AdvaMed Wants 1 Medical Device Cybersecurity Guidance

Share

AdvaMed says that FDA should better align its draft guidance on postmarket management of cybersecurity in medical devices with its premarket cybersecurity guidance. A 4/21 comment letter says that the trade group recognizes that combining the guidances “presents some administrative challenges [but] we believe the agency should combine both guidances into a single, holistic guidance on medical device cybersecurity.”

The trade association also says that because the agency is proceeding through guidance, it should clarify in the document that its recommendations are not prescriptive and should not form the basis of a citable event during an inspection. “This is particularly true given the number of technical guidances that FDA has released, which require the agency to take a flexible approach for cybersecurity management,” the letter says. “Should FDA intend for the recommendations described in the draft guidance to be prescriptive, the agency should proceed through notice and comment rulemaking.”

AdvaMed’s three general comments on the guidance are: (1) eliminate “essential clinical performance” from the document and instead focus on maintaining device functionality and safety, (2) provide more information about Information Sharing and Analysis Organizations, and (3) continue to rely on consensus standards such as the National Institute for Standards and Technology’s framework for improving clinical infrastructure.

Read more