Device Coordinated Voluntary Disclosures Good: Analysis

Share

Adoption of coordinated voluntary disclosure (CVD) policies by medical device manufacturers to promote medical device cybersecurity and patient safety supports public health and safety and also provides manufacturers with a number of legal and non-legal benefits. That’s the conclusion of the Medical Device Innovation Consortium, which includes an FDA representative on its steering committee, in a cybersecurity report.

The consortium’s report says that CVD policies establish formalized processes for obtaining cybersecurity vulnerability information, assessing vulnerabilities, developing remediation strategies, and disclosing the existence of vulnerabilities and remediation approaches to various stakeholders, often including peer companies, customers, government regulators, cybersecurity information sharing organizations, and the public.

The consortium says its key findings are: 

  •          there are numerous benefits to establishing CVD policies;
  •          CVD policies should reflect the heightened safety issues associated with medical devices;
  • ·        CVD policies need to involve the entire organization;
  •          CVD policies need the right organizational structure;
  •          there are a range of regulatory and legal considerations supporting establishment of CVD policies;
  •          medical device manufacturers should draft formal standard operating procedures to document the CVD policy;
  •          online portals can play a key role in the CVD process;
  •          reported vulnerabilities should be assess according to an established framework;
  •          FDA and the Department of Homeland Security are important collaboration partners;
  •          how a vulnerability is disclosed carries both regulatory and strategic considerations; and
  •          security researchers should be treated with respect.

“The growing adoption of CVD policies, including the use of online portals, is evidence of a maturing medical device industry that increasingly recognizes the benefits of transparency and cybersecurity risk mitigation,” the report concludes. “Collaboration among stakeholders in the medical device ecosystem is essential as the industry faces a growing range of cyber threats.”

Read more