The Food and Drug Administration Center for Devices and Radiological Health issued draft cybersecurity guidance for medical devices, which includes recommendations for designing devices with cybersecurity in mind and FDA guidance for premarket submissions for devices with risks.The guidance is designed to facilitate “an efficient premarket review process,” while ensuring medical devices marketed to healthcare are “sufficiently resilient to cybersecurity threats.” The FDA is seeking feedback from healthcare leaders to further develop the supportive insights. The FDA first issued premarket guidance in 2014, later updating it in 2018 to meet the continuously evolving landscape. Industry leaders have been awaiting an update in the last few years.The latest guidance builds on its initial efforts, incorporating input from healthcare leaders from public meetings, previous comment periods, and recommendations from the Health Care Industry Cybersecurity Task Force Report to identify cybersecurity issues device manufacturers should address in the development and design process, as well as premarket submissions. The FDA developed the insights in response to the rapid evolution and scope of connected digital medical and Internet of Things (IoT) devices, especially with the increased electronic exchange of health information through medical devices.As the threats to healthcare become more frequent, severe, and clinically impactful, the FDA warns that “cybersecurity incidents have rendered medical devices and hospital networks inoperable, disrupting the delivery of patient care across healthcare facilities in the US and globally.”For example, some individual devices act as “single elements of larger medical device systems,” which can include facility networks, other devices, software update servers, and other interconnected components.“Consequently, without adequate cybersecurity considerations across all aspects of these systems, a cybersecurity threat can compromise the safety and/or effectiveness of a device by compromising the functionality of any asset in the system,” the FDA explained.“As a result, ensuring device safety and effectiveness includes adequate device cybersecurity, as well as its security as part of the larger system,” it added. With patient safety risks in mind, the FDA guidance seeks to address a number of longstanding challenges posed by increased connectivity.
Endpoint/Device Security, Security Architecture, Asset Management, Risk Assessments/Management
Seeking CISO feedback, FDA shares draft medical device cybersecurity guide

FDA is calling on healthcare stakeholders to provide feedback on its new medical device cybersecurity guide to ensure necessary elements are include to protect vulnerable tech through the lifecycle. ("
Lt. James Kelty monitors a critically-ill COVID-19 patient in the intensive care unit at Javits New York Medical Station, April 13, 2020.
" by
Official U.S. Navy Imagery
is marked with
CC BY 2.0
.)
Get daily email updates
SC Media's daily must-read of the most current and pressing daily news
You can skip this ad in 5 seconds