GAO says: Revise FDA cyber deal to update medical devices.

December 28, 2023
1 min read

The Government Accountability Office (GAO) has recommended that the Food and Drug Administration (FDA) update its five-year-old medical device cybersecurity agreement with the Cybersecurity and Infrastructure Security Agency (CISA). The update is necessary to address cybersecurity vulnerabilities in heart monitors and other medical devices. While the FDA has increased its oversight of medical device cybersecurity, it has not determined additional cybersecurity authorities, according to the GAO. The FDA and CISA have accepted the GAO’s recommendations.

The GAO notes that available data on cybersecurity incidents in hospitals do not show that medical device vulnerabilities have been commonly exploited. However, the Department of Health and Human Services (HHS) still considers medical devices a source of cybersecurity concern that warrants significant attention and can introduce threats to hospital cybersecurity. The GAO’s recommendation for an updated agreement reflects the need to proactively address potential vulnerabilities and protect patient safety.

Latest from Blog

Bridging the cyber talent gap: tips for CISOs

TLDR: – Global cyber threats have increased twofold in recent years, leading to a talent gap of nearly 4 million cyber professionals worldwide. – Existing cyber staff are under strain, with vacancies

North Korean hackers pivot to ransomware attacks

TLDR: North Korean hackers from APT45 have shifted from cyber espionage to ransomware attacks APT45 has targeted critical infrastructure and is linked to ransomware families SHATTEREDGLASS and Maui A North Korea-linked threat