The FDA is finally doing something about the medical device security dumpster-fire

The problem with public-private partnerships is they’re halfway to regulatory capture from the moment of inception. (That’s not to say we should pre-judge this effort, but rather we should be prepared to judge it.)


Mandating firmware updates is going to get a lot more disquieting as the availability and complexity of neurally interfaced devices increases.


"they may choose to address potential defects by sandboxing or airgapping devices, rather than by updating them "

Not a bad solution. The need for medical devices to be networked may be overrated.


Most critical devices already have a functional air gap design built in. Pacemakers for example have an underlying hardware-only, uneditable set of parameters that are enabled whenever there is a fault or unknown validity of the programmed settings. It can’t be hacked and represents a safe mode of operation. It isn’t ideal for all patients, but it’s safe until they can be seen and the problem diagnosed.

Recently, devices like hemodialysis and infusion pumps have introduced similar designs. These were mandatory changes drafted by industry/clinical working groups and adopted as guidance by FDA.


