Shared Responsibility in Medical Device Cybersecurity with Greg Garcia | Ep. 28
Featured Guest
Episode Summary
This episode of The Med Device Cyber Podcast features Greg Garcia from the Health Sector Coordinating Council (HSCC), discussing the critical issue of shared responsibility in medical device cybersecurity. Garcia, with a background spanning the Department of Homeland Security and financial services, highlights the HSCC Cyber Security Working Group's efforts to foster collaboration between medical device manufacturers (MDMs) and healthcare delivery organizations (HDOs). A central theme is moving past blame to develop unified strategies for medical device security. Garcia emphasizes the "secure by design" and "secure by default" principles, crucial for total lifecycle product security. He touches upon the challenge of legacy devices, the 2023 FDA guidance changes, and the economic pressures faced by resource-constrained healthcare providers. The discussion also covers the importance of shifting cybersecurity from a cost center to an integral part of patient safety, the limitations of current regulations for all healthcare-connected technologies, and the need for a unified approach to achieve regulatory and patient confidence in a secure medical ecosystem. Key initiatives like the Joint Security Plan (JSP) and managing legacy technology security (MALTS) are presented as vital, free resources developed by the industry for the industry.
Key Takeaways
- 01Cybersecurity is a shared responsibility across all stakeholders in the healthcare ecosystem, from medical device manufacturers to healthcare delivery organizations and IT companies.
- 02The
- 03secure by design"
- 04 and
- 05secure by default"
- 06 principles are essential for establishing total lifecycle product security in medical devices.
- 07Addressing legacy medical devices that are no longer supported requires collaborative strategies for maintaining security and planning for risk transfer.
- 08The industry needs to shift its perception of cybersecurity from a costly burden to an indispensable component of patient safety.
- 09Adopting industry-developed resources like the Joint Security Plan (JSP) and managing legacy technology security (MALTS) can significantly enhance cybersecurity posture.
- 10Future regulation may need to expand beyond medical devices to encompass all technology systems critical to healthcare delivery, mirroring the rigor applied to critical infrastructure.
- 11The Health Sector Coordinating Council (HSCC) offers free, collaboratively developed best practices and encourages participation to strengthen healthcare cybersecurity collectively.
Frequently Asked Questions
Quick answers drawn from this episode.
-
This episode of The Med Device Cyber Podcast features Greg Garcia from the Health Sector Coordinating Council (HSCC), discussing the critical issue of shared responsibility in medical device cybersecurity.
-
Cybersecurity is a shared responsibility across all stakeholders in the healthcare ecosystem, from medical device manufacturers to healthcare delivery organizations and IT companies. The secure by design"
-
A central theme is moving past blame to develop unified strategies for medical device security. It's most useful for medical device manufacturers, cybersecurity engineers, regulatory affairs professionals, and MedTech founders preparing for FDA review.
-
Cybersecurity is a shared responsibility across all stakeholders in the healthcare ecosystem, from medical device manufacturers to healthcare delivery organizations and IT companies.
Listeners also asked
Quick answers pulled from related episodes.
-
What does Episode 27 cover about "Why Cybersecurity and Quality Are One and the Same"?
Episode 27 of The Med Device Cyber Podcast covers Why Cybersecurity and Quality Are One and the Same.
From Episode 027 · Why Cybersecurity and Quality Are One and the Same | Ep. 26 -
What does Episode 45 cover about "Cyber Risk Management for MedTech Legacy Devices"?
Episode 45 of The Med Device Cyber Podcast covers Cyber Risk Management for MedTech Legacy Devices.
From Episode 045 · Cyber Risk Management for MedTech Legacy Devices | Ep. 44 -
What does Episode 50 cover about "How Cybersecurity Shapes Regulatory and Quality Success with Jim Goodmiller"?
Episode 50 of The Med Device Cyber Podcast covers How Cybersecurity Shapes Regulatory and Quality Success with Jim Goodmiller.
From Episode 050 · How Cybersecurity Shapes Regulatory and Quality Success with Jim Goodmiller | Ep. 49
Hosted by
More from your hosts
Other episodes diving into Christian and Trevor's areas of focus.
More like this
Episodes covering similar ground.
Why this matches covers similar themes around delivery, total, plan.
Why this matches covers similar themes around delivery, healthcare, organizations.







