★ ANNUAL REVIEW 2027 SPONSORSHIPS NOW OPEN   Learn more →

Log In  |  Become a Member  |  Sponsor  |  ⌕ Search

News/Cyber & Privacy/FDA Should Further Integrate Its Review of Cybersecurity Into the Premarket Review Process for Medical Devices
Free SampleYou’re reading a free sample of the Cyber & Privacy Brief. Members get every case digest like this, six days a week.See Membership Options
News·Cyber & Privacy Brief

FDA Should Further Integrate Its Review of Cybersecurity Into the Premarket Review Process for Medical Devices

The Department of Health and Human Services Office of Inspector General says the Food and Drug Administration should further integrate cybersecurity considerations into the pre-market review process for medical devices. FDA reviewers consider known cybersecurity risks and threats when reviewing submissions and apply that knowledge to devices that display similar risk profiles. FDA reviewers also look for cybersecurity documentation in the submissions, and often request additional information from manufacturers when submissions lack sufficient cybersecurity documentation or when clarification is needed.

However, OIG found that FDA could further integrate cybersecurity into its overall review process. For example, FDA’s “Refuse-To-Accept” checklists, which the agency uses to screen submissions for completeness, do not include checks for cybersecurity information. Also, FDA’s “Smart” template, which FDA uses to guide its reviews of submissions, does not prompt FDA reviewers with specific cybersecurity questions to consider and also lacked a dedicated section for recording the results of the cybersecurity review.

[pdf-embedder url=”https://staging.pub-k.org/wp-content/uploads/2018/09/HHS-OIG-FDACybersecurityMedicalDevices.pdf”]

Not ready to join? Take the free Pub K Weekly digest.One email. Free. Top industry articles, the community calendar, and the latest job postings.