Congressman Supports FDA Device Cybersecurity Efforts

Share
Rep. Jim Langevin (D-RI), who co-chairs the Congressional Cybersecurity Caucus, is supporting FDA’s draft guidance on “Postmarket Management of Cybersecurity in Medical Devices.” In a 4/21 letter to the agency, Langevin said the guidance, when finalized, should help improve medical device cybersecurity.

“The risk-based nature of the guidance extends to the recommended cybersecurity practices medical device manufacturers should adopt,” he told FDA. “Rather than outline specific controls, which would rapidly become obsolete, the guidance suggests processes, such as monitoring cybersecurity information sources, that are tied to a holistic model of risk. Of note are the recommendations regarding vulnerability handling and disclosure, as effective vulnerability programs are essential for alerting manufacturers to security problems.”

Beyond the guidance, Langevin urged FDA to ensure that manufacturers are properly complying with the proposed mitigation methods or are properly reporting cybersecurity risks under 21 CFR part 806. “I encourage FDA to build upon its successful collaborations with industry in this space as exemplified by the cybersecurity workshops begun in 2014,” he said. “By working together with manufacturers, caregivers, patients, information technology experts, and security researchers, FDA can build a safer environment that still allows for innovations around medical device networking.”

Read more