Artwork

Greenlight Guru + Medical Device Entrepreneurs에서 제공하는 콘텐츠입니다. 에피소드, 그래픽, 팟캐스트 설명을 포함한 모든 팟캐스트 콘텐츠는 Greenlight Guru + Medical Device Entrepreneurs 또는 해당 팟캐스트 플랫폼 파트너가 직접 업로드하고 제공합니다. 누군가가 귀하의 허락 없이 귀하의 저작물을 사용하고 있다고 생각되는 경우 여기에 설명된 절차를 따르실 수 있습니다 https://ko.player.fm/legal.
Player FM -팟 캐스트 앱
Player FM 앱으로 오프라인으로 전환하세요!

Cybersecurity and the Future of MedTech

1:12:35
 
공유
 

Manage episode 374949593 series 3504807
Greenlight Guru + Medical Device Entrepreneurs에서 제공하는 콘텐츠입니다. 에피소드, 그래픽, 팟캐스트 설명을 포함한 모든 팟캐스트 콘텐츠는 Greenlight Guru + Medical Device Entrepreneurs 또는 해당 팟캐스트 플랫폼 파트너가 직접 업로드하고 제공합니다. 누군가가 귀하의 허락 없이 귀하의 저작물을 사용하고 있다고 생각되는 경우 여기에 설명된 절차를 따르실 수 있습니다 https://ko.player.fm/legal.

The "Consolidated Appropriations Act of 2023" (more commonly referred to as the Omnibus Act) was passed and signed into law on December 29th, 2022. This amendment to the Food and Drug Cosmetic Act has expanded the scope of the FDA beyond just "safety and efficacy" to include the cybersecurity of medical devices. This amendment resembles a watered-down version of the PATCH Act, which failed to pass in late 2022.

As a result, on March 29, 2023, the FDA gained the legal authority to define and enforce medical device cybersecurity. So for today’s episode, we got THE leading minds in MedTech cybersecurity together to discuss what we need to do next. Chris Gates, Director of Product Security at Velentium, Chris Reed, Vice President of Product Security at Medtronic, and Ken Hoyme, CEO of Dark Star Consulting, join the podcast today to discuss the new guidelines, what the FDA can and can’t say about it, and what kinds of deficiencies you’ll be seeing in the future because of the new legislation.

Some of the highlights of this episode include:

  • How the FDA tried to clear a path for routine patches and updates
  • The minimum that the omnibus bill is talking about
  • No longer needing to make the link between cybersecurity and safety and effectiveness
  • When they have the legal authority to enforce cybersecurity
  • Why the document took so long to go through
  • Security architecture analysis
  • Why you should be referencing the April 2022 draft
  • Unpatched vulnerabilities at the time of submission
  • The effort needed to understand the FDA’s intentions

Memorable quotes from this episode:

“Literally, if you’re not aware of this already, you’re already behind the 8-ball right now and there’s things you’ve got to do.”

“Basically, if you think it might be a cyber device, it is a cyber device.”

“Don’t sit there and try to be pedantic about this and say “I don’t need to do this because there’s a comma here.” It ain’t gonna work for you.”

“A synonym for threat modeling really is security architecture analysis.”

Links:

Christopher Gates

Chris Reed

Ken Hoyme

Velentium

Medtronic

DarkStar Consulting

Medical Device Cybersecurity in 2023 and Beyond Slides

Etienne Nichols LinkedIn

Greenlight Guru

  continue reading

350 에피소드

Artwork
icon공유
 
Manage episode 374949593 series 3504807
Greenlight Guru + Medical Device Entrepreneurs에서 제공하는 콘텐츠입니다. 에피소드, 그래픽, 팟캐스트 설명을 포함한 모든 팟캐스트 콘텐츠는 Greenlight Guru + Medical Device Entrepreneurs 또는 해당 팟캐스트 플랫폼 파트너가 직접 업로드하고 제공합니다. 누군가가 귀하의 허락 없이 귀하의 저작물을 사용하고 있다고 생각되는 경우 여기에 설명된 절차를 따르실 수 있습니다 https://ko.player.fm/legal.

The "Consolidated Appropriations Act of 2023" (more commonly referred to as the Omnibus Act) was passed and signed into law on December 29th, 2022. This amendment to the Food and Drug Cosmetic Act has expanded the scope of the FDA beyond just "safety and efficacy" to include the cybersecurity of medical devices. This amendment resembles a watered-down version of the PATCH Act, which failed to pass in late 2022.

As a result, on March 29, 2023, the FDA gained the legal authority to define and enforce medical device cybersecurity. So for today’s episode, we got THE leading minds in MedTech cybersecurity together to discuss what we need to do next. Chris Gates, Director of Product Security at Velentium, Chris Reed, Vice President of Product Security at Medtronic, and Ken Hoyme, CEO of Dark Star Consulting, join the podcast today to discuss the new guidelines, what the FDA can and can’t say about it, and what kinds of deficiencies you’ll be seeing in the future because of the new legislation.

Some of the highlights of this episode include:

  • How the FDA tried to clear a path for routine patches and updates
  • The minimum that the omnibus bill is talking about
  • No longer needing to make the link between cybersecurity and safety and effectiveness
  • When they have the legal authority to enforce cybersecurity
  • Why the document took so long to go through
  • Security architecture analysis
  • Why you should be referencing the April 2022 draft
  • Unpatched vulnerabilities at the time of submission
  • The effort needed to understand the FDA’s intentions

Memorable quotes from this episode:

“Literally, if you’re not aware of this already, you’re already behind the 8-ball right now and there’s things you’ve got to do.”

“Basically, if you think it might be a cyber device, it is a cyber device.”

“Don’t sit there and try to be pedantic about this and say “I don’t need to do this because there’s a comma here.” It ain’t gonna work for you.”

“A synonym for threat modeling really is security architecture analysis.”

Links:

Christopher Gates

Chris Reed

Ken Hoyme

Velentium

Medtronic

DarkStar Consulting

Medical Device Cybersecurity in 2023 and Beyond Slides

Etienne Nichols LinkedIn

Greenlight Guru

  continue reading

350 에피소드

Όλα τα επεισόδια

×
 
Loading …

플레이어 FM에 오신것을 환영합니다!

플레이어 FM은 웹에서 고품질 팟캐스트를 검색하여 지금 바로 즐길 수 있도록 합니다. 최고의 팟캐스트 앱이며 Android, iPhone 및 웹에서도 작동합니다. 장치 간 구독 동기화를 위해 가입하세요.

 

빠른 참조 가이드

탐색하는 동안 이 프로그램을 들어보세요.
재생