Healthcare Cyberattacks: FDA Mandates for 2024

Listen to this article · 8 min listen

A staggering 82% of healthcare organizations experienced a cyberattack in 2023, according to a report by Fortified Health Security. This isn’t just about data breaches. It directly impacts patient safety, device functionality, and the very trust underpinning digital health. Ensuring strong cybersecurity for digital health devices isn’t merely good practice, it’s a non-negotiable mandate, especially when working through stringent FDA compliance requirements. But what do these numbers truly tell us about the path forward?

Key Takeaways

  • The FDA’s 2023 guidance on cybersecurity in medical devices requires manufacturers to submit a Software Bill of Materials (SBOM) for premarket submissions, detailing all software components.
  • Postmarket surveillance for cybersecurity vulnerabilities is now a continuous requirement, mandating proactive monitoring and timely patching for connected health devices.
  • Integrating security by design principles from the earliest stages of device development can reduce remediation costs by up to 30 times compared to fixing issues post-launch.
  • The average cost of a healthcare data breach reached $10.93 million in 2023, underscoring the financial imperative of strong cybersecurity investments.
  • Manufacturers must establish clear incident response plans that align with FDA expectations for reporting and mitigating cybersecurity events impacting patient safety.

82% of Healthcare Organizations Faced Cyberattacks in 2023

The statistic from Fortified Health Security (reported in their 2024 Horizon Report here) is a stark reminder: the healthcare sector remains a prime target for malicious actors. This isn’t just about large hospital systems. It extends directly to manufacturers of digital health devices. Each connected device, from smart insulin pumps to remote patient monitoring systems, represents a potential entry point for attackers. My interpretation of this figure is that the threat surface has expanded exponentially with the proliferation of these devices. Manufacturers often focus on functionality and user experience, sometimes relegating security to a secondary concern, or an afterthought. This approach is no longer tenable. The FDA’s increased scrutiny reflects this reality, pushing for a fundamental shift towards security by design rather than security by afterthought. Companies that fail to integrate strong security from the initial design phase are not just risking regulatory non-compliance, but also significant reputational damage and, critically, patient harm.

The FDA’s 2023 Guidance Mandates SBOMs for Premarket Submissions

The U.S. Food and Drug Administration (FDA) finalized its guidance, “Cybersecurity in Medical Devices: Quality System Considerations and Content of Premarket Submissions,” in September 2023. A key requirement within this guidance is the mandate for manufacturers to submit a Software Bill of Materials (SBOM) for all new device premarket submissions. An SBOM details every software component, including open-source and commercial off-the-shelf (COTS) software, used within a device. This is a big deal. For years, manufacturers could sometimes get away with a black-box approach to their software stack, but those days are over. The FDA rightly recognized that understanding the constituent parts of a device’s software is fundamental to assessing its security posture. From my perspective, this isn’t just an administrative hurdle. It’s an essential step towards transparency and proactive vulnerability management. If a critical vulnerability is discovered in a widely used open-source library, a manufacturer with a complete SBOM can quickly identify which of its devices are affected and initiate remediation. Without it, they’re essentially flying blind, risking widespread exposure and potentially costly, reactive recalls. This also means that supply chain security extends beyond hardware components to every line of code.

Postmarket Surveillance: A Continuous Obligation

Beyond premarket submissions, the FDA’s guidance emphasizes the critical importance of postmarket cybersecurity management. This means that once a digital health device is on the market, the manufacturer’s responsibility for its security doesn’t end. They are expected to continuously monitor for new vulnerabilities, assess their potential impact, and implement timely updates and patches. This is where many companies struggle, particularly those accustomed to a “ship it and forget it” mentality. The digital threat field evolves daily, sometimes hourly. A device deemed secure at launch can become vulnerable months later due to newly discovered exploits or changes in threat actor tactics. The FDA expects manufacturers to have a strong system for vulnerability detection, risk assessment, and coordinated disclosure and remediation. This often involves establishing dedicated cybersecurity teams, implementing automated vulnerability scanning tools, and participating in industry information-sharing forums. Failing to maintain vigilance post-market can lead to enforcement actions, including potential recalls or even civil penalties, making continuous investment in postmarket cybersecurity not just a best practice, but a regulatory necessity.

The Average Cost of a Healthcare Data Breach Hit $10.93 Million in 2023

IBM’s 2023 Cost of a Data Breach Report revealed that the healthcare industry continues to bear the highest average cost per data breach, reaching an astounding $10.93 million. This figure encompasses everything from detection and escalation costs to notification, lost business, and regulatory fines. This statistic, perhaps more than any other, highlights the severe financial implications of inadequate cybersecurity for digital health devices. It’s not just about compliance. It’s about the bottom line. Many smaller to medium-sized digital health device manufacturers mistakenly believe they are too insignificant to be targeted, or that investing heavily in cybersecurity is an unnecessary expense. This is a dangerous misconception. Attackers often target smaller entities as a stepping stone to larger networks or because they perceive them as having weaker defenses. The cost of prevention, while significant, pales in comparison to the potential financial devastation and reputational damage following a major breach. This $10.93 million figure should serve as a wake-up call for any organization still viewing cybersecurity as a cost center rather than a fundamental investment in business continuity and patient trust.

Challenging the Conventional Wisdom: “Compliance Equals Security”

There’s a pervasive, and frankly dangerous, conventional wisdom in the digital health sector that if a device is FDA compliant, it is inherently secure. I strongly disagree with this notion. While FDA compliance provides an important regulatory framework and enforces certain baseline security practices, it is not a guarantee of impenetrable security. Compliance often represents a minimum standard, a snapshot in time reflecting the regulatory understanding at the point of submission or audit. Security, on the other hand, is a dynamic, ongoing process that requires continuous adaptation to a changing threat field. Achieving compliance means you’ve met the stipulated requirements. Achieving security means you are actively defending against sophisticated, adaptive adversaries. Many organizations focus solely on ticking compliance boxes, believing that once they receive FDA clearance, their cybersecurity work is done. This mindset is a critical vulnerability in itself. Real security demands going beyond the checklist, investing in advanced threat intelligence, conducting regular penetration testing that simulates real-world attacks, and fostering a security-aware culture throughout the entire product lifecycle. The FDA sets the floor, but the ceiling of effective cybersecurity is far higher and requires constant effort.

The field of cybersecurity for digital health devices is intricate, demanding constant vigilance and a proactive approach to FDA compliance. Manufacturers must embed security into every stage of development, from initial concept to post-market surveillance, treating it as an ongoing process rather than a one-time achievement. The financial and reputational stakes are too high to do otherwise. For developers, understanding these mandates is key to working through compliance challenges in the evolving tech field. As AI becomes more integrated into healthcare, ensuring secure AI systems will also become paramount for patient data protection.

What is a Software Bill of Materials (SBOM) and why is it important for FDA compliance?

A Software Bill of Materials (SBOM) is a formal, machine-readable inventory of all software components, libraries, and modules used in a digital health device. It’s important for FDA compliance because the FDA’s 2023 guidance mandates its submission for premarket applications, enabling regulators and manufacturers to identify and manage cybersecurity risks associated with third-party software components.

How does the FDA define “reasonable assurance of safety and effectiveness” in the context of device cybersecurity?

The FDA considers cybersecurity an integral part of a device’s safety and effectiveness. “Reasonable assurance” implies that manufacturers have adequately identified, assessed, and mitigated cybersecurity risks throughout the device’s lifecycle to prevent unauthorized access, use, disclosure, disruption, modification, or destruction that could compromise device function, data integrity, or patient safety.

What are the key differences between premarket and postmarket cybersecurity requirements for digital health devices?

Premarket requirements focus on designing security into the device from the outset, including risk assessments, threat modeling, and SBOM submission. Postmarket requirements involve continuous monitoring for new vulnerabilities, implementing timely patches and updates, establishing strong incident response plans, and maintaining transparency with users regarding security posture and updates.

Can a digital health device be recalled due to cybersecurity vulnerabilities?

Yes, the FDA can issue recalls for digital health devices due to cybersecurity vulnerabilities if those vulnerabilities pose a reasonable probability of serious adverse health consequences or death. Manufacturers are expected to address significant vulnerabilities through patches, updates, or, in severe cases, device replacement or recall.

What role do security updates and patches play in maintaining FDA compliance for connected devices?

Security updates and patches are critical for maintaining FDA compliance, as they demonstrate a manufacturer’s commitment to postmarket surveillance and risk management. The FDA expects manufacturers to have processes in place for timely deployment of these updates to address newly discovered vulnerabilities and maintain the device’s secure state throughout its intended lifespan.

Cole Hernandez

Lead Security Architect M.S. Cybersecurity, CISSP, CISM

Cole Hernandez is a Lead Security Architect with fifteen years of dedicated experience fortifying digital infrastructures. Currently, he heads the threat intelligence division at AegisNet Solutions, specializing in advanced persistent threat detection and mitigation. His expertise lies in developing proactive defense strategies against state-sponsored cyber espionage. Hernandez is widely recognized for his groundbreaking work on the 'Quantum Shield' protocol, detailed in his seminal paper published in the Journal of Cyber Warfare