Stronger FDA Cybersecurity Enforcement Needed: Analysis
An analysis by the Institute for Critical Infrastructure Technology (ICIT) says that the FDA cybersecurity guidelines for medical device manufacturers are following a “subtle suggestion” approach when regulatory enforcement is needed. In a blog white paper, ICIT says that the argument against enforcing cybersecurity standards typically “centers on the idea that a regulatory presence stifles innovation.”
The paper reviews the FDA 1/15 guidance that advises medical device manufacturers to address cybersecurity “throughout a product’s lifecycle, including during the design, development, production, distribution, deployment, and maintenance of the device.” It says that the guidance offers a voluntary framework that organizations can build upon to ensure that their cybersecurity policies, procedures, and strategies address cybersecurity risks in medical devices before the organization, patients, or the public at large realize financial or reputational harm from the exploitation of an unaddressed vulnerability by an unknown threat actor.
“The medical device community is compliance-oriented,” the paper concludes. “Currently, healthcare device manufacturers and healthcare providers have the ability to ignore FDA’s recommendations. However, it is in the best interest of each organization and the community at large if the target audience pays attention to FDA’s underlying message to adopt a comprehensive risk-based cybersecurity program…. It may be beneficial to healthcare providers, healthcare payers, and legislators to petition FDA to make the guidelines regulatory. Otherwise, medical device manufacturers could ignore the guidelines altogether…. The cyber threat is real and bad actors are continuously evolving in both stealth and sophistication. Regardless of how medical device manufacturers and healthcare providers receive the guidelines, FDA has clearly indicated that medical device cybersecurity is a priority. The healthcare community should note the gesture and take the initiative to assess their own networks and improve their cybersecurity.”