Hospitals, Healthcare Systems Under IT Attack: FDA

Share
FDA director of emergency preparedness, operations, and medical countermeasures Suzanne Schwartz says the agency wants medical device manufacturers and healthcare delivery organizations to incorporate threat monitoring, cyber hygiene for better prevention of attacks, and active responses to identified vulnerabilities. In an online interview with Healthcare IT News, Schwartz says those steps are necessary because hospitals and healthcare systems “are under constant attempts at attack and intrusion of their networks. Protection of these systems, which contain highly sought after personal information and personal identity information, means that medical devices need to be better secured as well.”

Schwartz discusses the agency’s work with MITRE Corp. to advance the medical device security vision. She says MITRE’s work includes “evolving a medical device vulnerability ecosystem that will share relevant cybersecurity information among both government and private sector stakeholders.” The company also is working with the agency on a Common Vulnerability Scoring System to serve as a vulnerability assessment tool that would be meaningful to the clinical environment, and directly applicable to medical devices. “We believe that having a common taxonomy that fits the needs of the healthcare setting where medical devices reside, and that takes into account specific considerations that are unique to use of these products will be of great benefit to stakeholders in advancing the state of medical device security,” she says.

Read more