Mitigation of Cybersecurity Risks in Medical Device Software: FDA Discussion & Insights for OEMs, Remanufacturers, and Servicers

General News

Summary

Dr. Fu has stated that he anticipates the FDA will issue an updated draft version of the premarket cybersecurity guidance for OEMs to take into consideration while designing software for medical devices. If you are an entity providing a maintenance service for a medical device that includes software, it is worth considering, in light of FDA’s Cybersecurity Discussion Paper, the following: • Report any known or suspected incidents of cyberattacks to the OEMs and/or remanufacturers as soon as possible. • Servicing, on the other hand, means the repair and/or preventive or routine maintenance of one or more parts in a finished device, after distribution, for purposes of returning it to the safety and performance specifications established by the OEM and to meet its original intended use.” (Id. Dr. Fu had previously written that hacking of medical devices is not the only cybersecurity risk, and that “the unavailability of patient care and the lack of health data integrity” are also significant concerns. Specifically, the approach that the FDA recommends in the February 2021 guidance regarding servicing of medical devices is based on the conventional requirements-specification-verification model that requires a priori knowledge of cybersecurity risks.

Classifications

industries
Aerospace
applications
Web and Content Management

AskAI Classifications

Labels
No AI classifications detected

Linked Companies