Skip to content

Menu

LexBlog, Inc. logo
NetworkSub-MenuBrowse by SubjectBrowse by PublisherJoin the NetworkGet StartedSubscribeSupportContact
Search
Close

Cybersecurity Risks in Medical Devices Discussed at Recent FDA Meeting

By Jean Tomasco on September 24, 2019
Email this postTweet this postLike this postShare this post on LinkedIn

The Patient Engagement Advisory Committee (Committee) to the Food and Drug Association (FDA) met recently to discuss cybersecurity in medical devices. Medical devices are increasingly connected to the internet, hospital networks, and other medical devices to provide features designed to improve healthcare and increase providers’ ability to treat patients. However, as medical devices become more connected and join the internet of things, cybersecurity risks increase. As the summary of the meeting indicates, preserving the benefit of the devices requires both continuous vigilance as well as timely and effective communications to users about evolving cybersecurity risks.

The Committee focused on factors for consideration by the FDA and industry when communicating cybersecurity risks to patients and the public, the role of healthcare providers and other stakeholders in communicating such risks to patients, and concerns patients have about changes to their devices to reduce cybersecurity risks.

Overall, the Committee members generally concluded that there is not one blanket approach that would work for all patients. However, they highlighted three strategic elements the FDA and industry should consider in conveying cybersecurity risks to patients when the probability of exploitation is not known: (1) explaining the unknown factor; (2) understanding patients’ fear of the potential unknown, and having those concerns addressed and factored in well in advance of the preapproval process; and (3) a balanced discussion between risk and benefits, particularly for lifesaving devices. The Committee felt the FDA could use an alert system similar to that used by other agencies (such as using green, yellow and red) to communicate the different levels of cybersecurity threat. The Committee also recommended that the FDA explore using Unique Device Identifiers (UDIs) to deliver targeted risk messages to patients who use particular devices.

The Committee believes it is important for patients to hear about a cybersecurity threat even before there is a risk reduction measure available, both for transparency and because patients might be able to detect potential harms. The FDA should also consider if and when to make the information public, given that there could be “bad actors” who take advantage of the risk upon learning about it through the media.

It will be interesting to see what the FDA does in response to the Committee’s recommendations, and whether guidance from the FDA will be forthcoming.

Photo of Jean Tomasco Jean Tomasco
Read more about Jean TomascoEmail
  • Posted in:
    Health Care and Life Sciences, Privacy and Cybersecurity
  • Blog:
    Data Privacy + Cybersecurity Insider
  • Organization:
    Robinson & Cole LLP
  • Article: View Original Source

Call us at 1-800-913-0988 or email sales@lexblog.com.

Facebook LinkedIn Twitter RSS
The Library at LexBlog
  • About LexBlog
  • The Field We Built
  • Library at LexBlog
  • Our Beliefs
  • Our Team
  • Contact LexBlog
  • Disclaimer
  • Editorial Policy
  • Terms of Service
  • Get Started
  • Publishing Solutions
  • Compass
  • Submit a Request
  • Support Center
  • System Status
Copyright © 2026, LexBlog, Inc. All Rights Reserved.
Law blog design & platform by LexBlog LexBlog Logo