Monitor Cybersecurity Regulation Developments: Attorneys
Medical device manufacturers should pay close attention to cybersecurity regulatory and legislative developments, expand their internal expertise, and otherwise invest in establishing robust cybersecurity risk assessment, design control, and risk management practices and procedures relating to their devices. That’s the advice of Ropes & Gray attorneys in an online Alert stressing the clear trend they see toward increasing cybersecurity expectations for medical device manufacturers.
The post reviews the 4/8 FDA draft guidance on “Cybersecurity in Medical Devices: Quality System Considerations and Content of Premarket Submissions,” which will replace a 2014 guidance when it is finalized. The attorneys discuss FDA recommendations for (1) device design and the Quality System regulation, (2) inclusion of cybersecurity information in device labeling, and (3) cybersecurity information in premarket submissions.
The post also covers the 3/15 introduction of the Protecting and Transforming Cyber Healthcare Act to address device cybersecurity concerns. If enacted, the attorneys say, the legislation would amend the Federal Food, Drug, and Cosmetic Act to require that all premarket submissions for software and Internet-connected devices include information showing that such devices meet cybersecurity requirements. It also would set minimum cybersecurity requirements, including that device manufacturers establish procedures for monitoring devices, addressing cybersecurity vulnerabilities, and coordinating vulnerability disclosures, and that manufacturers submit a software bill of materials as part of premarket submissions.