Suzanne Schwartz, who leads FDA’s medical device cybersecurity work, told The Medtech Conference that handling legacy devices remains a work in progress and a problem that needs regulators and industry at the same table. Legacy here means the installed base running software past its support life, which no premarket requirement reaches.
New submissions now carry security requirements under 524B. The fleet already in hospitals predates all of it, keeps running for a decade or more, and belongs to whoever bought it. Every serious answer on legacy, from segmentation to paid support extensions to replacement schedules, costs somebody money, which is why the honest status is still a conference panel shrug.