FDA MedWatch - Cybersecurity for Medical Devices and Hospital Networks: FDA Safety Communication

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

 



Title: FDA MedWatch - Cybersecurity for Medical Devices and Hospital Networks: FDA Safety Communication
MedWatch logoMedWatch - The FDA Safety Information and Adverse Event Reporting Program

Cybersecurity for Medical Devices and Hospital Networks: FDA Safety Communication

AUDIENCE: Biomedical Engineering, Health Professional, Risk Manager

ISSUE: FDA is recommending that medical device manufacturers and health care facilities take steps to assure that appropriate safeguards are in place to reduce the risk of failure due to cyberattack, which could be initiated by the introduction of malware into the medical equipment or unauthorized access to configuration settings in medical devices and hospital networks.

Recently, the FDA has become aware of cybersecurity vulnerabilities and incidents that could directly impact medical devices or hospital network operations (refer to the FDA Safety Communication for examples). FDA is not aware of any patient injuries or deaths associated with these incidents nor do we have any indication that any specific devices or systems in clinical use have been purposely targeted at this time.

FDA has been working closely with other federal agencies and manufacturers to identify, communicate and mitigate vulnerabilities and incidents as they are identified. FDA also released a draft guidance on how manufacturers should address cybersecurity in their pre-market submissions, as well as guidance on how manufacturers should address cybersecurity issues related to products that use off-the-shelf software.

BACKGROUND: Many medical devices contain configurable embedded computer systems that can be vulnerable to cybersecurity breaches. In addition, as medical devices are increasingly interconnected, via the Internet, hospital networks, other medical device, and smartphones, there is an increased risk of cybersecurity breaches, which could affect how a medical device operates.

RECOMMENDATION: The FDA is recommending that you take steps to evaluate your network security and protect your hospital system. In evaluating network security, hospitals and health care facilities should consider:

Healthcare professionals and patients are encouraged to report adverse events or side effects related to the use of these products to the FDA's MedWatch Safety Information and Adverse Event Reporting Program:

Read the Medwatch safety alert, including links to the safety communication and guidance document, at:

http://www.fda.gov/Safety/MedWatch/SafetyInformation/SafetyAlertsforHumanMedicalProducts/ucm357090.htm


This email was sent to list-fda@xxxxxxxxxxx using GovDelivery, on behalf of: U.S. Food & Drug Administration (FDA) · 10903 New Hampshire Ave · Silver Spring, MD 20993 · 800-439-1420 Powered by GovDelivery

[Index of Archives]     [CDC News]     [NIH News]     [USDA News]     [Steve's Art]     [Camping in Yosemite]     [PhotoForum]     [SB Lupus]     [STB]

  Powered by Linux