FDA issues draft cybersecurity guidance for device makers

In August, the Food and Drug Administration published a guidance recommending hospitals move away from using Hospira’s Symbiq Infusion System, a computerized pump designed for continuous infusion therapy delivery, because the devices were shown to be vulnerable to hacking attacks that could put patient safety at risk. In light of increasing awareness around the lack of cybersecurity for medical devices in hospitals and the risks for patients using the devices and the hospital networks they’re linked to, the FDA has issued a draft cybersecurity guidance for manufacturers that focuses on steps they can take to mitigate hacking risks.

Advertisement

  • Applying the 2014 NIST voluntary Framework for Improving Critical Infrastructure Cybersecurity, which includes the core principles of “Identify, Protect, Detect, Respond and Recover;”
  • Monitoring cybersecurity information sources for identification and detection of cybersecurity vulnerabilities and risk;
  • Understanding, assessing and detecting presence and impact of a vulnerability;
  • Establishing and communicating processes for vulnerability intake and handling;
  • Clearly defining essential clinical performance to develop mitigations that protect, respond and recover from the cybersecurity risk;
  • Adopting a coordinated vulnerability disclosure policy and practice; and
  • Deploying mitigations that address cybersecurity risk early and prior to exploitation.

The draft guidance also requires manufacturers to notify the FDA when designing protections for cybersecurity vulnerabilities that present a reasonable probability of serious adverse health consequences or death. The guidance is open for public comment for 90 days.

More articles on quality:

10 top patient safety issues for 2016
NH hospital: 800+ children may need revaccination after refrigeration problem
American College of Cardiology, Society of Cardiovascular Patient Care announce quality improvement merger

At the Becker's 11th Annual IT + Revenue Cycle Conference: The Future of AI & Digital Health, taking place September 14–17 in Chicago, healthcare executives and digital leaders from across the country will come together to explore how AI, interoperability, cybersecurity, and revenue cycle innovation are transforming care delivery, strengthening financial performance, and driving the next era of digital health. Apply for complimentary registration now.

Register to Attend Webinar

When nurses help build the AI, adoption follows: Lessons from 3 health systems

Tuesday, July 28
11:00 AM - 12:00 PM CDT

Presenters: Amy McCarthy, DNP, RNC-MNN, NE-BC, CENP, Hippocratic AIBeth Reimschissel, PhD, RN, CNL, Memorial HermannAllison Schlinkert, MSN, RN, NPD-BC, Cincinnati Children'sScott Estep, MBOE, BSN, RN, CSSBB, OhioHealth System

Advertisement

Next Up in Clinical Leadership & Infection Control

Advertisement

Comments are closed.