FDA Issues Draft Cybersecurity Guidance for Medical Devices
Time 2 Minute Read

On April 8, 2022, the Food and Drug Administration (“FDA”) issued Cybersecurity in Medical Devices: Quality System Considerations and Content of Premarket Submissions, a draft guidance document for industry and FDA staff. Industry stakeholders will have until July 7, 2022 to comment on the proposed guidance.

The FDA developed the draft guidance in response to increasing cybersecurity threats to the healthcare sector and growing use of wireless, Internet- and network-connected medical devices. The draft guidance provides recommendations regarding cybersecurity device design, labeling and documentation with the goal of facilitating an efficient premarket review process and ensuring that marketed medical devices are “sufficiently resilient to cybersecurity threats.”

The FDA previously issued guidance addressing premarket expectations in 2014 and proposed to update this guidance in 2018. The 2022 draft guidance, however, replaces the 2018 version and incorporates input from stakeholders at various public meetings, comments received on the 2018 version and recommendations from the Health Care Industry Cybersecurity Task Force Report. According to the FDA, the guidance “is intended to further emphasize the importance of ensuring that devices are designed securely, are designed to be capable of mitigating emerging cybersecurity risks throughout the Total Product Life Cycle, and to clearly outline [the] FDA's recommendations for premarket submission content to address cybersecurity concerns.”

You May Also Be Interested In

Time 3 Minute Read

On September 12, 2025, the majority of the provisions of the EU Data Act began to apply across EU Member States. The Data Act was formally adopted in November 2023 and entered into force on January 11, 2024.

Time 2 Minute Read

On June 16, 2025, the UK Information Commissioner’s Office published its draft guidance on Internet of Things products and services.

Time 3 Minute Read

On January 24, 2025, the UK Information Commissioner’s Office published a letter setting out proposals to boost business confidence, improve the investment climate, and foster sustainable economic growth in the UK.

Time 3 Minute Read

Last week President Biden issued Executive Order 14144, titled “Strengthening and Promoting Innovation in the Nation’s Cybersecurity,” which aims to strengthen software supply chain security, impose more stringent cybersecurity requirements on federal contractors, combat cybercrime, and encourage the development of identity verification technologies.

Search

Subscribe Arrow

Recent Posts

Categories

Tags

Archives

Jump to Page