Draft Guide on Cybersecurity for Legacy Devices

Share

The International Medical Device Regulators Forum (IMDRF), of which FDA is a member, has released for comment a proposed guidance entitled “Principles and Practices for the Cybersecurity of Legacy Medical Devices.” The document is intended to supplement the group’s 2020 guidance on Principles and Practices for Medical Device Cybersecurity to provide more information on cybersecurity expectations for legacy devices.

 

This guidance is intended to provide stakeholders with input on how to identify potential legacy devices and practical, feasible approaches for implementing cybersecurity protections for such devices. Under the guidance, if a single component within a device becomes end-of-life (EOL)/end-of-service (EOS), then a medical device maker should perform a risk assessment to determine if patient safety risks arise. “If there are patient safety impacts and the device is in the support phase, manufacturers should attempt to mitigate the risk of the unsupported component via an update or other design change,” it says. “When in the support ( phase, the goal of an update or design change would be to replace functionality of the unsupported component with either a supported alternative component or other design change such that the device can safely maintain its intended use until the device reaches its planned EOS.

 

If a risk is mitigated, without the use of unsupported components, then generally the device may remain in the support phase, the guidance says. “If the risk is mitigated such that the device may be reasonably protected but the mitigation includes unsupported components,” then the device can transition to limited support. Device makers are also expected to publicly communicate this and provide the more detailed security documentation needed to facilitate the transition, it says.

 

The guidance also provides other scenarios for legacy devices and recommendation on how to proceed.

Read more