> ## Content Index
> Fetch the complete content index at: https://www.fdaweb.com/llms.txt
> Use this file to discover other available public pages before exploring further.

# Device Security Should Start in Design: FDA
- URL: https://www.fdaweb.com/device-security-should-start-in-design-fda/
- Published: 2017-09-14T12:00:00.000Z
- Updated: 2026-09-14T22:50:35.000Z
- Author: David McFarland
- Tags: Devices, #legacy-id-D5139625

FDA does not want to be reactive as it approaches issues of cyber security, according to CDRH associate director for science and strategic partnerships **Suzanne Schwartz**, speaking 9/13 at the Healthcare Security Forum in Boston. She said the agency’s mission is “harnessing the collective will and creating a community of multi-stakeholder engagements,” according to a *Healthcare IT News* online [report](http://www.healthcareitnews.com/news/fda-exec-medical-device-manufacturers-bake-security-design?ref=fdaweb.com). She urged manufacturers to work continually to assess and address the cyber risks of medical devices on the market.

“The thrust of what we do has to be proactive and forward-leaning,” Schwartz said. “We don’t want to be reactive.” She said the agency is working to foster a culture of continuous quality improvement with an eye on a product’s total life cycle.

FDA has established a risk management program that incorporates cybersecurity provisions from the National Institute of Standards and Technology and encourages communication with groups such as the National Health Information Sharing and Analysis Center to share emerging information about cyber vulnerabilities and threats.

“Many vulnerabilities are identified later on, during the use of the device,” she said. “The key is to have a process in place to share that information.”

According to Schwartz, vendors are legally required to comply with all applicable regulations and are subject to pre- and post-market cybersecurity guidance that articulates a “comprehensive, structured, and systematic” cybersecurity risk management program. Medical device cybersecurity, she said, is not voluntary for manufacturers.

Because weaknesses in system architecture and software leave too many devices vulnerable to threats that could directly affect hospital network operations, data integrity or patient safety, she said manufacturers must work to “bake security into the design” because “it’s much easier to bake it in then to bolt it on as an afterthought.”