
Analysis finds nine in ten cleared ultrasound system designs predate the US cyber-device statute — and all four CISA advisories naming ultrasound lines had incomplete patch coverage
GUANGZHOU, China, Aug. 27, 2026 /PRNewswire/ -- Guangzhou Rongtao Medical Technology Co., Ltd. ("Rongtao Medical") today published an evidence-based framework for deciding whether a legacy ultrasound system should be patched, segmented, isolated or replaced — built from FDA clearance records, CISA advisories, adverse-event data and OEM support notices. The report argues that age is the wrong decision variable: supportability is, measured across five clocks that expire at different times — clinical usefulness, OEM product support, software and component support, security-control supportability, and physical serviceability.
The anchor statistic comes from all 2,066 FDA 510(k) clearances for cart and console ultrasound systems, 1977 through mid-2026: 90.1 percent were cleared before Section 524B's cyber-device requirements took effect on March 29, 2023 — and every console cleared between 2006 and 2020, the vintage band that dominates working fleets, predates the statute without exception. With clearance volume flat at 55 to 83 systems a year, the pre-statute population does not age out on any planning horizon.
The advisory record reinforces the case for dispositions beyond patching. Across 18 individually verified CISA medical advisories affecting imaging products, half left at least one named product with no software fix at publication — and all four advisories naming ultrasound product lines had incomplete patch coverage, with stated remedies of network restriction, physical access control, or replacement. The federal Known Exploited Vulnerabilities catalog, meanwhile, runs on a 21-day median remediation clock no validated medical device can meet, and names no diagnostic-imaging manufacturer among its 276 vendors.
The safety record is measurably silent: zero of the 8,525 ultrasound adverse-event reports filed with FDA since 2019 mention ransomware, malware, cybersecurity, hacking or a virus, and FDA's recall database holds exactly one ultrasound cybersecurity recall — from 2008. The report is careful about what that means: the silence measures a reporting pathway, not a risk level — hospitals cannot wait for a safety signal before deciding a disposition.
"The most useful sentence in the whole record comes from an OEM end-of-support letter that stopped a product's software clock and kept its hardware clock running in the same document," said Frank Zhu, General Manager of Rongtao Medical. "That is the reality of legacy fleets: the clocks are separable. When the software clock stops, somebody still has to keep the hardware running — and that is the lane independent service occupies, inside the disposition framework, never as a substitute for it."
The report states the boundary of that lane plainly: a hardware repair does not create an OEM patch, validate an operating-system change, or make a device cybersecure. Rongtao Medical is not a cybersecurity vendor and does not develop patches; it supplies the physical-serviceability evidence a disposition decision requires — board-level fault isolation, tested parts availability, and real-machine test documentation — under its ISO 13485:2016 and ISO 9001:2015 quality systems.
The full report — including the five-clock framework, the four dispositions with evidence gates and stop conditions, an OEM disclosure survey, procurement clauses for future purchases, and 38 source citations — is available at https://rongtaomedical.com/blog/reports/legacy-ultrasound-cybersecurity-patch-segment-isolate-replace.
About Rongtao Medical
Guangzhou Rongtao Medical Technology Co., Ltd. is an independent medical imaging equipment service provider specializing in ultrasound repair, core board repair, probe solutions and tested replacement parts. Founded in 2013, the company supports distributors, refurbishers and biomedical service teams across more than 140 countries and regions from its Guangzhou, China facility, operating under ISO 13485:2016 and ISO 9001:2015 quality management systems.
Company Contact
Rongtao Medical — General Inquiries
Guangzhou Rongtao Medical Technology Co., Ltd.
Phone: +86 195 6604 2918
Email: [email protected]
Web: https://www.rongtaomedical.com/contact
Media Relations
Rongtao Medical — Press Inquiries
Phone: +1 415 689 1868
Email: [email protected]
Note to Editors
Frank Zhu, General Manager, is available for interview through the company's contact page. The report covers the Olympus EU-ME2 end-of-support notice as its framing case, an analysis of the CISA Known Exploited Vulnerabilities catalog and ICS Medical Advisories series, a keyword analysis of 13,213 FDA MAUDE ultrasound reports, a ten-vendor OEM disclosure survey (zero of ten publish an ungated per-product operating-system or support-status document), the corrected WannaCry record from the UK National Audit Office and NHS England, and a two-axis serviceability-versus-supportability decision matrix. Where this release cites data, figures are drawn from the report's 38 cited sources, including FDA, CISA, IMDRF, Microsoft lifecycle records, HHS, NIST, the FBI, and OEM product-security notices. The methodology section states each dataset's limits, including that clearances are design decisions rather than installed units, and that safety-record silence reflects reporting pathways. The full report URL appears in the body of this release.
SOURCE Rongtao Medical
Share this article