Global Medical Device Podcast powered by Greenlight Guru

Cybersecurity and the Future of MedTech


Listen Later

The "Consolidated Appropriations Act of 2023" (more commonly referred to as the Omnibus Act) was passed and signed into law on December 29th, 2022. This amendment to the Food and Drug Cosmetic Act has expanded the scope of the FDA beyond just "safety and efficacy" to include the cybersecurity of medical devices. This amendment resembles a watered-down version of the PATCH Act, which failed to pass in late 2022.

As a result, on March 29, 2023, the FDA gained the legal authority to define and enforce medical device cybersecurity. So for today’s episode, we got THE leading minds in MedTech cybersecurity together to discuss what we need to do next. Chris Gates, Director of Product Security at Velentium, Chris Reed, Vice President of Product Security at Medtronic, and Ken Hoyme, CEO of Dark Star Consulting, join the podcast today to discuss the new guidelines, what the FDA can and can’t say about it, and what kinds of deficiencies you’ll be seeing in the future because of the new legislation.

Some of the highlights of this episode include:
  • How the FDA tried to clear a path for routine patches and updates
  • The minimum that the omnibus bill is talking about
  • No longer needing to make the link between cybersecurity and safety and effectiveness
  • When they have the legal authority to enforce cybersecurity
  • Why the document took so long to go through
  • Security architecture analysis
  • Why you should be referencing the April 2022 draft
  • Unpatched vulnerabilities at the time of submission
  • The effort needed to understand the FDA’s intentions

Memorable quotes from this episode:

“Literally, if you’re not aware of this already, you’re already behind the 8-ball right now and there’s things you’ve got to do.”

“Basically, if you think it might be a cyber device, it is a cyber device.”

“Don’t sit there and try to be pedantic about this and say “I don’t need to do this because there’s a comma here.” It ain’t gonna work for you.”

“A synonym for threat modeling really is security architecture analysis.”

Links:

Christopher Gates

Chris Reed

Ken Hoyme

Velentium

Medtronic

DarkStar Consulting

Medical Device Cybersecurity in 2023 and Beyond Slides

Etienne Nichols LinkedIn

Greenlight Guru


...more
View all episodesView all episodes
Download on the App Store

Global Medical Device Podcast powered by Greenlight GuruBy Greenlight Guru + Medical Device Entrepreneurs

  • 4.8
  • 4.8
  • 4.8
  • 4.8
  • 4.8

4.8

91 ratings


More shows like Global Medical Device Podcast powered by Greenlight Guru

View all
Economist Podcasts by The Economist

Economist Podcasts

4,214 Listeners

WSJ What’s News by The Wall Street Journal

WSJ What’s News

4,334 Listeners

99% Invisible by Roman Mars

99% Invisible

26,178 Listeners

Hidden Brain by Hidden Brain, Shankar Vedantam

Hidden Brain

43,359 Listeners

The Gray Area with Sean Illing by Vox

The Gray Area with Sean Illing

10,663 Listeners

Revisionist History by Pushkin Industries

Revisionist History

59,017 Listeners

The Daily by The New York Times

The Daily

110,759 Listeners

Up First from NPR by NPR

Up First from NPR

55,948 Listeners

Worklife with Adam Grant by TED

Worklife with Adam Grant

9,178 Listeners

Medical Device made Easy Podcast by easymedicaldevice

Medical Device made Easy Podcast

20 Listeners

Fiction - Comedy Fiction by The Sunset Explorers

Fiction - Comedy Fiction

6,447 Listeners

Chasing Life by CNN

Chasing Life

8,224 Listeners

Coaching Real Leaders by Harvard Business Review / Muriel Wilkins

Coaching Real Leaders

649 Listeners

ReThinking by TED

ReThinking

615 Listeners

HBR On Strategy by Harvard Business Review

HBR On Strategy

72 Listeners