Standards, Guidance & Notices
Showing 21–30 of 49
MHLW
Notice
Notice
MHLW-PSEHB-PSD-0115-No.2
Fundamental Approach to Adverse Event Reporting Related to Medical Device Cybersecurity
Notice clarifying handling of cybersecurity events in adverse event/serious adverse event reporting systems. Addresses reporting applicability for patient harm from cyber attacks or vulnerability exploitation, decision-making flowcharts, and manufacturer response procedures. Serves as foundational regulatory documentation for post-market cybersecurity management.
Published: 2024-01-15
FDA
CDRH
CDRH
FDA-Cybersecurity-Premarket-2023
Cybersecurity in Medical Devices: Quality System Considerations and Content of Premarket Submissions
⚠ NEWER VERSION
Cybersecurity in Medical Devices: Quality Management System Considerations and Content of Premarket Submissions (2026-02-03) →
This FDA final guidance (September 2023) establishes current cybersecurity requirements for medical device manufacturers, implementing legal mandates from the Consolidated Appropriations Act 2023 (Section 524B). The guidance specifies mandatory inclusion of software bill of materials (SBOM), vulnerability disclosure policies, and cybersecurity management plans in premarket submissions for devices with network connectivity or remote functionality. Manufacturers must establish processes for identifying, evaluating, and disclosing known and potential cybersecurity vulnerabilities to the FDA and relevant stakeholders. The cybersecurity management plan should address threat modeling, risk assessment, security design controls, and post-market monitoring strategies. The guidance demonstrates alignment with international standards including IEC 81001-5-1 (application of risk management to network security) and AAMI TIR57 (medical device security guidance), facilitating harmonized global regulatory compliance. Manufacturers should integrate cybersecurity considerations throughout the device lifecycle from design through post-market surveillance. The guidance represents current regulatory expectations and serves as the primary reference for FDA premarket submissions incorporating cybersecurity requirements. Compliance demonstrates manufacturer commitment to protecting patient safety and data integrity.
Published: 2023-09-27
NIST
SP
SP
SP 800-188
De-Identifying Government Datasets: Techniques and Governance
De-identification is a general term for any process of removing the association between a set of identifying data and the data subject. This document describes the use of deidentification with the goal of preventing or limiting disclosure risks to individuals and establishments while still allowing for the production of meaningful statistical analysis. Government agencies can use de-identification to reduce the privacy risk associated with collecting, processing, archiving, distributing, or publishing government data. Previously, NIST IR 8053, ""De-Identification of Personal Information,"" provided a detailed survey of deidentification and re-identification techniques. This document provides specific guidance to government agencies that wish to use de-identification. Before using de-identification, agencies should evaluate their goals for using de-identification and the potential risks that releasing de-identified data might create. Agencies should decide upon a data-sharing model, suc
Published: 2023-09-14
MHLW
Notice
Notice
Admin-Notice-2023-07-20
Q&A on Application of Essential Principles Article 12(3) for Medical Devices
Q&A addressing application and conformance assessment of Essential Principles Article 12(3). Covers transition period marketing approval application handling, submission documentation methods, third-party agency utilization for JIS T 81001-5-1 conformance, and reliability document review scope. References related MHLW regulatory notices issued in March and May 2023.
Published: 2023-07-20
MHLW
Notice
Notice
MHLW-PSEHB-MDED-0523-No.1
Conformance Assessment Procedures for Essential Principles Article 12(3) of Medical Devices
Notice specifying concrete compliance assessment considerations for Essential Principles Article 12(3). Details additional verification items against JIS T 81001-5-1 provisions (general requirements, maintenance processes, configuration management). Requires demonstration of intended use environment through system/network architecture diagrams and integration of vulnerability notification activities into quality management systems.
Published: 2023-05-23
IMDRF
IMDRF/CYBER WG/N70 FINAL:2023
Principles and Practices for the Cybersecurity of Legacy Medical Devices
This document provides IMDRF guidance on managing cybersecurity risks in legacy medical devices that are end-of-life (EOL) or difficult to maintain. It clarifies responsibilities and practical mitigation strategies for both manufacturers and healthcare facilities. The document establishes frameworks for EOL management planning, identifying alternative solutions, and making informed risk acceptance decisions. As a complementary document to N60, it addresses the specific challenges posed by legacy systems that cannot be readily updated with security patches or improvements. Manufacturers and healthcare organizations should use this guidance to systematically assess legacy device risks and implement appropriate risk mitigation measures aligned with current cybersecurity standards.
Published: 2023-04-11
MHLW
Notice
Notice
医政参発0331-No.1
Guideline for Ensuring Cybersecurity of Medical Devices in Healthcare Facilities
MHLW notification of Cybersecurity Guideline for healthcare facility administrators and staff. Presents practical procedures for information collection from manufacturers, risk assessment, pre-implementation verification, vulnerability response during operation, and EOL management. Positioned as the healthcare facility counterpart to the related manufacturer-directed guideline, structured to promote coordination between both parties.
Published: 2023-03-31
MHLW
Notice
Notice
MHLW-PSEHB-MDED-0331-No.11
Revision of Cybersecurity Implementation Guideline for Medical Devices
MHLW notification of revised Cybersecurity Guideline for Medical Device Manufacturers (2nd Edition). Updated to align with Essential Principles Article 12(3) implementation. Provides practical procedures for security requirements identification, architecture design, SBOM, PSIRT establishment, and vulnerability disclosure. Functions as specific guidance for JIS T 81001-5-1 application.
Published: 2023-03-31
MHLW
Notice
Notice
MHLW-PSEHB-MDED-0331-No.8
Notice on Application of Essential Principles Article 12(3) for Medical Devices
Interpretation notice accompanying April 1, 2023 enforcement of Essential Principles Article 12(3) cybersecurity requirements. Mandates three elements for network-connected medical devices: lifecycle cybersecurity planning, risk reduction design, and minimum operational environment specifications. Recognizes JIS T 81001-5-1 conformance as equivalent to Article 12(3) compliance. Provides transition period until March 31, 2024.
Published: 2023-03-31
JIS
Std
Std
JIS T 81001-5-1:2023
JIS T 81001-5-1:2023 Health software and health IT system safety, efficacy and security - Part 5-1: Security - Activities in the product lifecycle (equivalent to IEC 81001-5-1:2021)
This JIS standard specifies cybersecurity activities that medical device manufacturers must implement in addition to the software lifecycle processes defined in JIS T 2304, corresponding to IEC 81001-5-1:2021. The document establishes requirements for managing security risks throughout the product lifecycle, addressing threats related to unauthorized access, data integrity, and system availability. Enacted on February 25, 2023, and effective from April 1, 2024, this standard was developed by JEITA (Japan Electronics and Information Technology Industries Association) as a draft originator. The standard is positioned as a conformance specification for Article 12, Paragraph 3 of Japan's Medical Device Basic Requirements Standards (Yakuhin Kikai Kihon Youken Kijun). Manufacturers should integrate the cybersecurity activities outlined herein with their existing software development processes to ensure comprehensive protection against evolving security threats throughout the device lifecycle.
Published: 2023-02-25
