GxP Engineering Consultancy And Validation Services

Accelerating GxP clients towards their engineering compliance goals. Providing leading expertise in technology systems, which improve productivity, product quality and patient safety. Coming Soon : CPD Approved Medical Device Software Validation Training Course, in line with GAMP 5. Products for Sale : New Document Templates are now Available for Purchase.

GxP Engineering Consultancy And Validation Services

Zener Engineering Services Ltd Logo

GxP Engineering
Consultancy And
Validation Services


Blog Post

Zener Engineering Services Ltd Logo

Medical Device Cyber Security Considerations

  • by Zener Engineering Services Ltd
  • 20 May, 2020

Functionality Statement

Cyber Hacker

Digital data exchanges between Medical Devices and portable media containing patient health-related information present a significant opportunity for clinicians to provide speedier and more appropriate healthcare.

More recently, an effective Cyber Security approach, to ensure Medical Device functionality and in-turn patient safety, has become more paramount, due to the increased use of the internet, cloud services and network-connected Medical Devices, for Medical Device manufacturers and healthcare providers alike.

Cyber Security threats to all electronic installations have become more frequent. In May 2020 easyJet announced that a "highly sophisticated cyber-attack" had affected approximately nine million customers. Email addresses and travel details had been stolen and 2,208 customers had also had their credit card details "accessed". [Source BBC Website.]

Cyber Security threats have become more frequent and, in the case of the healthcare setting, potentially more severe due to the risk of clinical patient impact. Cyber Security incidents have rendered medical devices and hospital networks inoperable, disrupting the delivery of patient care across healthcare facilities in the UK and globally.

In May 2017, WannaCry malware, which spread to more than 150 countries in a worldwide ransomware outbreak, was the biggest cyber-attack to have hit the NHS to date. The malware encrypted data on infected computers and demanded a ransom roughly equivalent to £230 ($300). The consequences of the attack were exacerbated by the fact that an assessment of 88 out of 236 trusts undertaken by NHS Digital before the attack found that none passed the required cyber-security standards.[Source BBC Website.]

More and more Medical Devices are utilising-software with varying degrees of potential patient impact. In the healthcare setting, cyber attacks can delay diagnoses and/or treatment and may lead to significant patient harm.

During the manufacturing process of the software-utilising Medical Device, a suitable approach to Cyber Security and software vulnerabilities needs to be established by the manufacturer.

In order to demonstrate a reasonable and trustworthy assurance of safety and effectiveness of new software-utilising Medical Devices, against cyber incidents, Regulatory Bodies require documented evidence of a suitable level of software security. Suitable documented evidence that proves a medical device demonstrates suitable and effective Cyber Security measures is part of the pre-market review.

In October 2018 the FDA released draft Cyber Security Guidance,  'Content of Premarket Submissions for Management of Cybersecurity in Medical Devices’. The functionality statement includes Medical Device considerations such as:

  • Management Of Private Data
  • Security Capabilities
  • Audit Controls
  • Authorisations
  • Security Features
  • Upgrades

How Can ZES Help?

Zener Engineering Services Ltd provide expertise and practical assistance to help Medical Device manufacturers design their devices in such a way as to help protect against cyber incidents and subsequent potential patient harm.

ZES can advise and help implement suitable protection mechanisms to prevent all unauthorized use, whilst ensuring the security and integrity of the code, data, and the Medical Device's functionality.

As a part of premarket functionality statement submission, manufacturers should submit documentation demonstrating how Cyber Security design expectations are met by the Medical Device. ZES has helped Medical Device manufacturers to bring medical devices to market, with suitable Cyber Security approaches documented and validated.

If you require a Medical Device Cyber Security Functionality Statement template, ZES have a proven template for sale.

If you have concerns about Medical Device Cyber Security, 

contact ZES, where our experts are happy to help.

Share This Post

by Zener Engineering Services Ltd 13 November 2024
A 'well-established' cleanroom supplier proposed cleanroom fans unsuitable for a new sterile manufacturing facility, required by a Cell and Gene Therapy Client
by Zener Engineering Services Ltd 22 October 2024
The importance of the critical role performed by Authorising Engineers (AEs), can't be overstated.
by Zener Engineering Services Ltd 2 October 2024
NHS refreshed using ZES Mugs, one drop at a time.
by Zener Engineering Services Ltd 15 September 2024
A successful GxP Data Integrity training strategy is an ultimate goal for any Life Science Organisation
by Zener Engineering Services Ltd 22 August 2024
A successful GxP Calibration Management training strategy is the ultimate goal for any Life Science Organisation
by Zener Engineering Services Ltd 1 August 2024
Significant skills are required to implement compliant solutions, to satisfy the regulatory requirements of 21 CFR Part 11 and to ensure Data Integrity of Electronic Data.
by Zener Engineering Services Ltd 19 June 2024
Three New GxP Training Courses: ERES, Data Integrity And Calibration Management
by Zener Engineering Services Ltd 30 May 2024
A successful regulatory outcome is the ultimate goal for any Life Science Organisation
by Zener Engineering Services Ltd 8 May 2024
Various GxP Computer System Regulatory Requirements state that the integrity of the data held on such systems, is to be protected by a level of security that prevents tampering with records, or other unauthorised changes to ‘cover’ potential poor practice.
by Zener Engineering Services Ltd 19 April 2024
Effective documentation is the backbone of any successful Life Science organisation, whether it's creating manufacturing records or policies and SOPs.
Show More
Share by: