IMDRF Draft Cybersecurity Guidance
The International Medical Device Regulators Forum has issued a draft guidance, Principles and Practices for Medical Device Cybersecurity, “to provide fundamental concepts and considerations on the general principles and best practices to facilitate international regulatory convergence on medical device cybersecurity.” The document is intended to provide concrete recommendations to all responsible stakeholders on the general principles and best practices for medical device cybersecurity, including in vitro diagnostic medical devices.
In general, the guidance outlines recommendations for medical device manufacturers, healthcare providers, regulators, and users to: employ a risk-based approach to the design and development of medical devices with appropriate cybersecurity protections; minimize risks that could arise from use of a device for its intended purposes; and ensure maintenance and continuity of critical device safety and effectiveness.
The document considers cybersecurity in the context of medical devices that (1) contain software and (2) exist as software only. The forum says it is important to note that the guidance’s scope is limited to consideration of the potential for patient harm. “While other types of harm such as those associated with breaches of data privacy are important, they are not considered within the scope of this document,” it says.