We use cookies to understand how you use our site and to improve your experience. This includes personalizing content and advertising. To learn more, click here. By continuing to use our site, you accept our use of cookies. Cookie Policy.

Features Partner Sites Information LinkXpress
Sign In
Advertise with Us
GLOBETECH PUBLISHING LLC

Download Mobile App




FDA Issues Cybersecurity Recommendations for Medical Device Manufacturers

By HospiMedica International staff writers
Posted on 02 Feb 2016
Print article
The US Food and Drug Administration (FDA; Silver Spring, MD, USA) has issued a draft guidance outlining important steps medical device manufacturers should take to address cybersecurity risks.

According to the FDA, cybersecurity threats to medical devices are a growing concern, and exploitation of cybersecurity vulnerabilities presents a potential risk to the safety and effectiveness of such devices. While manufacturers can incorporate controls in the design of a product to help prevent these risks, they must also consider improvements during maintenance of devices, since the evolving nature of cyber threats means risks may arise throughout a device’s entire lifecycle. A structured and systematic comprehensive approach that responds in a timely fashion to identified vulnerabilities is thus recommended.

For the majority of cases, actions taken by manufacturers to address cybersecurity vulnerabilities and exploits should include routine updates or patches, for which no advanced notification, additional premarket review, or reporting under FDA regulations is required. For a small subset of cybersecurity vulnerabilities and exploits that may compromise essential clinical performance of a device and present a reasonable probability of serious adverse health consequences or death, the FDA would require medical device manufacturers to notify the agency.

In cases where the vulnerability is quickly addressed in a way that sufficiently reduces the risk of harm to patients, the FDA does not intend to enforce urgent reporting of the vulnerability to the agency, if certain conditions are met. These include no serious adverse events or deaths associated with the vulnerability; that within 30 days of learning of the vulnerability, the manufacturer notifies users and implements changes that reduce the risk to an acceptable level; and that the manufacturer reports the vulnerability, its assessment, and remediation to its Information Sharing Analysis Organization (ISAO).

“All medical devices that use software and are connected to hospital and health care organizations’ networks have vulnerabilities; some we can proactively protect against, while others require vigilant monitoring and timely remediation,” said Suzanne Schwartz, MD, MBA, associate director for science and strategic partnerships and acting director of emergency preparedness/operations and medical countermeasures in the FDA’s Center for Devices and Radiological Health (CDRH).

“The FDA is encouraging medical device manufacturers to take a proactive approach to cybersecurity management of their medical devices. Only when we work collaboratively and openly in a trusted environment, will we be able to best protect patient safety and stay ahead of cybersecurity threats,” continued Dr. Schwartz. “Today’s draft guidance will build on the FDA’s existing efforts to safeguard patients from cyber threats, by recommending medical device manufacturers continue to monitor and address cybersecurity issues while their product is on the market.”

Related Links:

US Food and Drug Administration


Gold Member
SARS‑CoV‑2/Flu A/Flu B/RSV Sample-To-Answer Test
SARS‑CoV‑2/Flu A/Flu B/RSV Cartridge (CE-IVD)
Gold Member
STI Test
Vivalytic Sexually Transmitted Infection (STI) Array
Silver Member
Wireless Mobile ECG Recorder
NR-1207-3/NR-1207-E
New
Electric Bariatric Patient Lifter
SVBL 205

Print article

Channels

Critical Care

view channel
Image: The stretchable microneedle electrode arrays (Photo courtesy of Zhao Research Group)

Stretchable Microneedles to Help In Accurate Tracking of Abnormalities and Identifying Rapid Treatment

The field of personalized medicine is transforming rapidly, with advancements like wearable devices and home testing kits making it increasingly easy to monitor a wide range of health metrics, from heart... Read more

Patient Care

view channel
Image: The portable, handheld BeamClean technology inactivates pathogens on commonly touched surfaces in seconds (Photo courtesy of Freestyle Partners)

First-Of-Its-Kind Portable Germicidal Light Technology Disinfects High-Touch Clinical Surfaces in Seconds

Reducing healthcare-acquired infections (HAIs) remains a pressing issue within global healthcare systems. In the United States alone, 1.7 million patients contract HAIs annually, leading to approximately... Read more

Point of Care

view channel
Image: The Quantra Hemostasis System has received US FDA special 510(k) clearance for use with its Quantra QStat Cartridge (Photo courtesy of HemoSonics)

Critical Bleeding Management System to Help Hospitals Further Standardize Viscoelastic Testing

Surgical procedures are often accompanied by significant blood loss and the subsequent high likelihood of the need for allogeneic blood transfusions. These transfusions, while critical, are linked to various... Read more
Copyright © 2000-2024 Globetech Media. All rights reserved.