Health-ISAC 2026 Health Sector Security Workshop
- Date:
- Thursday, October 22
- Location:
- Boston Scientific, St. Paul, Minnesota
The Health-ISAC Health Sector Security Workshop brings health sector security professionals together in St. Paul for a full day focused on building resilience in health sector organizations. Hosted at Boston Scientific, the workshop gives practitioners from across the health ecosystem space to trade threat intel, lessons learned, and new approaches, with tabletop exercises putting those ideas to work. Bishop Fox is supporting the workshop and the community of defenders it brings together.
Our own Shad Malloy takes the stage mid-morning with "Patched, Isolated, Proven?" Shad focuses on network penetration testing, vulnerability risk management, and application security, and has advised organizations across health care, financial services, energy, and technology. He has also worked in and managed security for education, health care, and national government agencies.
You'll find the Bishop Fox team on site throughout the day. Catch us between sessions to dig into Shad's talk, compare notes from the tabletop exercises, or talk shop about what's actually holding up in health sector security.
To RSVP, visit: Health-ISAC Security Workshop
"Patched, Isolated, Proven?"
Speakers: Shad Malloy, Sr. Managing Consultant II, Bishop Fox
Date/Time: Thursday, October 22 | 10:05–10:35 a.m. CDT
Abstract: Medical device security conversations still open with a myth: "we can't patch — FDA won't let us." The FDA has said the opposite for a decade. The real constraints are validation effort, vendor capacity, and clinical scheduling — solvable problems, but only once we stop blaming the regulator.
This talk reframes the problem around two realities. First, since March 2023, Section 524B has split every hospital's fleet into two eras: newer connected devices arrive with required postmarket plans, patch cadences, and SBOMs, while older devices still depend entirely on each manufacturer's discretion. You can't tell which era a device belongs to from the asset inventory — you ask, and the right time to ask is in procurement. Four contract metrics make that concrete: SBOM currency, a vulnerability-to-patch SLA, lifecycle dates including end-of-guaranteed support, and an MDS2 with a clear patch-responsibility split.
Second, for the devices you can't patch fast, isolation is the compensating control — and it is almost always assumed rather than proven. Drawing on 160+ Bishop Fox healthcare assessments from 2024–2026, the session walks through the predictable places isolation breaks: dual-homed biomed workstations, vendor remote access, unexpected device egress (Contec CMS8000 re-enabling its own NIC is the extreme case), and air gaps that red teams routinely cross. It closes with five test questions hospitals can run safely alongside clinical engineering, and a look at where the HIPAA Security Rule NPRM, HHS CPGs, and the September 2026 Health-ISAC MedTech Security Baselines are taking required practice next.