logo
episode-header-image
May 19
42m 21s

#407: Cybersecurity in MedTech: FDA Comp...

Greenlight Guru + Medical Device Entrepreneurs
About this episode

Christian Espinosa, founder of Blue Goat Cyber and leading voice in medical device cybersecurity, joins Etienne Nichols to unpack the urgent and often misunderstood topic of cybersecurity in MedTech. From FDA’s 2023 regulatory overhaul to real-world hacking scenarios that could harm patients, Christian provides practical advice for innovators, RA/QA professionals, and software teams. He also shares why waiting until the last minute on cybersecurity could cost startups millions—or even kill a project entirely.

Whether you're a quality professional trying to build compliant systems or an innovator racing toward FDA submission, this episode lays out exactly what you need to know to stay ahead of cyber threats and within regulatory guardrails.

Key Timestamps:

  • 00:01 – Intro to guest Christian Espinosa and Blue Goat Cyber
  • 06:28 – Why medical device cybersecurity is different from traditional IT security
  • 11:49 – Real-world hacking example: acne laser device turned skin-burner
  • 13:57 – FDA expectations post-September 2023: what changed
  • 17:12 – Secure boot: a microcontroller mistake that derailed a launch
  • 20:35 – Common cybersecurity vendor mistake MedTech companies make
  • 23:40 – SBOM: Software Bill of Materials and why it's legally critical
  • 27:58 – Cyberattacks in hospitals: assuming a hostile network
  • 35:44 – AI in medical devices: data bias and cybersecurity challenges
  • 41:10 – Developers ≠ cybersecurity experts: the training gap nobody talks about
  • 45:20 – What RA/QA professionals need to know now
  • 49:30 – Why cybersecurity must be iterative, not a final-phase add-on
  • 55:20 – Espinosa's final advice for MedTech professionals
  • 57:52 – The story behind “Blue Goat Cyber”

Standout Quotes:

“Cybersecurity for medical devices isn’t about data breaches—it’s about patient harm. You could paralyze someone or misdiagnose sepsis. This isn’t theoretical.”
— Christian Espinosa, on the real risks of insecure devices

“Most developers don’t understand cybersecurity. We assume they do—but that’s like expecting an architect to be a locksmith.”
— Christian Espinosa, on why so many devices fail security assessments

Top Takeaways:

  1. Cybersecurity isn’t just about data—it's about patient safety. From burning skin to missed sepsis diagnoses, vulnerabilities in devices have real-world harm potential.
  2. FDA now requires more than just a basic security plan. Post-September 2023 rules mandate testing (SAST, DAST, fuzzing), SBOMs, and risk assessments tied to patient harm.
  3. Start cybersecurity planning during the requirements phase. Hardware like microcontrollers must support secure boot and other protections—retrofits can cripple product plans.
  4. Iterate cybersecurity like any core development activity. One-time testing near submission is too late; build security into your pipeline just like QA or usability.
  5. Traditional cybersecurity vendors aren’t enough. Many fail to meet FDA’s nuanced expectations for medical devices, causing costly submission rejections.

References & Resources:


MedTech 101 – Understanding SBOM (Software Bill of...

Up next
Jul 7
#414: Why Global Certification is the Future of Clinical Research in Latin America
As global clinical trials become more competitive and data-driven, Latin America is stepping up with a new global standard in clinical trial quality. In this episode, Etienne Nichols speaks with Julio Martinez-Clark, CEO of BioAccess and a key advocate for clinical site certifica ... Show More
34m 49s
Jun 30
#413: Budgeting Blind Spots: What MedTech Startups Miss—and How Investors See It
In this episode of the Global Medical Device Podcast, Etienne Nichols sits down with seasoned MedTech founder and investor Jon Bergsteinsson to unpack a critical—but often overlooked—topic: budgeting in early-stage medical device startups. Drawing from his deep regulatory, clinic ... Show More
35m 24s
Jun 23
#412: How to Build a QMS That Actually Works: From Startup to Scale in MedTech
In this live episode from the LSI conference in California, Etienne Nichols is joined by Ashkon Rasooli to break down what it really takes to build a high-performing quality management system (QMS) in medtech—from startup chaos to post-market scale. Ashkon shares a phased approac ... Show More
16m 58s
Recommended Episodes
Nov 2024
Growing Diet Doctor to Over 500k Daily Website Hits w/Dr Andreas Eenfeldt
This interview explores innovation in health technology, focusing on the creation of user-friendly tools that simplify nutrition tracking and health monitoring for the average person. The speaker discusses the traditional complexity of tracking nutrition and calories, noting that ... Show More
24m 54s
Jul 2024
Digital Health Festival 2024: Medtech's Geoffrey Sayer on Transforming GP Software Systems
In this episode of The Good GP, hosts Dr Tim Koh and Dr Sean Stevens speak with Geoffrey Sayer, CEO of Medtech, at the Digital Health Festival 2024. Geoffrey introduces Medtech, an electronic health record system designed to service practices in Australia and New Zealand, providi ... Show More
13m 31s
Sep 2024
Software Development in the Evolving World of Medical Devices and Applications - with Urvashi Tyagi of ResMed
Today’s guest is Urvashi Tyagi, Advisor and Former CTO at ResMed. Urvashi joins us on today’s podcast with Emerj Senior Matthew DeMello to discuss the unique challenges healthcare leaders face in driving software development efficiencies for medical devices and customer-facing mo ... Show More
22m 53s
Feb 2025
AI Biohacking Breakthroughs: Transform Your Health with Gary Brecka's Top Strategies | EP #149
In this episode, Gary and Peter discuss the most important bio hacks people should know and cover a list of health tech gadgets they have at home and use daily to live longer.  Recorded on Jan 23rd, 2024Views are my own thoughts; not Financial, Medical, or Legal Advice. Gary Brec ... Show More
1h 37m
Jul 2024
The Change Management Prescription: Vital Strategies for Healthcare Transformation
In this episode, Dr. Fatih Mehmet Gül interviews Vivek Shukla, a renowned healthcare leader, about the critical role of change management in healthcare. They discuss the keys to successful change management, the leadership principles that foster excellence in healthcare, and the ... Show More
33m 42s
Sep 2024
Growing as a CPO as your product grows from 0 to $10B valuation | Tomer London, Co-founder and Chief Product Officer at Gusto | E235
In this episode, of The Product Podcast, we chat with Tomer London,Co-founder and Chief Product Officer of Gusto, the leading HR platform for small and medium-sized businesses in the US. Tomer shares his journey from coding his first inventory management system for his dad’s clot ... Show More
45m 50s
May 1
Building Readiness for AI Agents in Healthcare Systems - with Raheel Retiwalla of Productive Edge
Today’s guest is Raheel Retiwalla, Chief Strategy Officer at Productive Edge — a digital transformation consultancy focused on healthcare. Productive Edge works with payers, providers, and health tech firms to leverage AI, data, and modern platforms to streamline operations, cut ... Show More
33m 22s
Jun 2024
Unlocking Growth: How Digital Innovation is Transforming Commercial Manufacturing
In this episode of "Driving Digital in Biopharma," host Tom Lehmann welcomes Morrey Atkinson, the Chief Technology and Operations Officer at Vertex Pharmaceuticals. With a rich background in process development and manufacturing within the pharmaceutical industry, Morrey shares h ... Show More
33m 42s
Nov 2024
Episode 197: Aligning Product Development with Business Objectives in Healthcare with BJ Boyle
This time on the Product Thinking Podcast, Melissa Perri is joined by BJ Boyle, Chief Product Officer at PointClickCare, to discuss the critical intersection of healthcare technology and product management. With over two decades of experience in the health tech space, BJ shares i ... Show More
42m 15s
Oct 2024
Mastering Product-led Growth (PLG) & Sales-led Growth (SLG) for Enterprise | Calendly Chief Product Officer, Stephen Hsu | E241
In this episode, Stephen Hsu, Chief Product Officer at Calendly, shares his insights on navigating the AI landscape and transforming Calendly into a comprehensive meeting lifecycle platform. He discusses the challenges of evolving from a simple scheduling tool to a robust solutio ... Show More
42m 21s