FDA Finalizes Guidelines on CyberSecurity and the Usage of Medical Devices
This month the Food and Drug Administration (FDA) has finalized its guidelines on the development of management strategies covering cybersecurity, the use of medical device and requirements for premarket submissions. The document is titled: Content of Premarket Submissions for Management of Cybersecurity in Medical Devices, and is available on the FDA website. The document is essential reading for any medical device manufacturer to ensure future premarket submissions are accepted, and that steps are taken to ensure current medical devices being produced adhere to the new guidelines. The guidelines were prepared to force manufacturers to take the potential risk of cyber attacks into consideration and to incorporate appropriate security measures and safeguards to reduce the risk of susceptibility of attack and of device failure. The FDA identified potential vulnerabilities which could lead to the loss or theft of private data, although the agency has so far not released any information on specific injuries caused by cyber attacks. The presence of spyware/malware on doctors or...
FDA to Address Security Issues and HIPAA Compliance of Older Medical Devices
The FDA is to take action to address problems relating to the cybersecurity of medical devices following complaints from hospitals and healthcare providers that manufacturers of the devices are not being proactive in providing protection against cyber attacks. There has also been criticism of the makers of medical equipment for failing to upgrade older models, meaning threats remain or new equipment must be purchased. The FDA has already commenced a drive to build a more strategic and comprehensive cybersecurity program and has been running workshops to hear about security risks and concerns. The Agency is determined to get manufacturers to build in security controls rather than bolt them on afterwards and is in the process of finalizing its guidelines on pre-market approval procedures, which were first issued in the summer of 2013. The FDA director of Emergency Preparedness/Operations and Medical Countermeasures, Suzanne Schwartz, has stated that new guidance will be released imminently. Debunking Myths There is a common misconception that makers of medical devices have to obtain...
Cedars-Sinai HIPAA Breach Worse than Feared
A member of staff at the Cedars-Sinai Medical Center in Los Angeles, CA, reported the theft of a laptop computer in a home burglary in June this year. That laptop was reported to contain the medical records of “at least 500” individuals; however a forensic analysis has now been conducted that has revealed that the number of affected individuals is actually 33,136. The laptop was password-protected; however passwords can be cracked and they do not offer a sufficient level of protection to safeguard Protected Health Information. While HIPAA Rules do not demand that data must be encrypted – it is only an addressable area in the HIPAA Security Rule – Cedars-Sinai had decided to use data encryption software on all its portable devices. Unfortunately, this particular laptop had recently had operating system updates performed and the encryption software had mistakenly not been reinstalled. As a result, under HIPAA Rules Cedars-Sinai was obliged to send breach notification letters to all affected individuals to advise them that their PHI may have been inappropriately accessed and...
Privacy Protection Strengthened in California
On Tuesday 30th September, California Governor Edmund Brown introduced new legislation to improve the level of privacy protection for California residents. The new set of bills introduced a number of changes to the legislation which included clearer posting of privacy policies on government department websites, together with a requirement for private companies to offer victims of a data security breach services to prevent identity theft and financial loss as a result of the PHI exposure. According to the new legislation, “If the person or business providing the notification was the source of the breach, an offer to provide appropriate identity theft prevention and mitigation services, if any, shall be provided at no cost to the affected person for not less than 12 months, along with all information necessary to take advantage of the offer to any person whose information was or may have been breached if the breach exposed or may have exposed personal information” The new legislation also clarifies the procedures organizations must follow when issuing breach...
Important Information on HIPAA Business Associate Agreements
The Omnibus Rule has now been in effect for a week and is an amendment to HIPAA regulations which requires all Business Associate Agreements to be HIPAA-compliant. Any new BAA’s issued – or those issued after Sept 23, 2014 – must comply with the HIPAA Omnibus Rule; however the same applies to any business agreements already in place. Existing agreements must also be updated to take the new Omnibus Rule into account. If any agreements have not been updated, the HHS’ OCR will consider this a HIPAA violation and would be within its rights to issue a financial penalty for each agreement that does not comply with the new rule. It is therefore essential that healthcare organizations perform a full review of all BAA’s currently active and address any non-compliance issues. Issuing HIPAA Compliant Business Associate Agreements A HIPAA-compliant BAA must be issued and signed by a Business Associate (BA) to ensure that PHI is properly protected. A Business Associate is classed as any individual, company, organization or other entity that performs a function, offers a service or conducts...



