AHA Friday voiced support for the Protecting and Transforming Cyber Health Care Act (S. 3983/H.R. 7084), legislation that would require medical device manufacturers to meet certain cybersecurity requirements when seeking approval for devices that are internet connected or include software. For example, the bill would require medical device manufacturers to monitor and identify post-market vulnerabilities in a timely manner, develop a plan for coordinated vulnerability disclosure, and provide lifetime cybersecurity support of the device. It also would provide a “software bill of materials” for all software contained in the device, including third-party software. 
  
“Manufacturers should be accountable for developing products with appropriate security controls, as well as updating devices as cyber threats continue to evolve,” AHA said in  letters of support to the House and Senate sponsors, Sens. Bill Cassidy, R-La., and Tammy Baldwin, D-Wisc., and Reps. Michael Burgess, R-Texas, and Angie Craig, D-Minn. “We also encourage the inclusion of a provision to clarify that FDA approval of devices would not be jeopardized as manufacturers provide these updates.” 
 

Related News Articles

Headline
The FBI, Cybersecurity and Infrastructure Security Agency and Australian Cyber Security Centre June 4 released an advisory on updated actions and tactics used…
Headline
The National Security Agency, Cybersecurity and Infrastructure Security Agency and international partners May 22 released guidance on securing data used for…
Headline
The FBI, along with the National Security Agency and other international cybersecurity agencies, this week released a joint agency advisory on cyber operations…
Headline
The FBI's Internet Crime Complaint Center released an alert May 7 warning of cyber actors exploiting vulnerabilities in end-of-life routers. Routers dated 2010…
Headline
The FBI’s Internet Criminal Complaint Center May 15 released an alert warning of a malicious text and voice messaging campaign involving impersonators…
Headline
In his latest AHA Cyber Intel blog, John Riggi, AHA national advisor for cybersecurity and risk, examines the state of cyber and physical threats in 2025 as…