FDA Could Improve Device Security: Expert

Aspen Tech Policy Hub fellow Daniel Bardenstein says FDA should require all medical device makers to include a baseline of certain cybersecurity protections in their products and to build in a feature that allows safe vulnerability scanning of their devices without disrupting their safe operation with patients. In an interview with Information Security Media Group, Bardenstein says the FDA approach of providing non-binding guidance recommendations for cybersecurity standards leads to inconsistency among manufacturers.

“The idea of the baseline is not an exhaustive list,” Bardenstein told the media outlet. “Obviously there are many different types of medical devices with different considerations. But, regardless of what type of device, passwords should be required to be strong.”

The report says FDA did not immediately respond to a request for comment on the proposal.

Read more