WASHINGTON – U.S. Senators Bill Cassidy, M.D. (R-LA) and Tammy Baldwin (D-WI) today introduced the Protecting and Transforming Cyber Health Care (PATCH) Act, to ensure that the U.S. health care system’s cyber infrastructure remains safe and secure for American patients. Over the course of the pandemic, there have been a number of ransomware attacks within medical devices and larger networks. These attacks affect patients, hospitals, and the medical device industry.
“New medical technologies have incredible potential to improve health and quality of life,” said Dr. Cassidy. “If Americans cannot rely on their personal information being protected, this potential will never be met.”
“In recent years, we’ve seen a significant increase in cyber-attacks that have exposed vulnerabilities in our health care infrastructure, impacting patients across Wisconsin and the country. We must take these lessons learned to better protect patients,” said Senator Baldwin. “I am excited to introduce the bipartisan PATCH Act to ensure that innovative medical technologies are better protected from cyber threats and keep personal health information safe while also finding new ways to improve care.”
U.S. Representatives Michael C. Burgess, M.D. (R-TX) and Angie Craig (D-MN) introduced the companion legislation in the House of Representatives.
“The U.S. health care system is and will always remain to be a critical infrastructure,” said Congressman Burgess. “We must take action and necessary steps to ensure that it remains cyber secure. Throughout the pandemic, there was spike in ransomware attacks within medical devices and larger networks. These attacks affect hospitals, the medical device industry, and most importantly American patients. This legislation will implement cybersecurity protocols and procedures for manufacturers applying for premarket approval through the Food and Drug Administration to ensure that users are properly equipped to deal with foreign or domestic ransomware attacks. It is time to examine how to modernize and protect our health care infrastructure. I’d like to thank Congresswoman Craig, Senator Cassidy, and Senator Baldwin for joining me in this important initiative and the stakeholders involved in the process and making of this critical legislation.”
“Over the past several years, bad actors have increasingly relied on cybersecurity vulnerabilities to take advantage of unsuspecting individuals and undermine our national security. That trend is especially alarming when it comes to personal medical devices, which can be exploited by cybercriminals – threatening the health and wellbeing of countless Americans,” said Congresswoman Craig. “I’m proud to join Representative Burgess and Senators Baldwin and Cassidy in this effort to bolster security in the medical device industry and defend American patients from ransomware and other attacks.”
The PATCH Act would:
- Implement critical cybersecurity requirements for manufacturers applying for premarket approval through the FDA.
- Allow for the manufacturer to design, develop, and maintain processes and procedures to update and patch the device and related systems throughout the lifecycle of the device.
- Establish a Software Bill of Materials for the device that will be provided to users.
- Require the development of a plan to monitor, identify, and address post market cybersecurity vulnerabilities.
- Request a Coordinated Vulnerability Disclosure to demonstrate safety and effectiveness of a device.