Skip to content

Menu

LexBlog, Inc. logo
NetworkSub-MenuBrowse by SubjectBrowse by PublisherJoin the NetworkGet StartedSubscribeSupportContact
Search
Close

FDA Issues Draft Guidance on Cybersecurity for Postmarket Medical Devices

By John Devine, Neil P. DiSpirito, Sandra Maki Hashima & Philip N. Yannella on January 27, 2016
Email this postTweet this postLike this postShare this post on LinkedIn

The Food and Drug Administration’s (FDA) most recent draft guidance focuses on cybersecurity in postmarket medical devices and makes recommendations for identifying, assessing, and responding to cybersecurity vulnerabilities. The draft guidance, issued January 22, 2016, applies to medical devices that contain software (including firmware) and software that is a medical device.

The draft guidance follows the October 2014 guidance on cybersecurity in premarket medical devices, which recommended that developers and manufacturers consider cybersecurity risks as part of the design and development of medical devices. The guidance recommends they submit documentation to the FDA about those risks and the controls in place to mitigate them. The guidance also supplements the information addressed in the FDA’s previously issued guidance on cybersecurity for networked devices containing OTS software.

In its most recent guidance, the FDA recommends manufacturers of medical devices monitor, identify, and address cybersecurity vulnerabilities as part of their postmarket management of medical devices. Manufacturers should develop comprehensive risk management programs that include:

  • Monitoring cybersecurity information sources for identification and detection of cybersecurity vulnerabilities and risk
  • Understanding, assessing, and detecting the presence and impact of a vulnerability
  • Establishing and communicating processes for vulnerability intake and handling
  • Clearly defining essential clinical performance to develop mitigations that protect, respond, and recover from the cybersecurity risk
  • Adopting a coordinated vulnerability disclosure policy and practice
  • Deploying mitigations that address cybersecurity risk early and prior to exploitation

The FDA also strongly recommends manufacturers join an Information Sharing and Analysis Organization (ISAO) as a way to promote collaboration among manufacturers. The FDA believes that sharing information about cybersecurity risks can enhance management of individual vulnerabilities and allow others in the medical device community to collectively enhance cybersecurity.

As a part of the risk management process, the draft guidance recommends manufacturers maintain through the device lifecycle an ongoing process for identifying cybersecurity hazards, estimating, evaluating, and controlling the associated risks, and monitoring the effectiveness of the controls. This process should focus on assessing the risk to the device’s essential clinical performance (i.e., the performance that is necessary to achieve freedom from unacceptable clinical risk as defined by the manufacturer) based on the exploitability of the cybersecurity vulnerability and the severity of the potential impact on health. Based on the relationship between the two factors, manufacturers could determine whether a particular vulnerability poses a low risk of compromising the device’s essential clinical performance (a ”controlled risk”) or a high risk (an ”uncontrolled risk”).

The draft guidance also gives recommendations for remediating risks and reporting vulnerabilities. Most routine cybersecurity updates and patches do not require notification, premarket review, or reporting. Manufacturers are not required to report controlled risks and can update devices without notification, premarket review, or reporting because the update will be considered a routine update or patch. For uncontrolled risks, FDA notification may be required. The FDA, however, will not require notification for uncontrolled risks if there are no known serious adverse effects or deaths associated with the risk; if the manufacturer notifies users and addresses the issue within 30 days of learning of the vulnerability; and the manufacturer is a member of an ISAO.

Similar to previous guidance issued on cybersecurity, the FDA’s most recent guidance signals the FDA’s continued focus on the evolving and complicating role that technology is playing in the health care industry.

Ballard Spahr’s Privacy and Data Security Group monitors legislative and regulatory developments at both the federal and state levels and can assist with establishing or enhancing cybersecurity programs.

Philip N. Yannella

yannellap@ballardspahr.com | 215.864.8180 | view full bio

As Practice Leader of Ballard Spahr’s Privacy and Data Security Group, and Practice Leader of the firm’s E-Discovery and Data Management Group, Philip N. Yannella provides clients with 360-degree advice on the transfer, storage, and use…

yannellap@ballardspahr.com | 215.864.8180 | view full bio

As Practice Leader of Ballard Spahr’s Privacy and Data Security Group, and Practice Leader of the firm’s E-Discovery and Data Management Group, Philip N. Yannella provides clients with 360-degree advice on the transfer, storage, and use of digital information.

Phil regularly advises clients on the Stored Communications Act (SCA), Computer Fraud and Abuse Act (CFAA), EU-US Privacy Shield, General Data Protection Regulation (GDPR), Defense of Trade Secrets Act, PCI-DSS, Telephone Consumer Protection Act (TCPA), New York Department of Financial Services Cybersecurity Regulations, ISO 27001 compliance, HIPAA Security Rules, and FTC enforcement activity, as well as eDiscovery issues—leveraging his experience serving as National Discovery Counsel for more than two dozen companies in nationwide litigation. He harnesses his deep knowledge of privacy, data security, and information governance laws to help multinational companies develop global information governance programs to comply with overlapping, and sometimes conflicting, laws. Phil serves on the advisory board for the ACC Foundation’s Cybersecurity Survey, the largest survey of in-house counsel on cybersecurity issues.

Email
Show more Show less
  • Posted in:
    Health Care and Life Sciences, Privacy and Cybersecurity
  • Blog:
    Health Care Reform Dashboard
  • Organization:
    Ballard Spahr LLP
  • Article: View Original Source

Call us at 1-800-913-0988 or email sales@lexblog.com.

Facebook LinkedIn Twitter RSS
The Library at LexBlog
  • About LexBlog
  • The Field We Built
  • Library at LexBlog
  • Our Beliefs
  • Our Team
  • Contact LexBlog
  • Disclaimer
  • Editorial Policy
  • Terms of Service
  • Get Started
  • Publishing Solutions
  • Compass
  • Submit a Request
  • Support Center
  • System Status
Copyright © 2026, LexBlog, Inc. All Rights Reserved.
Law blog design & platform by LexBlog LexBlog Logo