PATCH Act: How to Comply in 2023 & Beyond
PATCH Act: How to Comply in 2023 & Beyond
John Koontz
August 16, 2023
Table of Contents
- What is the Patch Act?
- When does the Patch Act of 2022 become mandatory?
- What are the Major Patch Act Dates?
- How does the Patch Act work with Substantial Equivalence?
- Patch Act compliance & auditing in 2023
- Patch Act Requirements
- What industries are most impacted by the Patch Act?
- How to ensure postmarket cybersecurity vulnerabilities are monitored
- Tools for Patch Act compliance and FDA audits
What is the Patch Act?
H.R. 7084, also known as the “PATCH Act of 2022,” outlines a framework for minimal cybersecurity focus within medical devices. The Patch Act (Protecting and Transforming Healthcare Act) has been in development for several years, and a key section grants the FDA long-awaited authority to strengthen its cybersecurity guidance for medical device premarket submissions and post market security management. While the Act and FDA Guidance reflect best practices, the diverse landscape of medical device systems and software ecosystems poses challenges for effective implementation. In particular, the requirement for a Software Bill of Materials, or SBOM, while well-intentioned, isn’t particularly useful to regulators or to users. In fact, the guidance can even make it easier for hackers to exploit known vulnerabilities to compromise patient safety.
When does the Patch Act of 2022 become mandatory?
The Patch Act comes into force on October 1, 2023. The act specifies creation, tracking, and submission of the following:
- Product monitoring plan
- Product cyber-anomaly response plan
- Coordinated messaging of cyber vulnerabilities
- Product software releases on a ‘reasonably justified regular cycle’
- Software Bill of Materials (SBOM)
- Ability to release a critical vulnerability patch ‘as soon as possible’
- Collect and maintain additional information in the future
What are the Major Patch Act Dates?
- October 1, 2023: The Patch Act comes into effect. The FDA expects that sponsors of such cyber devices will have had sufficient time to prepare premarket submissions that contain information required by section 524B of the FD&C Act, and the FDA may Refuse to Accept (RTA) premarket submissions that do not.
- March 29, 2023 - October 1, 2023: During this period, the FDA's general approach is to refrain from issuing "refuse to accept" (RTA) determinations for premarket submissions of cyber devices submitted before October 1, 2023. Instead, the FDA will adopt a collaborative stance during this time by engaging with the premarket submissions’ sponsors through interactive processes and deficiency reviews.
- March 29, 2023: The new cybersecurity prerequisites are not relevant to an application or proposal that has been presented to the FDA before this date. However, if a cyber device previously granted authorization implements new alterations that require FDA evaluation, the new legislation rules would be applicable to the updated premarket proposal.
- December 29, 2022: The Consolidated Appropriations Act, 2023 was signed into law. Section 3305 of the Omnibus — "Ensuring Cybersecurity of Medical Devices" —amended the Federal Food, Drug, and Cosmetic Act (FD&C Act) by adding section 524B, Ensuring Cybersecurity of Devices.
How does the Patch Act work with Substantial Equivalence?
In evaluating substantial equivalence under the section for a Cyber Device, the FDA will be able to:
- Determine that the cybersecurity information presented for the Cyber Device within its relevant premarket application is insufficient.
- Issue a non-substantial equivalence determination based on this insufficiency finding.
Patch Act compliance & auditing in 2023
What products meet the "Cyber Device" definition?
According to the Patch Act, the term " Cyber Device” means a device that either (A) incorporates software; or (B) is designed to establish an internet connection.
This definition emerges due to the changing nature of safety critical systems, such as medical devices. Medical devices range from implantables, such as pacemakers and prosthetics, to proton beam accelerators and biological testing to mobile health apps, and more.
Patch Act Requirements
Software Bill of Materials (SBOM)
The requirement to supply an SBOM is more than just a listing of what code sources are in use; it’s also tracking the versions, vulnerabilities, and risk evaluations for all code sources. An effective SBOM tracks all software sources and associated cybersecurity risks and mitigations of said sources.
Product Monitoring Plan
If a product has an online capability, the interfaces are obvious attack surfaces. Products should be able to self-detect and report when an error state is entered.
Cyber Response Plan
The PATCH Act “asks,” if a vulnerability is discovered, what actions would be necessary to assess and document risk? Almost all organizations have a cyber security response plan for corporate assets; this requirement extends such plans to individual products/devices.
Coordinated Disclosure
The PATCH Act specifically calls for planning on how to communicate vulnerabilities to appropriate parties. The key item with disclosure is the coordination of messages over time.
Software Releases
The act calls for software updates on a ‘justified regular cycle,’ as well as the capability to do an ASAP ‘out of cycle’ update.
Ensuring Cybersecurity in Pre- and Post-Market Surveillance
Manufacturers of cyber devices must develop plans to effectively monitor, detect, and address cybersecurity vulnerabilities after the device's introduction to the market.
What industries are most impacted by the Patch Act?
The MedTech industries will be most affected by the Patch Act come October 1st:
- Medical Device Manufacturers: Need to comply with new requirements for cybersecurity measures.
- Healthcare Providers and Systems: Must ensure they have proper processes in place for managing cybersecurity updates.
- Healthcare IT Professionals: Will likely be responsible for ensuring cybersecurity requirements are implemented effectively.
How to ensure postmarket cybersecurity vulnerabilities are monitored
- Vulnerability Tracking System: Implement a robust system to track and manage cybersecurity vulnerabilities and risks.
- Post-market Surveillance and Incident Response Plan: Create an incident response plan outlining how the company will respond to identified vulnerabilities or breaches.
- Patch Management: Establish a systematic process for developing, testing, and deploying patches and updates.
- Documentation and Traceability: Maintain comprehensive documentation of all vulnerability management activities.
- Audit and Compliance Checks: Regularly conduct internal audits and compliance checks to ensure alignment with the Patch Act.
Tools for Patch Act compliance and FDA audits
By approaching the new requirements with care, you can enhance user safety and mitigate risk proactively. Tools are starting to catch up with regulatory demands, and teams can determine what is needed to succeed.