FDA is reviewing comments on its proposed cybersecurity guidance for medical devices. The FDA’s draft post-market cybersecurity guidance issued last January recommends that medical device manufacturers “address cybersecurity throughout the product lifecycle” The draft guidance emphasizes that manufacturers should monitor, identify and address cybersecurity vulnerabilities and exploits. An expert says the draft guidance has several weaknesses, including patching and unauthentic software updates. The College of Healthcare Information Management Executives recommends that the FDA and the Department of Health and Human Services’ Office for Civil Rights work together to coordinate their implementation guidance.”]
Source: https://www.govinfosecurity.com/critiquing-fda-medical-device-cybersecurity-guidance-a-9200