Myth
Applying security updates and patches to FDA-regulated systems involves making onerous changes requiring FDA approval and paperwork; hence, incorporating such updates and patches into business processes is difficult and cumbersome.
Applying security updates and patches to FDA-regulated systems involves making onerous changes requiring FDA approval and paperwork; hence, incorporating such updates and patches into business processes is difficult and cumbersome.
The FDA views security for medical devices and their associated communication networks as a shared responsibility between medical device manufacturers and medical device user facilities. The proper maintenance of security for medical devices and hospital networks is vitally important to public health because it ensures the integrity of the computer networks that support medical devices. While updates or patches may still require internal validation and approvals, the FDA itself does not need to grant such approval.
The FDA has further clarified its interpretation of the appropriate regulations in the following documents:
In summary, the FDA emphasizes: