Accessibility Statement Skip Navigation
  • Resources
  • Investor Relations
  • Journalists
  • Agencies
  • Client Login
  • Send a Release
Return to PR Newswire homepage
  • News
  • Products
  • Contact
When typing in this field, a list of search results will appear and be automatically updated as you type.

Searching for your content...

No results found. Please change your search terms and try again.
  • News in Focus
      • Browse News Releases

      • All News Releases
      • All Public Company
      • English-only
      • News Releases Overview

      • Multimedia Gallery

      • All Multimedia
      • All Photos
      • All Videos
      • Multimedia Gallery Overview

      • Trending Topics

      • All Trending Topics
  • Business & Money
      • Auto & Transportation

      • All Automotive & Transportation
      • Aerospace, Defense
      • Air Freight
      • Airlines & Aviation
      • Automotive
      • Maritime & Shipbuilding
      • Railroads and Intermodal Transportation
      • Supply Chain/Logistics
      • Transportation, Trucking & Railroad
      • Travel
      • Trucking and Road Transportation
      • Auto & Transportation Overview

      • View All Auto & Transportation

      • Business Technology

      • All Business Technology
      • Blockchain
      • Broadcast Tech
      • Computer & Electronics
      • Computer Hardware
      • Computer Software
      • Data Analytics
      • Electronic Commerce
      • Electronic Components
      • Electronic Design Automation
      • Financial Technology
      • High Tech Security
      • Internet Technology
      • Nanotechnology
      • Networks
      • Peripherals
      • Semiconductors
      • Business Technology Overview

      • View All Business Technology

      • Entertain­ment & Media

      • All Entertain­ment & Media
      • Advertising
      • Art
      • Books
      • Entertainment
      • Film and Motion Picture
      • Magazines
      • Music
      • Publishing & Information Services
      • Radio & Podcast
      • Television
      • Entertain­ment & Media Overview

      • View All Entertain­ment & Media

      • Financial Services & Investing

      • All Financial Services & Investing
      • Accounting News & Issues
      • Acquisitions, Mergers and Takeovers
      • Banking & Financial Services
      • Bankruptcy
      • Bond & Stock Ratings
      • Conference Call Announcements
      • Contracts
      • Cryptocurrency
      • Dividends
      • Earnings
      • Earnings Forecasts & Projections
      • Financing Agreements
      • Insurance
      • Investments Opinions
      • Joint Ventures
      • Mutual Funds
      • Private Placement
      • Real Estate
      • Restructuring & Recapitalization
      • Sales Reports
      • Shareholder Activism
      • Shareholder Meetings
      • Stock Offering
      • Stock Split
      • Venture Capital
      • Financial Services & Investing Overview

      • View All Financial Services & Investing

      • General Business

      • All General Business
      • Awards
      • Commercial Real Estate
      • Corporate Expansion
      • Earnings
      • Environmental, Social and Governance (ESG)
      • Human Resource & Workforce Management
      • Licensing
      • New Products & Services
      • Obituaries
      • Outsourcing Businesses
      • Overseas Real Estate (non-US)
      • Personnel Announcements
      • Real Estate Transactions
      • Residential Real Estate
      • Small Business Services
      • Socially Responsible Investing
      • Surveys, Polls and Research
      • Trade Show News
      • General Business Overview

      • View All General Business

  • Science & Tech
      • Consumer Technology

      • All Consumer Technology
      • Artificial Intelligence
      • Blockchain
      • Cloud Computing/Internet of Things
      • Computer Electronics
      • Computer Hardware
      • Computer Software
      • Consumer Electronics
      • Cryptocurrency
      • Data Analytics
      • Electronic Commerce
      • Electronic Gaming
      • Financial Technology
      • Mobile Entertainment
      • Multimedia & Internet
      • Peripherals
      • Social Media
      • STEM (Science, Tech, Engineering, Math)
      • Supply Chain/Logistics
      • Wireless Communications
      • Consumer Technology Overview

      • View All Consumer Technology

      • Energy & Natural Resources

      • All Energy
      • Alternative Energies
      • Chemical
      • Electrical Utilities
      • Gas
      • General Manufacturing
      • Mining
      • Mining & Metals
      • Oil & Energy
      • Oil and Gas Discoveries
      • Utilities
      • Water Utilities
      • Energy & Natural Resources Overview

      • View All Energy & Natural Resources

      • Environ­ment

      • All Environ­ment
      • Conservation & Recycling
      • Environmental Issues
      • Environmental Policy
      • Environmental Products & Services
      • Green Technology
      • Natural Disasters
      • Environ­ment Overview

      • View All Environ­ment

      • Heavy Industry & Manufacturing

      • All Heavy Industry & Manufacturing
      • Aerospace & Defense
      • Agriculture
      • Chemical
      • Construction & Building
      • General Manufacturing
      • HVAC (Heating, Ventilation and Air-Conditioning)
      • Machinery
      • Machine Tools, Metalworking and Metallurgy
      • Mining
      • Mining & Metals
      • Paper, Forest Products & Containers
      • Precious Metals
      • Textiles
      • Tobacco
      • Heavy Industry & Manufacturing Overview

      • View All Heavy Industry & Manufacturing

      • Telecomm­unications

      • All Telecomm­unications
      • Carriers and Services
      • Mobile Entertainment
      • Networks
      • Peripherals
      • Telecommunications Equipment
      • Telecommunications Industry
      • VoIP (Voice over Internet Protocol)
      • Wireless Communications
      • Telecomm­unications Overview

      • View All Telecomm­unications

  • Lifestyle & Health
      • Consumer Products & Retail

      • All Consumer Products & Retail
      • Animals & Pets
      • Beers, Wines and Spirits
      • Beverages
      • Bridal Services
      • Cannabis
      • Cosmetics and Personal Care
      • Fashion
      • Food & Beverages
      • Furniture and Furnishings
      • Home Improvement
      • Household, Consumer & Cosmetics
      • Household Products
      • Jewelry
      • Non-Alcoholic Beverages
      • Office Products
      • Organic Food
      • Product Recalls
      • Restaurants
      • Retail
      • Supermarkets
      • Toys
      • Consumer Products & Retail Overview

      • View All Consumer Products & Retail

      • Entertain­ment & Media

      • All Entertain­ment & Media
      • Advertising
      • Art
      • Books
      • Entertainment
      • Film and Motion Picture
      • Magazines
      • Music
      • Publishing & Information Services
      • Radio & Podcast
      • Television
      • Entertain­ment & Media Overview

      • View All Entertain­ment & Media

      • Health

      • All Health
      • Biometrics
      • Biotechnology
      • Clinical Trials & Medical Discoveries
      • Dentistry
      • FDA Approval
      • Fitness/Wellness
      • Health Care & Hospitals
      • Health Insurance
      • Infection Control
      • International Medical Approval
      • Medical Equipment
      • Medical Pharmaceuticals
      • Mental Health
      • Pharmaceuticals
      • Supplementary Medicine
      • Health Overview

      • View All Health

      • Sports

      • All Sports
      • General Sports
      • Outdoors, Camping & Hiking
      • Sporting Events
      • Sports Equipment & Accessories
      • Sports Overview

      • View All Sports

      • Travel

      • All Travel
      • Amusement Parks and Tourist Attractions
      • Gambling & Casinos
      • Hotels and Resorts
      • Leisure & Tourism
      • Outdoors, Camping & Hiking
      • Passenger Aviation
      • Travel Industry
      • Travel Overview

      • View All Travel

  • Policy & Public Interest
      • Policy & Public Interest

      • All Policy & Public Interest
      • Advocacy Group Opinion
      • Animal Welfare
      • Congressional & Presidential Campaigns
      • Corporate Social Responsibility
      • Domestic Policy
      • Economic News, Trends, Analysis
      • Education
      • Environmental
      • European Government
      • FDA Approval
      • Federal and State Legislation
      • Federal Executive Branch & Agency
      • Foreign Policy & International Affairs
      • Homeland Security
      • Labor & Union
      • Legal Issues
      • Natural Disasters
      • Not For Profit
      • Patent Law
      • Public Safety
      • Trade Policy
      • U.S. State Policy
      • Policy & Public Interest Overview

      • View All Policy & Public Interest

  • People & Culture
      • People & Culture

      • All People & Culture
      • Aboriginal, First Nations & Native American
      • African American
      • Asian American
      • Children
      • Diversity, Equity & Inclusion
      • Hispanic
      • Lesbian, Gay & Bisexual
      • Men's Interest
      • People with Disabilities
      • Religion
      • Senior Citizens
      • Veterans
      • Women
      • People & Culture Overview

      • View All People & Culture

      • In-Language News

      • Arabic
      • español
      • português
      • Česko
      • Danmark
      • Deutschland
      • España
      • France
      • Italia
      • Nederland
      • Norge
      • Polska
      • Portugal
      • Россия
      • Slovensko
      • Suomi
      • Sverige
  • Explore Our Platform
  • Plan Campaigns
  • Create with AI
  • Distribute Press Releases
  • Amplify Content
  • All Products
  • General Inquiries
  • Editorial Bureaus
  • Partnerships
  • Media Inquiries
  • Worldwide Offices
  • Hamburger menu
  • PR Newswire: news distribution, targeting and monitoring
  • Send a Release
    • ALL CONTACT INFO
    • Contact Us

      888-776-0942
      from 8 AM - 10 PM ET

  • Send a Release
  • Client Login
  • Resources
  • Blog
  • Journalists
  • RSS
  • News in Focus
    • Browse All News
    • Multimedia Gallery
    • Trending Topics
  • Business & Money
    • Auto & Transportation
    • Business Technology
    • Entertain­ment & Media
    • Financial Services & Investing
    • General Business
  • Science & Tech
    • Consumer Technology
    • Energy & Natural Resources
    • Environ­ment
    • Heavy Industry & Manufacturing
    • Telecomm­unications
  • Lifestyle & Health
    • Consumer Products & Retail
    • Entertain­ment & Media
    • Health
    • Sports
    • Travel
  • Policy & Public Interest
  • People & Culture
    • People & Culture
  • Send a Release
  • Client Login
  • Resources
  • Blog
  • Journalists
  • RSS
  • Explore Our Platform
  • Plan Campaigns
  • Create with AI
  • Distribute Press Releases
  • Amplify Content
  • All Products
  • Send a Release
  • Client Login
  • Resources
  • Blog
  • Journalists
  • RSS
  • General Inquiries
  • Editorial Bureaus
  • Partnerships
  • Media Inquiries
  • Worldwide Offices
  • Send a Release
  • Client Login
  • Resources
  • Blog
  • Journalists
  • RSS

Statement from FDA Commissioner Scott Gottlieb, M.D. on FDA's efforts to strengthen the agency's medical device cybersecurity program as part of its mission to protect patients

U.S. Food and Drug Administration (FDA) logo (PRNewsfoto/FDA)

News provided by

U.S. Food and Drug Administration

Oct 01, 2018, 13:21 ET

Share this article

Share toX

Share this article

Share toX

SPRING, Md., Oct. 1, 2018 /PRNewswire/ -- The threat of cyber attacks is no longer theoretical. Cyber criminals and adversaries can inflict significant harm on networks through relatively simple methods, like emails or bugs known as malware.

In recent years, we've witnessed the far-reaching and negative consequences of successful cyber campaigns on organizations. Victims include financial institutions, government agencies, and now health care systems. Even when medical devices are not being deliberately targeted, if these products are connected to a hospital network, such as radiologic imaging equipment, they may be impacted.

As the number of cyber attacks has increased, we've heard concerns about the potential for cyber criminals to attack patient medical devices. Cybersecurity researchers, often referred to as "white hat hackers" have identified device vulnerabilities in non-clinical, research-based settings. They've shown how bad actors could gain the capability to exploit these same weaknesses, thereby acquiring access and control of medical devices. The FDA isn't aware of any reports of an unauthorized user exploiting a cybersecurity vulnerability in a medical device that is in use by a patient. But the risk of such an attack persists. And we understand that the threat of such an attack can cause alarm to patients who may have devices that are connected to a network. We want to assure patients and providers that the FDA is working hard to be prepared and responsive when medical device cyber vulnerabilities are identified.

At the FDA, we'll continue to put protecting patients at the forefront of what we do. Today, we are building on a foundation of shared responsibility with our stakeholders. In coordination with the MITRE Corporation, we're announcing the launch of a cybersecurity "playbook" for health care delivery organizations that's focused on promoting cybersecurity readiness. We're also announcing the signing of two significant memoranda of understanding. These agreements bring together multiple stakeholders to allow for increased information sharing and transparency around cybersecurity risks.

Securing medical devices from cybersecurity threats cannot be achieved by one government agency alone. Every stakeholder—manufacturers, hospitals, health care providers, cybersecurity researchers and government entities – all have a unique role to play in addressing these modern challenges. That's why the FDA has long been committed to working hard with various stakeholders to stay a step ahead of constantly evolving cybersecurity vulnerabilities. In this way, we can ensure the health care sector is well positioned to proactively respond when cyber vulnerabilities are identified in products that we regulate.

Our Center for Devices and Radiological Health (CDRH) has taken a holistic, systematic approach to building our medical device cybersecurity program, as well as creating an environment where industry and other stakeholders understand the importance of this shared responsibility.

The FDA's work in this area dates back to 2013, when we established the foundations of our medical device cybersecurity program. We created a Cybersecurity Working Group within CDRH that's well-poised to respond to concerns and actively addresses the need for new approaches and new policies. We also established a framework to address cybersecurity regulatory considerations which, taken together, represent our recommendations for product developers at each stage of a product's life cycle.

Our premarket guidance identifies issues manufacturers should consider in the design and development of their medical device to ensure their product adequately addresses cybersecurity vulnerabilities. Our postmarket guidance outlines a risk-based framework manufacturers should use to ensure they can quickly and adequately respond to new cybersecurity threats once a device is in use. The FDA's policy leverages the National Institute for Standards and Technology's Framework for Improving Cybersecurity of Critical Infrastructure. This underscores the importance of adoption by medical device manufacturers of the Framework's five core functions – identify, protect, detect, respond and recover. The FDA does not compartmentalize its premarket and postmarket activities, nor assess them in isolation.

The premarket guidance was finalized in 2014. In the coming weeks, we plan to publish a significant update to that guidance to reflect the FDA's most current understandings of, and recommendations regarding, this evolving space. For instance, the new draft guidance will highlight the utility of providing customers and users with a "cybersecurity bill of materials" – a list of commercial and/or off-the-shelf software and hardware components of a device that could be susceptible to vulnerabilities. Depending on the level of cybersecurity risk associated with a device, this list can be an important resource to help ensure that device customers and users are able to respond quickly to potential threats. We look forward to comments from stakeholders on the updated recommendations and how the FDA can continue to advance our regulatory approach to keep pace with changing cybersecurity risks.

Beyond our own policies, the FDA works proactively to create an environment of shared responsibility with diverse stakeholders, including other government agencies, industry, health care delivery organizations, cybersecurity researchers and others. These collaborations include actions through public-private coordinating councils and engagement directly with industry and patients alike.

Our efforts have yielded tools to advance cybersecurity awareness and readiness. For example, we've supported the development of a tool to help health care delivery organizations (HDOs), such as hospitals, better respond to medical device cybersecurity incidents. Following recent cybersecurity attacks, the FDA recognized a need to close a gap in HDO readiness and response tactics to incidents or exploits affecting medical devices. Today, I'm pleased to announce that the MITRE Corporation, with support from the FDA, released a Medical Device Cybersecurity Regional Incident Preparedness and Response Playbook.  The playbook describes the types of readiness activities that'll enable HDOs to be better prepared for a cybersecurity incident involving their medical devices. These include steps such as developing a medical device inventory and conducting training exercises. The goal is to give product developers more opportunity to address the potential for large scale, multi-patient impact that may raise patient safety concerns. The FDA also developed our own internal playbook to help our staff address cybersecurity threats, vulnerabilities and incidents. Our internal playbook establishes an effective and appropriate incident plan that's flexible and clear. It aims to help the agency respond in a timely manner to medical device cybersecurity attacks – mitigating impacts to devices, health care systems and ultimately, patients.

Another example of our commitment to shared responsibility is our announcement today of two memoranda of understanding with multiple stakeholder groups to create information sharing analysis organizations (ISAOs) — groups of experts that gather, analyze and disseminate important information about cyber threats. As we noted in our post-market cybersecurity guidance, the FDA believes that manufacturers that participate in ISAOs signal they're being proactive in addressing cybersecurity.

In these ISAO forums, manufacturers have the opportunity to share information about potential vulnerabilities and emerging threats. We believe this transparent sharing of information will help manufacturers address issues earlier and result in more protection for patients.

We also recognize that our part in shared responsibility is partnering with other government agencies to strengthen our preparation for and response to cybersecurity threats. This includes discussions with the U.S. Department of Homeland Security (DHS) about executing a memorandum of agreement (MOA) related to our inter-agency work on medical device cybersecurity. We'll share additional details about this MOA in the future, but our goal is to provide a durable framework for coordination and information sharing between the two agencies about medical device cybersecurity vulnerabilities and threats. We believe this type of coordination will lead to more timely and better responses to potential threats to patient safety.

Our partnering also extends to joint cybersecurity exercises that simulate scenarios involving medical device cybersecurity threats. The FDA has been exploring steps to continue building on the work that our stakeholders and the agency have already achieved toward these ends. We based these activities on our evolving experience from engagement with stakeholders, our review of premarket submissions, investigations of device-specific vulnerabilities, and participation in functional and table top exercises simulating medical device cybersecurity threats. These exercises include the DHS-led 'Cracked Domain' functional exercise in 2013, the DHS-Led Capstone National Level Exercise in 2016, AdvaMed's Cybersecurity Summit in 2016, and a MITRE-convened table top on behalf of the FDA in 2017. Most recently, we've also had the opportunity to gain further insight into discovery of device vulnerabilities and to continue cultivating our working relationship with the security researcher community by being present and participating with manufacturers in the DefCon Biohacking Village – Medical Device Hacking Lab in 2018.

Finally, we're taking steps to bring additional resources to the FDA to continue building our medical device cybersecurity program. In the FDA's Fiscal Year 2019 Budget, we proposed to create a Center of Excellence for Digital Health. This Center of Excellence would help establish more efficient regulatory paradigms, consider the building of new capacity to evaluate and recognize third-party certifiers, and support a cybersecurity unit to complement the advances in software-based devices. 

When we issued our Medical Device Safety Action Plan in April, we outlined our vision for how the FDA will continue to enhance our programs and processes to assure the safety of medical devices including advancing medical device cybersecurity. Our actions today, and those we'll take in the coming weeks, build on that effort. We're committed to staying ahead of these risks and unscrupulous cybercriminals who may seek to use cybersecurity vulnerabilities in a way that puts patient lives in danger. In order to protect against these threats and mitigate them when they do emerge, we must be forward leading and nimble. Continuing to proactively address medical device cybersecurity is a key priority for the FDA. We remain fully committed to protecting American patients by fully addressing these emerging threats.

More Information:
FDA: Cybersecurity
FDA: Health Information Sharing & Analysis Center and MedISAO MOU
FDA: Health Information Sharing & Analysis Center and Sensato Critical Infrastructure ISAO MOU

The FDA, an agency within the U.S. Department of Health and Human Services, promotes and protects the public health by, among other things, assuring the safety, effectiveness, and security of human and veterinary drugs, vaccines and other biological products for human use, and medical devices. The agency also is responsible for the safety and security of our nation's food supply, cosmetics, dietary supplements, products that give off electronic radiation, and for regulating tobacco products

Media Inquiries: Stephanie Caccomo, 301-348-1956, [email protected] 
Consumer Inquiries: 888-INFO-FDA

SOURCE U.S. Food and Drug Administration

Related Links

http://www.fda.gov

WANT YOUR COMPANY'S NEWS FEATURED ON PRNEWSWIRE.COM?

icon3
440k+
Newsrooms &
Influencers
icon1
9k+
Digital Media
Outlets
icon2
270k+
Journalists
Opted In
GET STARTED

Modal title

Also from this source

FDA Roundup: March 28, 2025

FDA Roundup: March 28, 2025

Today, the U.S. Food and Drug Administration is providing an at-a-glance summary of news from around the agency: On Thursday, the FDA's Learning and...

FDA Approves Novel Treatment for Hemophilia A or B, with or without Factor Inhibitors

FDA Approves Novel Treatment for Hemophilia A or B, with or without Factor Inhibitors

Today, the U.S. Food and Drug Administration approved Qfitlia (fitusiran) for routine prophylaxis to prevent or reduce the frequency of bleeding...

More Releases From This Source

Explore

Medical Pharmaceuticals

Medical Pharmaceuticals

Pharmaceuticals

Pharmaceuticals

Health Care & Hospitals

Health Care & Hospitals

Biotechnology

Biotechnology

News Releases in Similar Topics

Contact PR Newswire

  • Call PR Newswire at 888-776-0942
    from 8 AM - 9 PM ET
  • Chat with an Expert
  • General Inquiries
  • Editorial Bureaus
  • Partnerships
  • Media Inquiries
  • Worldwide Offices

Products

  • For Marketers
  • For Public Relations
  • For IR & Compliance
  • For Agency
  • All Products

About

  • About PR Newswire
  • About Cision
  • Become a Publishing Partner
  • Become a Channel Partner
  • Careers
  • Accessibility Statement
  • APAC
  • APAC - Simplified Chinese
  • APAC - Traditional Chinese
  • Brazil
  • Canada
  • Czech
  • Denmark
  • Finland
  • France
  • Germany
  • India
  • Indonesia
  • Israel
  • Italy
  • Japan
  • Korea
  • Mexico
  • Middle East
  • Middle East - Arabic
  • Netherlands
  • Norway
  • Poland
  • Portugal
  • Russia
  • Slovakia
  • Spain
  • Sweden
  • United Kingdom
  • Vietnam

My Services

  • All New Releases
  • Platform Login
  • ProfNet
  • Data Privacy

Do not sell or share my personal information:

  • Submit via [email protected] 
  • Call Privacy toll-free: 877-297-8921

Contact PR Newswire

Products

About

My Services
  • All News Releases
  • Platform Login
  • ProfNet
Call PR Newswire at
888-776-0942
  • Terms of Use
  • Privacy Policy
  • Information Security Policy
  • Site Map
  • RSS
  • Cookies
Copyright © 2025 Cision US Inc.