US issues medical device security recommendations
The US Food and Drug Administration has finalised recommendations to manufacturers for managing cybersecurity risks to better protect patient health and information.
The final guidance recommends that manufacturers consider cybersecurity risks as part of the design and development of a medical device and submit documentation to the FDA about the risks identified and controls in place to mitigate those risks. It also recommends that manufacturers submit their plans for providing patches and updates to operating systems and medical software.
The FDA’s concerns about cybersecurity vulnerabilities include malware infections on network-connected medical devices or computers, smartphones and tablets used to access patient data; unsecured or uncontrolled distribution of passwords; failure to provide timely security software updates and patches to medical devices and networks; and security vulnerabilities in off-the-shelf software designed to prevent unauthorised access to the device or network. The FDA has neither an indication that specific devices or systems have been purposely targeted, nor reports that any patients have been harmed as a result of cybersecurity breaches, but remains concerned about device-related cybersecurity vulnerabilities and their potential to adversely impact public health.
“There is no such thing as a threat-proof medical device,” said Suzanne Schwartz, MD, MBA, director of emergency preparedness/operations and medical countermeasures at the FDA’s Center for Devices and Radiological Health. “It is important for medical device manufacturers to remain vigilant about cybersecurity and to appropriately protect patients from those risks.”
As medical devices become more interconnected and interoperable, they can improve the care patients receive and create efficiencies in the healthcare system. Some medical devices, like computer systems, can be vulnerable to security breaches, potentially impacting the safety and effectiveness of the device. By carefully considering possible cybersecurity risks while designing medical devices, and having a plan to manage system or software updates, manufacturers can reduce the vulnerability in their medical devices.
The FDA has been working closely with other federal agencies and the medical device industry to identify and communicate with stakeholders about vulnerabilities. The agency is planning a public workshop this fall to discuss how government, medical device developers, hospitals, cybersecurity professionals and other stakeholders can collaborate to improve the cybersecurity of medical devices and protect the public health.
The FDA, an agency within the US Department of Health and Human Services, protects the public health by assuring the safety, effectiveness and security of human and veterinary drugs, vaccines and other biological products for human use, and medical devices. The agency also is responsible for the safety and security of its nation’s food supply, cosmetics, dietary supplements, products that give off electronic radiation, and for regulating tobacco products.
Wearable generator powers electronics by body movements
Researchers have developed a device that can generate electricity from vibrations or even small...
Ion speed record holds potential for faster battery charging
Scientists have broken a speed record using nanoscience that could lead to new advances in...
CSIRO opens facility to bring flexible solar tech to market
CSIRO has launched its state-of-the-art Printed Photovoltaic Facility in south-east Melbourne, to...