Why FDA's New Cyber Device Regs Are a 'Watershed Moment' episode artwork

EPISODE · Apr 18, 2023

Why FDA's New Cyber Device Regs Are a 'Watershed Moment'

from Info Risk Today Podcast · host InfoRiskToday.com

The FDA's new cybersecurity policy is a "watershed moment" for the industry, says Kevin Fu of Northeastern University. The agency will soon begin rejecting manufacturers' new medical device submissions that lack detailed cybersecurity measures, which will help ensure uniformity, he says.

Episode metadata supplied by the publisher feed · Published Apr 18, 2023

Embed this episode

NOW PLAYING

Why FDA's New Cyber Device Regs Are a 'Watershed Moment'

0:00 0:00
of MATCHES

TRANSCRIPT · AUTO-GENERATED

I'm Mary and Colby Seckmiki, executive editor at Information Security Media Group. I'm here with him, talking to Kevin Fu, who is professor at Northeastern University and director of its new Archimedes Center for Healthcare and Medical Device Cybersecurity. Hi Kevin. Hi Marianne.

So Kevin, as you know, the Food and Drug Administration recently announced that medical device makers must include a cybersecurity plan in new products emissions to the agency for pre-market approval. Beginning on October 1st, the FDA will refuse to accept new medical device emissions that don't detail security measures, including a plan to address post-market vulnerabilities and a method for coordinated disclosures of exploits. How significant is this new policy in Hawaii? Yes, well, it's very significant.

And it's not only for medical device approvals, but also for 510k clearances as well. This is really a watershed moment because it's no longer just FDA guidance, which is traditionally non-binding. This is now a federal statute. So this is a federal law, which is very different.

So the Congress has given FDA no option. They said, FDA, you are now required to regulate the medical device security engineering pre-market, as well as post-market. And the new law has a number of very specific pieces of technical language in there. So this is very significant.

But I think it's for the better. And I think many of the leading companies have already been working on these. Now I think this is probably going to accelerate the uniformity of better cybersecurity. And but it will take some time.

And that's why there's a six month, approximately six month period where the FDA is offering sort of an olive branch to help manufacturers who are deficient to come up to speed. And so what do you think will be the impact on medical device makers? Do you think we'll be seeing many makers having to go back to the drawing board in terms of putting more attention on cybersecurity of their products? And are they the sort of the less mature device makers that might be most effective?

Well, whether you go back to the drawing board, I think there's shades of gray. So I think if at the extreme side, if there's a manufacturer who has based their entire security architecture on a perimeter based policy, sort of a yes, no, do you have a firewall, yes, no, do you have a secure hospital network, if their security depends on those kinds of requirements, it could be a flag day for them. I mean, that could be pretty hard for them because they shouldn't have been that in the first place. But I think most manufacturers probably don't have that extreme view of pushing all responsibility on to the health care delivery organization.

I think for the manufacturers who are more common, who have at least some semblance of a security architecture, a notion of not whether the security fails, but how gracefully does it fail? And so I think the manufacturers who are able to answer the question how gracefully does it fail in a coherent and intelligent manner are going to have a much easier time. But those on the extreme side who weren't thinking about security, they're going to have a very quick learning period, I think. And now we've all heard about the scary scenarios involving attacks on medical devices that distargeted attacks on cardiac devices, of VIP patients, and those sorts of things.

But on a day-to-day basis, what are the cyber threats and risks involving medical devices that you're seeing right now that are most worrisome and why? Well, the cybersecurity, medical device, cybersecurity risks that are worrisome to me, I would divide in today and tomorrow. Today, I'm worried about massive outages that's affecting availability. Availability is a type of cybersecurity.

That's something that worries me today. You'll see this with, for instance, the ransomware that brings down an entire health care system. You'll see ransomware that affects entire product lines, especially cloud-based medical devices. There's a single choke point if you have a cloud provider.

If that cloud provider becomes unavailable for various reasons, then that is not safe or effective. Now, looking for the future, one thing that concerns me would be remote programming or remote therapy devices as well as home health care. These are really important things where we can have really innovative therapies and diagnoses. But if we don't get the cybersecurity story right, patients and clinicians are going to lose confidence in the technology.

So what I really hope is that we can have technology that maintains the confidence of the patient and the clinical team. And we know that the security engineering techniques that are coming through these guidance documents that are part of a consensus of a large stakeholder group, we know that this is going to lead to better confidence and safety and effectiveness. And now, how might the FDA's new refuse to accept policy affect medical device makers in countries outside the U.S.? For instance, are there other influential medical device regulatory agencies that have taken similar moves or might consider doing this as far as you know?

Right. Well, the omnibus bill, of course, is purely U.S.-centric. But there is the International Medical Vice Regulators Forum, which shares frameworks for its regulatory policies. So I don't know if every country is going to have their equivalent to the U.S.

Congress implement a law requiring that kind of detail. It's possible. What I do think you're going to see is slowly over time, this much more movement to requiring just on the cybersecurity alone, because it's become just so obvious. It's such an essential ingredient in technology today.

You just have to have that cybersecurity security. Congress, of course, foresaw this, making it, making it law. I predict other countries will follow suit, but perhaps not through their legislative process, but through a regulatory process. I think the FDA's influence being such a large country, and the pressure now on medical device makers to sort of get their acts together could benefit internationally other organizations that use the same products that the American market uses.

Well, as a former IT cog in the IT machine producing, making products in the IT sector, I know one of the things we really liked is being able to make a single product, as opposed to one for every country. So I think, for instance, software bill materials, S-Bombs, those are going to help once you have the S-Bombs. It's going to help a lot in producing S-Bombs in other countries. And frankly, I think it's going to make those devices more competitive, because the larger healthcare delivery organizations are going to be wanting these S-Bombs contractually.

And that's probably going to give them a competitive edge if they're able to satisfy the FDA U.S. regulatory regime on medical security. And finally, Kevin, you recently joined the Northeastern University in Boston and took on the role as Director of the Arch-Media Center for Healthcare and Medical Devices. What sort of interest are you seeing from students and the healthcare community of this new center?

And what is it going? So I am just so happy with the number of students and faculty and manufacturers who've reached out, everything from how can I take your class and medical device security to, hey, I study regulatory affairs, and I would really like to get involved with the cybersecurity side, I'm just really pleased with that. The other thing I think is really interesting is that Northeastern is most known for its co-op program, where the majority of its students go on, you know, six-month co-ops at manufacturers, regulators. And just today, I met one of our Archimedes members, who's a CSO, at a very large medical device manufacturing company, and he pointed out, you know, I went through the Northeastern co-op program and worked at the VA, and that led to his career.

And so it's really happy to see already the full circle going on of students being interested in joining, but also seeing the alums from 10, 20 years ago, coming back saying they're just so thankful of that opportunity. Northeastern has a very different approach to education, being very mission-driven as opposed to method-driven. So it's not, I'm a computer scientist, it's more, I'm helping healthcare, or I'm making medical devices more trustworthy. And then what tools do you need to achieve that?

It might be computer science, it might be electrical engineering, it might be biomedical engineering. And so it's really great to have that interdisciplinary nature and a real hunger to do better for society. And finally, very briefly, Kevin, is there one or two things you're keeping your eye on right now? About medical device cybersecurity, you know, aside from the FDA's recent regulatory changes?

Well, I think what I'm keeping my eye on are the progression of manufacturers. Certainly we do training, and so we're always seeing, you know, waves of different requests for training, things like threat modeling and SBOM and the regulatory affairs aspect. So I'm keeping my eye on that because that to me is a litmus test for the maturity of the manufacturing community, and so I'm pleased to see an uptick, but I know it's not universal. So education and training is something that I am thinking heavily about, as well as co-op programs, because I hear from every manufacturer that they're having difficulty hiring, and so part of my job at Northeastern University is to help develop pipelines, especially with diversity, equity, inclusion, and working with minority-serving institutions to really help provide opportunities to students who don't even realize they could use their gifts to improve healthcare cybersecurity, and we hope to link them to the many employers out there in the U.S.

and the world at large. Well, thanks so much, Kevin. I've been speaking to Professor Kevin Fu. I'm Mary Ann Cobis at McGee of Information Security Media Group.

Thanks for joining us.

No similar episodes found.

No similar podcasts found.

Frequently Asked Questions

When was this Info Risk Today Podcast episode published?

This episode was published on April 18, 2023.

Can I download this Info Risk Today Podcast episode?

Yes. Use the download control on the episode player to save the publisher-provided media file.
URL copied to clipboard!