Integrate Cybersecurity in Medical Device Reviews: OIG

Share

The HHS Inspector General (IG) says FDA should promote use of presubmission meetings to address cybersecurity-related questions, include cybersecurity documentation as a criterion in the agency’s Refuse-to-Accept checklist, and include cybersecurity as an element in its “Smart” template. The recommendations are in a study report that notes that cybersecurity is an area with increasing risk to patients and the healthcare industry as more medical devices use wireless, Internet, and network connectivity.

The IG analysts found that FDA reviews the cybersecurity documentation in premarket submissions that manufacturers submit to the agency before the devices can be marketed. Agency reviewers look for cybersecurity documentation in company submissions, the report says. At the time of the study, FDA had almost always cleared or approved the cybersecurity aspect of networked medical devices because manufacturers had been able to respond with supplemental cybersecurity information that FDA deemed sufficient.

“FDA could further integrate cybersecurity into its overall review process,” the report concludes. “FDA’s ‘Refuse-to-Accept’ checklists, which the agency uses to screen submissions for completeness, do not include checks for cybersecurity information. Also, FDA’s ‘Smart’ template, which FDA uses to guide its reviews of submissions, does not prompt FDA reviewers with specific cybersecurity questions that they should consider and also lacks a dedicated section for recording the results of the cybersecurity review.” The report says the agency concurred with the IG’s three recommendations.

Read more