Health-ISAC 2026 Health Sector Security Workshop

Date:
Thursday, October 22
Location:
Boston Scientific, St. Paul, Minnesota
Health-ISAC Health Sector Security Workshop conference graphic featuring the Health-ISAC logo on a retro computer monitor.

The Health-ISAC Health Sector Security Workshop brings health sector security professionals together in St. Paul for a full day focused on building resilience in health sector organizations. Hosted at Boston Scientific, the workshop gives practitioners from across the health ecosystem space to trade threat intel, lessons learned, and new approaches, with tabletop exercises putting those ideas to work. Bishop Fox is supporting the workshop and the community of defenders it brings together.

Our own Shad Malloy takes the stage mid-morning with "Patched, Isolated, Proven?" Shad focuses on network penetration testing, vulnerability risk management, and application security, and has advised organizations across health care, financial services, energy, and technology. He has also worked in and managed security for education, health care, and national government agencies.

You'll find the Bishop Fox team on site throughout the day. Catch us between sessions to dig into Shad's talk, compare notes from the tabletop exercises, or talk shop about what's actually holding up in health sector security.

To RSVP, visit: Health-ISAC Security Workshop

"Patched, Isolated, Proven?"

Speakers: Shad Malloy, Sr. Managing Consultant II, Bishop Fox

Date/Time: Thursday, October 22 | 10:05–10:35 a.m. CDT

Abstract: Medical device security conversations still open with a myth: "we can't patch — FDA won't let us." The FDA has said the opposite for a decade. The real constraints are validation effort, vendor capacity, and clinical scheduling — solvable problems, but only once we stop blaming the regulator.

This talk reframes the problem around two realities. First, since March 2023, Section 524B has split every hospital's fleet into two eras: newer connected devices arrive with required postmarket plans, patch cadences, and SBOMs, while older devices still depend entirely on each manufacturer's discretion. You can't tell which era a device belongs to from the asset inventory — you ask, and the right time to ask is in procurement. Four contract metrics make that concrete: SBOM currency, a vulnerability-to-patch SLA, lifecycle dates including end-of-guaranteed support, and an MDS2 with a clear patch-responsibility split.

Second, for the devices you can't patch fast, isolation is the compensating control — and it is almost always assumed rather than proven. Drawing on 160+ Bishop Fox healthcare assessments from 2024–2026, the session walks through the predictable places isolation breaks: dual-homed biomed workstations, vendor remote access, unexpected device egress (Contec CMS8000 re-enabling its own NIC is the extreme case), and air gaps that red teams routinely cross. It closes with five test questions hospitals can run safely alongside clinical engineering, and a look at where the HIPAA Security Rule NPRM, HHS CPGs, and the September 2026 Health-ISAC MedTech Security Baselines are taking required practice next.


Shad Malloy Headshot

About the speaker, Shad Malloy

Sr. Managing Consultant II

Shad Malloy is a Sr. Managing Consultant II at Bishop Fox focused on network penetration testing, vulnerability risk management, and application security. He has advised multiple industries including health care, financial services, energy, and technology. In addition to time working and managing security for education, health care, and national government agencies. Shad holds a Bachelor of Science in Computer Information Systems as well as industry certifications like the CISSP.

Ready to get started? We can help.

Contact Us