Cybersecurity Questions to Ask Before Connecting a Diagnostic Device
Connecting a home health imaging device or diagnostic tool to your Wi-Fi and creating an account raises three separate cybersecurity questions: is the device itself secure, is your account secure, and where does your health data actually go once it leaves the device? Most people answer none of these before tapping “allow.” This guide walks through all three, using current FDA and HHS guidance, without evaluating any specific product.
Why Device, Account, and Data Privacy Are Three Different Questions
A connected diagnostic device is not one thing to secure. It is at least three, and each has its own weak points:
- The device itself — protects its software and wireless connection. Key question: does the manufacturer still support updates?
- Your account — protects the login used to view your results. Key question: is your password unique, with two-factor enabled?
- Your health data — protects images or readings once they leave the device. Key question: who operates the app or portal receiving them?
Stage One: What to Check Before You Connect the Device
The FDA notes that medical devices increasingly connect to the internet, hospital networks, and other devices to improve care — and that these same connections create cybersecurity risk. Under a 2023 federal law change, manufacturers of many newly regulated “cyber devices” must build in cybersecurity considerations and document them as part of getting a device cleared for sale.
Before connecting a device to your network, it’s worth asking:
- Does the manufacturer publish a way to receive security updates, and has it committed to supporting the device for a stated period?
- Does the device let you set a unique password, rather than shipping with one you can’t change?
- Is there a public channel for reporting a suspected security problem with the device?
You don’t need to evaluate the engineering yourself. You’re checking whether the manufacturer treats these as answerable questions at all — a manufacturer with no visible update process or reporting channel is a different risk profile than one that publishes both.
Stage Two: Everyday Use and Account Security
Once a device is running, most day-to-day risk shifts to the account and app layer, which behaves like any other online account you manage. Steps that apply regardless of which device or app you’re using:
- Use a password you don’t reuse elsewhere, and turn on two-factor authentication if it’s offered.
- Review what the app’s permissions actually allow — location or contact access it doesn’t need to function.
- Check whether old devices or logins are still listed as “active,” and remove ones you no longer use.
Stage Three: Where Does Your Health Information Actually Go?
This is the layer people assume HIPAA covers, and it often doesn’t — depending on who built the app.
HHS explains that once your health information is sent, at your own direction, to an app that is neither your doctor’s office, hospital, nor insurer (and not working on their behalf), that information is generally no longer covered by HIPAA’s rules. The app becomes responsible to you under its own privacy policy and applicable consumer protection law, not HIPAA. HHS also notes your provider generally cannot refuse to send data to an app of your choosing out of concern for how that app might use it.
This means the relevant question is rarely “is this HIPAA compliant?” It’s usually:
- Who actually built and operates this app — my clinic, my insurer, or an independent company?
- Does the app’s privacy policy say whether it sells or shares data with advertisers or data brokers?
- Can I delete my account and data, and what happens to copies that already exist?
A Decision Path You Can Use
Working through the three layers in order keeps the decision manageable:
- Device: Confirm the manufacturer supports updates and publishes a way to report problems.
- Account: Set a unique password and review the app’s permissions.
- Data: Identify who operates the app receiving your information and what its policy says about sharing it.
If you can’t answer one of these, that tells you exactly where to slow down and ask more questions — of the manufacturer, your clinician, or the app’s own support channel.
When Something Feels Wrong
If a device or app behaves unexpectedly — unrecognized logins, a device that won’t update, or an app requesting data access unrelated to its function — the FDA maintains a public reporting channel (MedWatch) for patients and caregivers to report suspected device cybersecurity issues. Reporting doesn’t require certainty that something is wrong; it’s a way to flag a concern for review.
Frequently Asked Questions
Does HIPAA protect my data once it’s sent to a health app?
Only if the app was provided by, or works on behalf of, your covered provider or insurer. If you chose an independent app yourself, HHS guidance says that data is generally no longer subject to HIPAA once it reaches the app.
Can my doctor refuse to send my data to an app I choose?
Generally no. HHS guidance states a covered provider cannot refuse to send readily producible data to a third-party app you’ve designated, including over concerns about how that app will use the data.
Who is responsible for a device’s cybersecurity — the manufacturer or my healthcare facility?
Both, in different ways. The FDA describes manufacturers as responsible for identifying and addressing device-level risks, while healthcare facilities are responsible for their own network security and mitigations on their end.
What should I do if I suspect a cybersecurity problem with a device?
Patients and caregivers can report suspected cybersecurity issues to the FDA through the MedWatch voluntary reporting program. You don’t need certainty that something is wrong to report a concern.
Are all connected medical devices legally required to have cybersecurity protections?
Not automatically. The additional cybersecurity submission requirements under federal law, effective March 2023, apply specifically to devices meeting the legal definition of a “cyber device,” not to every connected device on the market.
This information is general and educational. It does not evaluate any specific device, brand, or app, and it is not a substitute for guidance from your device manufacturer, your healthcare provider, or a qualified security or privacy professional about your individual situation.
Sources: U.S. Food and Drug Administration, Medical Device Cybersecurity; U.S. Department of Health and Human Services, The Access Right, Health Apps, and APIs.
For more on how this publication evaluates and sources its guides, see How We Research and our Editorial Policy. New to the site? Start with our Start Here page.
By Connected Diagnostics Evidence Editorial Team. Last updated September 9, 2026. Connected Diagnostics Evidence is an independent educational publication and is not affiliated with, and does not continue the products, research, or operations of, any former company that previously used this domain.
Leave a Reply