FDA 524B Cybersecurity Rule: A Dental Imaging Device Buying
Information Technology Solutions for Dentists and the Dental Industry. Serving the GTA and Southern Ontario.
Dental I/T, Dental Information Technology, Network Security, Toronto, GTA, Dental, Network, I/T, Information Technology, Computer, Data, Abeldent, Dentrix, LiveDDM, Patterson Dental, Henry Schein, K-Dental, Sinclair Dental, Schick CDR, Dexis, Carestream, Carestream Dental, Digital Radiography, X-ray, Dental X-ray, Dental Software Support, Software
18794
bp-nouveau,wp-singular,post-template-default,single,single-post,postid-18794,single-format-standard,wp-theme-bridge,wp-child-theme-bridge-child,theme-bridge,woocommerce-no-js,ajax_fade,page_not_loaded,,columns-4,qode-child-theme-ver-1.0.0,qode-theme-ver-10.0,wpb-js-composer js-comp-ver-4.12,vc_responsive

The FDA Now Requires Imaging Devices to Be Cyber-Secure by Design. Here Is How to Make It Your Purchasing Checklist.

A modern dental cone-beam CT scanner shown as a blue device with a protective cybersecurity shield built directly into the hardware and a small approval checkmark badge, illustrating imaging devices that are secure by design under FDA rules

The FDA Now Requires Imaging Devices to Be Cyber-Secure by Design. Here Is How to Make It Your Purchasing Checklist.

When your practice buys a new cone-beam CT unit, an intraoral sensor or a chairside scanner, the questions in the room are predictable: image quality, workflow, price, service contract. There is one question almost no one asks – and since 2023, U.S. federal law has quietly made it a fair one. The manufacturer of that connected device now has a legal duty to build cybersecurity into it and prove that to the FDA before it can be sold. You paid for that work. You are entitled to see it. Most practices never think to look.

This is not a breach alert and there is nothing to patch this morning. It is something more useful: a durable rule you can turn into leverage at the exact moment you have the most of it – before you sign the purchase order.

What the law actually requires

In December 2022, Congress added Section 524B to the Food, Drug, and Cosmetic Act, and it took effect in March 2023. It applies to “cyber devices” – broadly, any device that includes software and can connect to the internet or a network, which covers essentially every modern digital imaging system in a dental office. To win FDA clearance, the maker must now do several things and document them in the premarket submission:

  • Design, develop and maintain the device to be reasonably cyber-secure – so-called secure by design, rather than security added after the fact.
  • Provide a plan to monitor, identify and address post-market vulnerabilities, including issuing patches on a reasonable cadence and out-of-cycle for critical flaws.
  • Publish a coordinated vulnerability disclosure process, so researchers have a legitimate way to report problems.
  • Provide a Software Bill of Materials (SBOM) – a machine-readable inventory of the software components inside the device, including the open-source libraries it depends on.

A modern dental cone-beam CT scanner shown as a blue device with a protective cybersecurity shield built directly into the hardware and a small approval checkmark badge, illustrating imaging devices that are secure by design under FDA rules
The idea behind the rule is simple: security should be engineered into an imaging device before it ships, not bolted on by the practice years later.

The FDA has been willing to refuse submissions that fail to include this material since late 2023. In 2026 the guidance was refreshed to line up with the agency’s new Quality Management System Regulation (QMSR), which folds these expectations into the manufacturer’s overall quality system. The headline for a buyer is unchanged and worth repeating: the SBOM and cybersecurity requirements did not loosen. They are the baseline now.

Why a dental practice should care about a manufacturing rule

Because the burden of a device’s flaws does not stay with the manufacturer. It lands on the practice that owns the device, holds the patient records it touches, and answers to patients and to PHIPA when something goes wrong. We have written before about how imaging hardware becomes a security question the moment it joins your network – from where a sensor was made and what it quietly talks to, to the awkward reality of keeping an older scanner or CBCT running safely after the vendor stops patching it.

Section 524B attacks that problem at the source. A device built to the standard is one whose maker has committed, on the record, to shipping patches and telling you about vulnerabilities for the life of the product. A device that predates or ignores the standard is one where you are on your own. The difference between those two purchases is invisible on the spec sheet and enormous over the eight-to-ten years the equipment will sit in your operatory.

The one document that changes your leverage: the SBOM

A blue imaging device connected to an orderly exploded diagram of dozens of small software component blocks it is built from, with a magnifying glass over the list, illustrating a Software Bill of Materials that reveals what is inside a device
A Software Bill of Materials is an ingredients list for the device’s software – so when a component makes headlines, you can tell in minutes whether your scanner contains it.

Of everything in the rule, the SBOM is the piece a practice can use directly. Think of it as an ingredients list for the device’s software. Modern imaging systems are assembled from dozens of third-party and open-source components you never chose and cannot see – and those components are where a growing share of critical vulnerabilities live. When one of them makes the news, the first question is always the same: do we run it?

Without an SBOM, answering that means waiting on the vendor’s goodwill and hoping they respond before an attacker does. With one, you – or the IT partner who manages your network – can check in minutes whether the flawed component is inside your scanner. That is the same discipline that turned a recent scramble over a buried software flaw into a five-minute lookup for practices that knew what they were running. The SBOM is what makes “know what you run” possible for a sealed medical device.

Turn the rule into three purchasing questions

A calm blue practice decision-maker with a three-point checklist speech bubble asking questions of a vendor holding an imaging device, with an unsigned purchase order between them, illustrating asking cybersecurity questions before buying
You do not need to read the FDA submission. You need three questions and the confidence to withhold the purchase order until you get straight answers.

You do not need to read an FDA submission or become a compliance expert. You need to make three requests part of every imaging-equipment evaluation, and treat a vague answer as the answer:

  1. “Please provide the SBOM for this device.” A vendor building to the standard has one ready. Hesitation, confusion or a promise to “look into it” tells you where cybersecurity sits on their priority list.
  2. “What is your patching commitment and your end-of-support date?” Get the cadence for routine and emergency updates, and the year support ends, in writing. This is the single most valuable fact for planning, because the device will outlive its support window and you need to know when.
  3. “How do I report a security problem, and how will you notify me of one?” A real coordinated-disclosure process and a defined customer-notification path separate a serious manufacturer from one that will go quiet the day a flaw surfaces.

A blue imaging device on a timeline stretching into the future with recurring update-and-shield badges representing ongoing vendor patching, and one faded badge at the far end marking an end-of-support point to plan for
The rule is a floor, not a guarantee. The device you buy today will outlive its support window – so ask, in writing, how long the patches will keep coming.

None of this slows a purchase you were going to make anyway. It simply ensures that when two units are close on price and image quality – the situation you are usually in – the tiebreaker is the one that will cost you the least grief three years from now. It also pairs naturally with the questions you should already be asking about how a new device connects to your network, the same due diligence we applied when the FDA cleared AI that reads 3D dental scans and when a widely used imaging server flaw showed why a PACS should never face the internet.

What to do this week

Nothing here is urgent, and that is the point – it is far cheaper to build this into how you buy than to retrofit it after an incident. If you have a device purchase on the horizon, add the three questions above to your evaluation. If your existing fleet is a mystery, start a simple inventory: what each connected imaging device is, what it runs, when its support ends, and whether the vendor can supply an SBOM. That list is the foundation of every good decision that follows.

At Compudent Systems we help dental practices across the GTA and Ontario vet imaging and IT equipment before it is purchased, inventory what is already on the network, and build the segmentation and monitoring that keep it all safe for its full service life. If you have a device on order – or a fleet you have never fully mapped – contact Compudent Systems for an assessment. The best time to ask these questions is before the invoice is paid.


Sources & further reading:

Related Reading



Contact us today - How can we help you?