AHA Friday voiced support for the Protecting and Transforming Cyber Health Care Act (S. 3983/H.R. 7084), legislation that would require medical device manufacturers to meet certain cybersecurity requirements when seeking approval for devices that are internet connected or include software. For example, the bill would require medical device manufacturers to monitor and identify post-market vulnerabilities in a timely manner, develop a plan for coordinated vulnerability disclosure, and provide lifetime cybersecurity support of the device. It also would provide a “software bill of materials” for all software contained in the device, including third-party software. 
  
“Manufacturers should be accountable for developing products with appropriate security controls, as well as updating devices as cyber threats continue to evolve,” AHA said in  letters of support to the House and Senate sponsors, Sens. Bill Cassidy, R-La., and Tammy Baldwin, D-Wisc., and Reps. Michael Burgess, R-Texas, and Angie Craig, D-Minn. “We also encourage the inclusion of a provision to clarify that FDA approval of devices would not be jeopardized as manufacturers provide these updates.” 
 

Headline
The White House issued an executive order March 6 to combat cybercrimes by threat groups. The order highlights how such groups can receive willing or…
Headline
The Administration for Strategic Preparedness and Response has released a new cybersecurity module for organizations to conduct risk assessments. The free…
Perspective
Public
As the world has learned in recent years, today’s conflicts are fought with many weapons, and cyber warfare is an integral part of the arsenal.As of this…
Headline
The FBI is reminding critical infrastructure organizations to implement mitigations from a June 2025 fact sheet on potential actions by Iranian-affiliated…
Headline
The Cybersecurity and Infrastructure Security Agency Feb. 26 released a report that updates findings from last year on RESURGE malware used to gain covert…
Headline
U.S. and international agencies Feb. 25 released guidance on protecting Cisco Software-defined Wide-area Networking systems from exploitation by malicious…