Pub. L. 117-328, div. FF, tit. III, subtit. C, sec. 3305

ENSURING CYBERSECURITY OF MEDICAL DEVICES.

EnactedYear: 2022Length: 847 wordsOfficial source
SEC. 3305. ENSURING CYBERSECURITY OF MEDICAL DEVICES.(a) In General.—Subchapter A of chapter V of the Federal Food, Drug, and Cosmetic Act (21 U.S.C. 351 et seq.) is amended by adding at the end the following:“SEC. 524B. ENSURING CYBERSECURITY OF DEVICES.“(a) In General.—A person who submits an application or submission under section 510(k), 513, 515(c), 515(f), or 520(m) for a device that meets the definition of a cyber device under this section shall include such information as the Secretary may require to ensure that such cyber device meets the cybersecurity requirements under subsection (b).136 STAT. 5833 “(b) Cybersecurity Requirements.—The sponsor of an application or submission described in subsection (a) shall—“(1) submit to the Secretary a plan to monitor, identify, and address, as appropriate, in a reasonable time, postmarket cybersecurity vulnerabilities and exploits, including coordinated vulnerability disclosure and related procedures; “(2) design, develop, and maintain processes and procedures to provide a reasonable assurance that the device and related systems are cybersecure, and make available postmarket updates and patches to the device and related systems to address—“(A) on a reasonably justified regular cycle, known unacceptable vulnerabilities; and “(B) as soon as possible out of cycle, critical vulnerabilities that could cause uncontrolled risks; “(3) provide to the Secretary a software bill of materials, including commercial, open-source, and off-the-shelf software components; and “(4) comply with such other requirements as the Secretary may require through regulation to demonstrate reasonable assurance that the device and related systems are cybersecure. “(c) Definition.—In this section, the term ‘cyber device’ means a device that—“(1) includes software validated, installed, or authorized by the sponsor as a device or in a device; “(2) has the ability to connect to the internet; and “(3) contains any such technological characteristics validated, installed, or authorized by the sponsor that could be vulnerable to cybersecurity threats. “(d) Exemption.—The Secretary may identify devices, or categories or types of devices, that are exempt from meeting the cybersecurity requirements established by this section and regulations promulgated pursuant to this section. The Secretary shall publish in the Federal Register, and update, as appropriate, a list of the devices, or categories or types of devices, so identified by the Secretary.” . (b) Prohibited Act.—Section 301(q) of the Federal Food, Drug, and Cosmetic Act (21 U.S.C. 331(q)) is amended by adding at the end the following:“(3) The failure to comply with any requirement under section 524B(b)(2) (relating to ensuring device cybersecurity).” . (c) Rule of Construction.—Nothing in this section, including the amendments made by this section, shall be construed to affect the Secretary’s authority related to ensuring that there is a reasonable assurance of the safety and effectiveness of devices, which may include ensuring that there is a reasonable assurance of the cybersecurity of certain cyber devices, including for devices approved or cleared prior to the date of enactment of this Act. (d) Effective Date.—The amendments made by subsections (a) and (b) shall take effect 90 days after the date of enactment of this Act. An application or submission submitted before such effective date shall not be subject to the requirements under subsection (a) or (b) of section 524B of the Federal Food, Drug, and Cosmetic Act, as added by this section. (e) Guidance for Industry and FDA Staff on Device Cybersecurity.—Not later than 2 years after the date of enactment of this Act, and periodically thereafter as appropriate, the Secretary, 136 STAT. 5834 in consultation with the Director of the Cybersecurity and Infrastructure Security Agency, shall review and, as appropriate and after soliciting and receiving feedback from device manufacturers, health care providers, third-party-device servicers, patient advocates, and other appropriate stakeholders, update the guidance entitled “Content of Premarket Submissions for Management of Cybersecurity in Medical Devices” (or a successor document). (f) Resources Regarding Cybersecurity of Devices.—Not later than 180 days after the date of enactment of this Act, and not less than annually thereafter, the Secretary shall update public information provided by the Food and Drug Administration, including on the website of the Food and Drug Administration, with information regarding improving cybersecurity of devices. Such information shall include information on identifying and addressing cyber vulnerabilities for health care providers, health systems, and device manufacturers, and how such entities may access support through the Cybersecurity and Infrastructure Security Agency and other Federal entities, including the Department of Health and Human Services, to improve the cybersecurity of devices. (g) GAO Report.—Not later than 1 year after the date of enactment of this Act, the Comptroller General of the United States shall publish a report identifying challenges in cybersecurity for devices, including legacy devices that may not support certain software security updates. Through such report, the Comptroller General shall examine—(1) challenges for device manufacturers, health care providers, health systems, and patients in accessing Federal support to address vulnerabilities across Federal agencies; (2) how Federal agencies can strengthen coordination to better support cybersecurity for devices; and (3) statutory limitations and opportunities for improving cybersecurity for devices. (h) Definition.—In this section, the term “device” has the meaning given such term in section 201(h) of the Federal Food, Drug, and Cosmetic Act (21 U.S.C. 321(h)).
Pub. L. 117-328, div. FF, tit. III, subtit. C, sec. 3305: ENSURING CYBERSECURITY OF MEDICAL DEVICES. | Justis AI