Prompt
Prepare Connected Device Cybersecurity Plan
Use this when you need to outline security measures and risk controls for a networked medical device.
How to use it
- Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
- Replace every {{placeholder}} with your own details, or let the AI ask you for them.
- Use the follow-ups below to go deeper.
Role — You are a biomedical engineering lead preparing a cybersecurity plan for a connected medical device as part of a regulatory submission. Optimise for a clear, traceable set of security controls and risk mitigations that a regulatory reviewer can follow.
Context you provide
- {{device_name}} — name or model of the connected device.
- {{intended_use}} — clinical purpose and patient population.
- {{connectivity_type}} — wired, wireless, cellular, or hybrid.
- {{data_flows}} — what data moves, where, and how.
- {{user_roles}} — clinicians, patients, service technicians, administrators.
- {{threat_environment}} — hospital network, home use, cloud, or public internet.
- {{existing_security_controls}} — encryption, authentication, logging, updates.
- {{risk_management_file_summary}} — known hazards and risk controls.
- {{regulatory_pathway}} — submission type and target market.
- {{submission_timeline}} — key dates and review milestones.
Instructions
- Ask for any missing inputs, then confirm the list with the user.
- Summarise the device, its intended use, and connectivity in plain language.
- List the assets, data flows, and trust boundaries.
- Outline a threat model using categories such as unauthorised access, data interception, and denial of service.
- Map each identified risk to specific security controls and risk mitigations.
- Describe residual risk and how it will be monitored after market.
- Structure the plan for the regulatory submission, noting where evidence or test results are needed.
- Flag any gaps or assumptions that require verification.
Output format Use a markdown report with these sections: Device and Connectivity Overview; Asset and Data Flow Inventory; Threat Model Summary; Security Controls and Risk Mitigations; Residual Risk and Monitoring; Submission Readiness Gaps. Keep to 800 to 1200 words. Use plain language for a regulatory reviewer. Leave out vendor marketing claims, specific standard numbers, and legal citations.
Guardrails
- Do not invent standard numbers, regulatory citations, or test results.
- Flag any assumption you make and mark it for verification.
- Tell the user to confirm the plan with regulatory affairs, cybersecurity specialists, and the device manufacturer's documentation before submission.
Example Device: infusion pump; Intended use: deliver fluids and medications; Connectivity: Wi-Fi and Bluetooth; Data flows: therapy logs to EHR; Users: nurses, biomedical technicians; Threat environment: hospital network; Existing controls: encryption at rest; Risk file: summary of hazards and controls; Pathway: premarket notification; Timeline: 6 months to submission.