FDA Appoints Acting Director of Medical Device Security, Signaling Increased Commitment to Medical Device Cybersecurity

Feb 26, 2021

Reading Time : 1 min

Medical device manufacturers can anticipate updated draft guidance on best practices in 2021.  The FDA released previous guidance in October 2018.2  Fu has also outlined his anticipated primary activities as the Acting Director of Medical Device Security during 2021:

  • Envisioning a strategic roadmap for the future state of medical device cybersecurity;
  • Assessing opportunities to fully integrate cybersecurity principles through the lens of the center’s total product life cycle model;
  • Training and mentoring the FDA’s Center for Devices and Radiological Health staff for premarket and postmarket technical review of medical device cybersecurity;
  • Engaging multiple stakeholders across the medical device and cybersecurity ecosystems; and
  • Fostering medtech cybersecurity collaborations across the federal government, including the National Institute of Standards and Technology, National Science Foundation, National Security Agency, Department of Health and Human Services, National Telecommunications and Information Administration, Cybersecurity and Infrastructure Security Agency, Department of Veterans Affairs, Department of Defense, Federal Trade Commission and others.3

Fu has separately urged that entities should involve security experts from the beginning of the design process for a new device and has encouraged companies to bring legacy medtech devices up to speed with the latest cybersecurity protections, explaining that “whether for manufacturers of the Internet of Things or medical devices, we’re not providing the necessary level of security engineering training that companies need.”  Fu noted that the FDA will be working closely with the U.S. Department of Health and Human Services (HHS) and the Cybersecurity and Infrastructure Security Agency (CISA) on sector incident and emergency response.


1https://news.umich.edu/u-m-professor-appointed-to-fda-medical-device-security-post.

2 https://www.fda.gov/regulatory-information/search-fda-guidance-documents/content-premarket-submissions-management-cybersecurity-medical-devices.

3 https://www.natlawreview.com/article/fda-names-first-acting-director-medical-device-cybersecurity.

Share This Insight

© 2024 Akin Gump Strauss Hauer & Feld LLP. All rights reserved. Attorney advertising. This document is distributed for informational use only; it does not constitute legal advice and should not be used as such. Prior results do not guarantee a similar outcome. Akin is the practicing name of Akin Gump LLP, a New York limited liability partnership authorized and regulated by the Solicitors Regulation Authority under number 267321. A list of the partners is available for inspection at Eighth Floor, Ten Bishops Square, London E1 6EG. For more information about Akin Gump LLP, Akin Gump Strauss Hauer & Feld LLP and other associated entities under which the Akin Gump network operates worldwide, please see our Legal Notices page.