Security and Privacy Qualities of Medical Devices: An Analysis of FDA Postmarket Surveillance

被引:34
|
作者
Kramer, Daniel B. [1 ]
Baker, Matthew [1 ]
Ransford, Benjamin [2 ]
Molina-Markham, Andres [2 ]
Stewart, Quinn [2 ]
Fu, Kevin [2 ]
Reynolds, Matthew R. [1 ]
机构
[1] Harvard Univ, Beth Israel Deaconess Med Ctr, Dept Med, Sch Med, Boston, MA 02215 USA
[2] Univ Massachusetts, Dept Comp Sci, Amherst, MA 01003 USA
来源
PLOS ONE | 2012年 / 7卷 / 07期
基金
美国国家科学基金会;
关键词
DEFIBRILLATORS; RECALLS;
D O I
10.1371/journal.pone.0040200
中图分类号
O [数理科学和化学]; P [天文学、地球科学]; Q [生物科学]; N [自然科学总论];
学科分类号
07 ; 0710 ; 09 ;
摘要
Background: Medical devices increasingly depend on computing functions such as wireless communication and Internet connectivity for software-based control of therapies and network-based transmission of patients' stored medical information. These computing capabilities introduce security and privacy risks, yet little is known about the prevalence of such risks within the clinical setting. Methods: We used three comprehensive, publicly available databases maintained by the Food and Drug Administration (FDA) to evaluate recalls and adverse events related to security and privacy risks of medical devices. Results: Review of weekly enforcement reports identified 1,845 recalls; 605 (32.8%) of these included computers, 35 (1.9%) stored patient data, and 31 (1.7%) were capable of wireless communication. Searches of databases specific to recalls and adverse events identified only one event with a specific connection to security or privacy. Software-related recalls were relatively common, and most (81.8%) mentioned the possibility of upgrades, though only half of these provided specific instructions for the update mechanism. Conclusions: Our review of recalls and adverse events from federal government databases reveals sharp inconsistencies with databases at individual providers with respect to security and privacy risks. Recalls related to software may increase security risks because of unprotected update and correction mechanisms. To detect signals of security and privacy problems that adversely affect public health, federal postmarket surveillance strategies should rethink how to effectively and efficiently collect data on security and privacy problems in devices that increasingly depend on computing systems susceptible to malware.
引用
收藏
页数:7
相关论文
共 50 条
  • [1] FDA amends postmarket program for medical devices
    不详
    [J]. JOURNAL OF NUCLEAR MEDICINE, 2007, 48 (01) : 24N - 24N
  • [2] Noninvasive Postmarket Security Monitoring for Medical Devices
    Ransford, Benjamin
    Kune, Denis Foo
    Gookin, Ann
    DeOrio, Andrew
    [J]. JOURNAL OF MEDICAL DEVICES-TRANSACTIONS OF THE ASME, 2016, 10 (02):
  • [3] EU postmarket surveillance plans for medical devices
    Pane, Josep
    Francisca, Reynold D. C.
    Verhamme, Katia M. C.
    Orozco, Marcia
    Viroux, Hilde
    Rebollo, Irene
    Sturkenboom, Miriam C. J. M.
    [J]. PHARMACOEPIDEMIOLOGY AND DRUG SAFETY, 2019, 28 (09) : 1155 - 1165
  • [4] FDA perspectives on postmarket surveillance of peripheral and aortic vascular devices
    Malone, Misti
    Johnson, Carmen Gacchina
    [J]. CATHETERIZATION AND CARDIOVASCULAR INTERVENTIONS, 2024, 104 (01) : 170 - 171
  • [5] Improving FDA postmarket adverse event reporting for medical devices
    Wunnava, Susmitha
    Miller, Timothy A.
    Bourgeois, Florence T.
    [J]. BMJ EVIDENCE-BASED MEDICINE, 2023, 28 (02) : 83 - 84
  • [6] Current development in medical devices postmarket surveillance in Taiwan
    Lan, Cheng-Wen
    Yeh, Ming-Kung
    Wu, Shiow-Ing
    Tu, Pei-Weng
    [J]. JOURNAL OF FOOD AND DRUG ANALYSIS, 2015, 23 (01) : 164 - 165
  • [7] Blockchain technology applications to postmarket surveillance of medical devices
    Pane, Josep
    Verhamme, Katia M. C.
    Shrum, Lacey
    Rebollo, Irene
    Sturkenboom, Miriam C. J. M.
    [J]. EXPERT REVIEW OF MEDICAL DEVICES, 2020, 17 (10) : 1123 - 1132
  • [8] THE SAFE MEDICAL DEVICES ACT OF 1990 - POSTMARKET SURVEILLANCE, MDR, AND OTHER POSTMARKET ISSUES
    BASILE, EM
    [J]. FOOD AND DRUG LAW JOURNAL, 1991, 46 (02): : 165 - 175
  • [9] Postmarket surveillance of medical devices: current capabilities and future opportunities
    Kathleen Blake
    [J]. Journal of Interventional Cardiac Electrophysiology, 2013, 36 : 119 - 127
  • [10] Postmarket surveillance for medical devices: America's new strategy
    Normand, Sharon-Lise T.
    Hatfield, Laura
    Drozda, Joseph
    Resnic, Frederic S.
    [J]. BRITISH MEDICAL JOURNAL, 2012, 345