fbpx
1-888-310-4540 (main) / 1-888-707-6150 (support) info@spkaa.com
Select Page

Four Steps to Securing Your Company’s Medical Devices

Four Steps to Securing Your Company’s Medical Devices
Published by Mike Solinap
on November 7, 2018

Connected medical devices offer enormous opportunity for manufacturers and consumers alike. They also carry the burden of increased risk due to cybersecurity flaws. Think about the dangers of having your email or bank account hacked. Now consider the damage hacking a connected medical device or the information stored from it can do.

Medical information is some of the most sensitive information most people have. However, it’s not just the potential consequences of a database hack users of connected devices need to worry about. It’s also the spectre of an attack on the device itself — an attack that could easily be deadly.

Current FDA Guidelines

There’s already FDA guidelines for connected medical devices, most recently updated in October 2018 with its Medical Device Cybersecurity Playbook developed with Mitre. The guidance seeks to prevent both unauthorized access to data and protect the security of the device itself. There are a number of steps to protect end users, as well as company reputation:

  • Identification: Threats and vulnerabilities to assets should be identified prior to manufacturing a device.
  • Assessment: Both the impact of a threat and the likelihood of a threat must be assessed.
  • Design: Balancing risk against mitigation, you must design a device meeting FDA standards to protect your end users.
  • Monitoring: Your company must also monitor potential threats after the device goes to market to ensure the continued safety of the device.

Medical device security isn’t an abstract problem. In October 2018, Medtronic Plc disabled all downloadable updates to connected pacemakers citing security issues. On a wider scale, the British National Health Service was effectively crippled by the WannaCry ransomware in April of the same year. Former Vice President Dick Cheney had his pacemaker disabled for fear of a hack.

It’s worth noting that every point of connectivity in a medical device is a potential place for hackers to access a device. This is why the FDA has stringent standards for connected devices. In our next blog post we will discuss what to expect when going through your 510k approval process.

Next Steps

Latest White Papers

How CloudBees Uses Feature Management to Gain Competitive Advantage

How CloudBees Uses Feature Management to Gain Competitive Advantage

In this whitepaper, you’ll discover how CloudBees Feature Management Flags can help you gain a competitive advantage in the market.  Discover CloudBees Feature Management In this CloudBees Feature flag whitepaper, you’ll learn: How to increase your developer...

Related Resources

Salesforce Migrates DevOps to the Cloud with CloudBees CI

Salesforce Migrates DevOps to the Cloud with CloudBees CI

Industry:  Software Geography: Global Salesforce empowers software developers to create high-quality, secure enterprise apps on its Force.com platform by moving development operations to the cloud using CloudBees CI and Amazon EKS. Challenge: Migrate app development...

Atlassian News Q1 2023 and What To Expect at Atlassian Team 23

Atlassian News Q1 2023 and What To Expect at Atlassian Team 23

In 2023, Atlassian continues to evolve with new product features, target markets and demographics. This is keeping their leader status for collaboration and productivity tools. Atlassian software is used by thousands of companies worldwide to manage projects, track...

Moving Code Corp to the Atlassian Cloud

Moving Code Corp to the Atlassian Cloud

Code Corp has around 250 users of their Atlassian suite and specializes in high-performance barcode readers and scanning software. This hardware and software provide data capture for many different industries and use cases. Additionally, they power track-and-trace...