Stakeholders Want Cybersecurity Guidance Changes
Symantec says the current iteration of an FDA draft guidance on content of premarket submissions for managing cybersecurity in medical devices has “significant improvements over the previous version and helps align stakeholders to the shared mission of providing a more secure and safer healthcare system.” In a comment letter, the company suggests several improvements:
- the document should include a deeper and more nuanced discussion and clarification of cybersecurity being an integral part of patient safety;
- the proposed device risk tiers should be expanded to include additional aspects of harm/risk;
- the document needs a more nuanced discussion rather than assuming certain types of medical devices with a particular feature set and capabilities; and
· some terminology used in the draft seems to be specific to the document and may not be aligned with precedents, common definitions, or typical industry understanding.
In its letter, Kaiser Permanente says standards development organizations are developing guidance for cybersecurity risk assessment methodologies for medical devices and it recommends that FDA continue working with those organizations to incorporate the other guidance documents into the FDA Consensus Standards Database and encourage adoption by medical device manufacturers.
Kaiser also asks for more clarification on the two-tier ranking of devices, intended manufacturer actions, and desired outcomes. “A risk-based approach with appropriate cybersecurity provisions, one that holistically assesses risks and mitigations throughout the entire product lifecycle, will move the industry forward toward trustworthy devices,” Kaiser’s letter concludes.