> ## Content Index
> Fetch the complete content index at: https://www.fdaweb.com/llms.txt
> Use this file to discover other available public pages before exploring further.

# Attorneys Weigh FDA Reporting of Cybersecurity Upgrades
- URL: https://www.fdaweb.com/attorneys-weigh-fda-reporting-of-cybersecurity-upgrades/
- Published: 2016-10-31T12:00:00.000Z
- Updated: 2026-09-14T21:43:47.000Z
- Author: David McFarland
- Tags: Devices, #legacy-id-D5137211

A [client alert ](https://www.remarksblog.com/2016/10/is-your-cybersecurity-upgrade-fda-reportable/?utm%5Fsource=DLA%20Piper%20-%20Remarks&utm%5Fcampaign=add78f9488-RSS%5FEMAIL%5FCAMPAIGN&utm%5Fmedium=email&utm%5Fterm=0%5F5a04e83928-add78f9488-72316073)by DLA Piper attorneys reviews when a cybersecurity-related change to a device is reportable to FDA. In particular, a correction to a device already in the field can trigger FDA reporting under 21 CFR Part 806, the alert says. “The reporting threshold is whether a correction or removal is initiated ‘to reduce a risk to health’ or to remedy a violation of FDA law ‘which may present a risk to health,’” it says.

With rising awareness of cyberattacks and device security oversights, FDA addressed the applicability of Part 806 earlier this year in a [draft guidance](http://www.fda.gov/downloads/MedicalDevices/DeviceRegulationandGuidance/GuidanceDocuments/UCM482022.pdf?ref=fdaweb.com) intended to help medical device makers address postmarket management of cybersecurity vulnerabilities. The document outlines important steps device makers should take to continually address cybersecurity risks to keep patients safe and better protect the public health. It also details the agency’s recommendations for monitoring, identifying and addressing cybersecurity vulnerabilities in medical devices once they have entered the market.

The guidance, according to the client alert, addresses (**1**) medical devices that contain software (including firmware) or programmable logic; and (**2**) software that is a medical device. It asserts that manufacturer obligations now include monitoring, identifying, and addressing cybersecurity vulnerabilities throughout the product lifecycle*.* “The FDA underscores key postmarketing responsibilities − the Quality System Regulation (QSR), Part 806, and PMA and 510(k) reporting and filing obligations − and their role in preventing and rapidly responding to cybersecurity threats,” the alert says. “With respect to Part 806 specifically, the agency states that most ‘cybersecurity routine updates or patches’ will not trigger Part 806 reporting as a correction. Rather, the FDA will typically consider changes that are made solely to strengthen cybersecurity to be ’device enhancements’ and thus not reportable.”

There is a caveat with such device corrections/enhancements, according to the DLA Piper attorneys. The guidance leaves open the possibility that changes made to prevent or remedy certain cybersecurity vulnerabilities and exploits will trigger Part 806 reporting. “For example, changes made or other actions taken to address ‘uncontrolled risk’ to ‘essential clinical performance’ would generally be subject to Part 806 reporting requirements,” they write, adding that the guidance provides some key definitions:

- A “vulnerability” is defined as a weakness in a system, security procedure, control, or implementation that leaves IT open to exploitation by a “threat.”
- An “exploit” means the vulnerability has either accidentally or intentionally been taken advantage of, “and could impact the essential clinical performance of a medical device or use a medical device as a vector to compromise the performance of a connected device or system.”
- “Threats” are circumstances or events with the potential to adversely impact “the essential clinical performance of the device, organizational operations…organizational assets, individuals, or other organizations.”

The attorneys note that not all such scenarios require reporting. The agency does not intend to enforce reporting requirements *if*:

**1**) there are no known serious adverse events or deaths associated with the vulnerability

**2**) within 30 days of learning of the problem, the manufacturer’s changes or compensating controls bring the residual risk to an acceptable level

**3**) within 30 days of learning of the problem, the manufacturer notifies users and

**4**) the manufacturer is a participating member of an Information Sharing Analysis Organization.

The client alert advises that device manufacturers begin a dialog with their IT, regulatory, quality, and legal teams, and to ensure they are aware of planned changes and upgrades and their potential impact on FDA reporting obligations.