FDA eye on medical device software after recall link

The Food and Drug Administration is knuckling down on software quality in medical devices after finding that nearly a quarter of recalls are due to a software failure.

The FDA's Office of Science and Engineering Laboratories will dedicate more time testing software quality and security to reduce the failure rate cited in a 2011 annual report released June 15. The testing increase is needed to prevent injury or death as a result of software that has been poorly designed or written.

In a statement sent to Threatpost, a blog owned by Kaspersky Lab, the FDA said it is developing "techniques and laboratory expertise to assist our review staff in identifying potential vulnerabilities and evaluating risk mitigation measures." The testing procedures being developed are in line with what are used in regulated industries.

An FDA spokesman was unavailable Thursday by phone, but the agency emailed a statement to CSO saying that it continues to "closely monitor [devices] for safety and security problems."

"Manufacturers are responsible for identifying risks and hazards associated with medical device software/firmware, including risks related to security, and are responsible for putting appropriate mitigations in place to address patient safety," the statement said. "Information related to theoretical device security problems is helpful. However, it is very important that the agency receive reports of devices that have had security breaches."

Software within medical devices poses a risk to patient safety, as well as security of personal medical data stored in the devices. The risk has increased, as devices are being designed and operated as special purpose computers. Many of these devices are connected to networks that could be vulnerable to malware attacks.

In 2008, the FDA started building a national electronic safety system designed to monitor the performance of medical devices. The so-called Sentinel Initiative enables the FDA to query electronic healthcare systems, administrative and insurance claims databases and registries to pinpoint possible medical product safety issues. A pilot of the system is currently in use.

Nevertheless, security failures remain a major concern with medical devices. This month, Google reported blocking a malware riddled Web site that distributed software updates for a wide-range of medical equipment. Among the devices receiving updates from the CareFusion Web site was the equipment manufacturer's AVEA Ventilators. A medical ventilator is a machine used to move air in and out of a hospital patient's lungs.

People visiting the CareFusion site ran the risk of downloading malware from any of 20 pages, said the Medical Device Security Center, a nonprofit organization dedicated to the security of medical equipment. Google identified 48 viruses on the CareFusion Web server.

In 2011, computer science researchers at the University of California, Berkeley, the University of Massachusetts, Amherst, and Carnegie Mellon University found several vulnerabilities in an external defibrillator used to regulate a person's heartbeat. "Our assessment demonstrates real vulnerabilities in medical devices and their software and gives a first glimpse into the viability of malware that can be expected in software-based medical devices," the team said in a paper(PDF).

Read more about application security in CSOonline's Application Security section.

Comments are now closed.
CSO Corporate Partners
  • Webroot
  • Trend Micro
  • NetIQ
rhs_login_lockGet exclusive access to CSO, invitation only events, reports & analysis.
CSO Directory

Security Solutions-GigaVUE-2404

Newgen provides innovative network monitoring and security solutions based upon Gigamon’s GigaVUE-2404

Security Awareness Tip

Incident handling is a vast topic, but here are a few tips for you to consider in your incident response. I hope you never have to use them, but the odds are at some point you will and I hope being ready saves you pain (or your job!).


  1. Have an incident response plan.

  2. Pre-define your incident response team 

  3. Define your approach: watch and learn or contain and recover.

  4. Pre-distribute call cards.

  5. Forensic and incident response data capture.

  6. Get your users on-side.

  7. Know how to report crimes and engage law enforcement. 

  8. Practice makes perfect.

For the full breakdown on this article

Security ABC Guides

Warning: Tips for secure mobile holiday shopping

I’m dating myself, but I remember when holiday shopping involved pouring through ads in the Sunday paper, placing actual phone calls from tethered land lines to research product stock and availability, and actually driving places to pick things up. Now, holiday shoppers can do all of that from a smartphone or tablet in a few seconds, but there are some security pitfalls to be aware of.