• Login
    • Join
  • FOLLOW:
  • Subscribe Free
    • Magazine
    • eNewsletter
    Checkout
    • Magazine
    • News
    • Opinions
    • Top 30
    • Research
    • Supply Chain
    • Device Sectors
    • Directory
    • Events
    • Resources
    • Microsites
    • More
  • Magazine
  • News
  • Opinions
  • Top 30
  • Research
  • Supply Chain
  • Device Sectors
  • Directory
  • Events
  • Resources
  • Microsites
  • Current / Back Issues
    Features
    Editorial
    Digital Edition
    eNewsletter Archive
    Our Team
    Editorial Guidelines
    Reprints
    Subscribe Now
    Advertise Now
    Top Features
    MPO's 2023 Medical Device Industry Year in Review

    The Beat Goes On in the Cardiovascular Device Market

    Medical Manufacturers Gain Support from 3D Printing

    The Intelligent Tools Medical Device Manufacturers Already Own

    MPO's 2023 Medtech Supply Chain Survey
    OEM News
    Supplier News
    Service / Press Releases
    Online Exclusives
    Press Releases
    People in the News
    Product & Service Releases
    Supplier News
    Medtech Makers
    Technical Features
    International News
    Videos
    Product & Service Releases
    Live From Shows
    Regulatory
    Financial/Business
    Top News
    MPO's Most-Read Stories This Week—Dec. 9

    Babson Diagnostics’ BetterWay Achieves Regulatory Milestone

    WhiteSwell Successfully Treats Acute Decompensated Heart Failure in Study

    Everly Health Releases At-Home Collection Kidney Health Test

    Kenco Adds Two to its Life Sciences Division Team
    From the Editor
    Blogs
    Guest Opinions
    Top Opinions
    MPO's 2023 Medical Device Industry Year in Review

    The Beat Goes On in the Cardiovascular Device Market

    Medical Manufacturers Gain Support from 3D Printing

    The Intelligent Tools Medical Device Manufacturers Already Own

    MPO's 2023 Medtech Supply Chain Survey
    Top 30 Medical Device Companies
    Market Data
    White Papers
    Top Research
    A Peek Into the 2028 MPO Summit

    Retail Healthcare Disruptors and Medical Devices

    Six Developments Your Talent Strategy Should Prepare for in 2024

    The Power and Paradox of Never

    Navigating the Q-Sub Program: How Experienced Lab Partners Can Help Streamline Regulatory Submission
    3D/Additive Manufacturing
    Contract Manufacturing
    Electronics
    Machining & Laser Processing
    Materials
    Molding
    Packaging & Sterilization
    R&D & Design
    Software & IT
    Testing
    Tubing & Extrusion
    Cardiovascular
    Diagnostics
    Digital Health
    Neurological
    Patient Monitoring
    Surgical
    Orthopedics
    All Companies
    Categories
    Company Capabilities
    Add New Company
    Outsourcing Directory
    maxon

    Qosina Corp.

    Providence Enterprise USA Inc.

    Cirtec Medical

    Poly-Med, Inc.
    MPO Summit
    Industry Events
    Webinars
    Live From Show Event
    Industry Associations
    Videos
    Career Central
    eBook
    Slideshows
    Top Resources
    Telemedicine for Neurology: 5 Benefits of Remote Management

    Machining 101: A Review of Machining Components with a Five-Axis System

    MedTech 2024: Top 5 Trends Shaping a Dynamic Industry

    Early Warning: A Q&A with Abbott's CMO of Heart Failure

    2023 in Review: Medtech's Mega-M&A Is MIA
    Companies
    News Releases
    Product Releases
    Press Releases
    Product Spec Sheets
    Service Releases
    Case Studies
    White Papers
    Brochures
    Videos
    Outsourcing Directory
    maxon

    Qosina Corp.

    Providence Enterprise USA Inc.

    Cirtec Medical

    Poly-Med, Inc.
    • Magazine
      • Current/Back Issues
      • Features
      • Editorial
      • Columns
      • Digital Editions
      • Subscribe Now
      • Advertise Now
    • News
    • Directory
      • All Companies
      • ALL CATEGORIES
      • Industry Associations
      • Company Capabilities
      • Add Your Company
    • Supply Chain
      • 3D/Additive Manufacturing
      • Contract Manufacturing
      • Electronics
      • Machining & Laser Processing
      • Materials
      • Molding
      • Packaging & Sterilization
      • R&D & Design
      • Software & IT
      • Testing
      • Tubing & Extrusion
    • Device Sectors
      • Cardiovascular
      • Diagnostics
      • Digital Health
      • Neurological
      • Patient Monitoring
      • Surgical
      • Orthopedics
    • Top 30 Company Report
    • Expert Insights
    • Slideshows
    • Videos
    • eBook
    • Resources
    • Podcasts
    • Infographics
    • Whitepapers
    • Research
      • White Papers
      • Case Studies
      • Product Spec Sheets
      • Market Data
    • MPO Summit
    • Events
      • Industry Events
      • Live From Show Events
      • Webinars
    • Microsite
      • Companies
      • Product Releases
      • Product Spec Sheets
      • Services
      • White Papers / Tech Papers
      • Press Releases
      • Videos
      • Literature / Brochures
      • Case Studies
    • About Us
      • About Us
      • Contact Us
      • Advertise with Us
      • eNewsletter Archive
      • Privacy Policy
      • Terms of Use
    Columns

    Ready or Not, the FDA’s Cybersecurity Regulation is Here

    The FDA’s recent draft guidance on medical devices with software will require companies’ complete attention.

    Ready or Not, the FDA’s Cybersecurity Regulation is Here
    Florence Joffroy-Black and Dave Sheppard, MedWorld Advisors11.01.23
    Most medtech companies have been under U.S. Food and Drug Administration (FDA) scrutiny since their inception and have become accustomed to the agency’s seeming constant barrage of guidance documents. Consequently, they should not be phased by the FDA’s latest draft guidance for medical devices with software; in fact, medtech firms should embrace it, as it possibly could create significant opportunities for them.

    One of this column’s authors moderated a panel of experts on this topic at last month’s MPO Summit in San Diego. Titled, “Risk or Reward? The Opportunities and Challenges With Digital Medtech,” the panel's speakers featured executives from various backgrounds: Jennifer Samproni, chief technology officer for Health Solutions at Flex; Christopher Gates, director of Product Security at Velentium; and Alex Goryachev, partner at PragmaticAI.

    The panelists agreed the FDA’s draft guidance on medical devices with software will require companies’ complete attention to ensure medical devices are safe and comply with upcoming regulations.

    More background on this topic can be found in the answers to some common questions:
    1. What is the FDA guidance for cybersecurity in 2023? On Sept. 26, the FDA issued its final guidance, “Cybersecurity in Medical Devices: Quality System Considerations and Content of Premarket Submissions.” This document provides recommendations on medical device cybersecurity considerations and the kind of information to include in premarket submissions. (note: “Pre-submission” meetings with the FDA are more important than ever nowadays as market dynamics are rapidly changing).
    2. Why is FDA guidance 524B such big news? Companies may or may not be aware that the “Omnibus” bill Congress passed and President Biden signed into law late last year (“The Consolidated Appropriations Act, 2023”) included a section—524B—“Ensuring Cybersecurity of Devices.”
    3. What does the implementation of 524B mean? It means the FDA is authorized by Congress to regulate cyber devices used in the healthcare industry.
    4. What is considered a cyber device? According to the section 524B(c), a “cyber device” (1) includes software validated, installed, or authorized by the sponsor as a device or in a device; (2) has the ability to connect to the internet; and (3) contains any such technological characteristics validated, installed, or authorized by the sponsor that could be vulnerable to cypersecurity threats.
    5. How can a medtech manufacturer comply with 524b? Starting on March 29, all new FDA premarket submissions must include information about the product. Companies must; (1) submit a plan to monitor, identify, and address postmarket cybersecurity threats; (2) design, develop, and maintain processes and procedures to provide a reasonable assurance that the device and related systems are cybersecure, and make available postmarket updates (patches) to the devices/systems, and (3) provide a software bill of materials (SBOM), including commercial, open-source, and off-the-shelf software components.
    6. What is a software bill of materials? It bears repeating: As mentioned in the preceding paragraph, manufacturers are now required to provide a SBOM (software bill of materials) with their medical device 510(k) submissions. An SBOM is effectively a nested inventory, a list of ingredients that make up software components, according to FDA guidance. An SBOM identifies and lists software components, information about those components, and supply chain relationships between them. The amount and type of information included in a particular SBOM may vary, depending on factors such as the industry or sector and the needs of SBOM consumers. For this initiative, the focus will be on establishing a minimum expectation for creating a baseline SBOM that outlines the minimum amount of information and process required to support basic and essential features. Manufacturers are not (yet) required to disclose the details of their proprietary algorithms.
    7. When must manufacturers comply with 524B? This requirement took effect on March 29.
    8. Does it apply to all medical devices? For now, the requirement is only for new FDA submissions—510(k)s, Pre-Market Approvals, De Novos, etc. Unless there is a known cyber threat issue with a specific product, legacy devices are currently exempt from these new policies.
    9. Anything else of concern? Yes. According to the MPO Summit panelists, the recent FDA draft guidance is a highly dynamic process that will result in more requirements down the road, so it’s important to pay attention to updates on this topic from the FDA and other regulatory experts.
    MPO Summit panelists offered excellent advice on the best ways to tackle these dynamically evolving cybersecurity changes. Some key takeaways from this session follow.
    • Be proactive in addressing cybersecurity in medical products. Don’t wait for the regulators to offer guidance. Medtech manufacturers should be compliant with regulations but also be proactive within their business and with their teams on prioritizing possible cybersecurity threats.
    • Being proactive in tackling cybersecurity within medical devices creates value and can set a company apart from its competitors. Although the entire industry is impacted, only those organizations that embrace this issue as a core competency will put themselves ahead of the game and create a competitive advantage for themselves in the market (and as an employer).
    • It’s not just about cybersecurity, it’s also about an artificial intelligence, big data, and risk management strategy. All of these items are connected.
    • Carefully make revisions to legacy software products. Updating or revising existing solutions requires compliance with the new rules. But the regulation should not stop medtech firms from doing the right thing. On the other hand, organizations should ensure the update is really necessary; if it is, then perhaps it’s time to consider developing a new product altogether. Here’s why: If a company is going to make the effort to provide a cybersecurity update and subject itself to further FDA scrutiny, it might be best served by creating a fresh offering that incorporates the latest advancements as well.
    Ready or not, the FDA is becoming more involved in the vast array of digital medtech solutions being offered by healthcare firms. Proactive companies can turn these digital capabilities into a competitive advantage, which could lead to better value for all stakeholders. 


    Florence Joffroy-Black, CM&AA, is a longtime marketing and M&A expert with significant experience in the medical technology industry, including working for multi-national corporations based in the United States, Germany, and Israel. She currently is CEO at MedWorld Advisors and can be reached at florencejblack@medworldadvisors.com.

    Dave Sheppard, CM&AA, is a former medical technology Fortune 500 executive and is now focused on M&A as a managing director at MedWorld Advisors. He can be reached at davesheppard@medworldadvisors.com.
    Related Searches
    • Software & IT
    Related Knowledge Center
    • Software & IT
      Loading, Please Wait..

      Breaking News
      • MPO's Most-Read Stories This Week—Dec. 9
      • Babson Diagnostics’ BetterWay Achieves Regulatory Milestone
      • WhiteSwell Successfully Treats Acute Decompensated Heart Failure in Study
      • Everly Health Releases At-Home Collection Kidney Health Test
      • Kenco Adds Two to its Life Sciences Division Team
      View Breaking News >
      CURRENT ISSUE

      November 2023

      • MPO's 2023 Medical Device Industry Year in Review
      • The Beat Goes On in the Cardiovascular Device Market
      • Medical Manufacturers Gain Support from 3D Printing
      • The Intelligent Tools Medical Device Manufacturers Already Own
      • View More >

      Cookies help us to provide you with an excellent service. By using our website, you declare yourself in agreement with our use of cookies.
      You can obtain detailed information about the use of cookies on our website by clicking on "More information”.

      • About Us
      • Privacy Policy
      • Terms And Conditions
      • Contact Us

      follow us

      Subscribe
      Nutraceuticals World

      Latest Breaking News From Nutraceuticals World

      Women in Nutraceuticals Hires Executive Director Rebecca Takemoto
      FDA Issues Interim Response to Nammex’s Mushroom Labeling Petition
      MSM Linked to Improvements in Knee Pain
      Coatings World

      Latest Breaking News From Coatings World

      Weekly Recap: PPG, PPG Asian Paints, AkzoNobel Top This Week’s Stories
      Orion S.A. Has Four Carbon Black Plants Awarded ISCC PLUS
      Peninsula Polymers Acquires New Distribution Center in Indiana
      Medical Product Outsourcing

      Latest Breaking News From Medical Product Outsourcing

      MPO's Most-Read Stories This Week—Dec. 9
      Babson Diagnostics’ BetterWay Achieves Regulatory Milestone
      WhiteSwell Successfully Treats Acute Decompensated Heart Failure in Study
      Contract Pharma

      Latest Breaking News From Contract Pharma

      FDA Approves Bio-Thera's Biosimilar Referencing Roche’s Avastin
      Full-Life Technologies to Build GMP Radiopharmaceuticals Mfg. Facility
      Innovent Biologics, Synaffix Expand ADC Licensing Deal
      Beauty Packaging

      Latest Breaking News From Beauty Packaging

      COSRX’s Latest TikTok Campaign Accumulates 3.2B Views on TikTok
      Christian Louboutin Taps Morgane Martini as Global Makeup Artist
      Shiseido Forms New Venture Fund
      Happi

      Latest Breaking News From Happi

      Estée Lauder Lead Scientist Dr. Nadine Pernodet To Lecture At SCC Science Meeting
      Topical Testosterone Formulation for Chest Hair Growth
      New York City Is Hub for Cosmetic Chemistry Next Week
      Ink World

      Latest Breaking News From Ink World

      Weekly Recap: Siegwerk, DIC, and Müller Martini Top This Week’s Stories
      Orion S.A. Now Has Four Carbon Black Plants Awarded ISCC PLUS
      BASF Commits to Scope 3.1 Emissions Targets
      Label & Narrow Web

      Latest Breaking News From Label & Narrow Web

      Analyzing the Russian label market, Carter boosts brands and more
      FLAG’s December Lunch & Learn to feature Omet
      UPM Raflatac releases neuromarketing study findings
      Nonwovens Industry

      Latest Breaking News From Nonwovens Industry

      Ginni Strikes Deal to Sell Spinning, Knitting Operations
      Campen Machinery Announces Patent Pending Status for Airlaid Trays
      Veocel Partners with Beauty and Feminine Care Brands in Asia Pacific
      Orthopedic Design & Technology

      Latest Breaking News From Orthopedic Design & Technology

      ODT's Most-Read Stories This Week—Dec. 9
      Fujitsu, iSurgery Launch Bone Health Promotion Project in Japan
      Wenzel Spine Hires Dr. Robert Gordon as Executive Chairman
      Printed Electronics Now

      Latest Breaking News From Printed Electronics Now

      Weekly Recap: Schreiner MediPharm, GIANCE and PragmatIC Top This Week’s Stories
      Intel CEO Pat Gelsinger to Cover AI During CES 2024 Keynote
      Ciena Invests in US Manufacturing with Flex

      Copyright © 2023 Rodman Media. All rights reserved. Use of this constitutes acceptance of our privacy policy The material on this site may not be reproduced, distributed, transmitted, or otherwise used, except with the prior written permission of Rodman Media.

      AD BLOCKER DETECTED

      Our website is made possible by displaying online advertisements to our visitors.
      Please consider supporting us by disabling your ad blocker.


      FREE SUBSCRIPTION Already a subscriber? Login