
Kicking Off Cybersecurity Month, FDA Launches New Medical Device Security Playbook
The playbook describes readiness activities that’ll enable health systems to better prepare for a MedTech cybersecurity incident.
Everyday objects are becoming “smart” at breakneck speed. Who would’ve thought a decade ago that we could hardly get on without our smart phones, cars, watches, and even refrigerators? The pace at which our surroundings are becoming “smart” — that is, connected to the internet – is so furious, that Wired co-founder Kevin Kelly recently declared that in the not-so-distant future, our children and grandchildren will look at any object that isn’t “smart” or interactive and immediately assume it’s broken.
This tide of smartness is washing indelibly over retail, investing, banking, and many other industries, but is being met with resistance in healthcare, where the personal health information that’s being exchanged on the internet of smart healthcare things is perhaps most valuable and most vulnerable.
Until now, health systems were left largely to their own devices to figure out how to stymie cyberattacks and ransomware. But today, US Food and Drug Administration (FDA) chairman Scott Gottlieb, MD,
The “
“The framework can help enable a unified response within [health systems] and across regions, as well as serve as a basis for enhanced coordination activities among medical device cybersecurity stakeholders,” the report read.
The FDA’s announcement follows the founding of a Cybersecurity Working Group within the Center for Devices and Radiological Health (CDRH) in 2013, and the establishment of a framework to address cybersecurity regulatory considerations, which, taken together, represent the agency’s recommendations for product developers at each stage of a product’s life cycle, Gottlieb said.
“In the coming weeks, we plan to publish a significant update…to reflect the FDA’s most current understandings of, and recommendations regarding, this evolving space. For instance, the new draft guidance will highlight the utility of providing customers and users with a ‘cybersecurity bill of materials’ — a list of commercial and/or off-the-shelf software and hardware components of a device that could be susceptible to vulnerabilities,” he said. “The list can be an important resource to help ensure that device customers and users are able to respond quickly to potential threats.”
Recent reports suggest that bundles of private health records and other health data can sell for
Get the best insights in healthcare analytics directly to your inbox
Related:








































