Cybersecurity: Page 3
-
Cybersecurity firm finds vulnerabilities in Baxter’s Sigma infusion pumps
The weaknesses could allow attackers to access Wi-Fi data and make the device unavailable.
By Nick Paul Taylor • Updated Sept. 8, 2022 -
‘Underfunded’ FDA falls short in ensuring medical devices protect against cyberattacks, experts say
Medical device manufacturers argue the agency’s current rules on cybersecurity requirements are too restrictive and should be phased in gradually.
By Elise Reuter • Aug. 11, 2022 -
Q&A
Friday Q&A: FDA’s former medical device cybersecurity director says more investment needed in staffing
The FDA and medtech companies will need more cybersecurity staff to stay ahead of hackers, says Kevin Fu, who is now focused on building that workforce for the government, private sector and academia.
By Elise Reuter • Aug. 5, 2022 -
Lack of payment pathway clarity hinders digital therapeutics, analysts say
The report warns of a sector beset by payment issues, “snake oil” and “middling adoption.”
By Nick Paul Taylor • July 15, 2022 -
DHS warns cybersecurity vulnerabilities in Illumina software could affect test results
Three of the flaws outlined by the Department of Homeland Security received the highest risk score. Vulnerabilities could allow attackers to remotely alter the results generated by Illumina products.
By Nick Paul Taylor • June 6, 2022 -
BD's Pyxis medication dispenser gets fifth DHS cybersecurity alert in 5 years
The company said there are no known public exploits that specifically target a password vulnerability and that it's working to address the problem.
By Nick Paul Taylor • June 1, 2022 -
Employees cause more cyber breaches in healthcare than other industries, report finds
Employees were responsible for 39% of healthcare breaches last year. That's compared to 18% across all industries, according to new Verizon research.
By Rebecca Pifer • May 27, 2022 -
House user-fees bill details clinical trial diversity, cybersecurity requirements
The legislation would let the FDA bring in $1.78 billion in fee revenue from 2023 to 2027 to fund the review of medical devices. That amount could increase to $1.9 billion if the agency meets certain performance goals.
By Elise Reuter • May 10, 2022 -
CDRH's Shuren expects center to return to normal this year despite ongoing COVID work
Jeff Shuren, the director of the FDA's Center for Devices and Radiological Health, also stressed the need for increased cybersecurity and supply chain funding and authority during an event on April 29.
By Ricky Zipp • May 2, 2022 -
Medtech survey finds widespread cybersecurity noncompliance despite rising investment
Over 80% of respondents see device security as a competitive advantage and almost every company budgeted more money for it this year. However, 80% view the issue as a "necessary evil" imposed by regulators.
By Nick Paul Taylor • April 21, 2022 -
FDA official: Draft cybersecurity guidance has 'teeth'
Not following the guidance in premarket submissions means potential delays for device makers, said Suzanne Schwartz, director of CDRH's Office of Strategic Partnerships and Technology Innovation.
By Greg Slabodkin • April 11, 2022 -
Sponsored by Skyflow
Going beyond HIPAA compliance is worthwhile
Just because HIPAA doesn't require the use of data governance technology doesn't mean you can do without it.
April 11, 2022 -
FDA clarifies cybersecurity recommendations for device makers in new guidance
The draft guidance, which replaces a 2018 document, sets recommendations for how medical device companies should approach cybersecurity in premarket submissions and maintaining products throughout their lifecycle.
By Elise Reuter • April 7, 2022 -
Senators drill down on rising user fees, cybersecurity and clinical trial diversity in MDUFA hearing
While Tuesday's Senate hearing did not include FDA officials, lawmakers questioned industry groups as they consider the MDUFA V agreement that would increase the amount the agency can collect in fees from device makers.
By Elise Reuter • April 6, 2022 -
CISA warns about cyber flaw in Philips MRI monitoring software
Philips' e-Alert has a vulnerability that could allow an unauthorized user to remotely shut down the system, the U.S. Cybersecurity and Infrastructure Security Agency said in an advisory.
By Greg Slabodkin • March 30, 2022 -
FDA asks Congress for 14% bump in device budget for supply chain, cybersecurity programs
For the devices program, the FDA is asking for roughly $698 million, with approximately $466 million from the budget authority and $232 million from user fees.
By Nick Paul Taylor • March 29, 2022 -
'On high alert': Hospitals wary of cyber threats from Russia-Ukraine war
Cybersecurity has always been chronically underfunded in hospitals, even before COVID-19 swallowed up more resources. Now, this major international threat is creating a "perfect storm," one cybersecurity expert said.
By Rebecca Pifer • March 21, 2022 -
FDA warns of cyber vulnerabilities in medical device software components
An agency alert warned that flaws in PTC's Axeda agent and desktop server, used in devices from several manufacturers, could allow an unauthorized attacker to take full control of the host operating system.
By Greg Slabodkin • March 9, 2022 -
75% of infusion pumps have cyber flaws, putting them at risk from hackers: study
An analysis of more than 200,000 infusion pumps, using crowd-sourced data supplied by healthcare organizations, found about half were susceptible to "critical" and "high" severity cybersecurity vulnerabilities.
By Greg Slabodkin • March 3, 2022 -
Deep Dive
Medtech, hospitals on alert for cyberattacks after Russia's invasion of Ukraine
While cybersecurity threats to healthcare and medical devices have grown during the pandemic, the Russia-Ukraine conflict has raised the threat level, putting patient safety at risk.
By Greg Slabodkin • Feb. 28, 2022 -
Cybersecurity leads ECRI's list of top medtech hazards for 2022
Cyber incidents can compromise patient care and attacks against hospitals have become more prevalent in recent years. However, ECRI said the worst consequences are preventable.
By Elise Reuter • Jan. 18, 2022 -
FDA warns about Log4j cybersecurity vulnerabilities in medical devices
The bugs in Apache's Java-based open source logging library could potentially allow unauthorized users to remotely impact the safety and effectiveness of device functionality, according to the agency.
By Greg Slabodkin • Dec. 20, 2021 -
Deep Dive
Medical device security continues to be casualty of hospital-medtech divide
FDA says manufacturers and hospitals are both responsible for protecting devices from growing cybersecurity threats. However, experts say healthcare providers carry a much heavier load.
By Greg Slabodkin • Dec. 1, 2021 -
Cyber playbook sets out strategies for modeling threats to medical devices
The FDA-funded guide arrives against a backdrop of calls from the agency for the medtech industry to step up its threat modeling throughout the device lifecycle in order to strengthen cybersecurity and patient safety.
By Nick Paul Taylor • Dec. 1, 2021 -
Siemens software vulnerabilities potentially put millions of medical devices at risk
A U.S. cybersecurity agency issued an alert about the vulnerabilities which could allow hackers to disrupt the operation of anesthesia machines and bedside monitors from multiple manufacturers.
By Nick Paul Taylor • Nov. 11, 2021