend on, yet many cannot be easily replaced, patched or taken offline without affecting care delivery or facility uptime.
One part of the challenge shows up in Honeywell Technologies’ recent OT cybersecurity research: 44% of healthcare respondents cite legacy or unsupported medical devices as a significant cybersecurity challenge.
If connected medical, safety, facility and building systems are not visible in OT cybersecurity monitoring systems and response plans, exposure can remain hidden. That risk becomes more urgent when disruption reaches the environments care teams rely on.
How cyber-physical security exposure moves across healthcare operations
Healthcare cyber-physical exposure does not follow one clean path. An IoMT device may sit with clinical engineering. Imaging, surgical or lab systems may depend on vendor support. Building controls, temperature sensors or power systems may sit with facilities. Visitor management or access control may involve physical security.
Our research reinforces that healthcare OT cybersecurity is not limited to clinical systems. It also needs to account for safety, physical security, facility and building systems.
The teams responsible for these systems need a shared view. Without it, ownership can blur and response can slow. Facilities may know how a building system operates. IT and OT cybersecurity teams may not have the same view into how it is connected, accessed or maintained.
Visibility gaps weaken healthcare OT cybersecurity
Including facility and building systems in a cybersecurity program is not the same as having the visibility needed to protect them. According to our recent research, only 19% of healthcare respondents say facility and building systems are fully integrated into cybersecurity monitoring and protection.
That gap matters during an incident. Standard IT processes do not always fit healthcare OT, IoMT and MCPS environments. A scan, patch or shutdown may affect a clinical workflow or require vendor coordination. IT and OT cybersecurity teams may know a risk exists, but still lack the evidence needed to act quickly.
In healthcare, that view is harder to maintain because facility and clinical systems are often distributed across sites and managed by different teams. Visibility must go beyond asset discovery. Leaders need to understand how systems are connected, how they are accessed and what could happen if those systems are disrupted.
Shared responsibility requires clear coordination
Healthcare OT, IoMT and MCPS security often require coordination across IT, OT cybersecurity, facilities, clinical engineering and operations teams. That shared model can be a strength when roles, monitoring and response plans are aligned. Our research reflects how common this model is: 40% of healthcare respondents say OT cybersecurity responsibility is shared across IT, security and operations.
The challenge comes when shared responsibility is not matched by clear accountability. Risks may be identified but not assigned. Decisions can stall. Response plans can also miss operational realities if facilities or clinical engineering teams are not included in cybersecurity planning.
The impact can be practical and immediate. If temperature monitoring, airflow management, pressure control or environmental controls are disrupted, healthcare teams may need to act quickly to protect operating rooms, ICUs, isolation areas, vaccine storage, cold-chain environments or other controlled care settings. Real-world cyber activity has also targeted the vaccine cold chain, underscoring why temperature-controlled healthcare environments need clear visibility, monitoring and response plans.1
The operational stakes are significant. In our OT cybersecurity research, 67% of healthcare respondents say a significant cyber incident could have severe or high impact on caregiver and/or patient safety, or physical equipment damage.
Compliance pressure requires operational evidence
Healthcare cyber compliance requirements are also increasing. It is no longer enough to document that policies exist. Leaders need evidence showing which OT, IoMT and MCPS systems are in scope, where cybersecurity controls apply and whether response plans account for operational disruption.
That evidence is difficult to produce without clear visibility across connected clinical, facility, infrastructure and medical device environments. Comprehensive visibility supports audit readiness and helps teams show how cybersecurity planning accounts for operational systems, response roles and potential disruption.
Healthcare OT, IoMT and MCPS cybersecurity expectations increasingly reinforce the need for visibility, accountability and evidence across connected environments.
- HIPAA Security Rule to Strengthen the Cybersecurity of Electronic Protected Health Information: Proposed updates call attention to several areas relevant to OT and cyber-physical security. These include technology asset inventory, risk analysis, patch management, assigned security responsibility, incident procedures and contingency planning. They also include compliance audits, facility access controls, vulnerability management and backup/recovery requirements.2
- FDA Medical Device Cybersecurity Guidance: Current FDA guidance provides recommendations for cybersecurity device design, labeling and premarket submission documentation for devices with cybersecurity risk.3
- HHS 405(d) Program and HICP: The HHS 405(d) Program provides healthcare and public health sector resources to strengthen cybersecurity practices, including Health Industry Cybersecurity Practices: Managing Threats and Protecting Patients.4
How Honeywell Technologies helps strengthen healthcare OT cybersecurity
For healthcare leaders, the next step is to understand where OT, IoMT and MCPS environments are exposed, who owns the risk and which actions can reduce disruption.
Healthcare environments tend to include technologies from many vendors. Honeywell Technologies helps healthcare organizations gain clearer visibility across IoMT, MCPS, building, safety, physical security and infrastructure systems that support connected healthcare operations. Its OT and CPS security capabilities are designed to help organizations assess exposure and improve vendor-neutral visibility.
That clearer view can strengthen cyber-physical security across connected operational environments. For teams with limited internal capabilities, Honeywell also offers managed and co-managed healthcare cybersecurity services to support ongoing improvement.
Connect with us to assess your healthcare operations exposure and identify practical next steps.
1 Cybersecurity and Infrastructure Security Agency. “IBM Releases Report on Cyber Actors Targeting the COVID-19 Vaccine Supply Chain.” Alert, Dec. 3, 2020; last revised Jan. 25, 2022.
2 Federal Register. “HIPAA Security Rule to Strengthen the Cybersecurity of Electronic Protected Health Information.” Proposed rule, Jan. 6, 2025.
3 U.S. Food and Drug Administration. “Cybersecurity in Medical Devices: Quality Management System Considerations and Content of Premarket Submissions.” Guidance for Industry and Food and Drug Administration Staff, Feb. 3, 2026.
4 U.S. Department of Health and Human Services 405(d) Program. “Health Industry Cybersecurity Practices: Managing Threats and Protecting Patients.” 2023 Edition.