LIVE FEED
Forescout found just 6 percent of connected medical devices support quantum-safe SSH, versus 50 percent of ordinary IT systems, across a 2.5 million device sample BridgeLink 26.9.0, the open source Mirth Connect fork, patched CVE-2026-82583, CVE-2026-78224, and CVE-2026-82578 from CISA's ICSMA-26-253-01 on October 1, plus eight inherited third party library CVEs Citrix's CVE-2026-88771 and CVE-2026-88772, two CVSS 9.5 NetScaler zero days under active attack, forced three Dutch hospitals to shut down systems as a precaution Fresenius Medical Care confirmed unauthorized access to internal systems September 22, after ShinyHunters listed the dialysis maker for extortion The Senate passed S. 3315, the Health Care Cybersecurity and Resiliency Act, by unanimous consent September 30; mandatory MFA, encryption, and penetration testing now await House action FDA docket FDA-2026-N-7874 on generative AI enabled devices remains open; comments due October 19 Forescout found just 6 percent of connected medical devices support quantum-safe SSH, versus 50 percent of ordinary IT systems, across a 2.5 million device sample BridgeLink 26.9.0, the open source Mirth Connect fork, patched CVE-2026-82583, CVE-2026-78224, and CVE-2026-82578 from CISA's ICSMA-26-253-01 on October 1, plus eight inherited third party library CVEs Citrix's CVE-2026-88771 and CVE-2026-88772, two CVSS 9.5 NetScaler zero days under active attack, forced three Dutch hospitals to shut down systems as a precaution Fresenius Medical Care confirmed unauthorized access to internal systems September 22, after ShinyHunters listed the dialysis maker for extortion The Senate passed S. 3315, the Health Care Cybersecurity and Resiliency Act, by unanimous consent September 30; mandatory MFA, encryption, and penetration testing now await House action FDA docket FDA-2026-N-7874 on generative AI enabled devices remains open; comments due October 19
Thursday, October 8, 2026 Issue #476  ·  Est. 2025
Independent brief for device makers
Section 03 // FDA · EU · Global Frameworks

FDA & Regulation

Premarket expectations, postmarket obligations, and the global regulatory map for device cybersecurity.

Latest Filings

23 stories on file
01
Policy

Senate passes S. 3315, mandating MFA and encryption for every HIPAA covered entity

The Senate passed S. 3315, the Health Care Cybersecurity and Resiliency Act, by unanimous consent on September 30. It sets mandatory MFA, encryption, continuous monitoring, and penetration testing for every HIPAA covered entity and business associate.

Congress.govSep 303 min read
02
Policy

Wyden and Warner reintroduce HISAA, and business associates are back in the penalty box

Sens. Ron Wyden and Mark Warner reintroduced the Health Infrastructure Security and Accountability Act on September 17, two years after the Change Healthcare attack first prompted it. The bill sets mandatory HIPAA security standards, requires CEO and CISO sign off on annual attestations, and ties penalties as high as $250,000 to uncorrected willful neglect.

HIPAA JournalSep 174 min read
03
Industry Standard

Health-ISAC sets nine security domains for medical devices, and a gap now needs an executive's name on it

Health-ISAC's Medical Device Security Council published nine capability domains for hospitals to score medical devices against, and any device that misses one now needs a documented exception with a named executive attached.

Health-ISACSep 173 min read
04
Legislation

HSCC tells Congress that patching old medical devices is not enough, and asks for money to replace them

HSCC's Greg Garcia told a House subcommittee that patching legacy medical devices is not enough, and asked Congress to fund outright replacement alongside two pending cybersecurity bills.

HIPAA JournalSep 153 min read
05
Policy

ENISA named the coordinating CSIRTs a week before CRA reporting starts

ENISA updated its list of CSIRTs designated as coordinators on September 4, 2026, covering all 27 member states, one week before Article 14 reporting obligations apply on September 11. The Single Reporting Platform launches with no API and no support for voluntary reporting under Article 15. Registration runs through EU Login with multi factor authentication, and platform downtime does not pause the 24 hour clock.

ENISASep 43 min read
06
Enforcement

DaVita agrees to pay up to $15 million over the Interlock ransomware attack

A federal court in Colorado granted preliminary approval on August 21, 2026 to a settlement of up to $15 million in Jenkins et al. v. DaVita Inc., resolving class litigation over the April 12, 2025 Interlock ransomware attack that compromised data on 2,689,826 dialysis patients. Class members can claim up to $2,500 in documented losses plus a cash payment expected near $50.

HIPAA JournalSep 12 min read
07
FDA

FDA asks how to regulate generative AI devices, comments due October 19

FDA's device center opened docket FDA-2026-N-7874 on August 18 with a discussion paper on generative AI enabled medical devices. It floats a two-axis risk framework, competency style premarket evaluation, and risk-proportionate postmarket monitoring that folds in cybersecurity and update handling. Comments are due October 19, 2026.

FDAAug 183 min read
08
Policy

One month to CRA reporting. The MDR exemption is thinner than it looks

Article 14 goes live September 11. Actively exploited vulnerability? You owe ENISA an early warning within 24 hours. MDR devices are carved out, but your companion apps and cloud services may not be.

European CommissionAug 114 min read
09
Regulation

The MDR revision reads like a cybersecurity regulation now

Software down-classification, a well established technology pathway, and a 30 day clock on reporting exploited vulnerabilities through Eudamed. The December proposal has teeth.

Osborne ClarkeAug 114 min read
10
Policy

CISA replaced the 2021 NTIA SBOM minimum elements and added ten data fields

CISA published the 2026 Minimum Elements for a Software Bill of Materials on July 29, replacing the NTIA baseline in force since July 2021. The NSA, the FBI and 15 international partner agencies co-sealed it. Ten data fields are new, among them Component Hash Value, Component Hash Algorithm and SBOM Generation Context, and FDA premarket guidance still points at the document CISA just superseded.

CISAJul 294 min read
11
FDA

FDA posted a pen-test validation paper, and it tells you what evidence it wants

FDA added an MDIC white paper on penetration-testing validation methods to its cybersecurity page, following two MITRE papers on risk analysis and SBOM data quality. Read them as scoping hints for your submission.

FDAJun 293 min read
12
Policy

The EU pushed high-risk AI obligations for medical devices to 2028

The Digital Omnibus agreement postpones AI Act high-risk obligations for AI embedded in medical devices from August 2027 to August 2028. The transparency duties keep their 2026 date.

Gibson DunnMay 133 min read
13
Global

The UK's draft device rules add explicit cybersecurity and a change-control path

MHRA published the draft statutory instrument for its 2026 pre-market framework, adding explicit cybersecurity standards for software devices and a Predetermined Change Control Plan route for updates.

Emergo by ULMay 83 min read
14
Standards

NIST refreshed its baseline for IoT manufacturers, and IoMT is squarely in it

Final NIST IR 8259 Revision 1 restructures foundational cybersecurity activities across pre-market and post-market phases and expands what manufacturers must tell customers about support and end of life.

NISTApr 203 min read
15
Regulation

The MDR revision makes cybersecurity a core requirement, with a reporting clock

The December 2025 MDR/IVDR revision proposal writes cybersecurity into the GSPRs and adds Articles 87a/82a requiring manufacturers to report actively exploited vulnerabilities and severe incidents to CSIRTs and ENISA.

Osborne ClarkeDec 174 min read
16
Policy

Germany turned NIS2 on with no grace period, and device makers are in scope

The German NIS2 implementation law entered into force in December 2025 with immediate effect. Medical device manufacturing is a NIS2 sector, so larger makers with German operations became important entities overnight.

usd AGDec 93 min read
17
Policy

The CRA just told you which digital products need a third party to sign off

Implementing Regulation (EU) 2025/2392 fixed the technical descriptions of important and critical products under the Cyber Resilience Act, including health-adjacent categories like wellness wearables.

C-PRAVDec 44 min read
18
Global

Australia refreshed its device cyber guidance around an SBOM expectation

The TGA updated its medical device cybersecurity guidance in October 2025, tying it to Essential Principle 12 and expecting manufacturers to maintain an SBOM and total-product-lifecycle monitoring.

TGAOct 62 min read
19
Global

IMDRF greenlit a new cybersecurity work item in Sapporo

The September 2025 IMDRF Management Committee approved a new work item on cybersecurity controls and testing considerations, the kind of document FDA, PMDA, TGA and EU regulators fold into converging expectations.

MedTech EuropeSep 223 min read
20
FDA

FDA finalized its premarket cyber guidance, and 524B now has a rulebook

The June 2025 final guidance adds a section built around Section 524B: secure development evidence, a machine-readable SBOM, and a postmarket vulnerability plan, all expected in the submission itself.

Federal RegisterAug 184 min read
21
Enforcement

$9.8 million says product security is now a False Claims Act problem

Illumina settled DOJ allegations that it sold genomic sequencers with vulnerable software to federal agencies while lacking an adequate security program from 2016 to 2023. A former insider brought the case and takes $1.9 million.

MedTech DiveAug 13 min read
22
FDA

FDA counted 111 open software defect tickets at BD

A warning letter over quality system violations flagged open tickets for software defects categorized as catastrophic or severe patient harm, plus safety complaints reported late.

MedTech DiveDec 202 min read
23
FDA

FDA’s legacy device answer is still a work in progress

At The Medtech Conference, FDA’s Suzanne Schwartz called legacy device cybersecurity a work in progress and a problem regulators and industry have to solve together.

MedTech DiveOct 172 min read