2013年6月19日 星期三

FDA提醒醫儀相關資安考量問題及建議預防措施

(http://bme.freebbs.tw 醫學工程論壇 同步發表)

Cybersecurity for Medical Devices and Hospital Networks: FDA Safety Communication

Posted 06/17/2013]

AUDIENCE: Biomedical Engineering, Health Professional, Risk Manager


ISSUEFDA is recommending that medical device manufacturers and health care facilities take steps to assure that appropriate safeguards are in place to reduce the risk of failure due to cyberattack, which could be initiated by the introduction of malware into the medical equipment or unauthorized access to configuration settings in medical devices and hospital networks.
Recently, the FDA has become aware of cybersecurity vulnerabilities and incidents that could directly impact medical devices or hospital network operations (refer to the FDA Safety Communication for examples). FDA is not aware of any patient injuries or deaths associated with these incidents nor do we have any indication that any specific devices or systems in clinical use have been purposely targeted at this time.
FDA has been working closely with other federal agencies and manufacturers to identify, communicate and mitigate vulnerabilities and incidents as they are identified. FDA also released a draft guidance on how manufacturers should address cybersecurity in their pre-market submissions, as well as guidance on how manufacturers should address cybersecurity issues related to products that use off-the-shelf software.


BACKGROUND: Many medical devices contain configurable embedded computer systems that can be vulnerable to cybersecurity breaches. In addition, as medical devices are increasingly interconnected, via the Internet, hospital networks, other medical device, and smartphones, there is an increased risk of cybersecurity breaches, which could affect how a medical device operates.


RECOMMENDATION: The FDA is recommending that you take steps to evaluate your network security and protect your hospital system. In evaluating network security, hospitals and health care facilities should consider:

  • Restricting unauthorized access to the network and networked medical devices.
    限制未經授權存取院內網路和己連線網路的醫療設備。
  • Making certain appropriate antivirus software and firewalls are up-to-date.
    適時更新防毒軟體及防火牆
  • Monitoring network activity for unauthorized use.
    監控未經授權使用的網絡活動。
  • Protecting individual network components through routine and periodic evaluation, including updating security patches and disabling all unnecessary ports and services.
    經由日常和定期評估來保護個人網路組件,包括更新安全修補,並禁用電腦上所有不必要的端口和服務。
  • Contacting the specific device manufacturer if you think you may have a cybersecurity problem related to a medical device. If you are unable to determine the manufacturer or cannot contact the manufacturer, the FDA and DHS ICS-CERT may be able to assist in vulnerability reporting and resolution.
    如果你認為你可能有一個與醫療設備相關的網路安全問題請聯繫該設備製造商。 如果您無法確定製造商或無法聯繫製造商,FDA和美國國土安全部ICS-CERT可能能夠幫助脆弱性報告和決議。
  • Developing and evaluating strategies to maintain critical functionality during adverse conditions.
    評估並發展相關因應策略,以能在不利條件下主要關鍵功能仍能持續運作。
Healthcare professionals and patients are encouraged to report adverse events or side effects related to the use of these products to the FDA's MedWatch Safety Information and Adverse Event Reporting Program:
  • Complete and submit the report Online: www.fda.gov/MedWatch/report.htm
  • Download form or call 1-800-332-1088 to request a reporting form, then complete and return to the address on the pre-addressed form, or submit by fax to 1-800-FDA-0178
[06/13/2013 - FDA Safety Communication - FDA]
[06/14/2014 - Cybersecurity in Medical Devices - Draft Guidance - FDA]

沒有留言: