FDA Prioritizing Medical Device Cybersecurity: Post
FDA wants to make the strengthening of medical device cybersecurity a top priority and will need additional legislative authorities to advance medical device safety by ensuring the agency and public have critical information about device cybersecurity. That’s the conclusion of an online MedTech Dive post based on discussions with agency staff.
The HHS FY 2021 budget justification contains an FDA proposed plan for a Software Bill of Materials (SBOM), an electronically readable format designed to provide an inventory of third-party components in devices, and other provisions to better safeguard them against new and emerging cyber threats.
FDA reportedly wants to require med tech companies to have an SBOM as part of premarket submissions and the capability to update and patch device security into a product’s design. It also wants new postmarket authority to require that manufacturers adopt policies and procedures for coordinated disclosure of cybersecurity vulnerabilities as they are identified.
Agency staff told the newsletter that the proposed requirements are in line with its 2018 Medical Device Safety Action Plan that laid out the FDA cyber roadmap for modern enhancements to its oversight that would apply throughout the product lifecycle of devices.
The post says the legislative proposal would codify the requirements for device companies.