> ## Content Index
> Fetch the complete content index at: https://www.fdaweb.com/llms.txt
> Use this file to discover other available public pages before exploring further.

# New FDA Guide Doesn’t Stop Some Device Hacking: Paper
- URL: https://www.fdaweb.com/new-fda-guide-doesnt-stop-some-device-hacking-paper/
- Published: 2025-07-09T12:00:00.000Z
- Updated: 2026-09-14T15:16:10.000Z
- Author: David McFarland
- Tags: Devices, #legacy-id-D5159479

The Foundation for Defense of Democracies (FDD) says that medical devices such as pacemakers, insulin pumps, and vital signs monitors that are already in use in healthcare settings are vulnerable to hacking despite a new FDA guidance. An FDD [paper](https://www.fdd.org/analysis/2025/07/09/medical-devices-still-vulnerable-to-hacking-despite-new-fda-guidance/?ref=fdaweb.com) says the guidance doesn’t have a requirement that companies fix cybersecurity flaws in devices that are already in use.

The new [guidance](https://www.fdaweb.com/device-cybersecurity-quality-system-consideration-guide/), *Cybersecurity in Medical Devices: Quality System Considerations and Content of Premarket Submissions*, contains recommendations for both pre- and post-market devices, the paper says, but its requirements are not mandatory for devices that received certification before a 2022 law requiring all pre-market medical devices to meet FDA cybersecurity standards.

The authors say that in January, researchers reported that widely used patient monitors were sending data back to a Chinese computer address through a pre-installed, intentionally hidden backdoor. The devices were manufactured in China and were in use in the U.S. Although FDA recommended that hospitals stop using the devices, they say, the monitors remain on the market.

The paper calls on the agency to require suppliers to routinely provide the same information for in-use devices as required for new devices seeking certification. It says FDA also should revoke certification for vulnerable devices when suppliers do not promptly address cybersecurity problems. And it says FDA should, by default, deny certification for all Chinese medical devices, which it says would decrease the cyber threats facing the U.S. healthcare system and provide time for the government to investigate post-market devices.