The Med Device Cyber Podcast
In a time where healthcare and technology are deeply intertwined, understanding medical device cybersecurity is not just important—it's essential. Welcome to The Med Device Cyber Podcast, your go-to resource for understanding the complexities of this critical field of cyber security. As the definitive podcast on medical device security, we explore everything from identifying and mitigating vulnerabilities to navigating this ever-evolving regulatory landscape. Hosted by Christian Espinosa, Founder & CEO of Blue Goat Cyber, and Trevor Slattery, Director of Medical Device Cybersecurity, each episode features expert insights into the latest cybersecurity threats, innovative solutions, and best practices for protecting the medical de...
Why the Best MedTech Candidates Aren’t Applying to Your Jobs with Darwin Shurig | Ep 82
What happens when AI starts screening job candidates who are also using AI to get through the screening process?
In this episode of the Med Device Cyber Podcast, Christian Espinosa speaks with Darwin Shurig, founder of Top Talent Accelerant, about why recruiting in MedTech is becoming increasingly difficult and what companies can do to avoid costly hiring mistakes.
Darwin explores why traditional “post and pray” recruitment is breaking down, how strong candidates can be screened out while weaker candidates use AI to get through the process, and why some highly specialized roles in AI, machine lear...
The Hidden Barriers to Clinical Adoption with Amel Havkic | Ep 81
Why do so many promising MedTech companies fail even when the technology is strong, the funding is there and the product is compliant?
In this episode of the Med Device Cyber Podcast, Christian Espinosa speaks with Amel Havkic, founder of EvoMed Consulting, about the hidden barriers that prevent medical technologies from achieving real clinical adoption.
Amel explains why clinical adoption is often treated too late, how workflow friction can derail an otherwise strong product and why the founder’s greatest strength can sometimes become the company’s biggest strategic blind spot.
The conversation also...
Why Consumer AI Is Not a Medical Device with Tyler Harmon | Ep 80
AI is moving quickly, but medical devices cannot afford to treat every new model like an ordinary software update.
In this episode of the Med Device Cyber Podcast, Christian Espinosa speaks with Tyler Harmon, CEO and co-founder of IASO Automated Medical Systems, about the risks and responsibilities surrounding AI as a medical device.
Tyler explains why consumer tools such as ChatGPT and Claude should not be treated as clinical diagnostic systems, even when a doctor remains involved in the final decision. He also explores why a human in the loop does not automatically make an...
Why Technical Intelligence Is Not Enough with Samantha Silk | Ep 79
A strong résumé may get someone an interview, but technical ability alone does not determine whether they will succeed within an organization.
In this episode of the Med Device Cyber Podcast, Christian Espinosa speaks with Samantha Silk, CEO of Apex Pro Placement, about recruitment, emotional intelligence, and the challenge of identifying the right people for highly technical roles.
Samantha explains why an unfilled critical position can cost an organization thousands of dollars every day, when using a specialist recruiter makes financial sense, and why job descriptions often fail to reflect what the company actually ne...
Productivity, Psychological Safety and AI with Sarah Ohanesian and Jeff Gibbard | Ep 78
Productivity means making meaningful progress on the work that matters most. Yet many organizations remain trapped in repetitive tasks, unclear priorities, unnecessary meetings and systems that rely too heavily on individual employees saving the day.
In this episode of the Med Device Cyber Podcast, Christian Espinosa is joined by Sarah Ohanesian and Jeff Gibbard, co-founders of Super Productive, to explore how teams can reduce friction, improve communication and build working environments that support different kinds of brains.
Sarah and Jeff share practical strategies organizations can implement immediately, including creating a universal system for capturing work...
From Science Fiction to Visual Prosthesis with Frederik Ceyssens | Ep. 77
What if a blind person could use a pair of glasses where information is transmitted wirelessly to an implant in the visual cortex, allowing them to perceive shapes, movement, and elements of their surroundings?
In this episode of the Med Device Cyber Podcast, Christian Espinosa speaks with Frederik Ceyssens, CEO and co-founder of ReVision Implant, about the development of a visual prosthesis designed to restore useful vision by stimulating the brain directly.
Frederik explores why his team chose to bypass the eyes and optic nerve, how flexible electrode arrays can stimulate thousands of points within...
Building Medical Devices Right the First Time with Helen Souris | Ep 76
Bringing an innovative medical device to market takes far more than a great idea. It requires regulatory strategy, cybersecurity, quality systems, and commercial planning from the very beginning.
In this episode of the Med Device Cyber Podcast, Christian Espinosa is joined by Helen Souris, CEO of CardiHab and Board Member of the Medical Technology Association of Australia (MTAA), to discuss why so many promising digital health companies struggle when they leave the startup phase and enter the realities of regulation.
Helen shares her experience leading a digital therapeutics company, raising investment in Australia, navigating software...
What MedTech Can Learn from the Casino Industry with Melissa Aarskaug | Ep 75
For years, cybersecurity has been viewed as an IT responsibility. Today's threat landscape demands something very different.
In this episode of the Med Device Cyber Podcast, Christian Espinosa is joined by Melissa Aarskaug, a cybersecurity executive with extensive experience protecting highly regulated industries, including banking and casino gaming. Melissa shares lessons from an industry where operations run 24 hours a day, every day of the year, and where even a few minutes of downtime can have enormous financial consequences.
The conversation explores why attackers increasingly target regulated industries, how cyber resilience differs from compliance, and why...
The Future of Cardio-Oncology Wearables with Ryan Neely | Ep 74
Cancer treatment is already difficult enough without adding more hospital visits, more testing, and more delays. Yet many cancer therapies carry a significant risk of damaging the heart, forcing patients to undergo regular cardiac screening throughout their treatment journey. What if clinicians could monitor cardiac function with a simple wearable patch instead?
In this episode of the Med Device Cyber Podcast, Christian Espinosa sits down with Ryan Neely, co-founder and CEO of Skribe Medical. Ryan shares his journey from neuroscience research and implantable neuroprosthetics to building a company focused on improving cardiac monitoring for cancer patients.
<...Navigating U.S. Market Entry for MedTech Developers with JJ Amell | Ep 73
When you develop a groundbreaking medical device, you assume the engineering and clinical data will carry you across the finish line. The legal landscape of U.S. market entry involves layers of corporate traps that most innovators completely overlook. In this episode of the Med Device Cyber Podcast, Christian and Trevor sit down with JJ Amell, the founder of Amell Law, to unpack the complex realities of international corporate structuring, business immigration, and intellectual property protection.
JJ shares his unique transition from building computers and working within his father's cardiology practice to guiding international medical technology firms...
The Psychology of Medical Device Security Awareness with Shahbaz Ahmed | Ep 72
When you try to communicate cybersecurity risks to medical device manufacturers, do you feel like you are speaking ancient Hieroglyphics? You are not alone. In this episode of the Med Device Cyber Podcast, Christian and Trevor sit down with Shahbaz Ahmed, the Founder and CEO of Leadership Studi. Together, they explore the intersection of human psychology, cross-cultural leadership styles, and the massive awareness deficit currently facing global medical device cybersecurity.
Shahbaz shares his unique framework on human engineering, detailing how the emotional depth of Eastern leadership can bridge with the logic-driven framework of the West to build...
The Age of Digital Health Humanity with Philippe Gerwill | Ep 71
Philippe Gerwill manages to be a board advisor for nearly 30 companies without losing his humanity. In this episode of the Med Device Cyber Podcast, Christian Espinosa sits down with the world-renowned futurist to discuss why “unlearning” is the most vital skill for today’s healthcare leaders. They explore the shift from traditional medicine to consumer-led health and why patients are flocking to ChatGPT regardless of what their doctors think!
Philippe explains how he maintains a presence on close to 30 company boards while using a massive AI ecosystem to scale his impact. This conversation is a reminder that the hu...
Why MedTech Needs Specialists with Zoltan Kevei and Saby Toth of Bishop & Co | Ep 70
Medical software is still underestimated by teams that think generic engineering habits will carry over cleanly into a regulated environment. They do not. The work gets harder when requirements, traceability, security, testing discipline, and approval timelines all collide.
A stronger strategy starts earlier, uses specialists sooner, and avoids making AI or code velocity the headline when architectural quality and compliance readiness are what determine whether a product can truly ship.
Episode Breakdown
00:01 Opening
08:02 When to bring in partners
10:48 Cybersecurity as a timing issue
12:24 AI pressure and code...
Science Before Hype in MedTech Investing with Varun Turlapati of Chaanakya Capital | Ep 69
Early-stage MedTech gets riskier when investors confuse a compelling story with a credible device. Stronger diligence starts by testing whether the science is real, whether clinicians would actually use the product, and whether the company has thought seriously about regulatory fit, reimbursement logic, and engineering durability.
That framework becomes even more important in neurotech, where public fascination can outrun the evidence base and where the difference between a breakthrough and a weak claim is often diligence quality.
Episode Breakdown
00:00 Opening
02:42 Science and engineering filters
07:55 Why neurotech still...
Why MedTech Needs More Than Approval with Michael Branagan Harris of HealthTech Strategies Limited
A device can clear regulatory hurdles and still struggle commercially if the evidence is too narrow. MedTech companies need proof that speaks to affordability, care quality, operational impact, and long term value, not just technical performance.
Market selection matters just as much. The same solution may fit the United States, the UK, Germany, or the Netherlands very differently because reimbursement models, provider incentives, and care delivery systems are not built the same way.
Episode Breakdown
00:00 Opening
09:02 What evidence actually needs to prove
14:16 Building a stronger adoption case
22:43...
De-Risking Product Decisions in MedTech Startups with Brent Lavin of Ironwood MedTech Partners
Product decisions made during early development determine commercialization outcomes years later. Wrong choices about regulatory pathways, feature sets, and market segments create compounding problems limiting commercial success.
Christian Espinosa and Trevor Slattery explore product management with Brent Lavin, Chief Product Catalyst of Ironwood MedTech Partners, covering why 510(k) pathways average four years while PMA programs require seven to nine years, and how feature set alignment shapes success.
The engineering mindset applies hypothesis testing to product development through iterative refinement.
Practical for MedTech founders and product teams.
Episode Breakdown:
00:02 Introduction04:35 Ironwood...Vibe Coding Security Risks and Malicious Code Injection with Jake Rodriguez of Triangle Tech
Vibe coding enables rapid development through AI-generated code but introduces security risks when developers accept outputs without verification. Malicious actors can inject vulnerabilities through manipulated training data or prompt engineering. Supply chain attacks become easier when developers blindly trust AI implementations.
Jake Rodriguez, Founder and CEO of Triangle Tech, joins Trevor Slattery and Christian Espinosa to explore the security implications of vibe coding, how attackers exploit AI code generation, and what verification processes prevent unverified code reaching production.
Understanding generated code requires technical knowledge many vibe coding adopters lack.
Practical for development and...
Why Clinical Trials Are the Most Expensive Capital Outlay for Startups with Rob Bedford, CEO of Franklyn Health
Early planning prevents expensive corrections when startups address clinical strategy, regulatory pathways, and cybersecurity requirements from day one rather than improvising solutions before launch. FDA pre-submission meetings provide feedback that de-risks strategies before execution.
Clinical trial design shapes feasibility for startups with limited budgets. Understanding target markets determines sample requirements since United
States sales need United States samples while Korean sales need Korean data. Reverse engineering where you want to sell enables appropriate planning.
Good Clinical Practice guidelines establish responsibility layers. Manufacturers remain accountable for outcomes even when delegating work to CROs or...
Traceability Requirements and Documentation Audit Trails with Dr. Basant Bajpai, CEO of Compliance MedQRA
Quality management system implementation delays create cascading failures across medical device development timelines. Startups using SharePoint or Google Drive for documentation discover at audit time that these tools provide no traceability, no version control, and no evidence of systematic processes.
Dr. Basant Bajpai discusses why design controls begin at the concept stage, regardless of whether companies acknowledge them, how reverse documentation costs 6-12 months when manufacturers reach the submission stage without proper systems, and what happens when scaling exposes foundational quality gaps.
Simple automated systems that enforce traceability outperform both manual approaches and enterprise platforms...
Early Design Decisions that Shape Medical Device Success with Chris Danek, CEO of Bessel
Early design decisions define the trajectory of a medical device long before commercialization begins. Choices related to software architecture, third-party components, and system connectivity establish both the opportunity and the risk profile of the product.
Cybersecurity introduces a layer of complexity that many teams underestimate. It extends beyond protecting data and into safeguarding patient outcomes, ensuring system reliability, and meeting increasingly stringent regulatory expectations.
Chris Danek, CEO of Bessel, joins Christian and Trevor to examine how a single overlooked dependency or unsupported component can become a critical vulnerability. In many cases, these issues remain hidden...
Patient Monitoring Systems and the Gingerbread Man: How Brandon Fertig, Senior Manager at Philips Healthcare Uses AI to Help Nurses PrioritizePatient Monitoring Systems and the Gingerbread Man: How Brandon Fertig, Senior Manager at Philips Healthcare Uses AI to Help Nurses Prioritize
Alarm fatigue happens when monitoring systems raise so many false flags that clinical staff begin ignoring them, even when real critical events occur. A surgeon during an operation gets alarms indicating patient bleeding, but observes stable blood pressure and no visible bleeding. The surgeon trusts direct patient observation over machine output because edge cases require human judgment that AI cannot reliably provide.
Brandon Fertig discusses why patient monitoring systems with visual indicators like the gingerbread man figure help nurses prioritize care without replacing their judgment, how edge cases become more important as automation increases, and why AI...
Spend Two Weeks in a Hospital Before Designing Your Medical Device (Professor Aamer Ahmed)
Devices that do not integrate into the clinical workflow sit unused regardless of technical sophistication. Physicians work in high-pressure environments where equipment must be 100 percent reliable, secure, and enhance workflow rather than disrupt it.
Professor Aamer Ahmed, a Consultant in Cardiothoracic Anaesthesia, Professor of Anaesthesia and Critical Care at the University of Leicester, and co-founder of Hemeo, a medical technology company designing AI-based personalized Clinical Decision Support Systems for coagulation disorders, discusses with Christian Espinosa and Trevor Slattery why involving Key Opinion Leaders at the design stage prevents expensive redesigns, what alarm fatigue does to clinical decision-making...
How to Move Stakeholders from Awareness to Sustained Adoption Without Friction
Marketing medical devices requires understanding that stakeholders are different, buying processes are longer, and friction points are more complex than consumer products or software. Most companies build websites and attend trade shows hoping prospects will decode their message, but prospects do not have time for that.
Sustained adoption is not the same as initial purchase. It means the device is used continuously with no friction, no concerns, and no barriers, causing users to stop or switch. Getting there requires understanding every stakeholder involved, what questions they have at each stage, and what fears might stop them.
<...Prevention Is Better Than Cure: Applying Medical Principles to Medtech Cybersecurity
Medical device risk assessments are failing patients, not because the process is too hard, but because nobody doing the assessment has ever been in the room where the device actually gets used.
Medtech quality and regulatory leader Stephen Smith describes sitting in a risk session for a device going into an intensive care unit. Twelve people in the room, and not one had ever set foot in an ICU. If you have never been in the environment your device will operate in, risk identification becomes guesswork, mitigations get written for problems that are not the actual problems...
Adversarial Attacks on Medical AI: What You Need to Know with Jun Xiang Tan
Ten years ago, Singapore's healthcare system got hacked. Patient records were stolen at a national scale. The government responded by building one of the most comprehensive medical device security frameworks in the world.
The Cybersecurity Labeling Scheme has four tiers. Level one means basic security controls exist. Level four means the device underwent independent code review, has advanced threat detection, and maintains continuous vulnerability management. Hospitals can see exactly what level of security they're getting before they buy.
Jun Xiang from CareHero explains why this matters, especially now that AI is showing up in medical...
SBOMs 101: What the FDA Expects and How to Get It Right
SBOMs are one of the most common sources of FDA deficiencies in medical device submissions. Most companies think they're doing it right, but then they get feedback asking for missing components or clarification on what's included.
In this webinar, Christian Espinosa and Trevor Slattery explain what the FDA actually expects in an SBOM and why it's not just about listing third-party libraries. You need to include first-party code too. You need to follow the NTIA minimum elements. And you need to provide it in a machine-readable format like SPDX or CycloneDX.
Trevor walks through the...
Secure Software Development for Medical Devices: The Real Story with Darcy Bachert
Building medical device software is hard. Building it the right way is harder. And getting it through FDA approval while managing cybersecurity requirements? That's what Darcy Bachert has been doing for 17 years.
Darcy runs Prolucid Technologies, an ISO 13485-certified software development firm in Toronto. They work with medtech companies across North America, Europe, and Australia.
And in that time, he's seen the same mistakes repeatedly.
The biggest one? Founders build products that solve problems nobody has. Or they build something physicians won't adopt because it adds complexity instead of making their lives easier.<...
The Hidden Cybersecurity Challenges in Software as a Medical Device
Marc Zemel has been building Retia Medical for 15 years. The company started as two guys with slides and licensed technology. Now their data-driven hemodynamic monitoring technology for consistently accurate cardiac output measurements in high-risk surgical and critically ill patients is in 75 hospitals across 18 countries, sold by Medtronic in the U.S, and the company is preparing to launch their new product Argos Infinity, pending FDA clearance.
But getting here meant dealing with cybersecurity challenges that Marc didn't see coming. In this conversation, he talks about what actually slowed them down, what he wishes he'd done differently, and...
Why Your Cloud Platform Decision Could Destroy Your Global Market Strategy
Thinking about taking your medical device to China? Or maybe you're a Chinese company looking at the American market?
William Jin has spent over 30 years helping companies do exactly that, and he'll tell you straight up that most of them aren't ready. Not because they lack good products, but because they didn't think about cybersecurity early enough.
William was trained as a medical doctor in Shanghai, then moved into the medtech industry working for companies like McCulloch and Stryker. Now he helps businesses on both sides of the Pacific figure out how to actually get...
Why Your Cloud Platform Decision Could Destroy Your Global Market Strategy
Thinking about taking your medical device to China? Or maybe you're a Chinese company looking at the US market?
William Jin has spent over 30 years helping companies do exactly that, and he'll tell you straight up that most of them aren't ready. Not because they lack good products, but because they didn't think about cybersecurity early enough.
William was trained as a medical doctor in Shanghai, then moved into the medtech industry working for companies like McCulloch and Stryker. Now he helps businesses on both sides of the Pacific figure out how to actually get...
How to Actually Get Your Medical Device Approved in China (Or the US)
Thinking about taking your medical device to China? Or maybe you're a Chinese company looking at the US market?
William Jin has spent over 30 years helping companies do exactly that, and he'll tell you straight up that most of them aren't ready. Not because they lack good products, but because they didn't think about cybersecurity early enough.
William was trained as a medical doctor in Shanghai, then moved into the medtech industry working for companies like McCulloch and Stryker. Now he helps businesses on both sides of the Pacific figure out how to actually get...
How to Avoid the 3 Biggest Mistakes in Medtech Startups
Ever thought about what it really takes to launch a successful medtech startup?
Omar M. Khateeb knows the challenges firsthand. As a founder with a track record of building healthtech companies, he’s lived through the hurdles that come with innovating in the medtech space.
In this episode, Omar dives into the highs and lows of his entrepreneurial journey, sharing key lessons, pivotal moments, and the strategies that helped him succeed. From tackling complex healthcare issues to navigating the regulatory maze, Omar breaks down what it takes to make a lasting impact in medtech.
...
Untangling Software Composition Analysis for MedTech Teams
Why does software composition analysis matter beyond regulatory compliance?
This episode explores SCA (Software Composition Analysis) and explains how SBOMs (Software Bill of Materials), SOUP (Software of Unknown Provenance), and related tooling fit into the broader medical device cybersecurity landscape. Christian and Trevor clarify common misconceptions, including licensing fears, machine-readable requirements, and the role of static testing tools.
The Med Device Cyber Podcast is brought to you by Blue Goat Cyber, cybersecurity professionals specializing in providing elite cyber solutions for medical devices. Learn more about securing your product and business from cyber-criminals by visiting https...
When Medical Device Cyber Failures Become Fatal
What past ransomware and medical device incidents might reveal gaps that manufacturers are still overlooking today?
In this episode, Christian and Trevor examine real incidents where cybersecurity failures, software flaws, and insecure medical devices led to patient harm and death. They break down how ransomware attacks, implantable device vulnerabilities, and AI-driven therapies expose life-critical risks in healthcare. The conversation highlights why regulators are increasing scrutiny and why cybersecurity must be treated as a patient-safety imperative, not an afterthought.
The Med Device Cyber Podcast is brought to you by Blue Goat Cyber, cybersecurity professionals specializing in...
Trevor Slattery Answers Tough Medical Device Cyber Questions
This episode puts Trevor in the hot seat. If you were put in the hot seat, could you clearly explain cybersecurity, safety, and lifecycle terms like Trevor?
In this rapid-fire episode, Christian fires questions at Trevor about essential medical device cybersecurity concepts and standards. Together, they clarify how risk management, secure development, and lifecycle thinking intersect across safety, quality, and security.
The Med Device Cyber Podcast is brought to you by Blue Goat Cyber, cybersecurity professionals specializing in providing elite cyber solutions for medical devices. Learn more about securing your product and...
The Differences Between Black, Grey, and White Penetration Testing
MedTech developers, do you know which penetration testing methodology the FDA actually prefers for medical device submissions?
In this episode, Christian and Trevor explain the differences between black, grey, and white box penetration testing and how each impacts the completeness and realism of cybersecurity assessments. They highlight why regulators increasingly expect deeper testing supported by source-code-level insights. They also outline the risks, costs, and delays manufacturers face when choosing insufficient testing approaches during FDA submission.
Key points:
(01:25) Learn how black box testing mimics an attacker with no prior knowledge.
(06:27) How grey...
How Cybersecurity Shapes Regulatory and Quality Success with Jim Goodmiller
What risks do you take when cybersecurity is left off your development roadmap?
In this episode, Christian, Trevor and guest Jim Goodmiller explore how cybersecurity intersects with regulatory expectations and quality systems, creating new challenges and opportunities for medtech innovators. Jim helps to explain why founders must integrate cybersecurity from concept through commercialization, especially as FDA scrutiny increases.
Key points:
00:48 Why cybersecurity now influences every part of the regulatory landscape.
04:48 How technologies can create serious safety and compliance risks when not fully vetted.
10:45 Cybersecurity as a mandatory component of...
Webinar: Why FDA Cybersecurity Submissions Fail and How to Get Yours Approved
Medtech innovators and medical device manufacturers, how can you prevent cybersecurity deficiencies from delaying your FDA submission?
In this webinar, Christian Espinosa, CEO of Blue Goat Cyber, and Trevor Slattery, CTO of Blue Goat Cyber, reveal the most common reasons FDA cybersecurity submissions fail and how you can avoid them. They explain the importance of early risk management, security-by-design practices, and comprehensive testing aligned with NIST and AAMI frameworks.
Explored in this webinar:
00:37 Why poor cybersecurity is a top reason for FDA medical device rejection.
02:56 The FDA’s to...
Cybersecurity Qs MedTech Innovators Ask: Christian’s Hot Seat
MedTech manufacturers, how can you avoid the cybersecurity pitfalls that most often lead to FDA rejection?
In this episode, Trevor puts Christian “in the hot seat” to tackle the most common—and sometimes misunderstood—cybersecurity questions MedTech innovators ask. Christian breaks down key concepts such as ISO 13485, HIPAA vs. FDA expectations, SAMD vs. SIMD, global regulatory demands, and more.
Key points:
(00:30) The purpose of ISO 13485 and why traceability, quality, and documentation are foundational to medical device safety.
(02:34) How cybersecurity is now the most common reason FDA reviewers reject medical...
What Is Required for an FDA Pre-Market Cyber Submission?
What are the 18 required cybersecurity deliverables for a pre-market submission, and how do they map to eSTAR’s 13 sections?
This episode breaks down the cybersecurity deliverables required for an FDA pre-market submission and explains why they apply consistently across all device types. Christian and Trevor walk through each deliverable in detail, outline how they map to eSTAR v6.0, and highlight common misconceptions that slow down manufacturers.
Key points:
(00:33) Why all devices—high-risk or low-risk—must submit the same 18 cybersecurity deliverables to the FDA.
(01:41) How device complexity influences documentation depth...