- Applying the 2014 NIST voluntary Framework for Improving Critical Infrastructure Cybersecurity, which includes the core principles of “Identify, Protect, Detect, Respond and Recover;”
- Monitoring cybersecurity information sources for identification and detection of cybersecurity vulnerabilities and risk;
- Understanding, assessing and detecting presence and impact of a vulnerability;
- Establishing and communicating processes for vulnerability intake and handling;
- Clearly defining essential clinical performance to develop mitigations that protect, respond and recover from the cybersecurity risk;
- Adopting a coordinated vulnerability disclosure policy and practice; and
- Deploying mitigations that address cybersecurity risk early and prior to exploitation.
The draft guidance also requires manufacturers to notify the FDA when designing protections for cybersecurity vulnerabilities that present a reasonable probability of serious adverse health consequences or death. The guidance is open for public comment for 90 days.
More articles on quality:
10 top patient safety issues for 2016
NH hospital: 800+ children may need revaccination after refrigeration problem
American College of Cardiology, Society of Cardiovascular Patient Care announce quality improvement merger