Nick Yuran, Author at Harbor Labs https://harborlabs.com Sat, 28 Feb 2026 05:36:31 +0000 en-US hourly 1 https://wordpress.org/?v=6.8.2 https://harborlabs.com/wp-content/uploads/harborlabs-website-favicon-150x150.png Nick Yuran, Author at Harbor Labs https://harborlabs.com 32 32 Harbor Labs Supports DOJ False Claims Act Litigation in Healthcare https://harborlabs.com/doj-false-claims-act-healthcare-cybersecurity-2/ Fri, 27 Feb 2026 17:09:55 +0000 https://harborlabs.com/?p=230688 Harbor Labs supports the U.S. Department of Justice in False Claims Act litigation involving healthcare IT and cybersecurity investigations.

The post Harbor Labs Supports DOJ False Claims Act Litigation in Healthcare appeared first on Harbor Labs.

]]>

Harbor Labs is proud to have supported the U.S. Department of Justice in its False Claims Act litigation against Kaiser Permanente. This work reflects our longstanding commitment to strengthening compliance, integrity, and cybersecurity across complex healthcare IT environments. Originally awarded in 2022, this engagement builds on Harbor Labs’ extensive history supporting DOJ and HHS healthcare IT and cybersecurity investigations. For this contract, Dr. Luis Vargas, Director of Medical Cybersecurity at Harbor Labs, served as the principal technical investigator, with Chief Scientist Dr. Mike Rushanan acting as the testifying expert. Congratulations to everyone involved in bringing this vital matter to a conclusion, and for contributing to stronger compliance, integrity, and trust across healthcare. We are honored to contribute technical expertise that reinforces trust in healthcare systems and supports the public interest.
Link to press release

The post Harbor Labs Supports DOJ False Claims Act Litigation in Healthcare appeared first on Harbor Labs.

]]>
The 2015 FDA Cybersecurity Alert That Shaped the Medical Device Industry https://harborlabs.com/2015-fda-medical-device-cybersecurity-alert/ Fri, 27 Feb 2026 16:42:51 +0000 https://harborlabs.com/?p=230716 The FDA’s 2015 cybersecurity alert on the Hospira Symbiq infusion pump marked a turning point in medical device safety and launched a new era of regulatory oversight.

The post The 2015 FDA Cybersecurity Alert That Shaped the Medical Device Industry appeared first on Harbor Labs.

]]>

It could be reasonably argued that the medical device cybersecurity industry was born in August of 2015, when the FDA issued its first ever cybersecurity alert for a medical device. The device that triggered that alert was the Symbiq drug infusion pump by the erstwhile manufacturer Hospira. The pump was reported to be vulnerable to a buffer overflow attack, which if successfully executed could give an attacker root access to the device, allowing the clinical functions of the pump to be altered or stopped entirely. It was the FDA response to this vulnerability and the tremendous publicity it received that abruptly transformed the medical device industry, establishing cybersecurity as a new, critical component of medical device safety. And it was this alert that would launch both a new set of regulatory standards and the medical device cybersecurity industry as we know it today.

At the time of this event, Harbor Labs was led by Dr. Avi Rubin, who in addition to serving as Chief Scientist was also the Director of the Health and Medical Security (HMS) Lab at Johns Hopkins University. Dr. Rubin had recently testified before US Congress on medical cybersecurity, and as a direct result of his testimony at these hearings Hospira selected Harbor Labs to analyze the Symbiq vulnerability and develop a remediation plan.

The effort was led by Dr. Mike Rushanan, who had himself received his PhD through the JHU HMS lab under Dr. Rubin, and today serves as the Harbor Labs Chief Scientist. Dr. Rushanan and the Harbor Labs staff were able to recreate the attack that produced the buffer overflow, writing their own custom input injector and shellcode. Then, working with the manufacturer, Harbor Labs developed the security patch needed to eliminate the vulnerability. The device was soon thereafter approved to resume clinical sales.

The publicity and market impact the Symbiq episode would have on Harbor Labs would shape the future of the company. With the distinction of being the cybersecurity consultants that rescued a medical device from a critical vulnerability and returned it to the market, Harbor Labs was put at the forefront of the burgeoning medical cybersecurity consulting industry. Over the coming years, Harbor Labs would benefit from this pioneering reputation, partnering with many of the medical device industry’s most prominent manufacturers on their cyber policies and regulatory submissions, and working with regulators to help shape the constantly evolving regulatory landscape. It was that critical roll played by Harbor Labs as the medical device industry was first forming in 2015 that would put the company on the trajectory to the market-leading position we enjoy in the industry today.

The post The 2015 FDA Cybersecurity Alert That Shaped the Medical Device Industry appeared first on Harbor Labs.

]]>
Compliance v. Completeness: Rethinking SBOMs Under FDA Premarket Cybersecurity Guidance https://harborlabs.com/fda-sbom-compliance-completeness/ Fri, 27 Feb 2026 16:40:48 +0000 https://harborlabs.com/?p=230709 Dr. Mike Rushanan explores how an FDA-compliant SBOM may still omit critical software and hardware dependencies, exposing hidden cybersecurity risks in medical devices.

The post Compliance v. Completeness: Rethinking SBOMs Under FDA Premarket Cybersecurity Guidance appeared first on Harbor Labs.

]]>

Harbor Labs Chief Scientist Dr. Mike Rushanan served as the Principal Investigator for the paper Compliance v. Completeness: A Case Study on SBOMs in Consideration of FDA Premarket Cybersecurity Guidance, to be presented at the upcoming HealthSec 2025 Conference this December in Honolulu, HI.

The paper examines the FDA’s premarket cybersecurity guidance on the use of a Software Bill of Materials (SBOM) in medical device submissions, and how it is possible for a SBOM to be compliant but still incomplete. This assertion is supported by a recent Harbor Labs case study highlighting an anonymized medical device SBOM that met regulatory submission standards, but omitted deeply embedded third-party components and dependencies hidden by software development tooling. The extended SBOM revealed additional vulnerabilities, exposing the blind spots of the original SBOM. The study also found that excluding hardware components, or the HBOM, introduced additional unseen vulnerabilities, leaving devices exposed to risks such as microarchitectural attacks.

The findings reinforce an important distinction: building a SBOM solely for regulatory compliance does not always guarantee effective cybersecurity risk management. Manufacturers are encouraged to build BOMs that incorporate both transitive software dependencies and hardware components in order to maximize the effectiveness of vulnerability monitoring and postmarket surveillance.

The post Compliance v. Completeness: Rethinking SBOMs Under FDA Premarket Cybersecurity Guidance appeared first on Harbor Labs.

]]>
Regulatory Science Meets Cyber Science; Why It’s So Much More than a Pen Test https://harborlabs.com/cyberscience-blog2/ Mon, 09 Feb 2026 16:59:14 +0000 https://dev.harborlabs.com/?p=227209 Harbor Labs CEO Nick Yuran distinguishes cybersecurity from cyberscience, and explains why understanding the shared scientific disciplines of regulators and security professionals are important in achieving positive regulatory outcomes.

The post Regulatory Science Meets Cyber Science; Why It’s So Much More than a Pen Test appeared first on Harbor Labs.

]]>

Anyone who has had professional interaction with the FDA has encountered the term regulatory science.

It is used extensively within the agency to convey the scientific disciplines that FDA Centers employ in performing their regulatory functions. More than just examiners with a checklist of pass/fail criteria, the role of the FDA examiner requires a diverse technical, clinical, and analytical skillset that clearly qualifies as a field of science.

 

At Harbor Labs, we apply a very similar mindset to our professional titles, starting with the question, when does cybersecurity become cyberscience?

When the work you perform involves information security, hardware security, computer science, clinical functionality, and an understanding of how all of this affects medical safety, you are certainly deserving of the title scientist. And this is precisely why the unique professional title Cyberscientist is given to most Harbor Labs technical staff positions. It is intended to recognize the diverse technical nature of our staff’s skillsets, as well as convey a subtle marketing identity to our community of clients.

We are frequently engaged by medical device manufacturers who are actively working on a regulatory submission, and have come to us because they “need a pen test performed.” While this is a perfectly reasonable request, at Harbor Labs, the term pen test is rarely used, and only then in a very specific context. The concept of a pen test, in which a variety of tools (Nessus, Metasploit, e.g.) are applied against a target system to identify known vulnerabilities, is only a subset of what is required to truly expose all potential flaws, weaknesses, and vulnerabilities in a medical system. We prefer instead to refer to the testing phase of our analysis as clinical cybersecurity testing. This more comprehensive term captures a broad variety of tests intended to stress the target system in ways that expose all categories of vulnerability. This can include fuzzing, reverse engineering, SAST, MITM, dynamic analysis, robustness (DoS and DDoS), software component analysis, and yes, various forms of COTS and custom pen testing.

 

But what makes this testing clinical?

Cybersecurity analysis alone can be insufficient if the therapeutic, diagnostic, or other clinical functions of the target system are not exercised in parallel. Without this additional context, the severity and functional impact of a vulnerability could be unknowable, leaving an examiner unclear on its true significance. At Harbor Labs, clinical context is at the forefront of our analysis, and has included such testing methods as:

  • The actuation of an infusion system by simulating a drug cassette’s behaviors
  • Removing the arm of a surgical robot to force an error condition
  • Processing actual samples of genetic material in a sequencer
  • Attaching EKG leads to our cyberscientists to generate real-time test data among other similar clinical exercises.

By integrating the medical characteristics and functions of the target device into the cybersecurity testing, the fidelity of the test results are far more meaningful and can lead to a clearer understanding of how security characteristics affect medical performance and patient safety.

When the results of such comprehensive testing are then combined with an understanding of the clinical functions of a target system, and the interactions that occur between the patient and clinician, only then is the testing sufficient for a CDRH examiner. Anyone who has been part of the more than 50% of all regulatory submissions that are rejected already understands this all too well.

Recognizing that medical cybersecurity is indeed a science and treating it as such will significantly reduce time to market for medical device manufacturers and lead to more positive regulatory outcomes for examiners and manufacturers alike.

The post Regulatory Science Meets Cyber Science; Why It’s So Much More than a Pen Test appeared first on Harbor Labs.

]]>
SBOM Transparency v. Exposure: Evaluating Adversarial Risk in Healthcare https://harborlabs.com/sbom-transparency-healthcare-cybersecurity/ Mon, 09 Feb 2026 16:40:45 +0000 https://harborlabs.com/?p=230700 A new case study explores the risks of public SBOM transparency in healthcare, evaluating how adversarial access may reduce exploitation effort and introduce unintended exposure.

The post SBOM Transparency v. Exposure: Evaluating Adversarial Risk in Healthcare appeared first on Harbor Labs.

]]>

Harbor Labs Chief Scientist Dr. Mike Rushanan served as the Principal Investigator for the paper The SBOM Transparency v. Exposure Dilemma: A Case Study on Adversarial Access to Public SBOMs in Healthcare. This is the second of his two papers to be presented at the upcoming HealthSec 2025 Conference this December in Honolulu, HI.

The FDA recommends that manufacturers publicly disclose a continuously updated Software Bill of Materials (SBOM) to support shared responsibility in cybersecurity risk management, vulnerability assessment, and mitigation. While this is a sound and proven security principle, caution should also be exercised in the public release of SBOMs without first evaluating the potential risks introduced by adversarial access.

To support this point, this paper examines a case study using a de-identified, FDA-compliant SBOM derived from a real-world medical device. Using a large language model (LLM), known vulnerabilities (CVEs) were extracted from the SBOM and an attack blueprint was automatically generated. The attack was then validated in a controlled containerized environment, demonstrating that even a minimally detailed SBOM can reduce adversary effort and streamline exploitation planning. The paper concludes with a recommendation that distinctions be made between the SBOM content provided to regulators, clinical end users, and the general public in order to limit unnecessary exposures.

The post SBOM Transparency v. Exposure: Evaluating Adversarial Risk in Healthcare appeared first on Harbor Labs.

]]>
New FDA Guidance On WiFi-Managed Infusion Pumps Is Cybersafe And Cybersecure https://harborlabs.com/fda-guidance-wifi-pumps/ Fri, 04 Jun 2021 11:56:35 +0000 https://harborlabs.com/?p=225661 HarborLabs’ CEO, Nick Yuran, was recently interviewed about misconceptions and concerns around the FDA’s new policies on wireless management of infusion pumps. Here are his thoughts regarding the interview and the overall risks involved.

The post New FDA Guidance On WiFi-Managed Infusion Pumps Is Cybersafe And Cybersecure appeared first on Harbor Labs.

]]>

I was recently interviewed by a prominent medical publication on my thoughts on the FDA’s new policies on wireless management of infusion pumps.

This new regulatory guidance allows infusion pump manufacturers to make limited modifications to the wireless capability of their devices without having to initiate a new 510(k) submission process. The goal is to allow for more effective and efficient remote wireless management of deployed devices by the available clinical staff. In this interview, the journalist wanted to understand the inherent security risks and threats to patient health in allowing such unregulated activities by the medical device industry.
 
I first had to politely correct the interviewer’s premise. The regulatory science behind the FDA’s decision was well-researched, and has informed a very sound policy change. The new guidance is based on the FDA’s belief that the potential security risks being introduced are minimal at best, and are far outweighed by the efficiency gains and clinical benefits. Moreover, even when their activities are unregulated, medical device manufacturers are highly motivated to follow industry best practices for cybersecurity and cybersafety. Indeed, our infusion pump clients have already engaged us to discuss the secure design and implementation of these new capabilities, intent on taking products to market that are every bit as secure as those that have gone through a rigorous regulatory review process.
 
To quote my interviewer, “You’re not giving me anything!”, and needless to say my remarks never made it to print. Nonetheless, I find it encouraging that there is nothing dire or sensational to say on the matter. The working relationship between regulators, medical device OEMs and the security community is cooperative and highly functional, promoting safe and beneficial innovations such as this one.

The post New FDA Guidance On WiFi-Managed Infusion Pumps Is Cybersafe And Cybersecure appeared first on Harbor Labs.

]]>