CISA updates software bill of materials guidance for medical devices

Advertisement

The Cybersecurity and Infrastructure Security Agency, alongside the National Security Agency, the Federal Bureau of Investigation and international partners, released updated guidance on the minimum elements required for a software bill of materials, or SBOM. 

The guidance replaces minimum elements first issued by the National Telecommunications and Information Administration in 2021.

An SBOM lists every component contained in a software product, giving hospitals and health systems a way to spot hidden vulnerabilities buried in vendor technology. The new guidance covers standard software but notes that artificial intelligence tools and software-as-a-service products in cloud environments may require additional elements beyond the baseline.

The update carries direct weight for medical device manufacturers. Section 524B of the Federal Food, Drug, and Cosmetic Act requires device makers to submit an SBOM with any new medical device application filed with the FDA after Oct. 1, 2023.

The stakes for hospitals were outlined in a July 29 news release from the American Hospital Association. 

At the Becker's 11th Annual IT + Revenue Cycle Conference: The Future of AI & Digital Health, taking place September 14–17 in Chicago, healthcare executives and digital leaders from across the country will come together to explore how AI, interoperability, cybersecurity, and revenue cycle innovation are transforming care delivery, strengthening financial performance, and driving the next era of digital health. Apply for complimentary registration now.

Register to Attend Webinar

The hidden cost of lost clinical time and how leading health systems are responding

Friday, August 7
12:00 PM - 1:00 PM CDT

Presenters: Kassaundra McKnight-Young, Zebra TechnologiesGregory Carras, Zebra TechnologiesJennifer Gene, Levata

Advertisement

Next Up in Digital Health

Advertisement