Showing posts with label FDA. Show all posts
Showing posts with label FDA. Show all posts

Saturday, October 19, 2024

FDA Sends HIPPA Cybersecurity NPRM to OMB

Yesterday, the OMB’s Office of Information and Regulatory Affairs (OIRA) announced that it had received a notice of proposed rulemaking from the Food and Drug Administration (FDA) on “Proposed Modifications to the HIPAA Security Rule to Strengthen the Cybersecurity of Electronic Protected Health Information”.

According to the Spring 2024 Unified Agenda Entry for this rulemaking:

“This rule will propose modifications to the Security Standards for the Protection of Electronic Protected Health Information (the Security Rule) under the Health Insurance Portability and Accountability Act of 1996 (HIPAA) and the Health Information Technology for Economic and Clinical Health Act of 2009 (HITECH Act). These modifications will improve cybersecurity in the health care sector by strengthening requirements for HIPAA regulated entities to safeguard electronic protected health information to prevent, detect, contain, mitigate, and recover from cybersecurity threats.”

I will probably not cover this rulemaking in any detail on this blog, unless it specifically addresses cybersecurity issues of medical devices that may contain, process, or transmit protected health information (PHI). Otherwise, there will just be a notification published in the appropriate ‘Short Takes’ post when this rulemaking is published in the Federal Register.

Thursday, September 26, 2024

OMB Approves FDA Electronics Record Guidance

Yesterday, the OMB’s Office of Information and Regulatory Affairs (OIRA) announced that it had approved an FDA guidance document on “Electronic Systems, Electronic Records, and Electronic Signatures in Clinical Investigations: Questions and Answers; Guidance for Industry”. The guidance document was sent to OIRA on September 16th, 2024. This is a very fast turnaround for OIRA, indicating a high priority within the Administration.

As is the case with most guidance documents, this was not listed in the Spring 2024 Unified Agenda. The FDA did, however, publish a draft of this document in March of 2023. That draft did include one question (question #11 on page 15): “What are FDA’s requirements and recommendations regarding the use of security safeguards?”

Such cybersecurity ‘requirements’ may be covered in this blog when the guidance document is published. 

Friday, March 8, 2024

OMB Approves FDA Premarket Cybersecurity Guidance Notice

Yesterday, the OMB’s Office of Information and Regulatory Affairs (OIRA) announced that it had approved a notice of availability from the FDA on “Select Updates for the Premarket Cybersecurity Guidance: Section 524B of the Federal Food, Drug, and Cosmetic Act; Draft Guidance for Industry and Food and Drug Administration Staff; Availability”. This guidance was submitted to OIRA on February 28th, 2024.

As with most guidance documents, this was not listed in the latest version of the Unified Agenda.

This notice will likely appear in the Federal Register within the next couple of weeks. There have been some unusual delays in these publications due to the large volume of rulemakings being processed by the Biden Administration.

Thursday, February 29, 2024

FDA Sends New Premarket Cybersecurity Guidance Notice to OMB

Yesterday, the OMB’s Office of Information and Regulatory Affairs (OIRA) announced that it had received a notice from the Food and Drug Administration (FDA) on “Select Updates for the Premarket Cybersecurity Guidance: Section 524B of the Federal Food, Drug, and Cosmetic Act; Draft Guidance for Industry and Food and Drug Administration Staff; Availability”. Such notices are not normally published in the Unified Agenda, so we have no guidance on what this new guidance may contain other than it almost certainly deals with medical device cybersecurity.

Thursday, July 27, 2023

FDA Sends Medical Tests as Medical Devices NPRM to OMB

Yesterday, the OMB’s Office of Information and Regulatory Affairs (OIRA) announced that it had received a notice of proposed rulemaking (NPRM) from the Federal Drug Administration for “Medical Devices; Laboratory Developed Tests”. According to the Spring 2023 Unified Agenda entry for this rulemaking:

“This proposed rule would propose to amend the Food and Drug Administration’s regulations to make explicit that laboratory developed tests (LDTs) are devices under the Federal Food, Drug, and Cosmetic Act.”

It will be interesting to see what portions of the FDA medical device rules will apply to these medical tests. Cybersecurity for testing equipment is one that I would be watching for in these proposed regulations.

Saturday, April 29, 2023

Review – Public ICS Disclosures – Week of 4-22-23

This week we have eighteen vendor disclosures from BD, Belden (2), Bosch (2), GE Gas Power (2), Genetec, Hitachi Energy (4), HPE, Mitsubishi, Moxa, Omron, Schneider, and VMware. There are two vendor updates from HPE, and Mitsubishi. Finally, we have an FDA report on the Illumina vulnerabilities.

Advisories

BD Advisory - BD published an advisory that describes a credential sharing incident that could affect their BD Kiestra product.

Belden Advisory #1 - Belden published an advisory that discusses an integer overflow or wraparound vulnerability in their HiSecOS and Cellular Router products.

Belden Advisory #2 - Belden published an advisory that discusses two vulnerabilities in their Hirschmann product line.

Bosch Advisory #1 - Bosch published an advisory that describes an incorrect authorization vulnerability in their B420 Ethernet communication module.

Bosch Advisory #2 - Bosch published an advisory that discusses a use of obsolete function vulnerability in their SLC-0-GPNT00300 interface module.

GE Gas Power Advisory #1 - GE published an advisory that discusses a path traversal vulnerability in multiple products.

GE Gas Power Advisory #2 - GE published an advisory that discusses a buffer underflow vulnerability in multiple products.

Genetec Advisory - Genetec published an advisory that discusses three vulnerabilities in the Security Center product.

Hitachi Energy Advisory #1 - Hitachi Energy published an advisory that discusses eight vulnerabilities in their Modular Switchgear Monitoring product.

Hitachi Energy Advisory #2 - Hitachi Energy published an advisory that discusses four vulnerabilities in their RTU500 series product.

Hitachi Energy Advisory #3 - Hitachi Energy published an advisory that discusses two vulnerabilities in their RTU500 series product.

Hitachi Energy Advisory #4 - Hitachi Energy published an advisory that discusses two vulnerabilities in their AFS65x, AFS67x, AFR67x and AFF66x series Products.

HPE Advisory - HPE published an advisory that describes an arbitrary code execution vulnerability in their ProLiant RL300 Gen11 Server.

Mitsubishi Advisory - Mitsubishi published an advisory that discusses nine vulnerabilities in their FA product line.

Moxa Advisory - Moxa published an advisory that discusses two Trusted Computing Group TPM2.0 implementation vulnerabilities.

Omron Advisory - Omron published an advisory that describes a heap-based buffer overflow vulnerability in their CX-drive support tool.

Schneider Advisory - Schneider published an advisory that discusses a recently published exploit for vulnerabilities in their KNX building automation systems.

VMware Advisory - VMware published an advisory that describes four vulnerabilities in their Workstation and Fusion products.

Updates

HPE Update - HPE published an update for their IceWall advisory that was originally published on March 9th, 2018 and most recently updated on January 27th, 2023.

Mitsubishi Update - Mitsubishi published an update for their Ethernet port of MELSEC and MELIPC Series advisory that was originally published on November 30th, 2021 and most recently updated on November 24th, 2022.

Reports

Illumina Report - The Federal Drug Administration (FDA) published a letter to healthcare providers on the Illumina vulnerabilities reported this week by CISA.

 

For more details on these disclosures, including links to 3rd party advisories and exploits, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/public-ics-disclosures-week-of-4-b33 - subscription required.

Thursday, March 30, 2023

Review - FDA Publishes ‘Refuse to Accept’ Policy Guidance Document

The Food and Drug Administration (FDA) published a notice of availability in the Federal Register (88 FR 19148-19150) for “Cybersecurity in Medical Devices: Refuse To Accept Policy for  Cyber Devices and Related Systems Under Section 524B of the FD&C Act; Guidance for Industry and Food and Drug Administration Staff”. The actual guidance document is available here. This guidance document was sent to the OMB’s Office of Information and Regulatory Affairs (OIRA) on March 22nd, 2023, and approved by OIRA on March 27th.

The effective date of this new guidance document is March 29th, 2023.

 

For more details about this guidance document, including a commentary on its current deficiencies, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/fda-publishes-refuse-to-accept-policy - subscription required.

Tuesday, March 28, 2023

OMB Approves Medical Device ‘Refusal’ Rule

Yesterday, the OMB’s Office of Information and Regulatory Affairs (OIRA) announced that it had approved a notice from the Food and Drug Administration on “Cybersecurity in Medical Devices: Refuse to Accept Policy for Cyber Devices and Related Systems Under Section 524B of the FD&C Act”. This notice was not listed in the Fall 2022 Unified Agenda. It was submitted to OMB on March 22nd, 2023.

As I noted in that earlier post, it appears that this notice is related to a recent amendment of 21 USC 331(q) making it unlawful for medical device manufacturers to fail  to comply with any requirement under §524B(b)(2). That paragraph reads:

‘‘(2) design, develop, and maintain processes and procedures to provide a reasonable assurance that the device and related systems are cybersecure, and make available postmarket updates and patches to the device and related systems to address—

‘‘(A) on a reasonably justified regular cycle, known unacceptable vulnerabilities; and

‘‘(B) as soon as possible out of cycle, critical vulnerabilities that could cause uncontrolled risks;”

We will probably see this notice published in the Federal Register later this week.

Thursday, March 23, 2023

FDA Sends Medical Device Cybersecurity Notice to OMB

Yesterday, the OMB’s Office of Information and Regulatory Affairs (OIRA) announced that it had receive a notice from the Federal Drug Administration (FDA) on “Cybersecurity in Medical Devices: Refuse to Accept Policy for Cyber Devices and Related Systems Under Section 524B of the FD&C Act”. There is no listing for this action in the Fall 2022 Unified Agenda.

The new §524B was added to the Food, Drug, and Cosmetic Act by §3305 (pg 1374), Ensuring Cybersecurity of Medical Devices, of the Consolidated Appropriations Act, 2023 (PL 117-328, HR 2617). Subsection 3305(b) amended 21 USC 331(q) making it unlawful for medical device manufacturers to fail  to comply with any requirement under §524B(b)(2). That paragraph reads:

‘‘(2) design, develop, and maintain processes and procedures to provide a reasonable assurance that the device and related systems are cybersecure, and make available postmarket updates and patches to the device and related systems to address—

‘‘(A) on a reasonably justified regular cycle, known unacceptable vulnerabilities; and

‘‘(B) as soon as possible out of cycle, critical vulnerabilities that could cause uncontrolled risks;”

It looks like this notice may be related to that section in relation to ‘§524B’.

Saturday, November 19, 2022

Review - FDA Publishes Medical Device Cybersecurity Response Playbook

This week the Food and Drug Administration published the updated version of their Medical Device Cybersecurity Regional Incident Preparedness and Response Playbook. Produced under contract by Mitre, the playbook presents target capabilities for medical device cyber incident preparedness and response. There are actually two parts to this playbook, the 54-page Regional Incident Preparedness and Response Playbook and the 10-page supplemental Quick Start Companion Guide.

According to the Mite web site for the publication:

“The playbook outlines how hospitals and other HDOs [Healthcare Delivery Organizations] can develop a cybersecurity preparedness and response framework. It supplements existing HDO emergency management and/or incident response capabilities with regional preparedness and response recommendations for medical device cybersecurity incidents. The revised version includes more explicit alignment with the Hospital Incident Command System for managing complex incidents, considerations for the widespread impacts and extended downtimes that are common during cyber incidents, and an appendix of resources.”

Commentary

The news almost daily reports a new healthcare delivery organization that has been impacted by some form of cybersecurity breach. It is clear that HDO’s need assistance to help them avoid the worst consequences of such attacks. Unfortunately, it does not look like either of these two documents is going to provide any timely assistance. To be fair, I do not think that any guidance document is going to be much help, as much of the problem is the lack of cybersecurity talent to support these organizations. Even if grant monies were thrown at HDO’s to improve their cybersecurity profiles, I do not think that there is a sufficient base of cybersecurity personnel to implement even minimal controls on all of the potential targets.


For more information about these two documents, including a discussion of their shortcomings, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/fda-publishes-medical-device-cybersecurity - subscription required.

Tuesday, September 13, 2022

FDA Publishes Draft Update for Software Assurance Guidance

Today the Food and Drug Administration published a notice in the Federal Register (87 FR 56059-56061) announcing the availability of a draft update for their Computer Software Assurance for Production and Quality System Software. The guidance is supportive of the requirements of 21 CFR 820.70(i) to “validate computer software for its intended use according to an established protocol.” The final version of this document is intended to supplement the current “General Principles of Software Validation”, superseding Section 6 of that document.

The FDA is soliciting public comments on this draft. Comments may be submitted via the Federal eRulemaking Portal (www.Regulations.gov; Docket # FDA-2022-D-0795). Comments should be submitted by November 14th, 2022.

Commentary

While most hacking of manufacturing control systems does not actually change the software, control system software that contains vulnerabilities that allow unauthorized changes to manufacturing parameters should not be considered ‘fit for purpose’. This guidance does not address trying to identify such vulnerabilities, and that is probably reasonable. What should be included, however, is a process for evaluating post-assurance identification of such vulnerabilities.

Manufacturing organizations are not typically going to be writing code for manufacturing or quality control system software/firmware, so they are not directly responsible for identifying vulnerabilities in that code. Vendors of the software are going to be responsible for receiving reports of vulnerabilities from internal and external researchers and taking such corrective action as is appropriate for those vulnerabilities. What the user/owner is going to be responsible for is deciding if/when changes to the software will be applied to their systems.

The guidance document should address how the user/owner is going to identify the existence of vendor updates to the covered software and what risk assessment process will be used to determine if a given update is necessary and when it should be applied, or if other mitigation measures identified by the vendor are adequate protection to the system as used.


Thursday, September 8, 2022

OMB Approves FDA Software Assurance Guidance Document

Yesterday, the OMB’s Office of Information and Regulatory Affairs (OIRA) announced that it had approved the FDA’s “Computer Software Assurance for Production and Quality System Software; Draft Guidance for Industry and Food and Drug Administration Staff”. Like most guidance documents reviewed by OIRA prior to release, this document was not listed in the latest Unified Agenda.

There is an interesting article here on the purpose and use of ‘computer software assurance’ processes in the medical device sector.

Saturday, April 9, 2022

Review - FDA Publishes Draft Medical Device Cybersecurity Guidance

Yesterday, the FDA published a notice of availability in the Federal Register (87 FR 20878-20875) for a Draft Guidance Document on “Cybersecurity in Medical Devices: Quality System Considerations and Content of Premarket Submissions”. The draft guidance can be downloaded from the Federal eRulemaking Portal.

According to the Summary in the Notice:

“This draft guidance is intended to further emphasize the importance of ensuring that devices are designed securely, are designed to be capable of mitigating emerging cybersecurity risks throughout the Total Product Life Cycle, and to clearly outline FDA's recommendations for premarket submission content to address cybersecurity concerns.”

The summary goes on to remind folks that: “This draft guidance is not final nor is it for implementation at this time.”

Comment Solicitation

The FDA is soliciting comments on this draft guidance. Comments may be submitted via the Federal eRulemaking Portal (www.Regulations.gov; Docket FDA-2021-D-1158). Comments should be submitted by July 7th, 2022.

Commentary

First off, I am not a doctor, not even a medical device engineer, nor have I played one on TV. Having said that, it seems to me that there may be a little too much focus on cybersecurity in this guidance document. I know, that is what the document is about, but it seems to miss the fact that it is not really cybersecurity that we are concerned about when we talk about medical devices, it should primarily be protecting patient safety, secondarily about protecting patient information and confidentiality, and only then protecting the device and medical network.

While a Secure Product Development Framework is certainly important in any software development cycle, it is not sufficient, since we know that what people design is going to be imperfect. This means that there will be vulnerabilities in even well-designed systems. Whenever safety is an issue, and it certainly is in medical devices, we need to go beyond SPDF and look at Consequence-driven Cyber-informed Engineering (CCE). This methodology developed at the Idaho National Laboratory (INL) concentrates on identifying the safety consequences of system errors and vulnerabilities and working to mitigate those consequences. This methodology should be included in any discussion about cybersecurity for medical devices.

For more details about the draft guidance document, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/fda-publishes-draft-medical-device - subscription required.

Thursday, April 7, 2022

Review - HR 7084 Introduced – PATCH Act

Last month, Rep Burgess (R,TX) introduced HR 7084, the Protecting and Transforming Cyber Health Care (PATCH) Act of 2022. The bill would amend the Federal Food, Drug, and Cosmetic Act by adding a new section dealing with the cybersecurity requirements (including software bill of material requirements) for medical devices. No new funding is authorized by this bill.

Moving Forward

Burgess, and his sole cosponsor {Rep Craig (D,MN)}, are members of the House Energy and Commerce Committee to which this bill was assigned for consideration. This means that there should be sufficient influence to see this bill considered in Committee. I see nothing in this bill that would engender any organized opposition beyond some pro forma objections from the medical device manufacturing sector. I suspect that this bill would receive substantial bipartisan support.

Commentary

I have two main concerns about this bill. First deals with definitions. There are two terms used in the provisions dealing with updates and patches that are not defined in the bill or current statute:

• Unacceptable vulnerabilities, and

• Critical vulnerabilities.

I would like to think that the first term would be dealing with vulnerabilities related to patient information disclosures and the second would be dealing with vulnerabilities that could interfere with the safe operation of the device. If this is what the staff intended, it should be clearly spelled out in the definition subsection of the bill.

My second concern is that the bill only covers cybersecurity issues with new ‘premarket submissions’. I understand concerns related to ex post facto rulemaking, but something needs to be done about the hundreds (thousands? I’m not sure) of existing FDA approved devices that have no cybersecurity requirements. I would add a new §2(e):

“(e) The Director of the Food and Drug Administration will work with manufacturers of existing approved cyber devices to ensure that those manufacturers can document substantial compliance with the new requirements under §524B added by this bill. Two years after this bill is approved, the Director will publish on the Administration’s web site a list of existing approved cyber devices which have not yet documented substantial compliance with these provisions.”

For more details about the provisions of this bill, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/hr-7084-introduced - subscription require.

Wednesday, April 6, 2022

OMB Approves FDA Medical Device Cybersecurity Guidance

Yesterday, OMB’s Office of Information and Regulatory Affairs (OIRA) announced that it had approved the publication of a draft guidance document for industry and the FDA Administrative Staff on “Cybersecurity in Medical Devices: Quality System Considerations and Content of Premarket Submissions”. As is typical for guidance documents, there was no listing for this in the Fall 2021 Unified Agenda. The document was submitted to OIRA on March 11th, 2022.

Monday, March 14, 2022

FDA Sends Medical Device Cybersecurity Guidance to OMB

On Friday, the OMB’s Office of Information and Regulatory Affairs (OIRA) announced that it had received a notice from the FDA on “Cybersecurity in Medical Devices: Quality System Considerations and Content of Premarket Submissions; Draft Guidance for Industry and Food and Drug Administration Staff”. This guidance document was not listed in the Fall 2021 Unified Agenda (guidance documents are not typically listed there), but this looks like it may be an update of the 2018 Draft Guidance: Content of Premarket Submissions for Management of Cybersecurity in Medical Devices.

Friday, March 4, 2016

FDA Publishes RFI for Medical Device Refurbishment

Today the Food and Drug Administration (FDA) published a request for information (RFI) notice in the Federal Register (81 FR 11477-11479) to receive information and comments on the medical device industry and healthcare community that refurbish, recondition, rebuild, remarket, remanufacture, service, and repair medical devices.

The RFI


The FDA’s notice explains that:

“Stakeholders have expressed concerns that some third-party entities who refurbish, recondition, rebuild, remarket, remanufacture, service, and repair medical devices may use unqualified personnel to perform service, maintenance, refurbishment, and device alterations on their equipment and that the work performed may not be adequately documented. Possible public health issues arising from these activities include ineffective recalls, disabled device safety features, and improper or unexpected device operation. OEMs have also requested clarification of their responsibilities when their devices have been altered by a third-party entity. Federal Agencies other than FDA address service and maintenance activities as well.”

The notice provides descriptive definitions of the activities of interest in this RFI. Those activities are:

Servicing;
Repairing;
Remanufacturing; and


The FDA is soliciting comments on concerning the service, maintenance, refurbishment, and alteration of medical devices, including endoscopes (Ref. 3), by third-party entities. They are specifically looking for responses to the following questions:

• Who are the different stakeholders involved with the medical device activities listed previously?
• What evidence exists regarding actual problems with the safety and/or performance of devices that result from these activities?
• What are the potential risks (patients/users) and failure modes (devices) introduced as a result of performing the previously defined activities on medical devices?
• Are the risks different depending on who performs the previously mentioned activities?
• Which of these activities are more difficult or riskier to perform on certain devices versus others?
• What information do third-party entities need in order to perform these activities in a way that results in safe and effective operation of the medical device?
• What additional challenges do stakeholders encounter with devices that result from these activities?

The FDA is soliciting public feedback on these questions. Responses can be submitted via the Federal eRulemaking Portal (www.Regulations.gov; Docket # FDA-2016-N-0436). Comments should be submitted by May 3rd, 2016.

Commentary


As more and more of these devices contain electronic control systems and data storage systems the issue of cybersecurity must be included in any discussion of refurbishment of medical devices. Some of the types of cybersecurity issues that will need to be looked at will include:

• Verification that there has not been has not been tampering with any firmware/software loaded on the device;
• Verification that any manufacturer updates to firmware/software have successfully been applied;
• Verification that any additional communications protocols associated with the device are up to date; and
• Where the device must be hooked to a personal computer (PC) similar questions about the software on the PC must be addressed;

Additionally, before the device is sent to a third party, or even the original vendor, for refurbishment, specific procedures are going to have to be established to ensure that all patient information is permanently removed from the device.


Since the FDA is planning on holding meetings on the medical device refurbishment issue, perhaps is should consider holding a meeting to specifically look at the related cybersecurity issues.

A copy of this post was submitted to the FDA Docket on March 6th, 2015.

Wednesday, January 13, 2016

FDA Workshop on Cybersecurity for Medical Devices

The Food and Drug Administration has announced the agenda for their conference on Medical Device Cybersecurity to be held later this month. The 2-day conference and workshop is designed to engage the multi-stakeholder community in focused discussions on unresolved gaps and challenges that have hampered progress in advancing medical device cybersecurity.

Included on the agenda are sessions on:

• Keynote Address: Marty Edwards, Director of ICS–CERT;
• Medical Device Cybersecurity: A Year in Reflection and Looking Ahead;
• Cyber Threat Landscape within the Healthcare and Public Health Sector;
• FDA's Current Thinking: Implementation of the NIST ‘Framework for Improving Critical Infrastructure Cybersecurity’ for Strengthening Security throughout the Total Product Life Cycle;
• Information Sharing and Analysis Organization (ISAO);
• Vulnerability Handling Processes and Coordinated Vulnerability Disclosure;
• Overcoming Challenges Manufacturers face with Increased Cybersecurity Collaboration;
• Identifying and Crafting Action Plans to Address Gaps and Challenges in Strengthening the Cybersecurity Stance of the Medical Device Ecosystem;
• Gaining Situational Awareness of Current Activities in the Healthcare and Public Health Sector to Enhance Medical Device Cybersecurity; and
• Adapting and/or Implementing Medical Device Cybersecurity Standards


The link for the webcast is still not available. It should be on the conference web site by the time of the meeting.

Monday, December 7, 2015

FDA Announces Cybersecurity Workshop

Today the Food and Drug Administration (FDA) published a meeting notice in the Federal Register (80 FR 76022-76025) for a public workshop entitled “Moving Forward: Collaborative Approaches to Medical Device Cybersecurity”. The two-day workshop will be held in Silver Springs, MD on January 20-21st, 2016. The workshop will be webcast.

Agenda

According to the meeting notice the FDA, in conjunction with the National Health Information Sharing Analysis Center (NH-ISAC), the Department of Health and Human Services, and the Department of Homeland Security, wishes to address the following questions related to coordinated disclosure:

• How might the stakeholder community create incentives to encourage stakeholder participation?
• What do individual stakeholders need to understand and be aware of regarding coordinated disclosure?
• What current tools and models presently exist that may aid stakeholders in implementing disclosure and vulnerability management?
• How can the security researcher community work in collaboration with HPH stakeholders to identify, assess, and mitigate vulnerabilities?

Additional topics of interest include:

• Sharing FDA's current thinking on the implementation of the Framework in the medical device total product lifecycle.
• Adapting cybersecurity and/or risk assessment tools such as CVSS for the medical device operational environment.
• Adapting and/or implementing existing cybersecurity standards for medical devices.
• Understanding the challenges that manufacturers face as they increase collaboration with external third parties (cybersecurity researchers, ISAOs, and end users), to resolve cybersecurity vulnerabilities that impact their devices.
• Gaining situational awareness of the current activities in the HPH sector to enhance medical device cybersecurity.
• Identifying cybersecurity gaps and challenges that persist in the medical device ecosystem and begin crafting action plans to address them.

Registration

Those wishing to attend the workshop in person may register on-line. Early registration is recommended due to the limited seating at the venue.

Registration is not required for the web cast, but the web cast link will not be available until January 13th, 2016.

Public Comments


The FDA is soliciting public comments on the topics to be covered in the workshop. Written comments may be submitted via the Federal eRulemaking Portal (www.Regulations.gov; Docket # FDA-2014-N-1286). Comments will be accepted until February 22, 2016.

Commentary

The one thing that looks to be missing from this workshop is a discussion of how reported cybersecurity vulnerabilities will be related to device recalls. More on this in a later blog post.

Wednesday, May 6, 2015

Reader Comment – FDA and Cybersecurity

Last night a long time reader and respected ICS security professional Dale Peterson took exception to my comments about the FDA response to the Hospira Infusion Pump vulnerabilities. He noted (in part, please read his entire comment) that:

“Yes they were late to the party and are not perfect, but they have issued guidance and provided rulings that are quite impressive given the short time they have been working on the issue.”

I will admit that I haven’t paid a great deal of attention to the FDA’s response to cybersecurity issues. I have only done three blog posts on the topic (here, here and here) and made some unfavorable comments in one other post about medical control system advisories from ICS-CERT (here). And I have not looked at the FDA regulations to see what authority the FDA does actually have in this respect. So, I’ll bow to Dale’s (and Billy Rios’) larger experience set with the agency and accept that the FDA may be making an honest effort to get their control system security program up and running.

Having said that, I am still very concerned that the FDA has not been more forthcoming in sharing information with the medical community about the control system security issues with this infusion pump. I understand that a full recall of these devices may put many hospitals, clinics, and doctors in a position of not being able to provide critical medical services, but at the very least there should have been some sort of notice to the medical community published yesterday in conjunction with the ICS-CERT advisory. It’s not like the average hospital IT department routinely monitors the ICS-CERT web site (Hell, I don’t expect that most ICS owners do that; that is the whole point of my blog posts on each advisory).

Now I understand that the federal government has the same problem that most large organizations have (scaled-up due to size of course) that there are too many silos and not enough communication between them. Cybersecurity is just one area where that lack of communication is readily apparent.

ICS-CERT does not have the authority (and certainly not the manpower) to regulate control system security in any sector. The one thing that they are supposed to be doing (by convention anyway, certainly not by law or regulation) is to be coordinating vulnerability disclosure. Most of us have assumed that coordination was between the researcher who discovered the vulnerability and the vendor who needed to resolve the issue. It seems like, in this instance in any case, that that coordination also included some conversations with the FDA since ICS-CERT reported that the FDA was reviewing the new software version. If that coordination with FDA did take place ICS-CERT is to be commended.

The FDA on the other hand, seems to have limited their response to that review process (a valuable and necessary thing in its own right). It seems to me, however, that they have at the very least a moral responsibility and probably a legal responsibility to communicate to the medical community (at least) the medial device vulnerability that potentially puts patients at risk. If there is not a legal responsibility to do so, the Congress needs to act immediately to rectify that situation (won’t happen, I know).

To be fair to the FDA, they are not the only organization that has this problem. You can pick just about any major agency in the federal government that has some dealing with control systems and you will see similar problems. This is the real information sharing conundrum that plagues cybersecurity issues; even when the federal government has information about vulnerabilities and mitigation measures, they don’t do an effective job of sharing that information with people who actually own the systems involved.


Okay, enough for today’s rant. Again, the FDA is apparently attempting to get its act together about medical device control system security; kudos for that. But I remain disappointed in their lack of effort to share what information they do have with the medical community.
 
/* Use this with templates/template-twocol.html */