As healthcare delivery has shifted toward more distributed, data-driven models, telehealth has transformed from a tool for remote consultations into a connected care environment. Today, it encompasses a sophisticated ecosystem where connected medical devices continuously transmit patient data from homes, clinics, and hospitals to clinical care teams across geographic boundaries. This transformation enables what healthcare professionals call “Hospital-at-Home” care — where patients receive monitoring and treatment in domestic environments supported by Internet of Medical Things (IoMT) devices and telecommunication infrastructure.
Telehealth use expanded sharply during the COVID-19 public health emergency and has remained part of routine care delivery, particularly for behavioral health, chronic condition management, and follow-up visits. This growth reflects sustained investment in telehealth infrastructure, expanding reimbursement coverage, and growing patient acceptance of remote care.
This growth reflects sustained investments in telehealth infrastructure, expanding reimbursement coverage, and growing patient acceptance of remote care. However, this expansion simultaneously creates cybersecurity challenges that the healthcare industry has to manage. Programs like the IEEE Medical Device Cybersecurity Certification Program have emerged to help device manufacturers, clinicians, and hospitals work collaboratively toward a safer, more integrated healthcare environment.
The Architecture of Connected Care
The technical architecture enabling telehealth relies on a three-layer IoMT system: the data acquisition layer, the personal server layer, and the medical server layer. At the foundation, connected medical devices capture biomedical signals through sensors which may be integrated with personal smart devices and hospital information systems supporting clinical decision-making.
Remote patient monitoring (RPM) and remote therapeutic monitoring (RTM) represent the vast majority of applications of IoT devices in healthcare. Medical devices can transmit vital signs and other data to clinicians, allowing them to make treatment changes in real time without requiring in-person visits. This capability has proven particularly valuable for managing chronic conditions where continuous monitoring can detect deterioration before it becomes critical.
The diversity of connected devices supporting telehealth is remarkable. Wearable monitoring devices include smartwatches tracking cardiovascular parameters, continuous glucose monitors for diabetes management, and wearable ECG patches detecting atrial fibrillation. Implantable devices encompass pacemakers, implantable cardioverter defibrillators, and insulin pumps delivering automated therapy. Approved devices or apps that can track patient’s musculoskeletal status, respiratory status, and medication or therapy adherence. Home-based clinical equipment includes smart blood pressure monitors, connected inhalers for asthma and COPD management, digital scales for heart failure patients tracking fluid retention, and home dialysis machines with remote monitoring capabilities.
These devices generate enormous quantities of real-time biometric data using communication protocols like MQTT, CoAP, and 6LoWPAN. Healthcare systems rely on a mix of these protocols to manage data from thousands of devices, ensuring telemetry, alerts, and security events reach central monitoring systems efficiently. Research published in Scientific Reports, a Nature Portfolio journal, demonstrates that hybrid fog-edge computing architectures tailored for real-time health monitoring achieve a 70% latency reduction and 60% bandwidth savings compared to cloud-only models — critical improvements for time-sensitive clinical applications where milliseconds can matter.
The Cybersecurity Challenge
While telehealth and connected medical devices offer tremendous clinical benefits, they simultaneously create what security professionals call an “expanded attack surface.” Traditional healthcare networks assume a secure internal environment protected by enterprise firewalls and professional IT security teams. Telehealth systems, by contrast, must operate reliably across residential internet connections managed by consumer-grade routers often characterized by insecure configurations and outdated firmware.
The scale of vulnerabilities affecting IoMT devices has reached concerning levels. According to DeepStrike’s 2025 IoMT Vulnerabilities Statistics, each connected medical device averages 6.2 software vulnerabilities. Approximately 60% of devices are classified as end-of-life and lack access to security patches. Perhaps most striking, 99% of hospitals manage IoMT devices with at least one known exploited vulnerability. These vulnerabilities persist for extended periods despite patch availability; research documents that patched medical devices remain exposed for an average of 3.2 years after security updates become available, reflecting the complex risk calculation healthcare organizations face when balancing cybersecurity requirements against clinical safety imperatives and operational continuity.
The real-world consequences are significant. In 2024, healthcare experienced 238 ransomware threats and 206 data breach incidents — more than any other critical infrastructure sector, according to the American Hospital Association. The Change Healthcare ransomware attack alone resulted in costs estimated at $2.457 billion according to UnitedHealth Group’s earnings reports, disrupting operations across the healthcare system and resulting in exfiltration of up to 6 terabytes of data including personal information, payment details, and insurance records.
Device-specific vulnerabilities present particularly concerning risks. In early 2025, the US Cybersecurity and Infrastructure Security Agency (CISA) released a notice regarding CVE-2024-12248, a critical vulnerability in the Contec CMS8000 patient monitor classified as a “backdoor” enabling remote code execution. The concern is that successful exploitation of this backdoor could lead to catastrophic outcomes for patients, from suppressing alarms in emergencies to actively manipulating data and preventing emergencies from being detected.
Research from the Proofpoint 2025 Healthcare Cybersecurity Report found that 72% of healthcare organizations experiencing cyberattacks suffered disruption to patient care, with 54% reporting increased medical procedure complications and 29% reporting increased mortality rates. These statistics underscore that cybersecurity in connected medical devices is fundamentally a patient safety issue, not merely an IT concern.
Standards and Industry Response
The healthcare industry has responded to these challenges through the development of cybersecurity standards specifically designed for connected medical devices. The IEEE Medical Device Cybersecurity Certification Program, developed by the IEEE 2621 Conformity Assessment Committee, represents one such effort. The committee includes manufacturers, clinicians, FDA representatives, test laboratories, and cybersecurity solutions providers from around the world.
The FDA has designated IEEE 2621.2 a Recognized Consensus Standard, aligned with national cybersecurity strategies. The standard addresses the FDA’s cybersecurity considerations and Section 524B of the FD&C Act, providing manufacturers with a clear framework for demonstrating device security. This recognition is significant because it means manufacturers can use IEEE 2621 certification to support their premarket submissions, potentially streamlining the regulatory approval process.
For manufacturers, certification offers practical benefits including streamlined regulatory submissions, standardized testing protocols that remove ambiguity from the evaluation process, and inclusion in the IEEE Medical Device Registry — a resource healthcare organizations increasingly consult when evaluating device security. For healthcare providers and patients, these standards provide assurance that certified devices have undergone rigorous third-party security evaluation.
Other IEEE standards also support the broader medical device cybersecurity landscape. IEEE/UL 2933-2024 addresses clinical IoT data and device interoperability through the TIPPSS framework: Trust, Identity, Privacy, Protection, Safety, and Security. IEEE 11073-40101-2020 focuses on cybersecurity processes for vulnerability assessment in health informatics device interoperability, while IEEE 11073-40102-2020 addresses capabilities for local-area-network-based device communication. Together, these standards show that medical device cybersecurity is part of a broader standards ecosystem for connected care.
Building Secure Telehealth Infrastructure
Beyond device certification, healthcare organizations deploying connected medical devices within telehealth programs must implement comprehensive security strategies. Network segmentation directly supports Zero Trust architecture principles by eliminating implicit trust and requiring explicit verification for all network communications involving medical devices and patient data. IEEE 3409-2026 Approved Draft Standard for a Zero Trust Security protects the identity, medical device data, and the healthcare organization by replacing outdated network perimeter defenses with granular, context-aware security controls that treat every internal device request as potentially hostile. By forcing a transition to a Zero Trust Architecture (ZTA), the standard moves medical environments away from broad “trusted networks” and enforces continuous verification across all operational layers
According to Elisity’s healthcare security analysis, effective implementations ensure that infusion pumps communicate only with infusion management servers, vital signs monitors send data exclusively to nurse station systems, and dialysis machines are segmented to communicate only with nephrology systems.
End-to-end encryption represents another foundational safeguard. For in-transit protections, organizations should use WPA3-Enterprise on clinical SSIDs and protect application sessions with TLS 1.2+ or TLS 1.3. For at-rest protections, databases and storage should be encrypted using AES-256, with keys protected in Hardware Security Modules.
Multi-factor authentication adds another layer of protection for telehealth platforms, patient portals, and clinical applications by making it harder for unauthorized users to access systems with stolen credentials. To be most effective, MFA should be aligned with recognized identity and authentication standards, such as NIST’s Digital Identity Guidelines.
Looking Ahead
The integration of connected medical devices into telehealth represents one of the most significant technological transformations in modern healthcare. These technologies offer unprecedented opportunities for improving patient outcomes, reducing healthcare costs, and expanding access to care, particularly for patients with chronic conditions or limited access to specialist providers.
As the telehealth ecosystem continues to mature, the collaboration between device manufacturers, patients, healthcare providers, regulators, and standards organizations will be essential to ensuring that innovation in connected care doesn’t outpace the security measures protecting it. The development of clear, consensus-based standards and programs such as the IEEE Medical Device Cybersecurity Certification Program provides a foundation for that work — helping the industry move toward a future where the benefits of connected healthcare can be realized without compromising patient safety.




