Texas Children’s: Biomedical Cybersecurity Upgrade
- Texas Children's Hospital is taking proactive steps to bolster its biomedical device cybersecurity, according to Gordon Groschl, CISO and Director of Healthcare Technology Management.
- The increasing connectivity of medical equipment presents unique challenges.Unlike traditional IT assets, these devices frequently enough have vendor-imposed limitations that prevent standard security measures.
- Located in the Texas Medical Center,the largest medical complex in the U.S., Texas Children’s has expanded its operations to Austin, with nearly 200 clinics and urgent care centers.
Texas Children’s Hospital is actively upgrading its biomedical device cybersecurity, prioritizing patient data protection and care delivery. Gordon Groschl, the Director of healthcare Technology Management, leads the charge, emphasizing the unique challenges posed by interconnected medical equipment. The hospital is implementing stricter access controls, including a third-party identity verification system and time-restricted access, bolstered by dedicated IT leadership for enhanced biomedical security. Vendor remote access is under rigorous monitoring, and employee education is crucial to ward off cyberattacks. This strategic shift places biomed under IT, fostering collaboration between IT and biomed teams. The primary focus is on biomedical cybersecurity with a commitment to continuous risk management. News Directory 3’s recent coverage underscores the hospital’s proactive approach. Discover what’s next for Texas children’s and its layered security defense.
Texas Children’s Hospital Strengthens Biomedical Device Cybersecurity
Updated April 30, 2025
Texas Children’s Hospital is taking proactive steps to bolster its biomedical device cybersecurity, according to Gordon Groschl, CISO and Director of Healthcare Technology Management. Groschl, a veteran of the hospital, now oversees a team of over 70 biomedical professionals responsible for securing a vast network of interconnected medical devices.
The increasing connectivity of medical equipment presents unique challenges.Unlike traditional IT assets, these devices frequently enough have vendor-imposed limitations that prevent standard security measures. Groschl noted that many devices outlive their operating systems, creating inherent vulnerabilities.
Located in the Texas Medical Center,the largest medical complex in the U.S., Texas Children’s has expanded its operations to Austin, with nearly 200 clinics and urgent care centers. This growth amplifies the need for robust cybersecurity measures to protect sensitive patient data and ensure uninterrupted care.
Historically, biomedical engineering teams reported to facilities departments. However, Texas Children’s shifted this structure, placing biomed under IT. Groschl’s appointment further emphasizes the hospital’s commitment to integrating cybersecurity expertise at the leadership level.
Groschl emphasized the importance of “mutual learning” between the IT and biomed teams. While the biomed team possesses extensive equipment knowledge, they may lack formal training in digital security. This creates an opportunity for collaboration and knowledge sharing.
A recent audit revealed gaps in vulnerability management and access controls. Many medical devices were not domain-joined and lacked standardized login protocols. The team also discovered inconsistent identity verification practices.
To address these issues, Groschl hired a dedicated IT lead for biomedical security and implemented dashboards to monitor progress. The hospital is also engaging a managed service provider specializing in biomedical security.
“everything is on the network now. Everything wants to exchange data. And that means cybersecurity can no longer be an afterthought,” Groschl said.
Vendor relationships also present challenges. Clinical teams often prioritize usability and diagnostic accuracy when purchasing equipment, sometimes overlooking cybersecurity implications. This can leave security leaders with devices they cannot easily configure.
Groschl believes the FDA should mandate long-term support and secure design practices for medical devices. He also highlighted the importance of carefully managing vendor remote access, implementing policies to control access pathways and monitor sessions.
“Identity is everything,” Groschl said.“Service accounts, contractor access, machine identities—if you don’t have that locked down, you’re vulnerable.”
Texas Children’s is implementing time-restricted access controls and transitioning to a third-party identity verification system. Managers are also required to participate in identity verification video calls for contractor access changes.
Groschl also stressed the need to educate high-risk departments, such as HR, finance, and IT, tailoring security awareness training to their specific needs.
What’s next
Texas Children’s Hospital will continue to refine its biomedical device cybersecurity strategy,focusing on continuous improvement,collaboration,and proactive risk management to protect patient data and ensure the delivery of safe,effective care.
