FDA Laws and Submission Guidance Catches up with Cyber Risks in Medical Devices

FDA Laws and Submission Guidance Catches up with Cyber Risks in Medical Devices

The forgiveness period for medical device manufacturers not following the PATCH (Protecting and Transforming Cyber Healthcare) Act came to a close in October 2023. The Act, which became a law in late 2022 and went into effect in March 2023, is the first enforceable law focused specifically on cyber safety of medical devices. Joshua Corman likens it to “minimum seatbelt laws for medical devices” by requiring manufacturers to provide demonstrable proof of cybersecurity controls and visibility into their devices during pre-market FDA submission. 


Corman, who teaches secure development lifecycle and product security for Carnegie Mellon University’s grad school, is the founder of Iamthecavalry.org, a collection of thousands of volunteer experts from around the world with a common mission to improve cybersecurity in medical devices, transportation, and infrastructure systems, and the connected home. Josh was active in developing the PATCH Act, as well as the FDA’s latest pre-market cyber security guidance for device manufacturers that was published in September (2023).  

Now backed by law, the FDA’s guidance is no longer elective, and dictates how the agency evaluates medical devices going to market, says Corman, who also co-founded CyberMedSummit.org, where he’s demonstrated dozens of ways medical devices could be hacked to charm patients.


In this show, he talks about the nine-year journey to get medical device manufacturers to follow best practices and shift left in their DevOps practices, starting with secure by design and throughout the product lifecycle. And, since medicface al device software utilizes up to 90 percent open-source components, SBOMs (software bill of materia ..

Support the originator by clicking the read the rest link below.