News | Cybersecurity | August 08, 2025

Study: More than 1 Million Healthcare Devices, Systems Exposed Online

Researchers found that 1.2 million healthcare devices and systems were exposed online — risking exposure of patient records.


Aug. 07, 2025 —- New research by European cybersecurity company Modat revealed more than 1.2 million internet-connected healthcare devices and systems are exposed and vulnerable to exploitation endangering patient data. The number one finding in the study showed there are more than 174,000 exposed systems in the United States (most results are across Europe, the USA, and the MENA). 

Research was conducted using Modat's unique internet scanning platform Modat Magnify.  Findings across more than 70 different types of medical devices and systems including: MRI, CT, X-rays, DICOM viewers, blood test systems, hospital management systems and other accessible medical systems. Reasons for Vulnerable Devices are misconfigurations and insecure management settings, default or weak passwords and unpatched vulnerabilities in firmware or software.

Researchers discovered many systems lacked even basic authentication. Some used factory-default or weak passwords like, “admin” or “123456.” In other cases, outdated or unpatched software left critical devices vulnerable to exploitation. These oversights compromise patient confidentiality and may open a path for cybercriminals to carry out fraud, extortion, or network infiltration.

One scan, for instance, exposed a patient’s chest and brain MRI results, with names and medical history. Records include highly sensitive PHI info and PII info. Researchers uncovered a range of other medical images: optician eye exams, dental X-rays, blood test results, detailed lung MRIs commonly used to aid patients suffering from lung cancer. 

Modat immediately reached to international partners Health-ISAC and Dutch CERT Z-CERT to initiate process of Responsible Disclosure as they will reach out to affected organizations to assist them in fixing these security breaches. 

The findings emphasize that cybersecurity in healthcare is an IT concern, and a matter of patient safety.

These systems should never be exposed to the internet in the first place. Soufian El Yadmani, Modat CEO stated, “The question we should be asking is, 'Why are there MRI scanners with internet connectivity that lack proper security measures?'”  

El Yadmani continued, "The primary risk is unnecessary network exposure. These medical systems should only be connected to secure, properly configured networks when there is a legitimate clinical need for remote access.” 

Recommendations include need for organizations to implement regular security assessments and maintain comprehensive asset inventories, continuous monitoring of network-connected devices is essential for identifying potential exposures, misconfigurations, or emerging vulnerabilities. 

Full blog post is available at http://bit.ly/4moChak  


Related Content

Feature | Cath Lab | Kyle Hardner

Since receiving FDA approval in 2016, intravascular lithotripsy (IVL) systems have grown in popularity among ...

Home November 14, 2025
Home
News | Cath Lab

Nov. 11, 2025 — FastWave Medical has successfully completed enrollment in its 30-patient coronary feasibility study and ...

Home November 13, 2025
Home
News | Cath Lab

Oct. 28, 2025 — Results from the first-of-its-kind randomized PROCTOR trial found that a strategy of saphenous vein ...

Home November 04, 2025
Home
News | Cath Lab

Oct. 27, 2025 — Results from the PREVUE-VALVE study suggest that there are currently at least 4.7 million people aged 65 ...

Home October 29, 2025
Home
News | Cath Lab

Oct. 25, 2025 — Medtronic plc has announced the launch of the Stedi Extra Support guidewire, designed to enhance ...

Home October 28, 2025
Home
News | Cath Lab

Oct. 27, 2025 — Elixir Medical, a developer of technologies to treat cardiovascular disease, has announced new clinical ...

Home October 28, 2025
Home
News | Cath Lab

Oct. 22, 2025 — Heartflow, Inc. has introduced Heartflow PCI Navigator, the newest addition to the Heartflow One ...

Home October 23, 2025
Home
News | Cath Lab

Oct. 15, 2025 — Stereotaxis recently announced it has obtained CE Mark in Europe and submitted a 510(k) application to ...

Home October 16, 2025
Home
News | Cath Lab

Oct. 7, 2025 — Medtronic has announced the full distribution of the Neuroguard IEP System (Neuroguard) after a ...

Home October 07, 2025
Home
News | Cath Lab

Sept. 22, 2025 — Nicklaus Children's Heart Institute in Miami, Florida, is now offering bedside transcatheter patent ...

Home September 23, 2025
Home
Subscribe Now