Whitepaper: Dr. Rushanan explains Best Practices for Ensuring Secure… Read Now
CASE STUDY

MRI Drug Infusion Pump – Securing a Custom Radio Protocol for Regulatory Approval

Medical System
MRI Drug Infusion Pump
Project Date
February 2025
Services
Project Leader

About the Author

  • Dr. Luis Vargas, Director of Medical Cybersecurity, professional headshot
    Director of Medical Cybersecurity

    Dr. Luis Vargas is the Director of Medical Cybersecurity at Harbor Labs. His extensive research and publications in the field of medical endpoint security in hospital networks allows him to combine the security perspectives of medical device manufacturers, regulators, and clinical end users together in every Harbor Labs engagement. Highly published and the holder of multiple security-related patents, it is Dr. Vargas’ broader expertise in data science and machine learning that allows him to lead Harbor Labs’ many AI-based medical projects. Dr. Vargas specializes in surgical robotics systems, Software-as-a-Medical Device (SaMD), clinical AI systems, and EHR/EMR systems. Dr. Vargas holds his Ph.D. in Computer Engineering from the University of Florida.

Harbor Labs partnered with a major manufacturer of MRI drug infusion pumps to resolve a set of disqualifying issues that arose during their initial FDA submission. Infusion pumps used to administer drugs to patients undergoing an MRI must be shielded in order to operate in the high magnetic field of the scanning machine. This manufacturer’s innovative approach was to employ a wireless controller that would communicate with the pump over a proprietary 2.4 GHz radio protocol designed to protect the connection from the effects of the magnetic field. However, when the device was submitted to the FDA for 510(k) clearance, the application was rejected due to insufficient evidence that such a radio interface was secure, and that its traffic could not be sniffed or hijacked by an attacker.

Working directly with the manufacturer’s hardware, Harbor Labs was able to tear down the devices comprising the system, analyze the cryptography in the firmware, and reverse engineer the radio protocol. Harbor Labs then produced documentation detailing how the manufacturer had in fact appropriately secured the infusion pump communication. This involved reproducing the build system used by the manufacturer to produce their signed firmware images and flash custom firmware builds with debugging enabled in order to dynamically analyze radio messages as they were sent and received. Harbor Labs was able to view the entire exchange of data between the controller and pump, showing the unencrypted “handshake” between the two devices authenticating a connection, and then the successive encrypted data transfer of pump instructions being transmitted.

Harbor Labs also performed a deep source code audit of the manufacturer’s firmware, specifically analyzing their implementation of cryptographic functions. Several issues were identified during this audit, and Harbor Labs worked with the manufacturer to modify the source to better ensure the security of their radio communication. Finally, Harbor Labs produced detailed documentation and diagrams describing the manufacturer’s system and the encryption/decryption processes to clearly communicate these complex processes to the FDA reviewer.

About the Author

  • Dr. Luis Vargas, Director of Medical Cybersecurity, professional headshot
    Director of Medical Cybersecurity

    Dr. Luis Vargas is the Director of Medical Cybersecurity at Harbor Labs. His extensive research and publications in the field of medical endpoint security in hospital networks allows him to combine the security perspectives of medical device manufacturers, regulators, and clinical end users together in every Harbor Labs engagement. Highly published and the holder of multiple security-related patents, it is Dr. Vargas’ broader expertise in data science and machine learning that allows him to lead Harbor Labs’ many AI-based medical projects. Dr. Vargas specializes in surgical robotics systems, Software-as-a-Medical Device (SaMD), clinical AI systems, and EHR/EMR systems. Dr. Vargas holds his Ph.D. in Computer Engineering from the University of Florida.

CAPABILITIES

Ready to Help at Any Stage

Not every project fits into a predefined path—and not every security challenge starts with compliance. We also support research teams, software developers, and security leads with targeted expertise and custom testing strategies. If it’s complex, connected, and critical, we’re ready to help.

Persistent Vulnerability Monitoring

Continuous analysis of deployed devices to surface and track emerging threats.

Security & Data Privacy

Design support and documentation to help meet regulatory expectations.

Hardware Testing

Interface validation, physical compromise evaluation, and teardown analysis.

Software & Firmware Testing

Vulnerability analysis, fuzz testing, and formal verification for medical codebases.

Let’s Talk!

Contact Us Today

Whether you’re navigating regulatory hurdles or scaling your security program, our team is here to help. Let’s talk about what’s next.

info@harborlabs.com

1.855.CYBR.SCI

1777 Reisterstown Road, Suite 230
Baltimore, MD 21208

Please fill out the form and we’ll get back to you shortly.

I’m interested in more information about: