FDA Changes Focus of Cybersecurity Guidance: Lawyer
Attorney Allyson Mullen (Hyman, Phelps & McNamara) says that in a finalized guidance on postmarket management of cybersecurity in medical devices, FDA appears to have changed the focus from “essential clinical performance” to “patient harm.” Writing in her firm’s FDA Law Blog, Mullen says the change from wording in the draft guidance appears to shift the way in which the agency plans to evaluate cybersecurity risk. She says the guidance now says that its purpose is to “recommend how to assess whether the risk of patient harm is sufficiently controlled or uncontrolled. This assessment is based on an evaluation of the likelihood of exploit, the impact of exploitation on the device’s safety and essential performance, and the severity of patient harm if exploited.”
Mullen suggests that while the shift from essential clinical performance to patient harm is significant for the guidance, it may ultimately be simpler for manufacturers to apply. “Essential clinical performance incorporated the concept of harm, but also used more amorphous concepts such as acceptable and unacceptable clinical risk,” she writes. “These elements may have been difficult for manufacturers to determine on a case-by-case basis. Patient harm appears to be more straightforward and in line with standards that the device industry is already used to, including, for example, reporting corrections and removals …, which is required when the action is undertaken to reduce a risk to health.”
Mullen lists many other changes in the final guidance and notes that the document imposes significant new requirements on manufacturers of medical devices with potential cybersecurity vulnerabilities. For legacy products, she says, manufacturers may need to consider cybersecurity vulnerability for the first time in a product’s lifecycle. She also notes that like the draft guidance, the final version gives no additional information as to how, or whether, FDA plans to enforce the recommendations it sets out.