PATCH Act: How to Comply in 2023 & Beyond

PATCH Act: How to Comply in 2023 & Beyond

John Koontz

August 16, 2023

Table of Contents

What is the Patch Act?

H.R. 7084, also known as the “PATCH Act of 2022,” outlines a framework for minimal cybersecurity focus within medical devices. The Patch Act (Protecting and Transforming Healthcare Act) has been in development for several years, and a key section grants the FDA long-awaited authority to strengthen its cybersecurity guidance for medical device premarket submissions and post market security management. While the Act and FDA Guidance reflect best practices, the diverse landscape of medical device systems and software ecosystems poses challenges for effective implementation. In particular, the requirement for a Software Bill of Materials, or SBOM, while well-intentioned, isn’t particularly useful to regulators or to users. In fact, the guidance can even make it easier for hackers to exploit known vulnerabilities to compromise patient safety.

When does the Patch Act of 2022 become mandatory?

The Patch Act comes into force on October 1, 2023. The act specifies creation, tracking, and submission of the following:

What are the Major Patch Act Dates?

How does the Patch Act work with Substantial Equivalence?

In evaluating substantial equivalence under the section for a Cyber Device, the FDA will be able to:

  1. Determine that the cybersecurity information presented for the Cyber Device within its relevant premarket application is insufficient.
  2. Issue a non-substantial equivalence determination based on this insufficiency finding.

Patch Act compliance & auditing in 2023

What products meet the "Cyber Device" definition?

According to the Patch Act, the term " Cyber Device” means a device that either (A) incorporates software; or (B) is designed to establish an internet connection.

This definition emerges due to the changing nature of safety critical systems, such as medical devices. Medical devices range from implantables, such as pacemakers and prosthetics, to proton beam accelerators and biological testing to mobile health apps, and more.

Patch Act Requirements

Software Bill of Materials (SBOM)

The requirement to supply an SBOM is more than just a listing of what code sources are in use; it’s also tracking the versions, vulnerabilities, and risk evaluations for all code sources. An effective SBOM tracks all software sources and associated cybersecurity risks and mitigations of said sources.

Product Monitoring Plan

If a product has an online capability, the interfaces are obvious attack surfaces. Products should be able to self-detect and report when an error state is entered.

Cyber Response Plan

The PATCH Act “asks,” if a vulnerability is discovered, what actions would be necessary to assess and document risk? Almost all organizations have a cyber security response plan for corporate assets; this requirement extends such plans to individual products/devices.

Coordinated Disclosure

The PATCH Act specifically calls for planning on how to communicate vulnerabilities to appropriate parties. The key item with disclosure is the coordination of messages over time.

Software Releases

The act calls for software updates on a ‘justified regular cycle,’ as well as the capability to do an ASAP ‘out of cycle’ update.

Ensuring Cybersecurity in Pre- and Post-Market Surveillance

Manufacturers of cyber devices must develop plans to effectively monitor, detect, and address cybersecurity vulnerabilities after the device's introduction to the market.

What industries are most impacted by the Patch Act?

The MedTech industries will be most affected by the Patch Act come October 1st:

How to ensure postmarket cybersecurity vulnerabilities are monitored

  1. Vulnerability Tracking System: Implement a robust system to track and manage cybersecurity vulnerabilities and risks.
  2. Post-market Surveillance and Incident Response Plan: Create an incident response plan outlining how the company will respond to identified vulnerabilities or breaches.
  3. Patch Management: Establish a systematic process for developing, testing, and deploying patches and updates.
  4. Documentation and Traceability: Maintain comprehensive documentation of all vulnerability management activities.
  5. Audit and Compliance Checks: Regularly conduct internal audits and compliance checks to ensure alignment with the Patch Act.

Tools for Patch Act compliance and FDA audits

By approaching the new requirements with care, you can enhance user safety and mitigate risk proactively. Tools are starting to catch up with regulatory demands, and teams can determine what is needed to succeed.