Postmarket surveillance is a crucial aspect of medical device safety and cybersecurity risk management. It is the primary means of gathering information about how your device performs in the real world so you can make improvements that deliver better diagnoses or therapies. The customer feedback process is a key entry point for field performance information into the quality management system.
US FDA requires a “cybersecurity management plan” be included in premarket submissions for medical devices (“Cybersecurity in Medical Devices: Quality System Considerations and Content of Premarket Submissions”) and provides guidance for creating an effective postmarket cybersecurity program (“Postmarket Management of Cybersecurity in Medical Devices”). The Medical Device Coordination Group provides similar guidance for postmarket surveillance and vigilance as part of their MDCG 2019-16 guidance (“Guidance on Cybersecurity for medical devices”) fulfilling security and postmarket surveillance requirements of the European Union’s Medical Device Regulation (2017/745) or In Vitro Diagnostic Regulation (2017/746).
The common goals of the postmarket surveillance system include:
Effective postmarket cybersecurity surveillance requires processes in place to monitor emerging threats and vulnerabilities. While this can be done in-house, it requires significant information technology and manpower resources to keep up with the rapidly evolving threat landscape. There are some automated solutions, and vendors are available to help you monitor your SBOM for new vulnerabilities and issue appropriate patches.
You can leverage existing quality management system elements to implement your cybersecurity postmarket surveillance system.
The above is not a comprehensive list of cybersecurity touchpoints throughout the medical device quality management system. Hopefully, it provides a starting point for you to think through the implications of securing your medical devices throughout their entire product life cycle including after product launch.
References
Cybersecurity in Medical Devices: Quality System Considerations and Content of Premarket Submissions, US Food & Drug Administration, September 27, 2023.
Postmarket Management of Cybersecurity in Medical Devices, US Food & Drug Administration, December 28, 2016.
MDCG 2019-16 Rev.1, Guidance on Cybersecurity for medical devices, Medical Device Coordination Group, July, 2020.
2017/745, REGULATION (EU) 2017/745 OF THE EUROPEAN PARLIAMENT AND OF THE COUNCIL of 5 April 2017 on medical devices, amending Directive 2001/83/EC, Regulation (EC) No 178/2002 and Regulation (EC) No 1223/2009 and repealing Council Directives 90/385/EEC and 93/42/EEC.
2017/746, REGULATION (EU) 2017/746 OF THE EUROPEAN PARLIAMENT AND OF THE COUNCIL of 5 April 2017 on in vitro diagnostic medical devices and repealing Directive 98/79/EC and Commission Decision 2010/227/EU.
IMDRF Terminologies for Categorizing Adverse Event Reporting, International Medical Device Regulators Forum, https://www.imdrf.org/consultations/imdrf-terminologies-categorized-adverse-event-reporting-terms-terminology-and-codes.
Gregg Van Citters – Senior Software Quality Engineer