Med-tech trade group launches online cybersecurity tool


Cybersecurity events like 2016’s NotPetya ransomware attack tend to arrive in bursts of confusion and concern, but the hard work of mitigating cybersecurity risks in health care technology is embedded in the daily grind of the medical technology industry, insiders said.

The Food and Drug Administration requires medical device companies to plan for cybersecurity at the earliest stages of design, and to monitor for new vulnerabilities long after devices have been shipped to customers. But industry insiders said companies are uneven in their abilities and willingness to address the issue and talk about it openly, which can hinder progress.

Now the Washington-based medical-technology trade group AdvaMed is creating a new communication tool for med-tech companies known as an “information sharing and analysis organization,” or ISAO (pronounced “I-sow”) that will allow technical-minded med-tech experts to trade tips and analysis of ongoing problems.

News of the ISAO’s impending creation comes as the FDA is finalizing an update to its five-year-old guidance on the things that device makers need to do on the cybersecurity front before asking for permission to market their devices in the U.S.

Known as the “premarket” submission guidance, the 24-page draft of the new rules spells out specific tasks and goals, like working to prevent unauthorized access and protect sensitive data. (Public comments on the guidance before it’s finalized are due on Monday.)

“These documents … don’t merely convey ‘guidance’ that a manufacturer may choose to follow,” Zach Rothstein, vice president of technology and regulatory affairs at AdvaMed, said in a conference call with reporters Thursday. “A manufacturer cannot choose to ignore the documents. If they were to do so, FDA would likely not review the premarket submission, or in the post-market setting FDA could take enforcement action.”

READ  Google says not disclosing the microphone in its Next home security device was an 'error'

Participating in an ISAO is one way a med-tech company can show regulators and the public that it is serious about cybersecurity.

The FDA’s post-market cybersecurity guidance, enacted in 2016, says manufacturers should fix uncontrolled cybersecurity vulnerabilities as quickly as possible, and report them to the FDA. However, if the manufacturer remediates the problem, discloses it to its ISAO, and the vulnerability has not led to death or serious health problems, then the company can avoid reporting the problem to the FDA, under the 2016 rules.

Rothstein said the AdvaMed ISAO will be like a regular online forum, except it will have strong security and its users will be restricted to experts in cybersecurity who have agreed to not share confidential information outside the forum.

The group will help experts compare notes in real time. But it will also serve an important function for smaller companies who may have a hard time affording the cybersecurity competence they need.

“It’s probably no surprise to hear that the smaller the med-device company, the harder it is for them to hire, retain and pay for cybersecurity expertise,” Rothstein said. “Part of what we are using the ISAO to do is to provide that type of education [for] our midsize, smaller-sized companies.”

 

rn{% endblock %}"},"start":"https://users.startribune.com/placement/1/environment/3/limit-signup-optimizely/start"},{"id":"limit-signup","count":12,"action":"ignore","mute":true,"action_config":{"template":"{% extends "grid" %}rnrn{% block heading_text %}Youu2019ve read your 10 free articles for this 30 day period. Sign up now for local coverage you wonu2019t find anywhere else, special sections and your favorite columnists. StarTribune puts Minnesota and the world right at your fingertips. {% endblock %}rnrn{% block last %}rn{{ parent() }}rn{# limit Krux pixel from https://www.squishlist.com/strib/customshop/328/ #}rnrnrn{% endblock %}"},"start":"https://users.startribune.com/placement/1/environment/3/limit-signup/start"},{"id":"meter-desktop-331","count":10,"action":"ignore","mute":false,"action_config":false,"start":"https://users.startribune.com/placement/1/environment/3/meter-desktop-331/start"},{"id":"PDA991499opt","count":9,"action":"ignore","mute":true,"action_config":false,"start":"https://users.startribune.com/placement/1/environment/3/PDA991499opt/start"},{"id":"limit","count":8,"action":"inject","mute":false,"action_config":{"template":"

rnrnrnrn

rn

rn

rn rn

rn t

rn SUBSCRIBErn Already a subscriber? Log in.rn

rn

All Star Tribune readers without a Digital Access subscription are given a limited number of complimentary articles every 30 days. Once the article limit is reached we ask readers to purchase a subscription including Digital Access to continue reading. Digital Access is included in all multi-day paper home delivery, Sunday + Digital, and Premium Digital Access subscriptions. After the 1 month Premium Digital Access introductory period you will be charged at a rate of $14.99 per month. You can see all subscription options or login to an existing subscription herern

rn rn

rn

rn

rn

rn

rn"},"start":"https://users.startribune.com/placement/1/environment/3/limit/start"},{"id":"nag","count":7,"action":"lightbox","mute":true,"action_config":{"height":null,"width":"630px","redirect_on_close":null,"template":"{% extends "shell" %}rnrn{% block substyles %}rn

rn{% endblock %}rnrn{% block page %}rn{#rnrn{{ limit - count - 1 }}rnrn{{ form.flow_form_open({nextAction: 'firstSlide'}, null, null, '_top') }}rn {{ form.btn('Save Now') }}rn{{ form.flow_form_close() }}rnrn

rnrnrnu2022 rnrnrnrn#}rn

rn

rn

You have {{ limit - count - 1 }} articles left

rn

rn rn u00a0u00a0u2022u00a0u00a0rn rn

rn

rn

rn

rn Save More Todayrn

Over 70% off!

rn

rn

rn

rn

99u00a2 for first 4 weeks

rn {{ form.flow_form_open({nextAction: 'firstSlide'}, null, null, '_top') }}rn {{ form.button('Save Now', 'btn nag-btn') }}rn {{ form.flow_form_close() }}rn

rn

rn{% endblock %}rnrn{% block last %}rn{{ parent() }}rnrn{% endblock %}"},"start":"https://users.startribune.com/placement/1/environment/3/nag/start"},{"id":"x","count":4,"action":"ignore","mute":true,"action_config":false,"start":"https://users.startribune.com/placement/1/environment/3/x/start"},{"id":"multi-start","count":3,"action":"fly_in","mute":true,"action_config":{"location":"bottom_left","slide_direction":"bottom","group_id":null,"display_delay":"0","collapse_delay":"10","template":"

rn

rn

rn

rn u00d7rn

rn

rn

From just

rn

$3.79 99u00a2 a week

rn Save nowrn

rn

rn

"},"start":"https://users.startribune.com/placement/1/environment/3/multi-start/start"}]};




READ SOURCE

LEAVE A REPLY

Please enter your comment!
Please enter your name here