FDA Can Help CMS with Hospital Cybersecurity: OIG
The HHS Inspector General (IG) says FDA should be working with the Centers for Medicare and Medicaid Services (CMS) on cybersecurity for networked medical devices in hospitals. In an Issue Brief, the IG says that without proper cybersecurity controls, hospitals’ networked medical devices can be compromised, which can lead to patient harm.
The report says the CMS survey protocol for overseeing hospitals is silent on device cybersecurity. It recommends that CMS identify and implement an appropriate way to address cybersecurity of networked medical devices in its quality oversight of hospitals in consultation with HHS partners and others.
The report notes the IG previously examined FDA’s role in assessing the cybersecurity risk of medical devices in premarket and postmarket settings. A 2018 report found the agency had taken steps to address emerging cybersecurity concerns, including issuing guidances on medical device cybersecurity and reviewing cybersecurity information in premarket submissions for networked medical devices.
The IG says CMS should work with partners inside and outside HHS, including FDA, to determine the best method for addressing cybersecurity of networked medical devices in hospitals.