It's a gift that keeps on giving.
Once a medical device talks to a hospital system, information security and device regulation become one problem. The systems you set up to hold it are worth more every year.
The entanglement between ISO 27001 and the medical device industry gets interesting once you've got active medical devices connecting to hospital systems. It's not optional, because you're dealing with the transfer, and potential storage, of patient health data. It goes beyond security and into data anonymization and a whole lot of other intricacies, which makes it an exciting challenge. (I did not mean that facetiously.)
I love this kind of thing, because not enough people talk about it, and it's so valuable.
I think one of the biggest pities in this field is that a lot of people see writing things down and setting up these systems as cumbersome. It really is something that grows in its value and compounds over time. It can be complex at the beginning, because there's a lot to think about, but it's a gift that keeps on giving.
Maybe that's my own personal bias as someone who is a QA officer at heart.
⋆˙⟡