logo
episode-header-image
May 2025
42m 21s

#407: Cybersecurity in MedTech: FDA Comp...

Greenlight Guru + Medical Device Entrepreneurs
About this episode

Christian Espinosa, founder of Blue Goat Cyber and leading voice in medical device cybersecurity, joins Etienne Nichols to unpack the urgent and often misunderstood topic of cybersecurity in MedTech. From FDA’s 2023 regulatory overhaul to real-world hacking scenarios that could harm patients, Christian provides practical advice for innovators, RA/QA professionals, and software teams. He also shares why waiting until the last minute on cybersecurity could cost startups millions—or even kill a project entirely.

Whether you're a quality professional trying to build compliant systems or an innovator racing toward FDA submission, this episode lays out exactly what you need to know to stay ahead of cyber threats and within regulatory guardrails.

Key Timestamps:

  • 00:01 – Intro to guest Christian Espinosa and Blue Goat Cyber
  • 06:28 – Why medical device cybersecurity is different from traditional IT security
  • 11:49 – Real-world hacking example: acne laser device turned skin-burner
  • 13:57 – FDA expectations post-September 2023: what changed
  • 17:12 – Secure boot: a microcontroller mistake that derailed a launch
  • 20:35 – Common cybersecurity vendor mistake MedTech companies make
  • 23:40 – SBOM: Software Bill of Materials and why it's legally critical
  • 27:58 – Cyberattacks in hospitals: assuming a hostile network
  • 35:44 – AI in medical devices: data bias and cybersecurity challenges
  • 41:10 – Developers ≠ cybersecurity experts: the training gap nobody talks about
  • 45:20 – What RA/QA professionals need to know now
  • 49:30 – Why cybersecurity must be iterative, not a final-phase add-on
  • 55:20 – Espinosa's final advice for MedTech professionals
  • 57:52 – The story behind “Blue Goat Cyber”

Standout Quotes:

“Cybersecurity for medical devices isn’t about data breaches—it’s about patient harm. You could paralyze someone or misdiagnose sepsis. This isn’t theoretical.”
— Christian Espinosa, on the real risks of insecure devices

“Most developers don’t understand cybersecurity. We assume they do—but that’s like expecting an architect to be a locksmith.”
— Christian Espinosa, on why so many devices fail security assessments

Top Takeaways:

  1. Cybersecurity isn’t just about data—it's about patient safety. From burning skin to missed sepsis diagnoses, vulnerabilities in devices have real-world harm potential.
  2. FDA now requires more than just a basic security plan. Post-September 2023 rules mandate testing (SAST, DAST, fuzzing), SBOMs, and risk assessments tied to patient harm.
  3. Start cybersecurity planning during the requirements phase. Hardware like microcontrollers must support secure boot and other protections—retrofits can cripple product plans.
  4. Iterate cybersecurity like any core development activity. One-time testing near submission is too late; build security into your pipeline just like QA or usability.
  5. Traditional cybersecurity vendors aren’t enough. Many fail to meet FDA’s nuanced expectations for medical devices, causing costly submission rejections.

References & Resources:


MedTech 101 – Understanding SBOM (Software Bill of...

Up next
Oct 6
#427: Medical Device Reimbursement - Pitfalls to Avoid
This episode tackles the often-overlooked but critical topic of medical device reimbursement. Host Etienne Nichols speaks with Haley King, co-founder and CEO of Paxos Health, about why this process is just as vital as FDA approval for a device's commercial success. They explore t ... Show More
41m 12s
Sep 29
#426: Software as a Medical Device: Securing Your Digital Future
In this episode, host Etienne Nichols sits down with Jose Bohorquez and Mohamad Foustok from CyberMed to dissect the complex world of Software as a Medical Device (SaMD) and cybersecurity. They emphasize that SaMD is first and foremost a medical device and should be treated as su ... Show More
44m 59s
Sep 22
#425: The "Front End" of Medical Device Innovation: From Idea to Market
This episode with Stuart Grant of Archetype MedTech demystifies the "front end of innovation," a critical yet often overlooked phase of medical device development. Stuart, a seasoned MedTech veteran with over two decades of experience at Johnson & Johnson, shares insights from hi ... Show More
41m 58s
Recommended Episodes
Nov 2024
Growing Diet Doctor to Over 500k Daily Website Hits w/Dr Andreas Eenfeldt
This interview explores innovation in health technology, focusing on the creation of user-friendly tools that simplify nutrition tracking and health monitoring for the average person. The speaker discusses the traditional complexity of tracking nutrition and calories, noting that ... Show More
24m 54s
Jul 2024
Digital Health Festival 2024: Medtech's Geoffrey Sayer on Transforming GP Software Systems
In this episode of The Good GP, hosts Dr Tim Koh and Dr Sean Stevens speak with Geoffrey Sayer, CEO of Medtech, at the Digital Health Festival 2024. Geoffrey introduces Medtech, an electronic health record system designed to service practices in Australia and New Zealand, providi ... Show More
13m 31s
Sep 2024
Software Development in the Evolving World of Medical Devices and Applications - with Urvashi Tyagi of ResMed
Today’s guest is Urvashi Tyagi, Advisor and Former CTO at ResMed. Urvashi joins us on today’s podcast with Emerj Senior Matthew DeMello to discuss the unique challenges healthcare leaders face in driving software development efficiencies for medical devices and customer-facing mo ... Show More
22m 53s
Feb 2025
AI Biohacking Breakthroughs: Transform Your Health with Gary Brecka's Top Strategies | EP #149
In this episode, Gary and Peter discuss the most important bio hacks people should know and cover a list of health tech gadgets they have at home and use daily to live longer.  Recorded on Jan 23rd, 2024Views are my own thoughts; not Financial, Medical, or Legal Advice. Gary Brec ... Show More
1h 37m
Jul 2024
The Change Management Prescription: Vital Strategies for Healthcare Transformation
In this episode, Dr. Fatih Mehmet Gül interviews Vivek Shukla, a renowned healthcare leader, about the critical role of change management in healthcare. They discuss the keys to successful change management, the leadership principles that foster excellence in healthcare, and the ... Show More
33m 42s
Sep 2024
Growing as a CPO as your product grows from 0 to $10B valuation | Tomer London, Co-founder and Chief Product Officer at Gusto | E235
In this episode, of The Product Podcast, we chat with Tomer London,Co-founder and Chief Product Officer of Gusto, the leading HR platform for small and medium-sized businesses in the US. Tomer shares his journey from coding his first inventory management system for his dad’s clot ... Show More
45m 50s
May 2025
Building Readiness for AI Agents in Healthcare Systems - with Raheel Retiwalla of Productive Edge
Today’s guest is Raheel Retiwalla, Chief Strategy Officer at Productive Edge — a digital transformation consultancy focused on healthcare. Productive Edge works with payers, providers, and health tech firms to leverage AI, data, and modern platforms to streamline operations, cut ... Show More
33m 22s
Apr 2025
Driving Multi-Modal Retail and Healthcare CX - with Brett Kiley of CVS Health
In this episode of the AI in Business Podcast, Brett Kiley, Executive Director of Customer Experience and Client Solutions at CVS Health, joins us for a compelling discussion on the evolving landscape of customer interactions. With over two decades of experience, Brett shares how ... Show More
18m 38s
Jan 2025
Launching a Medical Device Company with David Gomez
Have you ever dreamed of starting your own medical business but aren’t sure how to bring an idea to life? Today we’re excited to welcome on David Gomez, CRNA, to share his experience of starting a medical device company from the ground up. David's story is one of perseverance and ... Show More
47m 36s
Sep 17
From Clinician to Chief Health AI Officer: A Conversation with Dr. Karandeep Singh
Dr. Karandeep Singh brings two worlds together: programming and medicine. In this conversation, he explains how early experiments with code led him to biomedical informatics, why gaps between paper performance and clinical reality must be confronted, and how governance committees ... Show More
1h 2m