iStock
Promo Istock 64c126866a363

Medical Devices Face Pre-Market Review: FDA Targets Cybersecurity Vulnerabilities

July 26, 2023
FDA provisions on cybersecurity for medical devices require pre-market review.

Medical device manufacturers would be wise to take each cybersecurity safety warning and alert posted to the FDA’s website as a cue to beef up cybersecurity planning during the design and validation of their products. Breaches of unsecured protected health information have affected over 42.7 million U.S. citizens thus far in 2023, according to the U.S. Department of Health and Human Services (HHS) Office of Civil Rights.

Malicious actors and security breaches affect perceptions as well as behavior. GlobalData’s Q2 2023 tech sentiment poll reports that 70% of survey participants expect cybersecurity to disrupt the healthcare industry, with 41% expecting a significant disruption. 

“Hackers can exploit various entry points, ranging from physical medical devices in and outside of medical facilities to gaining unauthorized access to networks from nearly any connected device, medical or not,” noted Ashley Clarke, medical analyst at GlobalData. “The implications of such attacks can be far-reaching, affecting patient privacy, interrupting healthcare services, and jeopardizing the safety and effectiveness of medical devices.”

In recent cyber devices guidance, the Consolidated Appropriations Act, 2023 (“Omnibus”), the U.S. Food & Drug Administration issued provisions with respect to the cybersecurity of medical devices that require premarket review by the FDA. Medical device manufacturers will now need to submit a plan to monitor, identify and address post-market cybersecurity vulnerabilities when applying for new pre-market authorizations, according to Section 3305 (Ensuring Cybersecurity of Devices) of the Omnibus, which came into effect on March 29 of this year.

Manufacturers and healthcare facilities can manage the risk of unauthorized access by implementing such recommendations and following safety guidance set out by the FDA. The guidance is designed to help ensure patient safety and tackle vulnerabilities in tandem with health care providers and medical device manufacturers such as Medtronic.

A recent notification stemming from the medical technology solutions provider informed the public of a potential issue associated with the Medtronic MiniMed 600 Series Insulin Pump System. This pump system includes components that communicate wirelessly—such as the insulin pump, continuous glucose monitoring (CGM) transmitter, blood glucose meter and CareLink USB device. The issue was that the communication protocol used by the pump system could allow unauthorized access, specifically when the pump was being paired with other system components. Once breached, the pump could deliver too much or too little insulin. 

In this event, the FDA stated that it was not aware of any reports related to cybersecurity vulnerability, and Medtronic duly provided instructions on its website on how to address the vulnerability.

RELATED

About the Author

Rehana Begg | Editor-in-Chief, Machine Design

As Machine Design’s content lead, Rehana Begg is tasked with elevating the voice of the design and multi-disciplinary engineer in the face of digital transformation and engineering innovation. Begg has more than 24 years of editorial experience and has spent the past decade in the trenches of industrial manufacturing, focusing on new technologies, manufacturing innovation and business. Her B2B career has taken her from corporate boardrooms to plant floors and underground mining stopes, covering everything from automation & IIoT, robotics, mechanical design and additive manufacturing to plant operations, maintenance, reliability and continuous improvement. Begg holds an MBA, a Master of Journalism degree, and a BA (Hons.) in Political Science. She is committed to lifelong learning and feeds her passion for innovation in publishing, transparent science and clear communication by attending relevant conferences and seminars/workshops. 

Follow Rehana Begg via the following social media handles:

X: @rehanabegg

LinkedIn: @rehanabegg and @MachineDesign

Sponsored Recommendations

Safeguarding Robots and Robot Cells

Dec. 23, 2024
Learn which standards are relevant for robot applications, understand robot functionality and limitations and how they affect typical methods of safeguarding robots, and review...

Automation World Gets Your Questions Answered

Dec. 23, 2024
Enjoy the videos and music you love, upload original content, and share it all with friends, family, and the world on YouTube.

Basic OSHA Requirements for a Control Reliable Safety Circuit

Dec. 23, 2024
Control reliability is crucial for safety control circuits. Learn about basic wiring designs to help meet OSHA, Performance Level (PL), and Safety Integrity Level (SIL) requirements...

Safety Risk Assessment Guidelines for Automation Equipment

Dec. 20, 2024
This Frequently Asked Questions (FAQ) covers the basics of risk assessments, including the goals of the assessment, gathering the right team to perform them, and several methodologies...

Voice your opinion!

To join the conversation, and become an exclusive member of Machine Design, create an account today!