Medical Device Cybersecurity Guidance Outlined
Ropes & Gray attorneys say that medical device manufacturers should review a recent FDA final guidance on postmarket management of medical device cybersecurity and consider how to incorporate its recommendations into their postmarket management activities. In an online regulatory alert, the attorneys say that FDA recommends that manufacturer cybersecurity risk management programs include:
- monitoring cybersecurity information sources for identification and detection of cybersecurity vulnerabilities and risks;
- maintaining robust software lifecycle processes including mechanisms for monitoring third-party software components for new vulnerabilities and performing design validation for software updates and patches used to remediate vulnerabilities;
- understanding assessing and detecting vulnerabilities;
- establishing and communicating processes for cybersecurity vulnerability intake and handling;
- using threat modeling to define how to maintain safety and essential performance of a device by developing mitigations that protect, respond, and recover from a cybersecurity risk;
- adopting a coordinated vulnerability disclosure policy and practice; and
- deploying mitigations that address cybersecurity risk early and before exploitation.
The alert says the final guidance differs from an earlier draft in three important respects:
- uses the potential for patient harm, rather than risk to the safety and effectiveness of the device itself, as the touchstone for assessing risks posed by cybersecurity vulnerabilities;
- extends to 60 days the time that device manufacturers have to remediate an uncontrolled risk while remaining subject to FDA’s enforcement discretion policy for reporting a device correction, provided that the manufacturer communicates interim controls to its customers and the user community within 30 days after learning of the vulnerability; and
- provides additional details and guidance to manufacturers on a number of subjects.
Device manufacturers that have not already done so should consider conducting a comprehensive assessment of their cybersecurity practices and procedures,” Ropes & Gray says, “taking into account the recommendations in the FDA pre- and post-market guidance documents and third-party standards, and evaluate whether to become an active participant in an ISAO (information sharing analysis organization).”