iStock
Promo Istock 64c126866a363

Medical Devices Face Pre-Market Review: FDA Targets Cybersecurity Vulnerabilities

July 26, 2023
FDA provisions on cybersecurity for medical devices require pre-market review.

Medical device manufacturers would be wise to take each cybersecurity safety warning and alert posted to the FDA’s website as a cue to beef up cybersecurity planning during the design and validation of their products. Breaches of unsecured protected health information have affected over 42.7 million U.S. citizens thus far in 2023, according to the U.S. Department of Health and Human Services (HHS) Office of Civil Rights.

Malicious actors and security breaches affect perceptions as well as behavior. GlobalData’s Q2 2023 tech sentiment poll reports that 70% of survey participants expect cybersecurity to disrupt the healthcare industry, with 41% expecting a significant disruption. 

“Hackers can exploit various entry points, ranging from physical medical devices in and outside of medical facilities to gaining unauthorized access to networks from nearly any connected device, medical or not,” noted Ashley Clarke, medical analyst at GlobalData. “The implications of such attacks can be far-reaching, affecting patient privacy, interrupting healthcare services, and jeopardizing the safety and effectiveness of medical devices.”

In recent cyber devices guidance, the Consolidated Appropriations Act, 2023 (“Omnibus”), the U.S. Food & Drug Administration issued provisions with respect to the cybersecurity of medical devices that require premarket review by the FDA. Medical device manufacturers will now need to submit a plan to monitor, identify and address post-market cybersecurity vulnerabilities when applying for new pre-market authorizations, according to Section 3305 (Ensuring Cybersecurity of Devices) of the Omnibus, which came into effect on March 29 of this year.

Manufacturers and healthcare facilities can manage the risk of unauthorized access by implementing such recommendations and following safety guidance set out by the FDA. The guidance is designed to help ensure patient safety and tackle vulnerabilities in tandem with health care providers and medical device manufacturers such as Medtronic.

A recent notification stemming from the medical technology solutions provider informed the public of a potential issue associated with the Medtronic MiniMed 600 Series Insulin Pump System. This pump system includes components that communicate wirelessly—such as the insulin pump, continuous glucose monitoring (CGM) transmitter, blood glucose meter and CareLink USB device. The issue was that the communication protocol used by the pump system could allow unauthorized access, specifically when the pump was being paired with other system components. Once breached, the pump could deliver too much or too little insulin. 

In this event, the FDA stated that it was not aware of any reports related to cybersecurity vulnerability, and Medtronic duly provided instructions on its website on how to address the vulnerability.

RELATED

About the Author

Rehana Begg | Editor-in-Chief, Machine Design

As Machine Design’s content lead, Rehana Begg is tasked with elevating the voice of the design and multi-disciplinary engineer in the face of digital transformation and engineering innovation. Begg has more than 24 years of editorial experience and has spent the past decade in the trenches of industrial manufacturing, focusing on new technologies, manufacturing innovation and business. Her B2B career has taken her from corporate boardrooms to plant floors and underground mining stopes, covering everything from automation & IIoT, robotics, mechanical design and additive manufacturing to plant operations, maintenance, reliability and continuous improvement. Begg holds an MBA, a Master of Journalism degree, and a BA (Hons.) in Political Science. She is committed to lifelong learning and feeds her passion for innovation in publishing, transparent science and clear communication by attending relevant conferences and seminars/workshops. 

Follow Rehana Begg via the following social media handles:

X: @rehanabegg

LinkedIn: @rehanabegg and @MachineDesign

Sponsored Recommendations

Flexible Power and Energy Systems for the Evolving Factory

Aug. 29, 2024
Exploring industrial drives, power supplies, and energy solutions to reduce peak power usage and installation costs, & to promote overall system efficiency

Timber Recanting with SEW-EURODRIVE!

Aug. 29, 2024
SEW-EURODRIVE's VFDs and gearmotors enhance timber resawing by delivering precise, efficient cuts while reducing equipment stress. Upgrade your sawmill to improve safety, yield...

Advancing Automation with Linear Motors and Electric Cylinders

Aug. 28, 2024
With SEW‑EURODRIVE, you get first-class linear motors for applications that require direct translational movement.

Gear Up for the Toughest Jobs!

Aug. 28, 2024
Check out SEW-EURODRIVEs heavy-duty gear units, built to power through mining, cement, and steel challenges with ease!

Voice your opinion!

To join the conversation, and become an exclusive member of Machine Design, create an account today!