Companies Making Cybersecurity Progress: Schwartz
CDRH associate director for science and strategic partnerships Suzanne Schwartz says medical device manufacturers have made “a fair amount of progress that has been very encouraging” in dealing with cybersecurity issues. In an audio interview with the Information Security Media Group, Schwartz says the agency has seen industry be “more forward-leaning in adopting what we call coordinated disclosure, establishing policies and procedures within their firms so they can be best prepared to receive information around medical device vulnerabilities…, work internally and with partners to assess that information, and then appropriately communicate around the vulnerability as well as the mitigation in order to reduce the potential for risk to patients.”
Asked to identify myths that continue to be repeated about medical device cybersecurity, Schwartz highlighted two:
- the idea that manufacturers must come to FDA every time they have a software update or fix or patch that enhances cybersecurity; and
- the notion that it is voluntary for manufacturers to follow FDA cybersecurity guidances.
She said the notion of voluntary compliance comes from the fact that FDA has issued its position in guidance documents that contain the words “non-binding recommendations.” But she added that there already are laws and regulations in place on cybersecurity and the guidances exist to tell industry how FDA recommends that they meet those requirements within the broader construct of the Quality System Regulation.