Companies Not Ready for New Cyber Safeguards: Article

Share

A hard-hitting SC Media online post says even the most equipped health systems are unprepared to meet FDA’s new medical device cybersecurity safeguards. The post looks at FDA guidance to implement new requirements from the Consolidated Appropriations Act of 2023 and the six-month grace period given until the requirements take effect 10/1.

“It’s super exciting,” MedCrypt senior director of cybersecurity quality and safety Naomi Schwartz told SC Media. “There hasn’t been a change like this allowing regulatory bodies in the U.S. to go after something for cybersecurity” for the last decade.

The post says that while some outlets have suggested the 10/1 deadline is actually a delay for cyber requirements for new submissions, there’s evidence to suggest FDA is already bouncing back submissions for failing to meet certain criteria.

Even some manufacturers are incorrectly interpreting the news as “delayed enforcement,” said MedCrypt CEO Mike Kijewski. Rather, “the day is finally here,” and “FDA was gracious enough to give people six months to get their house in order.”

CDRH Office of Strategic Partnerships and Technology Innovation Suzanne Schwartz said manufacturers need to realize the enforcement delay to 10/1 isn’t an excuse to not put the cybersecurity elements in place.

Rather, she said, it should be viewed as six months of relief or a period of FDA support to get devices up to par.

“FDA is not going to accept your excuses anymore,” SC Media quotes MedCrypt’s Schwartz as saying. “It’s been pretty clearly explained for several years in draft guidance on what FDA’s expectations are moving forward.”

The post says that over the next six months, manufacturers can expect to see pushback from the agency when submitting new devices.

Read more