Panel on Cybersecurity Communications Standards

Share

An FDA advisory committee has recommended that FDA should develop standards for device companies to use when communicating any cybersecurity concern to patients. The agency’s Patient Engagement Advisory Committee met 9/10 to discuss communicating to patients about  cybersecurity risks. “Preserving the benefit of these devices requires continuous vigilance as well as timely and effective communication to medical device users about evolving cybersecurity risks,” the agency said in announcing the meeting.

 

Panel members recommended that the format for cybersecurity messages to patients should include e-mails, Web postings, social media and webinars, according to an FDA summary of the recommendations. “There should be a high standard of outreach to all patients regardless of the challenges with reaching them since connectivity will be increasing with time and those populations in rural or internet sparse areas will become increasingly vulnerable to cybersecurity threats,” it said.

 

The panel also recommended that FDA evaluate the standards that the Department of Transportation and other transportation agencies use to “hold high standards for manufacturers across their supply chains and the FDA should consider some of the mandates the transportations agencies use to communicate risks to their passengers,” the summary said.

 

Overall, the committee agreed that there is not a blanket approach that would work for all patients. They did, however, recommend three strategic elements that FDA and industry should consider when communicating cybersecurity risks to patients when the probability of exploitation is not known: 1) explain unknown factors; 2) discussing any concerns addressed and factored in well in advance of the preapproval process; and 3) a balanced discussion between risk and benefits, highlighting the benefits especially if it is a lifesaving device.

Read more