Guangzhou Rongtao Medical Technology Co., Ltd. has released an evidence-based framework designed to guide healthcare facilities on whether to patch, segment, isolate, or replace legacy ultrasound systems.
Formulated using regulatory data from the US Food and Drug Administration (FDA), the Cybersecurity and Infrastructure Security Agency (CISA), adverse-event registries, and original equipment manufacturer (OEM) notifications, the report argues that equipment age is an ineffective decision metric.
Instead, the framework evaluates supportability across five distinct lifecycles: clinical usefulness, OEM product support, software and component support, security-control supportability, and physical serviceability.
A central finding from the analysis of 2,066 FDA 510(k) cart and console ultrasound clearances granted between 1977 and mid-2026 reveals that 90.1% predated Section 524B cyber-device statutory requirements, which took effect on 29 March 2023.
Furthermore, every system cleared between 2006 and 2020—the vintage band comprising the majority of active fleets—predates the statute. With annual clearance volumes remaining flat at 55 to 83 systems, the pre-statute installed base will not age out naturally within standard planning horizons.
CISA advisory records further substantiate the necessity of alternative disposition strategies beyond traditional software patching. Across 18 verified CISA medical advisories covering imaging products, half left at least one named device without a software fix at publication.
Crucially, all four advisories explicitly naming ultrasound lines exhibited incomplete patch coverage, directing users toward network restriction, physical access controls, or complete replacement.
Concurrently, the federal Known Exploited Vulnerabilities (KEV) catalogue mandates a 21-day median remediation timeline that validated medical devices cannot realistically achieve, whilst listing zero diagnostic-imaging manufacturers amongst its 276 entries.
Regulatory safety filings highlight a separate operational dynamic: none of the 8,525 ultrasound adverse-event reports submitted to the FDA since 2019 reference ransomware, hacking, or malware, and the agency records only a single ultrasound cybersecurity recall dating back to 2008.
The report notes this silence reflects incident-reporting pathways rather than low risk, meaning healthcare providers cannot rely on safety alerts to trigger mitigation.
"The most useful sentence in the whole record comes from an OEM end-of-support letter that stopped a product's software clock and kept its hardware clock running in the same document," said Frank Zhu, general manager of Rongtao Medical.
"That is the reality of legacy fleets: the clocks are separable. When the software clock stops, somebody still has to keep the hardware running — and that is the lane independent service occupies, inside the disposition framework, never as a substitute for it." Frank Zhu
The framework clearly delineates that physical maintenance cannot substitute for software security or generate OEM patches. Operating under ISO 13485:2016 and ISO 9001:2015 quality standards, Rongtao Medical provides hardware-supportability data—such as board-level diagnostics and component testing—to help healthcare organisations make informed disposition decisions.


