ALLcrimesfood&drugstaxestelecomcommercehealthconservationtransportationagricultureveteransbrowse all titles »
0

21 U.S.C. § 360n–2Ensuring cybersecurity of devices

submitted 88 years ago by Pub. L. 117-328 to r/title-21-FOOD-AND-DRUGS · 328 words · no verdicts yet

in plain englishAI-generated · not legal advice

Makers of internet-connected medical devices must prove to the FDA that they are cybersecure. They need a plan to fix security flaws after sale, and must list all their software. The FDA can exempt certain devices from these cybersecurity rules.

(a) In general Anyone submitting certain device applications (under sections 360(k), 360c, 360e(c), 360e(f), or 360j(m)) for a device that counts as a "cyber device" must include whatever information the FDA requires to show the device meets the cybersecurity requirements in subsection (b). (b) Cybersecurity requirements The sponsor must: (1) submit a plan to reasonably monitor, find, and address cybersecurity vulnerabilities and exploits after the device is on the market, including a process for handling outside reports of vulnerabilities; (2) design and maintain processes giving reasonable assurance the device and its connected systems are secure, and provide updates and patches — on a regular, justified cycle for ordinary known vulnerabilities, and as fast as possible, outside the normal cycle, for critical vulnerabilities that could cause serious uncontrolled risks; (3) give the FDA a "software bill of materials" — a list of all commercial, open-source, and off-the-shelf software components in the device; and (4) meet any other requirements the FDA sets by regulation to reasonably assure the device and its systems are cybersecure. (c) Definition A "cyber device" is a device that: (1) includes software the sponsor validated, installed, or authorized as part of the device; (2) can connect to the internet; and (3) has technological features validated, installed, or authorized by the sponsor that could be vulnerable to cybersecurity threats. (d) Exemption The FDA can identify specific devices, or types of devices, that don't have to meet these cybersecurity requirements, and must publish (and keep updated) a list of these exempted devices in the Federal Register.
the actual law source: uscode.house.gov ↗public domain
(a) In general

A person who submits an application or submission under section 360(k), 360c, 360e(c), 360e(f), or 360j(m) of this title for a device that meets the definition of a cyber device under this section shall include such information as the Secretary may require to ensure that such cyber device meets the cybersecurity requirements under subsection (b).

(b) Cybersecurity requirements

The sponsor of an application or submission described in subsection (a) shall—

(1)

submit to the Secretary a plan to monitor, identify, and address, as appropriate, in a reasonable time, postmarket cybersecurity vulnerabilities and exploits, including coordinated vulnerability disclosure and related procedures;

(2)

design, develop, and maintain processes and procedures to provide a reasonable assurance that the device and related systems are cybersecure, and make available postmarket updates and patches to the device and related systems to address—

(A)

on a reasonably justified regular cycle, known unacceptable vulnerabilities; and

(B)

as soon as possible out of cycle, critical vulnerabilities that could cause uncontrolled risks;

(3)

provide to the Secretary a software bill of materials, including commercial, open-source, and off-the-shelf software components; and

(4)

comply with such other requirements as the Secretary may require through regulation to demonstrate reasonable assurance that the device and related systems are cybersecure.

(c) Definition

In this section, the term “cyber device” means a device that—

(1)

includes software validated, installed, or authorized by the sponsor as a device or in a device;

(2)

has the ability to connect to the internet; and

(3)

contains any such technological characteristics validated, installed, or authorized by the sponsor that could be vulnerable to cybersecurity threats.

(d) Exemption

The Secretary may identify devices, or categories or types of devices, that are exempt from meeting the cybersecurity requirements established by this section and regulations promulgated pursuant to this section. The Secretary shall publish in the Federal Register, and update, as appropriate, a list of the devices, or categories or types of devices, so identified by the Secretary.

Source credit: (June 25, 1938, ch. 675, § 524B, as added Pub. L. 117–328, div. FF, title III, § 3305(a), Dec. 29, 2022, 136 Stat. 5832.)

history & why it existsrecord from the source credit
  • 1938Enacted · Pub. L. 117-328 · 136 Stat. 5832

A history note hasn’t been published yet. The record shows enactment by Pub. L. 117-328 on 1938-06-25.

all 0 arguments · sorted by: best

0/280

no arguments yet — make the first case