Close
Digital Health & Ai Innovation summit 2026
Medical Taiwan 2026

FDA May Scrutinize Medical Device Cybersecurity More in 2026

Note* - All images used are for editorial and illustrative purposes only and may not originate from the original news provider or associated company.

Subscribe

- Never miss a story with notifications

- Gain full access to our premium content

- Browse free from any location or device.

Media Packs

Expand Your Reach With Our Customized Solutions Empowering Your Campaigns To Maximize Your Reach & Drive Real Results!

โ€“ Access the Media PackNow

โ€“ Book a Conference Call

โ€“ Leave Message for Us to Get Back

Related stories

ShiftMed Skilltrade Partnership Targets Allied Health...

ShiftMed has entered into a strategic collaboration with Skilltrade...

ARPA-H Launches IGoR Program for AI...

The Advanced Research Projects Agency for Health has officially...

Laboratory Automation Advancing Diagnostic Workflows

The modern clinical laboratory is undergoing a profound evolution as manual processes give way to sophisticated robotic systems. By streamlining testing procedures and integrating high-throughput technologies, facilities are achieving unprecedented levels of precision and speed. This shift towards automated solutions is not only reducing human error but also enabling medical professionals to handle increasing sample volumes with greater reliability, ultimately leading to faster and more accurate patient results.

The scrutiny by the US Food and Drug Administration – FDA around medical device cybersecurity is going to intensify prominently as one moves into 2026, forecasts an expert.

It is well to be noted that in June 2025, the agency went ahead and published its final expectations for premarket submissions and also post-market lifecycle obligations when it comes to medical device cybersecurity protocols as per theย Federal Food, Drug, and Cosmetic – FD&C Act under Section 524B.

The team lead of life science practice at Founder Shield, the technology broker, Justin Kozak, expects that the FDA is going to switch its focus from pre-market paperwork to active operational execution in the coming year.

Kozak went on to confirm to theย Medical Device Network that the FDA is going to move beyond reviewing plans under Section 524B in order to audit the real-world effectiveness when it comes to post-market security processes.

Notably, Section 524B, which was brought to the fore in December 2022 as part of the Consolidated Appropriations Act, goes on to mandate a range of cybersecurity needs all throughout the lifecycle for some medical devices. Those targeted through the legislation are the ones that connect to the internet and also include software that is validated and installed as well as authorized by a device manufacturer.

Required details go on to include information around security controls of the device and plans for vulnerability disclosure along with the provision of a software bill of materials – SBOM.

In October 2023, the FDA went on to execute its refuse to accept โ€“ FTA policy as per Action 524B. The action gave the agency authority to reject the pre-market application โ€“ PMA submissions for in-scope medical device submissions that lacked complete cybersecurity information.

Kozak further said that the fast integration of AI or generative AI โ€“ genAI within the devices is introducing quite distinct security risks, which go on to demand specialized governance along with secure-by-design principles in order to maintain the safety of the patient.

Kozak also remarked that this transition will force the companies to prove their vulnerability management works within the field and not only at pre-product launch.

Given the fact that the premarket enforcement has been in existence since 2023, the industry has been kind of bracing itself for the post-market cybersecurity needs. For instance, UL Solutions, the safety testing company, has a page that is dedicated on its website to going ahead and answering FAQs on how to navigate Section 524B to its best.

Kozak underscored that small medtech companies go on to face a heightened risk because of resource limitations and also a threat of regulatory failure.

He added that they often lack the deep pockets that the larger companies have, thereby resulting in a triple burden situation.

In order to deal with the requirements promulgated under Section 524B, Kozak advises the smaller companies to go ahead and treat security as a central engineering requirement right from day one, as opposed to an afterthought.

Kozak opines that the most effective strategy is certainly to embed automated security checks much earlier in the development pipeline. The reason for this kind of shift-left strategy is that fixing susceptibilities during coding is indeed more cost-efficient as compared to post-market remediation.

Never miss a healthcare headline

Healthcare moves fast โ€“ stay on top of it with our must - read briefings.

  • The top hospital and healthcare stories, straight to your inbox
  • The biggest news, features, interviews, and analysis
  • Dedicated coverage of the key developments transforming global healthcare management
MEDICAL FAIR ASIA 2026
MEDICAL FAIR CHINA

Latest stories

Related stories

ShiftMed Skilltrade Partnership Targets Allied Health Gaps

ShiftMed has entered into a strategic collaboration with Skilltrade...

ARPA-H Launches IGoR Program for AI in Biomedical Research

The Advanced Research Projects Agency for Health has officially...

Laboratory Automation Advancing Diagnostic Workflows

The modern clinical laboratory is undergoing a profound evolution as manual processes give way to sophisticated robotic systems. By streamlining testing procedures and integrating high-throughput technologies, facilities are achieving unprecedented levels of precision and speed. This shift towards automated solutions is not only reducing human error but also enabling medical professionals to handle increasing sample volumes with greater reliability, ultimately leading to faster and more accurate patient results.

Telemedicine Platforms Expanding Access to Remote Care

Modern healthcare systems are undergoing a radical transformation as digital infrastructure bridges the gap between urban specialists and rural patients. Through virtual consultations and digital triage, providers are overcoming geographical barriers, ensuring that high-quality medical expertise is no longer restricted by physical location. This evolution in care delivery prioritizes accessibility and efficiency, reshaping the patient experience across the globe.

Subscribe

- Never miss a story with notifications

- Gain full access to our premium content

- Browse free from any location or device.

Media Packs

Expand Your Reach With Our Customized Solutions Empowering Your Campaigns To Maximize Your Reach & Drive Real Results!

โ€“ Access the Media Pack Now

โ€“ Book a Conference Call

โ€“ Leave Message for Us to Get Back

Translate ยป