Team-NB has published a letter on cybersecurity in medical devices
Team-NB, the European Association of Medica devices Notified Bodies, has published a letter concerning cybersecurity in medical devices. The Association welcomed revisions included in the recent proposed revisions to the MDR and IVDR intended to strengthen cybersecurity in this context.
However, it considered that decisions concerning availability of medical devices and safety of patients remain with the “governance bodies” established and defined by MDR/IVDR. Governance bodies include the European Commission, the National Competent Authorities of the EU Member States, and notified bodies.
The Association expressed unease regarding the intention to include more granular cybersecurity requirements in the MDR and IVDR. It felt that technical provisions anchored in “hard” law hinder and prevent innovation.
Team-NB also recalled that “state-of-the-art (SOTA) is by no means a vague or imprecise benchmark while we appreciate this could be the impression to persons not familiar with regulatory compliance of medical devices”.
The Association considers SOTA to be fundamental to European product regulations, including the MDR and IVDR. This is because it reflects current technical capabilities or clinical practice and is based on consolidated insights from science, technology and practical considerations.
It concluded that SOTA may be even more important for cybersecurity than in other less dynamic fields such as clinical practice. This conclusion is based on the belief that cybersecurity can never be a compliance exercise of simply fulfilling requirements but must be conceived and implemented as a process.
The Association, therefore, considers that the principle of state-of-the-art should remain the guiding principle for this as for all other aspects of development and compliance of medical devices.