Whitepaper: Dr. Rushanan explains Best Practices for Ensuring Secure… Read Now
CASE STUDY

Mobile Cardiac Telemetry System – Cybersecurity Consulting Throughout the Product Development Lifecycle

Medical System
Mobile Cardiac Telemetry System
Project Date
February - October 2024
Services
Project Leader

About the Author

  • Dr. Abbas Acar, Senior Research Scientist, professional headshot
    Senior Research Scientist

    Dr. Abbas Acar is a Senior Research Scientist at Harbor Labs. Dr. Acar serves as a project lead, as well as a lead tester and analyst on Harbor Labs medical engagements. Dr. Acar is highly published and has performed extensive research on mobile device security, biometric security, and on-device ML for IoT systems. He specializes in cardiac devices, sleep apnea systems, drug compounders, genomic sequencing systems, and medical imaging. Dr. Acar holds his Ph.D. in Electrical and Computer Engineering from the Florida International University.

Harbor Labs collaborated with a manufacturer of a mobile cardiac telemetry platform to support the design, implementation, and validation of security features across their connected ecosystem. The system included a wearable ECG patch, mobile and desktop applications, a clinician-facing web portal, and a cloud-based backend infrastructure. Over the course of more than a year, Harbor Labs personnel were integrated with the client’s development teams, participating in architecture reviews, security planning, and ongoing technical consultation.

Harbor Labs’ involvement began at the requirements phase, where senior staff co-authored cybersecurity specifications to ensure alignment with standards. As development progressed, Harbor Labs guided the implementation of a Key Management System and an end-to-end encryption strategy for protecting ECG data across all layers of the system.

Harbor Labs provided continuous security support throughout the development lifecycle. This included reviewing design iterations, assessing architectural updates, and helping the client maintain secure-by-design principles as system complexity evolved.

As part of cybersecurity threat assessment, Harbor Labs produced regulatory-grade documentation covering asset identification, communication flow mapping, STRIDE-based threat modeling, and the development of system-level architecture views — including multi-patient harm analysis, updability/patchability view, and security use case scenarios. These materials directly supported regulatory submissions and internal reviews.

Harbor Labs then led a multi-phase penetration testing campaign that covered all critical surfaces of the product: the embedded firmware on the wearable device, mobile and web applications, backend cloud services, and the clinician desktop software used for ECG review and reporting.

Today, Harbor Labs continues to support the client with formal Verification & Validation (V&V) testing – closing the loop between early risk identification and post-development assurance. This long-term engagement exemplifies how Harbor Labs works with its partner device manufacturers to embed cybersecurity throughout the product development lifecycle.

About the Author

  • Dr. Abbas Acar, Senior Research Scientist, professional headshot
    Senior Research Scientist

    Dr. Abbas Acar is a Senior Research Scientist at Harbor Labs. Dr. Acar serves as a project lead, as well as a lead tester and analyst on Harbor Labs medical engagements. Dr. Acar is highly published and has performed extensive research on mobile device security, biometric security, and on-device ML for IoT systems. He specializes in cardiac devices, sleep apnea systems, drug compounders, genomic sequencing systems, and medical imaging. Dr. Acar holds his Ph.D. in Electrical and Computer Engineering from the Florida International University.

CAPABILITIES

Ready to Help at Any Stage

Not every project fits into a predefined path—and not every security challenge starts with compliance. We also support research teams, software developers, and security leads with targeted expertise and custom testing strategies. If it’s complex, connected, and critical, we’re ready to help.

Persistent Vulnerability Monitoring

Continuous analysis of deployed devices to surface and track emerging threats.

Security & Data Privacy

Design support and documentation to help meet regulatory expectations.

Hardware Testing

Interface validation, physical compromise evaluation, and teardown analysis.

Software & Firmware Testing

Vulnerability analysis, fuzz testing, and formal verification for medical codebases.

Let’s Talk!

Contact Us Today

Whether you’re navigating regulatory hurdles or scaling your security program, our team is here to help. Let’s talk about what’s next.

info@harborlabs.com

1.855.CYBR.SCI

1777 Reisterstown Road, Suite 230
Baltimore, MD 21208

Please fill out the form and we’ll get back to you shortly.

I’m interested in more information about: