Ready to Register?

MyLawCLE All-Access Pass

Best choice

Add the All-Access Pass and get this program —
plus 1,000+ live CLE programs every year.


All specialty & ethics credits included
38 practice areas
New sections: AI & the Law, Practice Management
100s of current and trending legal topics
Nationally recognized and highly experienced presenters

$395 / year — this program included
Register with the All-Access Pass

This program + 1,000+ CLE programs, all year

Or register for just this program

On-Demand Video

Recorded access + self-study credit.
$195 Register

Cybersecurity Failures and Legal Fallout in Medical Device Technology

Medical device cybersecurity regulatory landscape: FDA guidance, HIPAA compliance, risk management frameworks, and liability mitigation strategies for legal professionals.

2025-07-24 13:00:00

Program Details

2025-07-24 13:00:00

Program Details

2025-07-24 13:00:00

Over 1,000+ webinars

2025-07-24 13:00:00

Course Overview

Navigating Medical Device Cybersecurity Regulations

2025-07-24 13:00:00

Participants will learn to identify compliance requirements across FDA, HIPAA, and international frameworks for medical device cybersecurity. This knowledge enables effective risk mitigation and defense strategies during regulatory inspections.

Format

CLE Credit

2h CLE Credits

Level

Intermediate

Length

2

Key topics that will be covered

01
Regulatory Framework
FDA, HIPAA, state laws, and international regulations governing medical device cybersecurity.
02
AI Compliance
EU AI Act implementation and state-level AI legislation affecting medical devices.
03
Enforcement Agencies
DOJ, FTC, HHS OCR, and SEC authority over medical device cybersecurity enforcement.
04
Risk Management
Threat modeling, vulnerability assessments, and software bill of materials requirements.
05
Design Controls
Incorporating cybersecurity into device design, verification, and validation processes.
06
Defense Strategies
Mapping cybersecurity activities to design controls and consensus standards during inspections.

Program schedule

clock 1:00 pm - 1:05 pm EST

Noteworthy News in AI and Privacy Legislation

This session covers recent developments in the EU AI Act implementation and its impact on medical device classification. State-level AI legislation from Colorado and Texas is also examined, including neural data protections and responsible AI governance requirements.

Rachel V. Rose.Rachel V. Rose.
Eric HenryEric Henry
clock 1:05 pm - 1:30 pm EST

Common Cybersecurity and AI Terminology Essentials

Participants will learn fundamental cybersecurity definitions including the CIA triad (Confidentiality, Integrity, Availability) and key regulatory bodies like CISA and NIST. The session also explores AI categories—predictive, generative, and agentic—along with the five principles for AI compliance in healthcare settings.

Rachel V. Rose.Rachel V. Rose.
Eric HenryEric Henry
clock 1:30 pm - 2:00 pm EST

Navigating the Current Medical Device Regulatory Landscape

This comprehensive session examines enforcement authority across DOJ, FTC, HHS OCR, and SEC regarding medical device cybersecurity. Key topics include HIPAA Security Requirements, the H.R. 7898 safe harbor provisions, and international considerations such as GDPR compliance for global organizations.

Rachel V. Rose.Rachel V. Rose.
Eric HenryEric Henry
clock 2:00 pm - 2:10 pm EST

Break

A short break allowing participants to refresh before diving into detailed cybersecurity risk management topics. Use this time to review notes and prepare questions for the remaining sessions.

Rachel V. Rose.Rachel V. Rose.
Eric HenryEric Henry
clock 2:10 pm - 2:25 pm EST

Healthcare Cybersecurity Issues and Risk Management Overview

This session reviews the June 2025 FDA guidance and comprehensive cybersecurity literature for medical devices across U.S. and international frameworks. Key industry standards from AAMI, IMDRF, and IEC are examined alongside Health Sector Coordination Council resources.

Rachel V. Rose.Rachel V. Rose.
Eric HenryEric Henry
clock 2:25 pm - 2:50 pm EST

Medical Device Cybersecurity Design Controls Deep Dive

Participants explore ten common themes in regulatory literature including threat modeling, SBOMs, design controls, and incident response programs. The session covers the complete software lifecycle from planning through validation, with special attention to cloud considerations and common device deficiencies found during audits.

Rachel V. Rose.Rachel V. Rose.
Eric HenryEric Henry
clock 2:50 pm - 3:00 pm EST

Strategies for Defending Your Cybersecurity Practices

This session presents five key strategies for successfully navigating inspections, audits, and regulatory submissions. Learn how to map cybersecurity activities to design controls, leverage consensus standards, and prepare for remote FDA inspections authorized under the December 2022 omnibus bill.

Rachel V. Rose.Rachel V. Rose.
Eric HenryEric Henry
clock 3:00 pm - 3:10 pm EST

Comprehensive Risk Mitigation and Compliance Programs

The final session covers the seven fundamental compliance program elements evaluated by HHS OIG and DOJ, from written policies to risk assessments. AI-specific risk mitigation strategies are addressed, including algorithm integrity concerns and the current FDA limitations on adaptive algorithms.

Rachel V. Rose.Rachel V. Rose.
Eric HenryEric Henry
Rachel V. Rose.

Rachel V. Rose.

Rachel V. Rose – Attorney at Law, PLLC

Eric Henry

Eric Henry

Brooke & Associates

Rachel V. Rose.

Rachel V. Rose.

Rachel V. Rose – Attorney at Law, PLLC

Rachel V. Rose, JD, MBA has a unique background in healthcare, securities, cybersecurity, and international law. For over a decade, her practice has focused on transactional, compliance, and litigation matters related to cybersecurity, health care, securities, and Dodd-Frank/False Claims Act whistleblower claims.

Education & Credentials

MBA with minors in healthcare and entrepreneurship from Vanderbilt University, law degree from Stetson University College of Law, and an Executive Certification in Leadership and Negotiation from Harvard Law School.

Recognition & Leadership

Named consecutively to the Texas Bar College, National Women Trial Lawyers Association's Top 25, Houstonia Magazine's Top Lawyers (healthcare), National Trial Lawyers Association's Top 100, SuperLawyers (healthcare), and 1st Healthcare Compliance's 2019 and 2022 Top Presenter. Extensively published, sought-after presenter, and quoted expert. Co-editor of the American Health Lawyers Association's Enterprise Risk Management Handbook for Healthcare Entities (2nd Edition), co-author of the ABA's books The ABCs of ACOs and What Are International HIPAA Considerations?, as well as various chapters in legal and medical books.

Professional Involvement

Affiliated Member with Baylor College of Medicine's Center for Medical Ethics and Health Policy, where she teaches bioethics.

Experience

Worked on Capitol Hill when HIPAA passed in 1996 and at HHS in 2009 when the HITECH Act was being implemented. Has conducted HIPAA Risk Analyses for domestic and international organizations and represented persons related to government enforcement inquiries and responses on cybersecurity and healthcare related matters.
Eric Henry

Eric Henry

Brooke & Associates

Eric Henry is a 35-year veteran of the high-tech and medical device industries, now focusing on advising medical device company boards, management, and staff on medical device regulatory compliance, quality management systems, and strategic risk management, with a specific emphasis on software-enabled devices and digital health.

Professional Involvement

Adjunct faculty member at Pathway for Patient Health, member of the AFDO/RAPS MedCon strategic committee, and advisor to the Coalition for Health AI (CHAI) on the intersection of healthcare delivery and medical device manufacturing.

Experience

Led global quality and technical organizations at firms such as the Nasdaq Stock Market, Boston Scientific, GE Healthcare, Medtronic, and Philips. After leaving industry in 2018, worked at law firms King & Spalding and Brooke & Associates advising on medical device regulatory compliance.
Rachel V. Rose.

Rachel V. Rose.

Rachel V. Rose – Attorney at Law, PLLC

Rachel V. Rose, JD, MBA has a unique background in healthcare, securities, cybersecurity, and international law. For over a decade, her practice has focused on transactional, compliance, and litigation matters related to cybersecurity, health care, securities, and Dodd-Frank/False Claims Act whistleblower claims.

Education & Credentials

MBA with minors in healthcare and entrepreneurship from Vanderbilt University, law degree from Stetson University College of Law, and an Executive Certification in Leadership and Negotiation from Harvard Law School.

Recognition & Leadership

Named consecutively to the Texas Bar College, National Women Trial Lawyers Association's Top 25, Houstonia Magazine's Top Lawyers (healthcare), National Trial Lawyers Association's Top 100, SuperLawyers (healthcare), and 1st Healthcare Compliance's 2019 and 2022 Top Presenter. Extensively published, sought-after presenter, and quoted expert. Co-editor of the American Health Lawyers Association's Enterprise Risk Management Handbook for Healthcare Entities (2nd Edition), co-author of the ABA's books The ABCs of ACOs and What Are International HIPAA Considerations?, as well as various chapters in legal and medical books.

Professional Involvement

Affiliated Member with Baylor College of Medicine's Center for Medical Ethics and Health Policy, where she teaches bioethics.

Experience

Worked on Capitol Hill when HIPAA passed in 1996 and at HHS in 2009 when the HITECH Act was being implemented. Has conducted HIPAA Risk Analyses for domestic and international organizations and represented persons related to government enforcement inquiries and responses on cybersecurity and healthcare related matters.
Eric Henry

Eric Henry

Brooke & Associates

Eric Henry is a 35-year veteran of the high-tech and medical device industries, now focusing on advising medical device company boards, management, and staff on medical device regulatory compliance, quality management systems, and strategic risk management, with a specific emphasis on software-enabled devices and digital health.

Professional Involvement

Adjunct faculty member at Pathway for Patient Health, member of the AFDO/RAPS MedCon strategic committee, and advisor to the Coalition for Health AI (CHAI) on the intersection of healthcare delivery and medical device manufacturing.

Experience

Led global quality and technical organizations at firms such as the Nasdaq Stock Market, Boston Scientific, GE Healthcare, Medtronic, and Philips. After leaving industry in 2018, worked at law firms King & Spalding and Brooke & Associates advising on medical device regulatory compliance.

Credits by state

AK2.0
AL2.0
AR2.0
AZ2.0
CA2.0
CO2.0
CT2.0
DC2.0
DE2.0
FL2.0
GA2.0
HI2.4
IA2.0
ID2.0
IL2.0
IN2.0
KS2.0
KY2.0
LA2.0
MA2.0
MD2.0
ME2.0
MI2.0
MN2.0
MO2.4
MS2.0
MT2.0
NC2.0
ND2.0
NE2.0
NH120.0
NJ2.4
NM2.0
NV2.0
NY2.0
OH2.0
OK2.5
OR2.0
PA2.0
RI2.5
SC2.0
SD2.0
TN2.0
TX2.0
UT2.0
VA2.0
VT2.0
WA2.0
WI2.0
WV2.4
WY2.0

Upcoming Live Online CLE Broadcasts

1000+

Live stream programs

24/7

Access to live webinars & recordings

70,000+

Trusted by Legal Professionals

1000+

Live stream programs

24/7

Access to live webinars & recordings

70,000+

Trusted by Legal Professionals

1000+

Live stream programs

24/7

Access to live webinars & recordings

10,000+

Trusted by Legal Professionals

1000+

Live stream programs

24/7

Access to live webinars & recordings

70,000+

Trusted by Legal Professionals

MCLE Credits

Alabama
Pending
Alaska
Approved
Arizona
Approved
Arkansas
Approved
California
Approved
Colorado
Pending
Connecticut
Approved
Delaware
Pending
District of Columbia
No Required
Florida
Approved
Georgia
Approved
Hawaii
Approved
Idaho
Pending
Illinois
Pending
Indiana
Pending
Iowa
Pending
Kansas
Pending
Kentucky
Pending
Louisiana
Pending
Maine
Pending
Maryland
No Required
Massachusetts
No Required
Michigan
No Required
Minnesota
Approved
Mississippi
Pending
Missouri
Approved
Montana
Pending
Nebraska
Pending
Nevada
Pending
New Hampshire
Approved
New Jersey
Approved
New Mexico
Approved
New York
Approved
North Carolina
Approved
North Dakota
Approved
Ohio
Approved
Oklahoma
Pending
Oregon
Pending
Pennsylvania
Approved
Rhode Island
Pending
South Carolina
Pending
South Dakota
No Required
Tennessee
Pending
Texas
Pending
Utah
Pending
Vermont
Approved
Virginia
Not Eligible
Washington
Approved
West Virginia
Pending
Wisconsin
Approved
Wyoming
Pending

Alabama

Requirements

The Alabama State Bar MCLE Commission requires attorneys to complete 12 credits, including 1 ethics, by December 31 of each year. All credits must be reported by February 15 of the following year. A maximum of 12 credits, including 1 ethics credit, may be carried over for 1 year only.  

Formats

  • Attorneys can earn unlimited “live” credit through live seminars, live webcasts, and co-sponsored locations with MyLAWCLE-Alabama approved programs
  • Attorneys are limited to 6 credits per compliance period of “online” programs through MyLAwCLE On-Demand programs