> ## Content Index
> Fetch the complete content index at: https://www.fdaweb.com/llms.txt
> Use this file to discover other available public pages before exploring further.

# Improve FDA Cybersecurity Risk Policies, Procedures: OIG
- URL: https://www.fdaweb.com/improve-fda-cybersecurity-risk-policies-procedures-oig/
- Published: 2018-11-01T12:00:00.000Z
- Updated: 2026-09-15T00:41:58.000Z
- Author: David McFarland
- Tags: Devices, #legacy-id-D5142725

The HHS Inspector General (OIG) says FDA should take steps to have its policies and procedures better address medical device postmarket cybersecurity risks. In a [report](https://oig.hhs.gov/oas/reports/region18/181630530.pdf?ref=fdaweb.com), OIG says it conducted an audit because it had identified ensuring the safety and effectiveness of medical devices and fostering a culture of cybersecurity as top management challenges for HHS. “Our objective was to determine the effectiveness of FDA’s plans and processes for timely communicating and addressing cybersecurity medical device compromises in the postmarket phase,” the report says.

OIG found that FDA’s policies and procedures were insufficient for handling postmarket medical device cybersecurity events; FDA had not adequately tested its ability to respond to emergencies resulting from cybersecurity events in medical devices; and in two of 19 district offices, the agency had not established written standard operating procedures to address recalls of medical devices vulnerable to cyber threats.

According to the report, the weaknesses existed because at the time of the audit FDA had not sufficiently assessed medical device cybersecurity as part of an enterprise risk management process.

OIG recommended that the agency: 

- continually assess the cybersecurity risks to medical devices and update, as appropriate, its plans and strategies;
- establish written procedures and practices for securely sharing sensitive information about cybersecurity events with key stakeholders who have a “need to know”;
- enter into a formal agreement with federal agency partners, the Department of Homeland Security’s Industrial Control Systems Cyber Emergency Response Team, establishing roles and responsibilities as well as the support those agencies will provide to further FDA’s mission related to medical device cybersecurity; and
- ensure the establishment and maintenance of procedures for handling recalls of medical devices vulnerable to cybersecurity threats.

OIG says it shared its preliminary findings with FDA before issuing its draft report and the agency implemented some of them. As a result, the original findings were retained in the report but some of the recommendations were removed.

While agreeing with the recommendations, FDA said it disagreed with the conclusions that it had not assessed medical device cybersecurity at an enterprise or component level and that its preexisting policies and procedures were insufficient.

“We appreciate the efforts FDA has taken and plans to take in response to our findings and recommendations,” OIG concluded, “but we maintain that our findings and recommendations are valid.”