This document provides an introduction to medical device security. It defines medical devices and provides examples. Intended use determines if a device is regulated. Software can be a medical device. Regulations and standards like IEC 62443 govern security. Old devices increase interconnectivity and associated risks. Security goals are confidentiality, integrity and availability to prevent patient harm. Common vulnerabilities include unpatched systems and weak credentials. Risk assessments must consider safety impacts. Manufacturers must integrate security into development and handle incidents and vulnerabilities.