So, a big of tech legislation seems to have been missed… and thanks to Stacey on IOT for this. In the end-of-the-year spending bill, some new rules exist around connected medical devices.
Quoting from the blog, The law requires that any medical device that is connected to the internet get pre-market approval before being released to the public. It also requires several other security practices, such as a software bill of materials. But the most notable part of the law is that a company can’t sell a connected medical device without first showing it to the Food and Drug Administration and proving that, should any security vulnerabilities arise, it has plans to monitor, update, and fix the device.
That’s a big deal – the FDA can enforce security standards, and devices have to be shown to be able to monitor, update and fix devices ongoing. That’s a significantly higher bar than before and moves from self-enforcement to government enforcement. Expect to see more of this.
