While some devices that can cause fatal injuries, such as insuline pumps or pacemakers, are being actively monitored and recalled by the FDA, it is estimated that all other medical devices have an average of more than 6 vulnerabilities per device and that 40% of devices used by hospitals are at the end-of-life stage and do not have security patches or upgrades available.
Not surprisingly, FDA regulations in this field are lagging with the agency only saying both hospitals and manufacturers are responsible for protecting devices from cyber attacks. Hospitals are pointing fingers at manufacturers for not providing the necessary support and want the FDA to mandate lifetime support of medical devices by manufacturers. So far, the further the FDA went was to publish post-market guidance for medtechs on what they should do to secure their products. This is not enough as hospitals find themselves dealing with thousands of devices that they are supposed not only to track but also patch to prevent cyberattacks. With the ongoing Covid19 crisis, hospitals are unable to handle this task and as a result they become increasingly vulnerable to cyberattacks that could injure or kill patients.
Read more in Medtech Dive