Implementing Cybersecurity Provision in Spending Bill

Share

CDRH Office of Strategic Partnerships and Technology Innovation director Suzanne Schwartz says the agency is working to implement provisions in the recently-approved omnibus spending bill giving FDA authority to require medical device manufacturers to address cybersecurity issues. In an online interview with HealthcareInfoSecurity, Schwartz said the agency has spent several years urging voluntary action to address cybersecurity in medical devices and is “thrilled” to receive the legal authority to require that companies address the issue.

Asked how FDA is implementing the new law, Schwartz said the agency is currently conducting a legal analysis of the bill’s provisions to determine how it will need to move forward. She said a 4/2022 premarket draft guidance that is being finalized likely will cite provisions from the law.

Schwartz says the $5 million included in the bill for medical device cybersecurity will go a long way in helping FDA to hire additional expert staff to work on submissions. More resources likely will be needed in the future, she said, but the agency appreciates the initial funding that will get things started.

Read more