▶ 0:18:57The subcommittee on Oversight and Investigations will now come to order. The chair now recognizes himself for five minutes for an opening statement. Good morning and welcome to today's hearing entitled Aging Technology Emerging Threats Examining Cyber Security Vulnerabilities in Legacy Medical Devices. Legacy medical devices are medical devices that cannot be reasonably protected against current cyber security threats.
▶ 0:19:24In some instances, these are older devices that were made before existing cyber security requirements were established, but they can also be newer devices that have outdated software and lack the necessary cyber security protections required to defend against current threats. There's a broad range of medical devices that can be vulnerable to cyber security threats, but examples include patient monitors, infusion pumps, and imaging systems.
▶ 0:19:50With over 6,000 hospitals in the United States, each housing a range of rooms and beds and an average of 10 to 15 connected devices per bed, it is clear how integral medical devices are to delivering healthcare in the United States. One challenge with these devices that the hardware can last 10 to 30 years, but the software becomes obsolete much sooner.
▶ 0:20:12Patching and updating software are common ways to address cyber security vulnerabilities, but is unlikely that such vulnerabilities can be sufficiently mitigated through these approaches due to outdated technology and compatibility issues. Moreover, merely replacing devices comes with financial and logistical challenges which leads many hospitals to retain these legacy medical devices well beyond their life expecties. often without the software support to handle modern cyber security risk.
▶ 0:20:38This is particularly true in small rural and underresourced facilities making it crucial to find practical solutions. Is also important to recognize that the healthc care sector is one of the 16 critical infrastructure sectors in the United States and has become a significant target for cyber attacks. For example, in 2017, the global wan to cry ransomware attack severely impacted the health care sector.
▶ 0:21:03In the United States, medical device manufacturers rushed to patch affected devices after Wuk cry showed that malware could jump from PCs to embedded medical devices. This attack demonstrated how unpatched older Windows-based systems and medical devices can be immobilized by ransomware. Additionally, the risk of harm to patients is big is a big concern because if a medical devices vulnerability is exploited, the ability for a device to help monitor, diagnose, or treat a patient can be compromised.
▶ 0:21:34There's also national security concerns. On January 30th, the Cyber Security and Infrastructure Security Agency and the Food and Drug Administration released an alert about a Chinese-made patient monitor that had a hidden back door that could enable remote control and data While the vulnerability may have been unintentional, it raised concerns and highlighted the risk of nation state actors prepositioning destructive malware in our healthcare sector as part of a potential large-scale cyber attack
▶ 0:22:04to disrupt one of our nation's critical infrastructure sectors. Progress was made to address legacy medical devices in 2022 with the enactment of the patch act, which increased FDA's authority over medical device cyber security. The law now requires manufacturers to submit cyber security plans for new devices. Legacy medical devices that were on the market before this law took effect, however, still pose a significant risk. Therefore, addressing cyber security threats and legacy medical devices is critical.
▶ 0:22:35Fortunately, thanks to the ongoing work of the experts represented by our witnesses today, we have valuable partnerships and coordinated efforts to help address these risk and threats. I thank our witnesses for joining us today and sharing their expertise to guide the efforts in addressing these challenges and look forward to their testimony. The chair recognized subcommittee ranking member Miss Clark for five minutes for an opening statement. Thank you, Mr.
▶ 0:22:59Chairman, and I I thank our witnesses for appearing before us today and bring your expertise to bear. However, I'm deeply alarmed by the Trump administration's announcement that the Department of Health and Human Services is DOA's next target.
▶ 0:23:15HHS Secretary Kennedy has announced that he is terminating 20,000 positions and shuttering regional offices across the country, creating further chaos and turmoil for federal employees and the people who depend on the services they provide.
▶ 0:23:32I have difficulty seeing how we can have a hearing about how the FDA should approach legacy medical device cyber security without first addressing the fact that the Trump administration and Doge are dismantling the very agency responsible for medical device safety. The Trump administration's attacks on the health and safety of the American people have already done serious damage.
▶ 0:23:56proposed cuts to the National Institutes of Health grant funding for medical research, abrupt terminations of research projects already underway, and cancellations of advisory committees and review panels are stifling the scientific community. The government's partnership with the scientific community made the United States the undisputed global leader in scientific research and innovation for decades, and now that is being recklessly destroyed.
▶ 0:24:23Just last week, Peter Marx, who served as a crit a critical role at FDA by overseeing the regulation of vaccines, was forced to resign. And in his resignation letter, he stated that quote, "It has become clear that truth and transparency are not being desired by the secretary, but rather he wishes subservient confirmation of his misinformation and lies." End quote.
▶ 0:24:49In February, Elon Musk and Doge made the first workforce cuts to HHS and other agencies across the government, targeting probationary employees. Those terminations included hundreds of new hires from the Center of Device and Radiological Health or CDR, who had been recruited because of their expertise in artificial intelligence and other technological fields that support a review of medical devices.
▶ 0:25:16It took about a week for Elon Musk to realize the value of the work these employees were doing and many were offered reinstatements. We need to know how many employees have returned to CDR and which positions are still vacant. The administration has not provided us that information despite several requests from Democratic members and staff.
▶ 0:25:37After two federal judges ruled all of the probationary employees had been fired illegally, the administration has appealed to the Supreme Court to avoid complying with the court orders. We don't know. We yet don't know exactly how many of the 3,500 FDA employees are expected to be fired according to Secretary Kennedy's latest announcement work on medical device cyber security.
▶ 0:26:04HHS claimed that the medical device reviewers will not be affected, but said nothing about the many officials who are not considered reviewers, but do in fact support the pre-market review process and assess reports of postmarket adverse events. Securing medical devices being used in healthc care facilities and for home care every day requires coordination between the FDA, manufacturers, and providers.
▶ 0:26:31Congress passed an appropriations bill in 2022 that tasked FDA with improving its process to strengthen cyber security of medical devices to protect against malicious activity that threatens healthcare institutions and individual patients. Medical device manufacturers must meet enhanced cyber security standards in their pre-market applications to FDA and also conduct postmarket monitoring of adverse events.
▶ 0:26:58This process is intended to provide clarity for manufacturers and hold them accountable for the safety and effectiveness of the products they are bringing to market. The standards become completely irrelevant, however, if FDA doesn't have the capacity to assess whether applicants have met the standards. Day by day, the instability caused by the Trump administration is further undermining the ability of HHS divisions to carry out their public health missions.
▶ 0:27:28If Secretary Kennedy moves forward with the Doge plan to cut a quarter of the HHS workforce, including the 3,500 FDA staff, any progress FDA was making on cyber security review would be erased. The agency will have lost the people it needs to carry out fully informed cyber security reviews of devices and patient security will suffer as a result. This chaos is totally unnecessary.
▶ 0:27:58President Trump and Elon Musk are intentionally making broad unjustifiable cuts to the HHS workforce with no regard for the consequences on the health and well-being of the American people. It is impossible to make government work well with an administration in charge that is intent on dismantling it. And unfortunately, congressional Republicans are letting the destruction happen without the slightest push back.
▶ 0:28:24I urge the majority of this committee to prioritize our oversight authority and hold hearings with administration officials responsible for these attacks on our nation's health. And with that, Mr. Chairman, I yield back. Thank you. Uh the chair rec now recognizes the chairman of the full committee, Mr. Mr. Guthrie, for five minutes for an opening statement. Thanks, Chairman Ballerson for uh for holding this important oversight hearing on cyber security vulnerabilities and legacy medical devices.
▶ 0:28:54Uh the vulnerabilities in these devices pose serious risks to patient safety, care delivery, and the resilience of our healthcare infrastructure, which makes it critical to our healthcare e ecosystem and national security that we examine this issue. Legacy medical devices are devices that cannot be reasonably protected against current cyber security threats regardless of when they were manufactured.
▶ 0:29:17These include technologies such as patient monitors, infusion pumps, implantable devices, and diagnostic equipment that hospitals and patients re rely on every day. According to a cyber security firm reported report cited by the FBI, as of January 2022, 53% of connected medical devices and other internet of things devices in hospitals and known have had known critical vulnerabilities. This figure illustrates the potential scope of the problem.
▶ 0:29:46In 2022, Congress passed the Patch Act, which enhanced the FDA's authority over cyber security for new medical devices. This was an important step forward, but it only applies to new devices, leaving old devices unressed. This leaves a significant gap in our and extremely concerning hopefully to everybody in this room.
▶ 0:30:07In January, the federal government issued an alert about the discovery of a patient monitor made in China that had been with the US in the US market since 2011. The device made by contact a medical systems in China was configured to connect to an IP address belonging to a university in Beijing which had no appar no apparent connection with the manufacturer. I think we can guess what the connection is.
▶ 0:30:36Um, according to the cyber security and infrastructure security agency, the backdoor enables the IP address at the university to remotely download and execute unverified files on the patient monitor. Moreover, a cyber security firm noted that hackers working from the university to which the patient monitors backdoor is connected targeted US energy companies, communications companies, and state government of Alaska in 2018.
▶ 0:31:07Regardless of whether the patient monitors just a lowquality product with inadequate cyber security controls or as I believe the design was intentional, the discovery is concerning from a patient safety and national security perspective. FDA issued a safety communication with recommendations for healthcare providers and patients on how to mitigate the risk with this device.
▶ 0:31:31While we thankfully have no indication of direct harm caused by the vulnerability in these patient monitors, the risk identified calls attention to the patient safety risk posed by the vulnerabilities and legacy medical devices.
▶ 0:31:44Another example that is illustrative of these risk is that there have been case quote there have been cases where insulin pumps have been hacked and this security flaw meant that hackers could raise dose limits without the patients knowledge or consent Additionally, compromised devices can serve as entry points for larger network attacks, potentially disrupting hospital operations or exposing sensitive patient data.
▶ 0:32:10Stakeholders, including medical device manufacturers, healthcare delivery organizations, cyber security experts, and the federal government have been coordinating to address these risks, but the challenges remain. We must continue to support these efforts to ensure comprehensive protection of our healthc care infrastructure. I thank Chairman Palmer for holding this hearing. I thank chair um chair Troy Troy for Holderson for doing this.
▶ 0:32:36Boulders for doing this and uh this discussion will help us to continue addressing the press technological concerns, protect patients and help close security gaps. Again, Chair Balderson, I appreciate this and I look forward to hearing from our witnesses. And I yield back. Thank you, Mr. Chairman. And the chair now recognizes the ranking member of the full committee, Mr. Palone, for five minutes.
▶ 0:33:02Uh the top of this topic of this hearing, while important during normal times, is deeply divorced from the reality that we're in. The Trump administration has launched an unprecedented attack on the federal health workforce, but committee Republicans are ignoring that fact and instead examining the narrow issue of cyber security in legacy medical devices. In fact, at this very moment, there are civil servants at HHS buildings who have shown up to do their important work, but are being told that their position has been terminated.
▶ 0:33:32And I think they deserve much better than how they're being treated now. And this is really a shameful day for for the Trump administration. What we really should be doing is conducting oversight of how the Department of Health and Human Services and the Food and Drug Administration are supposed to function after massive restructuring and layoff announcements. Last week, HHS Secretary Kennedy announced his plan to cut 20,000 full-time employees from the department. That's 25% of the AY's total workforce.
▶ 0:34:02He also wants to consolidate the functions of several operating divisions. Kennedy claims that healthc care services will not be harmed by the dramatic downsizing, but he's wrong, and everyone who's paying any attention knows that he's wrong. You can't cut 3 thou or 3,500 employees from FDA and say to the American people that there will be no effect on their health and safety.
▶ 0:34:21You can't cut 2 2400 employees from the Centers for Disease Control and Prevention, some of whom are working to protect the public against bird flu and measles that are actively spreading through our communities, and tell the American people everything's just going to be fine. And you can't cut 20,200 scientists from the National Institutes of Health and say that America will continue to be at the cutting edge of innovation and developing life-saving medical breakthroughs.
▶ 0:34:44This needless destruction is already hurting people and will only get worse unless congressional Republicans join Democrats in demanding accountability and saying enough is enough. Secretary Kenny must testify before this committee immediately on this drastic action and how it will affect public health and safety. And it's also inexcusable that the Republican majority has ignored committee Democrats requests for an oversight hearing on the measles outbreak that has already resulted in two deaths and 483 cases across 31 states in the District of Columbia.
▶ 0:35:14There have already been more cases of measles than was reported all of last year. And this is a disease that was declared eradicated 25 years ago, but that status is in serious jeopardy with experts telling us the outbreak might rage on for a year. In addition to massively downsizing the CDC that responds to outbreaks like these, Secretary Kennedy has pushed unproven treatments while stripping billions of dollars of grant funding from local health departments, including in Lubuk, Texas, which is the center of the measles outbreak.
▶ 0:35:43And last week, the Trump administration pushed out Dr. Peter Markx, the FDA's top vaccine official. In his resignation, Markx wrote, and I'm quoting, "It has become clear that truth and transparency are not desired by the secretary, but rather he wishes subservient confirmation of his mismanagement and lies." Unquote. This is a crisis that the Trump administration is actively making worse. And yet, committee Republicans have refused to schedule a hearing on this critical issue.
▶ 0:36:09The American people cannot wait any longer for congressional Republicans to start holding this administration accountable. We've had numerous cyber security hearings over the years. We know cyber security and healthcare is a problem that needs to be addressed. But nothing will improve if thousands of federal employees who work to solve health challenges every day are laid off. FDA cannot address cyber security vulnerabilities of legacy medical devices if cyber security experts at FDA are fired.
▶ 0:36:35And we still don't have firm details on the results of the first round of Doge layoffs at HHS. Committee. Democrats have asked multiple HHS agencies for specific details about how many employees were terminated, what programs they're working on, how many were reinstated. These are basic questions, but none of them been have been answered by the Trump administration. We're sending another letter to Secretary Kennedy today on the massive layoffs and reorganization announced last week. It's time that this committee start getting answers from the Trump administration.
▶ 0:37:04And I invite the Republican majority to exercise oversight and join us in our request for information. Maybe they'll have better luck at getting some answers. Under ordinary circumstances, I would welcome a hearing on the topic of medical device safety because it's important. But I simply cannot pretend that these are ordinary circumstances. Americans are going to get hurt by President Trump and Elon Musk recklessness and we have a responsibility to prevent it and that's what we should be doing. I just want to say, Mr.
▶ 0:37:30chairman, you know, I'm getting caretakers, doctors, constituents who are telling me that they will no longer consider advice, uh, medical, scientific advice from HHS or FDA. They think that it's not reliable. So, we've gone from where at one time we were the gold standard to now where a significant number of Americans and more every day say, "I cannot rely on the advice. I'm a doctor.
▶ 0:37:56If the if if the FDA or some CDC tells me to do certain things, I have to assume that it's false. It's a sad situation. I yield back, Mr. Chairman. Thank you, Ranking Member Palone. That concludes member opening statements. The chair would like to remind members that pursuant to the rule committee rules. All members written opening statements will be made part of the record. Please provide those to the clerk promptly.
▶ 0:38:24We want to thank our witnesses for being here this morning and taking the time to testify before this subcommittee. You have the opportunity opportunity to give an opening statement followed by a round of questions from members. Our witnesses today are Dr. Christian Damoth, an emergency physician. I hope I got that correct, sir. Emergency physician and co-director of the center for healthc care cyber security at the University of California San Diego Health. Next is Mr.
▶ 0:38:53Greg Garcia, the executive director of the Healthc Care Sector Coordinating Council Cyber Security Group. We also have with us today Mr. Eric Decker, the vice president and chief information security officer of Inter Mountain Healthcare. We also have with us Miss Michelle Jump, the chief executive officer of MedSack. And finally, Dr.
▶ 0:39:16Kevin Fu, a professor in the department of electrical and computer engineering at Kilroy College of Computer Sciences, Department of Bioengineering and Kostas Research Institute, KRI for Homeland Security at Northeastern University. We appreciate you being here today and I look forward to hearing from all of you.
▶ 0:39:42You are all aware that the committee is holding an oversight hearing and when doing so has the practice of taking the testimony under oath. Do you have an exection objection to testifying under oath? Any of you? Seeing no objection, we'll proceed. The chair advises that you are entitled to be advised by councel pursuant to house rules. Do you desire to be advised by councel during your testimony today?
▶ 0:40:08Seeing none, please rise and raise your hand. Do you promise to tell the truth, the whole truth, and nothing but the truth? So help you God. Thank you. Seeing the witnesses answered in the affirmative, you are now sworn in under oath and subject to the penalties set forth in title 18 section 10001 of the United States Code.
▶ 0:40:39With that, we will now recognize uh Damf Damoth for five minutes to give an opening statement. I I would uh let all the witnesses today also know that we have time frames. When you see the yellow light, that means you're down to almost done. And then when you see the red light, we'd like you to wrap up. So in cognizance of a time, but with that uh Dr. Imoff for five minutes to give your opening statement.
▶ 0:41:09Thank you, Chairman Guthrie, Chairman Palmer, Ranking Member Palone, Ranking Member Clark, and distinguished members of the subcommittee. Thank you for the opportunity to testify today. My name is Dr. Christian Deth, and I'm a practicing emergency medicine physician. I'm a little different than your typical emergency room doctor, however. I'm a hacker. I now conduct research on the patient safety impacts of cyber attacks as co-director of the UC San Diego Center for Healthcare Cyber Security.
▶ 0:41:34In over my 15 years of medical training and practice, I have treated thousands of patients in over a dozen healthcare systems. I have worked at large academic medical centers and small rural hospitals. Across all healthcare settings, I know this to be true. Medical devices are miraculous. Doctors and nurses use them every day to restart stopped hearts, deliver life-saving medications, and precisely target disease. At their core, many modern medical devices are just computers. And this means there will be unavoidable flaws in software and hardware.
▶ 0:42:04Flaws that can be exploited by malicious hackers and our nation's adversaries. The truth when it comes to the cyber security of medical devices is that we lack many of the basic statistics needed to understand this threat. Legacy devices are ubiquitous across our hospitals. But how many? Which types? How secure or not? These are all open questions that exist in a vacuum of data. Such as the case with contact and the next dozen devices we find with significant vulnerabilities.
▶ 0:42:33No one knows how many CMS 8000s there are in US hospitals or where they are. The FDA has done a tremendous job over the last 12 years of improving the cyber security of medical devices. However, it is critical to understand that cyber security is not a solvable problem. Cyber security is a dynamic and ever evolving game of cat-and- mouse. Attack methods of the past have waned with improved defenses only to be reinvented to exploit new vulnerabilities in an ever raging virtual arms race.
▶ 0:43:01The modern medical devices of today are the legacy medical devices of tomorrow. And this paradigm is unlikely to change. The financial and operational stress that rural and critical access hospitals are currently under means they are unable to invest in the latest generation of medical devices. Many are using medical medical devices that are no longer supported by their original manufacturers.
▶ 0:43:22I have personally witnessed a hospital system struggling to fix an old CT scanner and ultimately resorting to purchasing parts off of eBay because of the cost of a new scanner being prohibitive. Financial considerations aside, many rule and critical access hospitals also lacked a necessary workforce. The unique combination of cyber security ability and biomedical engineering talent required to properly deploy, proactively patch, and continuously protect legacy devices is scarce even in urban, heavily populated regions.
▶ 0:43:53I respectfully offer three recommendations for consideration. One, national healthcare dependency mapping. Strategic cyber defense of our critical healthcare infrastructure requires identifying weak points in hardware, software, vendors, supply chains, cloud computing, and networks. How can we defend hospitals against malicious hackers and highly skilled state actors when we ourselves lack even a basic understanding of the interconnections and dependencies that sustain the overall system?
▶ 0:44:23I support the important work led by the Health Sector Coordinating Council to map healthc care's dependencies and associated risks. Two, we need to remove barriers to security research. The progress made over the last decade on improving medical device cyber security is commendable, but credit must also be given to the seminal work of ethical hackers and security researchers who first demonstrated these medical device vulnerabilities. Efforts to continue to make devices available for security research should be encouraged.
▶ 0:44:51Legal protections for ethical hackers and security researchers acting in good faith and using coordinated research coordinated disclosure practices should be strengthened. Current DMCA exemptions related to medical device cyber security research should be made permanent to ensure the exact type types of discoveries like the contact vulnerability happen again. Build and automate resilient systems.
▶ 0:45:14The enormous effort required not not just to respond to known vulnerabilities but proactively discover new threats and patch them at scale is hard to comprehend. Government leadership in the form of evidence-based policy development and research support coupled with innovative technology solutions from industry and academia may provide the force multiplier needed to address these threats.
▶ 0:45:35The universal patching and remediation for autonomous defense upgrade program created by ARPAH provides one such example of a next generation approach to legacy medical device cyber security by innovating new ways for hospitals to proactively defend their legacy devices. If successful, technologies from this program may transform how we approach medical device cyber security. In conclusion, legacy medical device cyber security vulnerabilities threaten our ability to deliver care to our patients when it matters most. But we can make progress on this pressing challenge.
▶ 0:46:05I applaud the committee's leadership on this critical issue. I'm optimistic that we can improve cyber resiliency in healthcare and sincerely thank you for your opportunity from this opportunity to share my perspective and Thank you very much. Uh Mr. Decker, five Thank you, Chairman, uh, Chairman Palmer, Vice Chairman Balderson, Ranking Member Clark, and members of the subcommittee. In the health sector, we believe cyber safety is patient safety.
▶ 0:46:35I'm Eric Decker, vice president and chief information security officer for Inter Mountain Health and former chair of the health sector coordinating council's cyber security working group. Inner Mountain is a nonforprofit integrated health system with facilities in six states: Colorado, Idaho, Montana, Nevada, Utah, and Wyoming. Thank you for the opportunity to speak on behalf of Inner Mountain to share the thoughts on aging technology, cyber threats, and achieving defensive resilience of our critical health sector. I will seek to address the following questions.
▶ 0:47:05Who are our adversaries and how do they operate? How are we defending medical technology? How can we leverage shared defense to better? The health sector is is a utility largely owned and operated by private entities. Yet, as a society, we rely on the safe and 247 availability of care. Thus, we must tackle this problem together. The federal government and the private health sector working in close collaboration. I'd like to focus on two cyber adversarial groups.
▶ 0:47:34Nation state actors and organized crime. Nation state actors are state sponsored and backed with the resources of their respective national intelligence apparatus. Their motives are primarily focused on intellectual property theft for economic gain and positioning for advantage in case of a geopolit political conflict.
▶ 0:47:51To illustrate, the five eyes and and the cyber security infrastructure security agency warned about Volt Typhoon, a Chinese state-backed hacking group targeting US critical infrastructure to preposition malware in anticipation of a cyber conflict. It is unknown if similar prepositioning has occurred in medical devices.
▶ 0:48:11The second adversarial group is organized crime who generally present themselves as Russian-speaking financially motivated criminal actors that regularly target the health sector through ransomware attacks. These attacks can also cause disruption to medical technology. The sophistication of the nation state and organized crime threat groups is evidenced by their ability to run cyber operations at scale.
▶ 0:48:34They use the tactics such as social engineering, exploitation of internet accessible vulnerabilities and attacks on connected third parties. We should defend accordingly. The good news is the health sector and the federal government have been actively collaborating to do so since 2018 under the cyber security act of 2015's section 405D. We produced the health industry cyber security practices managing threats and protecting patients publication also known as hiccup.
▶ 0:49:02Hiccup was aligned to the NIST cyber security framework and serves as a how-to guide for implementing 10 key cyber practices. It is a dedicated has a dedicated section focused on managing medical device security. However, in the 2024 hospital cyber resiliency landscape analysis, another jointly produced and freely available study, we saw that only 55% of hospitals have implemented the medical device security practices recommended in Hiccup. It's understandable why these practices are lagging.
▶ 0:49:30For example, to ensure the clinical effectiveness of medical devices before patches can be applied, they must go through vigorous quality checks and testing to ensure the device will continue to operate in a safe manner. This intrinsically introduces a time lag in patching vulnerabilities. We've made progress with incentives.
▶ 0:49:47As part of public law 116321 signed by President Trump in January of 2021, Hiccup was identified as a recognized security practice which provides relief to organizations who have adopted it in the case of a regulatory enforcement. More incentives especially for small, rural, and underresourced organizations as needed. I'd like to highlight three recommendations to establish a better collective set of defenses and more within my written testimony.
▶ 0:50:14Number one, as of March 7th, all 16 critical infrastructure policy advisory committees were disbanded through executive order. We urgently need these reestablished so we can get back to work on securing our critical infrastructure without fear of our most sensitive vulnerabilities being publicly exposed. The critical infrastructure policy advisory committees allow for crit all critical infrastructure sectors to partner with their respective federal agencies in a protective forum.
▶ 0:50:40Number two, leverage the private private sector clearance program and the cyber security working group to get more cyber security professionals cleared for participation. This is then establish a joint task force among industry, academics, and our intelligence agencies to study the very real threat of nation state actors attacking and compromising medical technology.
▶ 0:51:00We need to connect the dots between national security intelligence and the critical infrastructure cyber Number three, and finally, promote the health sector's cyber security working group, which is free to join, and actively amplify the materials and solutions developed by this working group. In closing, and in words of Chris, the nation's first cyber security director, we must build our critical infrastructure in such a way that one would need to quote beat all of us to beat one of us. End quote. I welcome your questions.
▶ 0:51:31Thank you, Mr. Decker. Jump. Five minutes. Good morning, Mr. Chairman, Vice President Balderson, Vice Vice Chairman, excuse me, Ranking Member Clark, and members of the committee. Thank you for inviting me to testify today on the challenges of managing security of the healthcare critical infrastructure.
▶ 0:51:53I'm Michelle Jump, CEO of Medssek, a compliance and technical services firm dedicated to helping medical device manufacturers and hospitals to develop and maintain more secure medical devices. While our organization is not large, our footprint is. Taken together, the combined revenue of our clients represents over 70% of the global market. We partner with these clients to develop their product security programs, navigate their regulatory goals, and perform penetration tests on their devices.
▶ 0:52:23Prior to this, I worked as a regulatory expert within various large medical device companies. I've also spent the last 15 years working in both domestic and international standards to drive better practices. I've made it my life's goal to support this work and have been witness and a contributor to the significant gains that we've achieved and to make and to make medical devices safer and more secure for the patients and users who depend on them. One of my specific areas of specialty is risk management.
▶ 0:52:52As such, I am glad to see the committee committee focusing on this important issue today. Over the past 12 years, I've seen the industry take great strides in the pursuit of more secure devices. When the FDA released its first pre-market cyber security guidance back in 2013, very few medical device manufacturers employed dedicated cyber security engineers, nor did they have other staff focused on this particular challenge.
▶ 0:53:18As larger medical device manufacturers started investing in focused cyber security programs, they began speaking out and sharing best practices. FDA's initial efforts brought this group of stakeholders together and hosted workshops. While the first FDA meeting back in 2014 fit into a small room, I was there.
▶ 0:53:39Um the one in 2016, it filled an entire conference Today the bar the FDA bar for cyber security is the highest in the world and new laws from Congress have enabled the FDA to enfor enforce cyber security on its own merit. This has driven the most effective push for cyber security compliance that I've seen in my career.
▶ 0:54:03There's one point that I'd like to successfully convey in my testimony today and that is that people and process are issue or as much of this issue as a technical one. While the regulatory oversight may be impactful in driving the industry to do better, we can't regulate ourselves out of this issue. While new technology, better encryption, powerful tools continue to become available. This will not solve our problem completely.
▶ 0:54:29We don't have enough skilled people with security knowledge to help protect the patients and care systems from the growing cyber security threats. Another significant driver of the Lexi issue is that medical devices are built using numerous software components, many of which are developed and maintained by thirdparty vendors. These may include commercial operating systems, um, communication protocols, and open source libraries.
▶ 0:54:54While these components enable innovation and efficiency, they only often they are often only supported by these component developers for a limited amount of time. Once that support ends, the component and therefore the medical devices become increasingly difficult to secure. This creates a mismatch. Medical devices used in clinical environments to 10, 15 or 20 years, but their underlying software components may only be supported for a fraction of the time. As a result, devices that were secure at launch become vulnerable.
▶ 0:55:24It is not just the medical devices that are vulnerable, but the whole healthcare infrastructure, which is not regulated in the way that medical devices are. So, why not just replace all the outdated devices, you might ask? Unfortunately, it's not that simple. Most hospitals cannot afford to replace medical devices as they age at the pace needed to keep up with these software changes and the life cycle. As these devices age and manufacturers and support, hospitals are often less to assume the associated risk.
▶ 0:55:51However, taking on this responsibility requires more than acceptance. It dep demands careful and proactive management. So, what do we do? Manufacturers need to commit to patching as many vulnerabilities as possible, not just those that are unacceptable and do so on a regular ba on a regular basis as part of maintenance. I also support hospitals leveraging the cyber performance goals to better secure their networks and also maintain better asset inventories to know what they have to protect.
▶ 0:56:18In closing, I would like to share my opinion that what I have seen develop in this space over the past 12 years, this community of stakeholders has come together to achieve great things in this space and I think that if provided more resources, especially for smaller and rural hospitals, this will continue and we will hold the line on cyber security, but it will take effort. Thank you. Thank you, Miss Ch. Mr. Garcia, five minutes. Okay.
▶ 0:56:48Um, Mr. Chairman, ranking member Clark, members of the committee, thank you for inviting me to testify about healthcare and medical device cyber security. I am Greg Garcia, the executive director of the Health Sector Coordinating Council's Cyber Security Working Group or CWG and I'm also the nation's first assistant secretary for cyber security and communications for the US Department of Homeland Security from 2006 to 9.
▶ 0:57:10Uh the CWG is a government recognized critical infrastructure industry council of more than 470 health care providers, pharmaceutical and medical technology companies, payers, health IT entities, and government agencies. We partner with government to identify and mitigate cyber threats to health data, research systems, manufacturing, and most importantly, patient care.
▶ 0:57:36The CWG membership collaboratively develops and publishes free healthcare cyber security leading practices and policy recommendations and we produce outreach and communications emphasizing the imperative that cyber safety is patient safety. We're glad the committee is taking up the important issue of leg legacy medical device security. It is a complex issue involving technical, operational and business interdependencies between manufacturers and health providers.
▶ 0:58:03And while cyber attacks more often go through medical devices to reach other healthcare data than they actually target the devices for disruption, we cannot ignore the many vulnerabilities in both new and devices. But we also cannot ignore how the broader healthcare ecosystem is the most targeted now of all critical infrastructure sectors by both criminal criminal gangs and nation states. As Mr.
▶ 0:58:31Decker attested, "This fact requires a more urgent effort by public private partnerships to protect health care systems that cannot match the fire power nationstate cyber trade craft. For our own part on medical device security alone, the CWG has published five extensive cyber security practices that were negotiated between medical device product manufacturers and health providers.
▶ 0:58:58These publications guide manufacturers and health systems on how to one design and build cyber security into medical devices from the ground up rather than bolted on later. To manage the security of medical devices as they age in the clinical environment recognizing it is a shared responsibility. to write model terms and conditions into contracts for the sale and service of medical devices.
▶ 0:59:24To deliver simple and actionable and consistent cyber security vulnerability communications related to products or services to respond and recover from cyber incidents that impact computer-controlled medical manufacturing. and still to come soon later this spring to safely and cost-effectively patch and update devices used in the clinical environment.
▶ 0:59:47While we continue to improve on these practices, cost and operational pressures among both manufacturers and health providers continue to complicate uniform implementation. But a key point to be made is that the health sector is an interconnected interdependent ecosystem. We cannot address the security of our medical device manufacturing in a vacuum.
▶ 1:00:08We must scrutinize uh the sec the the pro procurement of unregulated software and components that support medical devices uh and other network systems and the government needs to bolster its counter espionage capabilities to protect America's critical infrastructure from nationstate cyber attacks. So there are many moving parts. Fixing a flat tire won't do us much good if the steering column is loose and the oil warning light is dark.
▶ 1:00:35So let me let me summarize with recommendations relative to the importance of medical device cyber security. First, we submitted to the administration yesterday a policy statement which I would ask be entered into the record. In it, we recommend initiation of a consultative process between the health sector and the government that starts with the best practices that we have developed by the sector for the sector and jointly with HHS.
▶ 1:01:00This process would supplant one-way government regulation that presumes the best way to do things with a more deliberate pathway toward eventual requirements for minimum minimum cyber security accountability. Such discussions could include, for example, recommendations that CMS review bundled payments to more thoroughly account for the expense of medical devices and the need to keep devices patched and update.
▶ 1:01:23uh development and enforcement of higher standards of secure by design, secure by default for otherwise unregulated thirdparty technology and service providers that sell into critical healthcare infrastructure and medical manufacturers. This recommendation uh involves our national effort to diagram essential medical workflows supported by critical third-party services and functions that Dr.
▶ 1:01:46DEF referred to that can cause systemic risk and cascading damage to patient care and operational resiliency if they are disrupted. Finally, in closing, mobilization of a more reflexive government and industry intelligence, preparedness, and rapid response capability is essential for cyber events at the federal, state, regional, and local levels, particularly against resource constrained health systems and connected medical devices. That concludes my opening statement and I look forward to discussing your questions.
▶ 1:02:17Thank you, Mr. Garcia. Dr. Fu, five minutes, please. Good morning, uh, Chairman Balderson, Ranking Member Clark, and distinguished members of the committee. Uh, thank you for the opportunity to provide testimony on the critical issue of cyber security vulnerabilities in legacy medical devices. Uh, my remarks today are informed by my over 30 years of working in healthcare and cyber security, despite my looking youthful.
▶ 1:02:41uh and uh include my previous experience as the inaugural acting director of medical device security at FDA's center for devices and radiological health. I'm a professor at Northeastern University in Boston, Massachusetts, where I conduct fundamental cyber security research. I teach medical device security engineering and I serve as the director of the Archimedes Center for Healthcare and Medical Device Cyber Security.
▶ 1:03:06My educational uh qualifications include three degrees from MIT and today I am speaking as an individual. All opinions, findings and conclusions are my own and do not necessarily represent any views of my past or present sponsors or employers. Let me make a few observations. If we fail to better manage the cyber security risks of legacy medical devices, the consequences are not theoretical. They are immediate and potentially life-threatening.
▶ 1:03:34In 2008, I co-led a research team that wirelessly exploited a legacy implantable defibrillator, demonstrating how an attacker could induce fatal heart rhythms wirelessly without physical contact. These are not abstract scenarios. Devices with similar insecurities remain in hospitals today.
▶ 1:03:54A bad actor who discovers a vulnerability could disable patient monitors during surgery, spoof vital signs and intensive care units, or hijacked infusion pumps to administer incorrect dosages. Without proactive cyber security measures, including postmarket oversight, we risk turning these life-saving equipment into attack services that endanger patient safety. Now, a legacy medical device is one that is not merely insecure, but is insecurable.
▶ 1:04:25Its software simply cannot be patched. It was never designed to be patched. It's the difference, in my opinion, between an unbuckled seat belt versus a car without any seat belts at all. Unsafe at any speed. While these devices are vital to patient care, many lack the necessary security features to defend against a modern threats.
▶ 1:04:45They often operate on unpatchable software and unsupported operating systems, making them vulnerable to attacks that can disrupt clinical operations or endanger patient safety. Unlike consumer smart home devices, failures in medical device cyber security can have life consequences. With regards to the cyber security concerns of the contact patient monitor, in my opinion, the cyber security flaws are likely the result of poor engineering rather than malice. although I previously suspected malice.
▶ 1:05:16Um, however, a key lesson from that advisory is that the FDA scrutiny of legacy medical devices should not simply be about pre-market, but needs to also focus on postmarket risk management. Moreover, in my testimony uh to this committee nine years ago, I emphasized that the nation lacks an independent largescale testing facility such as those comparable to the NTSB automotive crash safety testing or the Nevada National Security Test Site for destruction and survivability testing.
▶ 1:05:46Such proving grounds would be essential for evaluating the cyber security defenses of medical devices in whole hospital environments. In my written testimony, I offer several recommendations to manage these cyber security risks, but let me just highlight one this morning. Um, for patient safety and national security, I believe it's important to preserve and expand FDA's in-house cyber security expertise.
▶ 1:06:11Postmarket vulnerability management requires FDA staff with deep technical expertise in cyber security, not just regulatory affairs. And these cyber security staff are crucial to national security and are not necessarily the same as the pre-market review team. But these are often nonreview staff who monitor and manage newly discovered vulnerabilities and incidents and coordinate.
▶ 1:06:35These subject matter experts are essential for evaluating the risks, working with manufacturers on coordinated vulnerability disclosures, and issuing effective guidance. The loss ofme capacity at FDA would seriously hinder national readiness to respond to emergent threats, posing risks to security.
▶ 1:06:55In my opinion, if two cyber security incidents were to occur simultaneously at present staffing levels as of yesterday, it's unlikely the FDA would be able to meet its congressionally mandated duties to ensure the availability of safe and effective medical devices. Um in summary I believe that cyber security is not a problem but rather it's part of the solution to protecting uh medical devices.
▶ 1:07:20It enables trust in medical technologies and ensures continuity of patient care. Legacy medical device security is spoiled milk not fine wine. It does not age gracefully. It's lumpy. Uh with that uh I'll end here and I thank the committee for your leadership and bringing attention to this important problem and I'd be happy to respond to your questions. Thank the witnesses for your testimony and we'll now move to questioning.
▶ 1:07:48I will begin and recognize myself for five minutes. Mr. Decker. According to a research report cited in a September 2022 FBI cyber notification, as of January 2022, 53% of connected medical devices and internet of things devices in hospitals had known critical vulnerabilities.
▶ 1:08:13Are there uh updated estimates on of how many legacy medical devices are currently in use across uh the US health care system? So I think uh Dr. Christian Death kind of mentioned this in his opening comments. The the problem is actually sort of unknown as far as how many of these devices exist especially when we start talking about the concept of what is legacy versus what is uh non-leacy devices. This is an undefined term.
▶ 1:08:42uh if we decided that it was based on the patch act and things that were all devices that were released postpatch act, we're still very early in the the phases of those devices sort of entering the market. Now you can we can estimate how many devices we think exist. So if you look at uh inside any typical hospital you have for any bed you have between 10 to 15 8 to 10 8 to 15 some devices connected to it.
▶ 1:09:09uh there's uh stats that show there's about nine uh 913,000 beds in the United States. So extrapolating that you get to about easily 10 million devices that that exist. So it's a I mean it's it's very pervasive. Uh lots of devices that are out there. Um how can a cyber security vulnerability when exploited in a legacy uh medical device directly impact patient safety?
▶ 1:09:34Is is that a a big concern that that someone would manipulate a device to harm a patient? Yeah. So the devices themselves so we we have to think of this as a connected ecosystem. So we have the the ability to sort of cause damage to a device which is uh doing that at scale is actually quite difficult to do unless there an actor has has those credentials and those accesses. Uh these devices are also connected to systems. systems run the devices.
▶ 1:10:04Uh in largecale attacks like ransomware attacks, what you see is intruders breaking into the environment, taking over the IT credentials that exist that it uses to control the whole stack of health IT and shutting down systems that they have access to, that the IT folks have access to. So if you shut down an upstream system from a medical device, then the medical device could be operating, but it's operating in a silo and standalone method.
▶ 1:10:30charge nurse sitting uh in the floor monitoring the devices from a central location would be unable to monitor that. So you you lose your scale. Yeah. Mr. Garcia, how how does the widespread use of legacy medical devices make health care sector more susceptible to cyber attacks? and and I have a particular interest in this is um there have been ransomware attacks against hospitals and I don't know that I've ever gotten a clear explanation for how those occurred.
▶ 1:11:00Would it is it possible that that an entire hospital could be subject to a cyber attack because they they gain entry through a medical device? I think there's many different ways that hackers can get into hospitals through medical devices is certainly one of them. Uh Mr. Decker um highlighted three other methods um vulnerabilities um from unpatched internetf facing devices or social engineering like email fishing.
▶ 1:11:29Um there's so many different ways that you can get into um a hospital system and um where the medical devices aren't targeted so much directly. It's more about getting money out of the hospitals when you ransom the entire hospital system and all of the data and devices. But when you do that, Mr.
▶ 1:11:47Danif, um I think there I just wonder if there's other ways that if if you had let's say the cyber attack occurred on the hospital, could there be, for lack of a better way to describe it, a backflow into a medical device where they could park uh something u that they could use Uh the theoretical um yet to be proven um example that you bring up is definitely possible.
▶ 1:12:15So some of these medical devices are just computers like are sitting right in front of you with your laptop. They can have the same type of malware on them that uh you could experience in in just run-of-the-mill infections. Those types of cascading failures are spread through those devices to the rest of the healthare system is definitely possible. We typically have seen hospital systems be ransomed by much easier ways. Yeah.
▶ 1:12:40But but once they solve the the initial attack, could they have at the same time planted something into a medical device that that you don't even pick up because you've solved the main problem in in the It's absolutely possible that a skilled adversary um someone like a state actor could deploy advanced tactics like that to persist on a network despite you trying to clean it up.
▶ 1:13:04So if hospitals then ransomed they think they can get rid of the infection to have um some type of foothold in a network in something like a medical device is likely possible. It depends on the medical device and again the sophistication of the adversary. But then again to just highlight we don't even have the cap the capability to detect those types of attacks with our normal hospitals. Our hospitals don't have advanced cyber security staff most of the time. They don't have these types of advanced tools.
▶ 1:13:33The answer to that question is is it theoretically possible? Yes. Is it likely we would discover that with what we have in place across this country? The answer is no. Thank my time has expired. The chair now recognizes the ranking member of the of the committee, Miss Clark, for her questions. Thank you very much, Mr. Chairman. According to HHS's announcement on Thursday, it'd be cutting 20,000 positions. FDA would see the largest staffing cut compared to other operating divisions.
▶ 1:14:013,500 employees will be terminated under the plan. Stripping thousands of FDA employees from their jobs all at once poses incredible risk for the public. We count on the FDA to, among other things, ensure food, drug, and device safety for the country. Top scientists at FDA and elsewhere are also resigning and being forced out by HHS leadership. Dr. for food.
▶ 1:14:29What impact could such a massive staff reduction have on the ability of the FDA to carry out its missions, including for the review, approval, and oversight of medical devices? I think any reduction would have a tremendous negative impact on the cyber security of medical devices.
▶ 1:14:48And the reason for that uh uh belief is because when I was the uh acting director of medical device security at FDA a few years ago, it was a skeleton crew, a very small number of individuals where uh it would have been already stressed at that point. Uh I think losing any of those very capable individuals, those um subject matter experts would be very difficult to address.
▶ 1:15:17uh uh the next contact kind of vulnerability or the next ransomware outage uh that affects uh at nation scale hospitals across the country. Uh it's it's really a capacity issue in my view. It takes very specific expertise and interdisciplinary skills to execute this and and FDA has some very qualified individuals on on the cyber security space. Very well. Thank you, Dr. Fu. Mr.
▶ 1:15:41Decker, in your testimony, you mentioned the FDA as a key stakeholder in securing medical devices and the ongoing collaboration that's necessary to maximize safety. Would a depleted FDA workforce negatively affect what you see as FDA's role in improving the response to cyber security threats from legacy medical devices and new devices being reviewed by the FDA? Uh yes, this it it will have an impact.
▶ 1:16:10Uh you know, this is a a three-legged stool. When we think about the medical technology, we talk about the manufacturers, we talk about the hospital organizations that deploy the medical technology, and then we talk about the FDA who help make sure the quality of the devices being released and managed post uh postmarket are entered into the environment. So all three parties, we have to partner together on that.
▶ 1:16:33And uh one of the major ways we actually do that to we used to do that is and I think we should get back to it is the critical infrastructure policy advisory committee construct. Uh all three of those parties are part of that construct. It actually allows for a lot of excellent work to happen a lot of strategy work to happen and you know potentially even policy changes that need to occur. Absolutely. Thank you. In February, DOE removed thousands of probationary employees across HHS.
▶ 1:17:01After outcry from stakeholders, particularly the medical device industry, those reverse course and HHS offered reinstatement to more than 200 employees at fired from FDA Center for Devices and Radiological Health. Our understanding is that while many of them accepted the offer to return to work, some did not. I will reiterate that the administration has not responded to Democrats requests for information about the status of the FDA employees who were fired and possibly rehired.
▶ 1:17:31So, we don't know the full fallout from the first round of firings as we anticipate the next one. Dr. Fu, does the staffing instability at the FDA interfere with its ability to efficiently conduct medical device safety oversight, including postmarket Yes, I believe it does. It would be difficult with any kind of staffing reduction to manage the postmarket or pre-market cyber security.
▶ 1:17:57And who are the specialists at the FDA who may not be a direct reviewer of device applications but still contribute to the pre and postmarket review processes by directing assisting directly assisting reviewers? Sure. Well, there are regulatory experts who understand both the technology but also the the regulatory guard rails there.
▶ 1:18:19I think those are a very special breed of communicators that are really important to connect with the hospitals, the law enforcement organizations, uh the medical device manufacturers in order to speak that language. You need more than a scientist. You need more than a technical reviewer. Very well. Well, thank you for being here today. Your expertise is invaluable.
▶ 1:18:41Uh, Secretary Kennedy claims that food and drug and medical device reviewers and inspectors ignores the many other kinds of personnel that are vital to allowing reviewers and inspectors to do their jobs. With the huge cuts they have planned, there's no doubt that the entire agency will be left severely hamstrung in the aftermath. That should be where we conduct congressional oversight immediately. I yield back, Mr. Chairman. The gentle lady yields. The chair now recognizes the chairman of the full committee, Mr.
▶ 1:19:10Guthrie for five minutes for his questions. Thank you, Mr. Chair. I appreciate that. And so, uh, Mr. Decker, Miss Jump. Um, so we're talking about backdoor medical device, what that means and in the discovery and what vulnerabilities that has and how it's concerning. So, how often do we find this type of thing? Mr. Decker, Miss Jump, if you uh, well, within medical devices specifically, it's unknown.
▶ 1:19:36You know, there was that report that came out about the contact Chinese device and uh in your opening comments, you mentioned there's two potential opportunities for that to occur. We we know that there we know that certain nation state adversaries are prepositioning themselves into critical infrastructure and other critical infrastructure have been targeted for this. So, it's certainly within the realm of possibility that that's occurring within healthcare. Okay, Miss Jump. Thank you.
▶ 1:20:06Um, I would say that as a risk expert, I think that with the increased uh enforcement of risk management efforts, pen testing, threat modeling that FDA has placed on manufacturers, not only for new devices, but also for any devices going in for a significant change of modification.
▶ 1:20:26So older devices do still go through this process that manufacturers are being forced to actually look critically at their devices across the whole spectrum the entire threat landscape of that device. And therefore I think that we are going to find more and more of these. I certainly with my clients I'm a risk management expert. We do threat modeling. We do pen testing. We help those manufacturers find those issues before they become problems and start causing issues within the healthcare industry.
▶ 1:20:53So, so when you when when you say uh you find these are they mostly Chinese or they other countries are the other countries of origin in I would any kind of back the source really the manufacturers typically vulnerabilities are not necessarily anything but design issues that people have gotten creative and figure out how to break the original design to do things that are malicious. Right?
▶ 1:21:19We're this is fighting what we're doing is we're fighting problems uh against a targeted group of people regardless of where they are in the globe and they have various reasons as as uh Mr. Garcia mentioned sometimes it's financial ransomware. If they can shut down a hospital, they can make money doing that. Sometimes it's just to disrupt critical infrastructure is a scary place and if we don't feel safe going to get health care, that can cause a problem and it can cause disruption in a society.
▶ 1:21:48But it's also for espionage as well, right? Sure. Yeah. So, if you were NIH, would you buy medical equipment from China? Like say diagnostic diagnostic equipment or any other medical devices? Uh, I'm not sure I could speak for being um in a hospital environment and what I would purchase. Well, a federal government like would the Do you think it would be more I would I would assume if you're China, an adversary like China, you're looking more well you I don't know what they look for. We know what's going on with Tik Tok, right?
▶ 1:22:17So the question is uh you think and and I believe if I'm accurate at least I've been told that our governmental institutions do buy medical equipment from China, federal government. we're a little concerned about. Would you be concerned about that? Well, first of all, if I was in that position, I would make sure that I was purchasing devices that have recently gone through the FDA's um oversight, right?
▶ 1:22:39Some kind of submission because if you've gone through the FDA in the last two years, you are under a much higher scrutiny and a much higher bar than you ever would have. Also, if you're going to be selling into the government, there is an additional bar of excellence that you have to meet in order to achieve that. So, any device, regardless of where it's purchased, if they can get through those um levels of review and acceptance, I would feel comfortable with those devices. Okay. Thanks, Mr.
▶ 1:23:09Decker. Anybody else want to kind of So, you're right. So, you have the ransomware issue, then you have the espionage issue that we we're concerned about. Dr. True. Uh I think there are examples that you need to worry about. In particular, don't forget the cloud. Uh many medical devices now use cloud technology and they're just like any other computer as has been stated. For example, there are there's published reports on nation states compromising what's known as the certificate authority.
▶ 1:23:36These are the the key managers of the world and those also affect medical devices. There have been nation statebacked ransomware that brought down cancer radiation therapy devices. So, a government entity might be purchasing a medical device and they might not even realize there's technology from country X or country Y on the inside and the manufacturer might not know as well. Okay. Well, thank you. Well, with just 15 seconds left, I really can't get to my next question, so I will yield back and I appreciate the witnesses for being here.
▶ 1:24:03This is very concerning and and uh we're be on top of it. I yield back. Gentlemen yields. Chair now recognizes the ranking member of the full committee, Mr. Palom, for five minutes for his questions. Thank you, Mr. Chairman. The staffing and funding cuts being implemented at HHS are going to have serious consequences for health care across the nation.
▶ 1:24:23And if we're going to be able to respond effectively to health crisis today in the future, we need a strong, experienced workforce at HHS and resources devoted to risk mitigation and preparedness, enabling rapid action when it's needed. So I wanted to ask um Dr.
▶ 1:24:39FU uh how do the cyber security experts and other subject matter experts support the medical device reviewers and how might the speed and quality of device review suffer without that expertise on hand if you will? So there are there are several experts at the table I think who can opine on this as well.
▶ 1:24:59the uh uh it's there's a council of uh I would say a council of elders who've been through special cyber security training who helped to bring more consistency to the cyber security reviewing process. I think that's uh one way to describe it at the high level.
▶ 1:25:14uh but it's really important to both have that rigor to ensure the uh controls are in place to manage those cyber security risks but also to be consistent and and that's very important for the manufacturers to ensure that consistency across product lines and such. All right. Let me ask you also my understanding is that individuals with expertise in cyber security and artificial intelligence both of both are needed to examine medical devices and that those people are in very high demand.
▶ 1:25:44So are you concerned uh that the way the administration is treating federal employees, you know, I talked about how some were fired today when they just showed up for work. Are you concerned at all that the way the administration is treating federal employees will harm FDA and HH's ability to recruit and retain this top talent that's very much in demand, if you will.
▶ 1:26:08I I think it will be very difficult for FDA to recruit and and retain the the type of qualified individuals you'll need for this very specialized specialized work. cyber security and medical devices. You won't find too many people who study this in school uh or even do it in in the industry.
▶ 1:26:26So, the the people I've met and worked with at the FDA during my time were highly dedicated public servants uh patriots and I I think by and large they did it because they felt it was good for the country and the no one's going into public service for a great salary. So, I think it'll be very difficult when um in the current climate. I um I appreciate that.
▶ 1:26:55Let me say, you know, I have a lot of concerns about not only what Secretary Kennedy's doing with these firings, but the indiscriminate nature of this downsizing. And I I don't want to repeat I know chairman Guthrie we had uh this um exchange in the other committee in the health subcommittee because he said that you know he was hopeful I guess that um all this would you know all these uh firings and downsizing would lead to a
▶ 1:27:25uh more efficient agency whether it was the FDA or the HHS or whatever. And my concern is that I haven't seen that. In other words, it seems like it's very indiscriminate. There's no indication that this is being done in a way uh that's going to be more efficient. And that's why we need to have a hearing uh on what's happening with these firings. And he I think he said that he was willing to do that at some point. Um and I'm going to follow up on it.
▶ 1:27:55But what I said at the other hearing also was that and I think you're hinting at it is that what I'm hearing from industry. You talked about certainty, right? You know, they always worry in industry, whether it's uh, you know, medical devices, dietary supplements, you know, prescription drugs that there's good and bad actors, right? And that if you're a good actor, you you want certainty.
▶ 1:28:17You don't want, you know, uh, the bad actors to sell things that, you know, are not safe or are not actually going to help out. So, just we got 45. Let's talk about the importance of certainty with industry because and and and the dangers if you will of you know not having people that you can rely on FDA anymore that if you if you wouldn't 30 seconds or so okay I I'll try so there many different kinds of certainty there's technical certainty we'll never have 100% certainty
▶ 1:28:47of cyber security and and that's something we have to accept but uh the industry FDA they understand how to do the risk management of that and and and get it to tolerable levels On the business front, medical device manufacturers uh many of whom are are part of my research center care deeply about the consistency of reviewing as well as the certainty of what to expect.
▶ 1:29:10And when you have a lead reviewer suddenly disappearing, that's going to create market uncertainty of time to market and that's going to hit the bottom line of the company if they cannot get their products to market for these life-saving uh devices for patients. Thank you. Thank you, Mr. Mr. gentleman yields. Before I recognize Mr.
▶ 1:29:32Balderson, I just want to point out to um the committee that uh we recognize that there's some confusion around the modernization effort for the American people and we've already requested a briefing from HHS so we can have a a better understanding of of the potential impact to our constituents. Chair now recognizes uh the vice chairman of the subcommittee, Mr. Bald for five minutes for his questions. Thank you, Mr. Chairman.
▶ 1:29:59Uh, thank you again for all of you for being here today. Uh, my first question goes to Mr. Damouth. Dr. Dom, I apologize, sir. What challenges do hospitals face because of the differences between the life cycles that medical device hardware and software have? Uh, the impacts to those hospitals are are multiffactorial. So number one, they don't have the latest and greatest medical technology in some in some cases, especially if they can't afford that.
▶ 1:30:27Let's think about rural critical access hospitals because of the financial constraints. They don't have the latest generation medical devices. So any of the features that are released in these newer devices, they don't have too. Um because of the other constraints they have with staffing expenditures, their thin margins, etc. uh these types of devices are going to persist on their networks for years and years and years until they are physically broken for the most part. Many hospitals in this country do not have the luxury of replacing medical devices solely for cyber security risk concerns.
▶ 1:30:57And so, as I mentioned in my testimony, there's um a health system I've personally witnessed who will buy parts from the third party um secondary markets just to keep an old CT scanner going. That is a absolute mega legacy medical device. It is vulnerable to attack. It's running an outdated operating system. It is nearly impossible to defend without significant resources. So these are just some of the impacts and limitations that hospitals have when it comes to these types of devices.
▶ 1:31:24U mainly due to their financial Thank you. Thank you. Uh my next question is for you doctor uh again but I also want to include Mr. Decker. Uh Mr. Decker. Uh, can you explain why cyber security risks are unlikely to be sufficiently mitigated through patching and updating a devices software? Yes.
▶ 1:31:48So, as I mentioned in my testimony, there's a life cycle to the quality management of the devices themselves. So there there's a time lag by when a a patch can actually be released and installed on a device that has to generally be cleared through the manufacturer and be deemed safe and then we have to deploy it into the environment and confirm that. So you might have a critical vulnerability and that critical vulnerability may be in an IT system can be patched within 3 days.
▶ 1:32:16It could take upwards of 30 to 60 days for that to happen inside a medical device if it's even a certified patch. The other thing I would just note is the vulnerability itself is not necessarily the only problem. There's three factors that are involved in a device being exploited for harm. You have to have the vulnerability. It has to have some kind of exposure by which that that vulnerability can be accessed and there has to be an actor that actually does something with it.
▶ 1:32:43So you can manage you can manage all three of those those factors. Thank you. Um Dr. Me myth would you? Um I think this comes down to another thing that I tried to highlight in my testimony which is that hospitals lack the workforce that are able to effectively mitigate these concerns.
▶ 1:33:01So even if there's a patch available uh miraculously like a p a vulnerability has been identified device manufacturer has made a patch it still has to be deployed and these devices are sometimes in the most sensitive and time critical parts of the hospital operating systems trauma bays emergency departments. It's sometimes not a trivial process to go and update all of those devices. You can't update it in the middle of a surgery when it's connected to a patient. So these are some of the considerations we have that these are critical devices.
▶ 1:33:29They are hard to patch at scale and that the hospitals would far often or there are many hospitals that would have other constraints and concerns that that staff would be used for before taking them away from their daily duties to do something like patching. It's hard for hospitals to understand theoretical cyber risk versus seeing the things right in front of them, which is this scanner has to work for the stroke patient. That's the number one priority. We'll take cyber uh as it comes. Thank you. Um my next question uh is for Mr. Decker and Mr. Garcia. Mr.
▶ 1:33:58Garcia, you may lead off. How does removal of legacy medical devices that are still broadly in use present risk to patient safety and clinical operations? I actually would defer to Mr. Decker on that as I'm not involved in the operational side of of protecting patients and devices. Perfect, sir. Thank you, Mr. Decker. So, to confirm your the questions about how does removal of the legacy devices Yes, sir.
▶ 1:34:25So if we if we get a a clinically effective device that is patchable uh and has security baked in by design, then one would surmise that that's going to make it a a better clinically effective device that that has, you know, better security associated to it.
▶ 1:34:42But that those elements, you know, we we have a a fair amount of this over the last several years that has been baked in with some of the newer devices, but as we've said, uh as many other witnesses have said on the panel, some of these devices are 10 years old, uh or longer because of just sort of the lifespan of them as well. It's going to take 5 to 10 years for them to get cycled out. Thank you very much, Mr. Chairman. I yield back. Thank the gentleman. Chair now recognizes the gentle lady from Massachusetts, Miss Treyan, for five minutes for her question.
▶ 1:35:11Uh thank you to the chair, thank you to the ranking member and for our witnesses here today. Um just question for the chair. Uh the briefing that you mentioned in your in your remarks, um uh the briefing on the department, is that going to include all of us? Will that be bipartisan? We'll let you know. I look forward to it.
▶ 1:35:33Um, so this administration's reckless acrosstheboard cuts to NIH grant awards have been described by one researcher as quote the apocalyp apocalypse of American science end quote. While a federal court has temporarily blocked these unlawful cuts from taking effect, the damage is already being felt. Researchers and institutions across the country are facing uncertainty, disruptions, and in some cases the threat of projects ending altogether.
▶ 1:36:03In Massachusetts, NIH funding supports groundbreaking research on heart transplant risks and the potential of gene editing as a treatment for spinal muscula atrophy. And these are just two examples of the life-saving work that could be that will be jeopardized by these cuts. While NIH funding is often associated with drug development, it also plays a critical role in advancing medical devices, ensuring they are effective, they're safe, and accessible to patients.
▶ 1:36:32Significant cuts to research grants would stifle that innovation, slow down the development of medical technologies uh that improve and save lives. So, Dr. Fu, what role does federally funded biomedical research play in the devel development of medical devices that eventually reach our patients? So I do not presently take any funding from NIH nor have I, but I have colleagues who do and I I work with companies that benefit from the discoveries at NIH.
▶ 1:37:02And I would say the NIH research is extremely important for the the fundamental beginning of the science and for lack of a better term de-risking before it becomes a business. Uh and also understanding what therapies and diagnoses are going to be effective. Uh you'll find a lot of collaboration to ensure that the safe and effective drugs and devices will eventually reach the market.
▶ 1:37:28But it takes a huge amount of effort in order to sort out um the effective from the the less effective. Yeah. And how essential is fedally funded research in ensuring that medical devices enhance effectiveness, improve patient health outcomes, and uphold public safety? So, how important is how essential is it? Uh so, post World War II, I think it would be very difficult to have it be anything but essential.
▶ 1:37:58It's it's become essential to just how America discovers new new therapies and diagnostics. U I think uh the US has historically led in domain. If these cuts move forward, they won't just limit research, they'll force some labs to close entirely. uh and I hope the majority does convene us in a bipartisan way to do our primary function in this subcommittee which is oversight.
▶ 1:38:28Despite uh you know the nationwide impact on scientific progress uh should these cuts go through the majority should not show they need they must show interest in fulfilling our obligation uh for oversight. In my district, federal research funding drives medical innovation at a leading biotech incubator where NIHbacked projects turn early stage ideas into real world solutions. Like you mentioned, Dr. Fu, these investments, they fuel breakthroughs.
▶ 1:38:57They create highquality jobs uh and sustain the small businesses that power our region's economy. Cutting this funding will cost jobs, stall economic growth, and set back life-saving advancements. Federal support for biomedical research isn't just about science. It's about our nation's health, competitiveness, and security. And I think every member on this committee should oppose reckless NIH cuts and be in attendance when that briefing happens. Thank you. I yield.
▶ 1:39:28Gentle lady yields. The chair now recognizes the gentleman from Virginia, Mr. Griffith, for five minutes for his question. Thank you very much, Mr. Chairman. Uh, Miss Jump, we've been hearing all this stuff going on, and you all know what you're talking about, and some of us have some idea of what you're talking about, but we got all these folks who will be watching this either now or sometime in the middle of the night when we're the rerun on C-SPAN.
▶ 1:39:54So could you give us an example of a common legacy medical device where a backdoor into the system may be present but the capability of generating an alert is not. I'm not sure I could give you an example other than the the the example of the contact situation that we've been discussing.
▶ 1:40:17Um however as has been mentioned previously from other folks on this panel um there are not a lot of ways of monitoring when this is happening. Right. So uh in from my perspective I think it is very important that we put a lot of focus on preemptively finding these issues through risk management and testing these devices to make sure that we understand what kind of soft spots are there in the form of vulnerabilities.
▶ 1:40:47So whether it's a back door, whether it's another way of entering a medical device either for malicious behavior inside the medical device or for pivoting into a hospital as an easy access point. All of those um aspects are there. So the concern is if you're at a hospital, they may be get getting data data on the population in general. Is that correct?
▶ 1:41:12Uh there's a long-standing concern for privacy breaches in hospitals from a variety of sources. Um however, I'm not aware of any instance where there has been a backdoor has been the source of that uh like we've talked about here.
▶ 1:41:27And and then another concern might be that that if if uh and I heard somebody in the opening statements say that there was a concern about, you know, a device that had been discovered and while it might not be used that way, there was a backdoor way to maybe turn the device off so that if we found ourselves in a conflict with u China or some other nation that makes some of these devices and they had a way to turn it off, they could along with all the other typical
▶ 1:41:59things that are done. They could turn off a bunch of medical devices. In theory, they could turn those devices off, create chaos in the domestic scene. Is that correct? Is that one of the concerns? I'm not aware of that concern. Somebody raised that issue. Yes, sir. Mr. Decker, go for it. Yeah, I was I I raised predispos uh prepositioning malware. So, the the the challen So, we know that that I mean it's been publicly announced. the five eyes have have announced that they've done this in water and uh communications.
▶ 1:42:28We don't know if it's happening in healthcare. It's it's a it's a largely unanswered question at this point. I think the way to answer that question is to get together with our national intelligence apparatus with our our HDOS's or health health delivery organizations with the medical device manufacturers put it under clearance clear the the entire you know task force and study and and actually study this problem. bring the academics in and see where this could occur.
▶ 1:42:54The problem is is on the on the delivery side, we're unaware of the intelligence outside of what comes through the flash reports from the FBI and SISA. And you mentioned Five Eyes for the folks back home. Five Eyes is Yeah, that's the the the five intelligence agencies, uh, United Kingdom, uh, United States of America, Australia, New Zealand, and Canada. Canada, right? All right. Dr. Dr. DeF last Congress subcommittee saw the effects of a large cyber security incident with United Health.
▶ 1:43:22But on a smaller scale, have you seen an example of an incident where vulnerabilities were not being assessed and it contributed to patient harm or operational disruptions? I think the best example of that uh is ransomware. It's a scourge upon uh health care. We are the most commonly targeted critical healthcare infra or critical infrastructure for it. Uh those are vulnerabilities in healthcare infrastructure.
▶ 1:43:45they are attacked, malware, ransomware is deployed and what we see as a consequence of that is uh huge cascading failures not just at the hospitals that are infected but also in the regions around them. Uh so I'll give an example. Uh there was a ransomware attack in San Diego in 2021. Five hospitals went out. Um the adjacent hospitals to those ransomed hospitals saw huge spikes in emergency department visits, waiting times, ambulance traffic skyrocketed.
▶ 1:44:12We did a follow-up study about a year later that looked at what happened to patients that had cardiac arrest. Their heart stopped and they needed something like CPR. We looked at their outcomes from the same attack and saw a t-fold decrease in their survivability just because there was a ransomware attack in the city. These are the true meaningful patient impacts to these types of cyber attacks. Legacy medical devices are one risk of that, but there are still many other ways that these adversaries are getting into our hospitals.
▶ 1:44:42I appreciate that very much, Mr. Chairman and witnesses. I think this is a very important hearing. I apologize that I had another hearing going on and I'm now being called to the floor. I usually like to sit and listen from beginning to end because I learned so much, but thank you all so much for being here and educating us on this important issue. I yield back. Gentleman yells. Chair now recognizes gentleman from New York, Mr. Tonko, for five minutes for his questions. Thank you, Mr. Chair. Um, a strong FDA is central to keeping patients who use medical devices safe.
▶ 1:45:09While FDA rigorously reviews new medical devices before they enter the market, is it important to maintain vigilance once a product is being marketed and in use? Despite the Republicans's interest in discussing medical device security, they're turning a blind eye to Elon Musk and Secretary Kennedy's workforce reductions that will make it impossible for FDA to effectively regulate medical devices and protect patient safety. Secretary Kennedy has announced that HHS will lose 20,000 staff.
▶ 1:45:39More than a third of the employees that HHS plans to lay off currently work at FDA. So, Dr. Fu, can you explain what the subject matter experts in cyber security, device connectivity, and other technical fields contribute to the medical device review process in both pre and postmarket Sure, I'll give a go at that.
▶ 1:46:02So there are a number of uh uh cyber security experts who are not just good at uh the information technology but also understanding how it affects kinetic systems, systems that move, systems that emit electricity to uh change your hard characteristics.
▶ 1:46:19uh you will you will find these both in in the review staff themselves but you'll also find subject matter experts that have to bridge the divide with other constituencies not just with the manufacturers but also with the health care systems with law enforcement organizations especially when there's a suspected crime uh I would draw the attention to uh when I was uh acting director of medical device cyber security at FDA we witnessed the first case of patient harm from ransomware ware
▶ 1:46:49this ransomware uh had infected the private cloud of a radiation therapy device company. Uh I believe uh it was marketed to be able to uh uh uh have an uptime uh loss of no less than two hours uh a year but it was down for six weeks uh because of ransomware.
▶ 1:47:09and having those subject matter experts to as that interstitial tissue to connect with all the groups was extremely important uh to to uh uh rectify that situation and get these devices back online. Well, thank you very much for that.
▶ 1:47:23Uh on this committee, we have repeatedly heard from the government accountability office and others of the challenges FDA faces in recruiting and retaining staff in jobs like foreign and domestic inspections and in positions requiring specialized technical skills. FDA's ability to oversee medical devices is supported by subject matter experts who can advise on the review of medical device applications which involve increasingly complex technology.
▶ 1:47:52Um, we need people in these positions who know how to spot vulnerabilities that can indeed harm patient safety. So, Mr. Garcia, even the highest tech devices eventually age. What are some of the challenges of identifying cyber security risks in devices already on the market?
▶ 1:48:12Well, I think that the health care sector has a very broad mandate for evaluating technology and that includes medical devices, that includes all of the IT and communication systems and all of the software that runs them. Um, it is a vast task.
▶ 1:48:30Um and uh what we're focused on in the sector coordinating council is looking at the totality of risk management requirements of the health care industry knowing that medical devices is just one component in this broader infrastructure.
▶ 1:48:45So it's it's it's very difficult and we're focused on developing best practices, leading practices in the whole range of cyber security functions, whether it's medical device security, whether it's supply chain cyber security, knowing who your third parties are, uh whether it's workforce development, um whether it's incident response or vulnerability patching, there's a whole range of things. So we're focused on looking over the long term. How do we get ahead of this threat?
▶ 1:49:16Not just today's regulatory environment, but how do we do this better? Thank you. And Dr. Fu, if the FDA loses a significant number of employees with cyber security and technological expertise, what would be the impact on FDA's ability to respond to postmarket discoveries of vulnerabilities or reports of safety If you lose one, you're probably going to have a much harder time responding to simultaneous threats, which seem to be a natural course of the future.
▶ 1:49:45If you lose two, we might just not have a response. Well, without sufficient staff and resources at FDA, it will take longer for good products to become available for patient use, as well as for unsafe products to be taken off the market, and patients will be forced to suffer these avoidable consequences. every problem that we should be trying to solve becomes infinitely worse and more dangerous as long as our Republican colleagues continue to enable this needless chaos that President Trump and Elon Musk have unleashed.
▶ 1:50:14And with that, Mr. Chair, I yield back. Gentleman yields. Chair now recognizes gentleman from Texas, Mr. Weber, for five minutes for his questions. I thank the gentleman. U I've got an interesting question for all of the panelists to start with. Um, should medical device manufacturers have any liability? Is there a legal cause uh here that the lawyers could take up and uh take the medical device manufacturers to task? Doctor, we'll start with you.
▶ 1:50:43Um, the liability of um a failure of a medical device for a cyber security vulnerability is one that would be tricky to only uh pin on the device manufacturers. Because of this what we discussed previously is this kind of life cycle of a device um vulnerabilities can be discovered and were previously unknown. So a flaw in hardware or software may one day no one knows anything about it.
▶ 1:51:07Next day a hacker, an adversary to this country, a state actor with good cyber security uh talent may find a vulnerability. That device manufacturer would have no idea that vulnerability existed and if they followed the standard practices and uh made it through FDA guidance probably should not be held liable for something like that. Now um let's say it's not the device manufacturer.
▶ 1:51:29the device manufacturer had a security control in place when it was sold but a healthcare delivery organization turned it off when they installed it and then there was a subsequent breach that would shift the liability to the healthcare delivery organization for instance what I'm trying to do is highlight that there is a it's not just a single point of failure any part across of this spectrum device manufacturing engineering it hospitals deploying it monitoring it patching it to the effective end of it where they have to decommission it at fail at any of those failure points the liability
▶ 1:51:59could shift to who's a responsible party at that time. Have you experienced that? And you're you were with San Diego. You're still with San Diego Center. Uh yes. Uh yes, I do. Um I don't represent them currently during this hearing, but I have seen medical devices be infected with malware. I have seen those devices not function appropriately. The scale and scope of that problem is unknown. We do not know or have the capability to understand how extensive that problem is in hospitals across this country.
▶ 1:52:28But you did say that some there was some heart failures. I think it was you and some of your earlier testimony, but and that never resulted in a legal proceeding. Not to my knowledge, but there has been some case law regarding ransomware attacks on patient outcomes. There was an horrible case in Alabama where um a pregnant mother was undergoing labor at a hospital under ransomware attack. It is alleged.
▶ 1:52:51Again, um I don't know the individual details that were in uh court testimony, uh but it is alleged that the ransomware attack contributed to the death of a child. Okay. Um I'm going to go to you, Miss J, and ask you specifically, should medical device manufacturers have any Well, I'm not a lawyer.
▶ 1:53:15I am a regulatory person and I have been I've spent the last 15 years of my career interacting with the regulatory field and I would just echo from my oral statement today that the regulatory bar held for medical device manufacturers today is second to none in the world. The new statutory authority that they've been given by Congress, they've been applying consistently, transparently and rigorously. And I feel that because as Dr. Dr.
▶ 1:53:43Duff had mentioned the shared responsibility where a medical device manufacturers creates a product. It's put out into what is often a hostile environment in a hospital because those environments from their just the way they're built. They're difficult to defend. It's difficult to say that someone has had an legal liability when there's that shared responsibility. I think they should be held to the regulatory bar which I think is high. Mr. Decker, you agree with that? I also will concur. I'm not a lawyer. uh cyber geek over here.
▶ 1:54:13Um so but uh it's complex and you know I I play a lawyer you know when we do contract negotiations we do have liability clauses that are built into these into these contracts. Um but it's a case by case basis as far as like what is actually occurring. Mr. Garcia well as M said it is a shared responsibility. So you can see liability going both ways. If if if a health provider knows of a vulnerability that needs to be patched and it isn't patched, who's to blame?
▶ 1:54:42We in the sector council have produced a model contract. So, a lot of liability concerns are are sometimes based on lack of clarity about who's responsible and accountable. So, we developed a model contract. It was essentially negotiated by large medical device manufacturers and large health delivery organizations about what each side should be um accountable for and that can make commitments to in both the sale and the service of medical devices.
▶ 1:55:12And we're now um nearing conclusion of uh version two which is based on um how it has been implemented and lessons learned. And in this way, we're going to get better clarity between the device manufacturers and the hospital systems about who's responsible and who's accountable. Okay, I appreciate that, Mr. Chairman. I yield Gentleman yields. The chair now recognizes the gentleman from California, Mr. Mullen, for five minutes for his questions. Thank you, Mr. Chair, and and thank you all for your testimony today.
▶ 1:55:42The FDA's approval process for drugs and medical devices is often referred to as a worldwide gold standard. Around the world, governments and regulators look to us for rigorous evaluation of safety and efficacy, which is the result of decades of investment and continuous improvement in our approval and monitoring processes. The world of medical devices is becoming ever more complex. Devices are becoming smaller, smarter, and more capable of improving patient outcomes and treating or monitoring new conditions.
▶ 1:56:11But as devices become more sophisticated, we need to ensure that the FDA has the workforce and review processes that can not only keep up with the innovation, but continue to encourage it and drive it forward. This requires the retention and recruiting of real experts in cyber security, biology, chemistry, and numerous other fields involved in the approval and monitoring of devices.
▶ 1:56:35and requires reliable investment in biomedical and engineering research like through the research grants provided by the NIH. The Trump administration's actions are taking us in the opposite direction. Instead of leaning into our strengths, the administration is crippling the FDA, an institution that is a role model for the world. This will cause delays in approval for medical device companies and potentially increase both cyber security and patient safety risks.
▶ 1:57:04This matters not only to my district, which is a hub of medical innovation, home to dozens of medical device manufacturers, but also to the broader world, which relies on the life-saving work these companies do. But their work will never see the light of day if the FDA is hamstrung. So, Mr. Decker, uh, in your testimony, sir, you describe the need for expanded partnerships between the government and industry industry to continue to develop best practices and ensure adequate cyber security.
▶ 1:57:33So, how important is it to the device industry that the FDA maintains cyber security and other expertise on staff to thoroughly and and efficiently uh and effectively evaluate devices, especially those that contain new and innovative technologies. Yeah, the FDA is a critical part of the critical infrastructure policy advisory committee, that construct that allows for the sector coordinating councils and the government coordinating councils to come together and partner on these on these issues. So, it's it's an incredibly important factor.
▶ 1:58:05And uh to Dr. Fu, same question. How important is the in-house expertise at the FDA to both the medical device industry and the safety of the American people in examining uh innovative It just simply stated it's extremely important and happy to expand.
▶ 1:58:24So I am uh concerned that if we do not maintain the level of expertise and excellence at the FDA, innovation will slow as review times increase or if uh corners are cut to speed up the review process. Patient safety issues uh also increase. I also worry that if we do not continue to invest in research both within and outside the federal government, we will totally lose our competitive edge and patients will lose out on the benefit of medical devices that can save or improve uh their lives.
▶ 1:58:53So I have time for uh one more question, Dr. Fu, if you will. Uh how important is maintaining America's biomedical research enterprise through uh the NIH and other federal funding sources to developing safe and effective medical It's extremely important for that foundational engineering and science and medicine pre-product that was described earlier pre-business. It's extremely important. Great.
▶ 1:59:19And uh uh I think with that I will um I will wrap. Thank you all again for your testimony and I yield back. Gentleman yields. The chair now recognizes the gentleman from Florida, Mr. Dunn for five minutes for his questions. Thank you very much, Mr. Chair. And I thank the witnesses for being here today. As a medical doctor, I've seen the landscape of medical devices change dramatically throughout my time practicing. Devices are constantly becoming more sophisticated, which is better, of course, for patients and providers.
▶ 1:59:49However, I'm concerned with the increased sophistication comes from increased risk, especially cyber risk and catastrophic single point failures. This uh is demonstrated by that contact CMS 8000 patient monitor that contained a backdoor connected to China. As a member of the uh China select committee also I'm gravely concerned with the ways in which these back doors can be exploited by adversarial nations and just adversarial hackers.
▶ 2:00:19This vulnerability could be used to directly harm patients. It hinders the ability of the doctors to provide correct care and of course if the risks are not understood then these failures of patient care can so panic and confusion. Dr. DeF when a cyber threat for a device is identified what tools are available to inform the public and providers who may be using equipment and do you think these tools are adequate? That is a fantastic question.
▶ 2:00:49Um the parallel I'm going to draw is that when there is a adverse drug effect event um that is discovered or a flaw in a medical device in its clinical functionality, there's a pretty wellestablished uh process to let providers know that there is an unintended side effect or a consequence of this particular drug.
▶ 2:01:10In regards to providers, doctors, nurses, other folks that might be using these types of medical devices in clinical practice, to my knowledge, the dissemination of information of these vulnerabilities to them is quite limited. Typically, what happens is that a medical device will have a vulnerability found it that will be communicated by the device manufacturer to the relevant parties and then the hospital systems through their processes will go to seek and patch those devices.
▶ 2:01:36Um to my knowledge and I uh could be mistaken I as a clinician as a doctor have never received a notification personally that there was a cyber security vulnerability in a device I may have used. The reason is that it is incredibly difficult to know where these devices actually are.
▶ 2:01:54In my statement uh in my written and in my oral testimony I mentioned that we do not have as a nation the cap capability to discover where these devices are to know what their security state is to find a vulnerability in a device and then go to our country and find out how big a deal this is that capability is not currently exist.
▶ 2:02:14I support the efforts of things like sector mapping and potentially developing these capabilities so that we can answer that question of when when we find a vulnerability where is it how do we fix it how do we know it's fixed we currently don't have those capabilities well I thank you for that you know by the way it mirrors my own experience which is not cyber hacking or anything but just point of failure on a device and then the only people who knows that it failed why it failed are the people who are involved in the ICU at the moment and you became
▶ 2:02:44sort of local lore. Uh second question also to Dr. DeF you noted in your testimony the cutting edge devices of today are the legacy devices of tomorrow. I think that's a a normal cycle. I don't know how you break that cycle of frankly but he you know has a devices in a legacy device that's been out there longer more chance to hack it come up with new things. Uh but also surely the new the new devices that have built-in back doors may pose more risk. What's your opinion on that?
▶ 2:03:15I do appreciate the committee's focus on legacy medical devices because that is likely the easiest um for adversaries to target. But there really is not much of a distinction between legacy medical devices and current uh medical devices when you consider the capabilities that our adversaries have. Every time you've had they can get them both, huh? I don't care. They can get them both.
▶ 2:03:36So, if you have a talented team, um, a state sponsored actor for instance, and you dedicated resources towards a modern medical device by any definition, you could certainly find vulnerabilities and exploit those, and they wouldn't have to be back doors. I think back doors are are a concerning thing because they imply intent. They imply being sneaky and hiding. But our adversaries don't need back doors to come in through the front door of these devices because at their heart, with enough resources and power and talent, um, these again are just computers. They have flaws and weaknesses that can be exploited.
▶ 2:04:07Well, that's sort of a frightening world you paint there. I I wonder how many nights I've spent wandering around the ICU trusting all those machines, but uh thank you very much for your insights and I think I'll stop there. Mr. Chairman, um I I do agree that this this is a topic that deserves our attention. Thank you so much. Take care. Gentleman yields. The chair now recognizes gentle lady from York, Miss Aassio Cortez, for five minutes for her questions. Thank you, Mr. chair and I share in the committee's concern regarding cyber security and legacy medical devices.
▶ 2:04:37Um I'm also worried that in the search for solutions, we are also ignoring one of the biggest threats to people's privacy and public health in decades, which is the gutting of our federal agencies that are responsible for implementing these policies. Um Dr. Fu, I understand you were the first acting director of the Food and Drug Administration Center for Devices and Rad Radiological Health, otherwise known as the CDR.
▶ 2:05:04Can you tell us about the agency and its role in ensuring the safety of medical devices? I can give you an overview of uh pre-market and postmarket and maybe give an example of an incident management. So uh pre-market it works with the FDA reviewers and the manufacturers to ensure that security is built in by design rather than figured out as an afterthought. And so there's regulatory guidance that's now been published after several years of effort.
▶ 2:05:31Uh and so this is part of the uh uh consistency and help giving manufacturers certainty on what are the rules of the game basically the syllabus of the course. Uh on the postmarket side, the team will field reports of vulnerabilities from security researchers like Dr. Damoth. Uh they'll handle reports from uh hospitals who are discovering ransomware. They'll handle influx from law enforcement. Sometimes FDA will find it on their own and then communicate with the the parties.
▶ 2:06:00Uh and then there are many examples of incidents that have been managed using this inter interdisciplinary team approach. Uh, one again is the radiation therapy device that was down for about six weeks globally because ransomware broke into the manufacturers's private cloud. Yes. Thank you.
▶ 2:06:19and and you know digging into examples like that uh if someone or an entity wanted to interfere with an implanted pacemaker or hijack a medical laser uh is it correct to say that CDR would be the primary agency responsible for monitoring the cyber security of these medical devices?
▶ 2:06:42CDR uh as well as uh Asper would be the two I would say organizations that would be the gateways if you discover a security incident in a pacemaker or defibrillator. Thank you. And I see here that in 2024 alone, the FDA cleared or approved 33 medical devices and regulated more than 6,000 types of medical devices already on the market. And Dr. Dr.
▶ 2:07:05Fu, to the best of your knowledge, were public health advocates calling for a reduction in the CDR's workforce prior to February 2025? I I'm not aware of any call for reduction. And were medical device makers, the industry, advocating for shrinking the CDR? My understanding from the industry members of my center is that they would advocate for the increase. That's that's what we're seeing as well. And Mr. Decker, I understand that you are an executive of a health care system.
▶ 2:07:35Were you aware of any calls from physicians or providers to shrink the CDR prior to February 2025? I was not aware of any. Thank you. And in fact, uh to your point, um medical device and medtech companies were actually calling for more employees with greater specialization to the CDR. I'd like to enter that statement to the record today.
▶ 2:07:58Um, but in February, Elon Musk's team fired an estimated 700 employees from the FDA, including more than 200 employees at the CDR. And then days later, they scrambled to unfire some of these employees because they realized what we already know, that a strong and fully staffed FDA is better for everyone. But there is one interesting thing in terms of some of the few people that Elon Musk sought to reinstate.
▶ 2:08:27Um, reinstated scientists that were reviewing his Neurolink device. Um, Neurolink is a brain computer interface, a chip surgically implanted to the brain that Elon Musk has in front of the FDA. This kind of technology deserves secure safeguards and testing done by employees that aren't being held hostage right now. In fact, employees at the CDR are reviewing the Neurolink right now.
▶ 2:08:55And when we're looking at this pattern of Elon Musk inter uh Elon Musk with other agencies, we saw that Federal A aviation Administration workers were threatened with firings if they impeded Musk's company at SpaceX. The National Relations the National Labor Relations Board had 24 investigations into shady labor practices at three of Musk companies, SpaceX, Tesla, and X.
▶ 2:09:23And now and now we saw three of the top executives at the NLRB are gone. Um Dr. Fu, what could be some of the risks of the politicization of some of the oversight of devices that could be reviewed at the uh CDR? General's time is expired, but the gentleman may answer the question. Thank you.
▶ 2:09:51I would say the the main risk in my view from my technical background is the inconsistency in reviewing and so um and then that would have impact on patients. Chair now recognize gentleman from Georgia, Mr. Allen for five minutes for his questions. Uh thank you. Thank you, Mr. Chairman. And I'd like to for the record correct Elon Musk has no authority to hire and fire anybody in the federal government.
▶ 2:10:19uh in a meeting with him two weeks ago, we talked about that. We talked about how he was going about it. But he is simply an adviser. He is running algorithms in every department. He has no responsibility for firing and hiring anybody. And I think the record needs to reflect that. The other thing is do uh obviously y'all are experts in the threat here.
▶ 2:10:47Um, how many I mean do do you know how many government agencies are involved in cyber security? Do you have any idea how many people are involved in cy cyber security in the federal government? And then like Mr. Decker, your hospital also has experts involved in cyber security. Is that correct? Yes. And the manufacturers have people involved in cyber security. Correct.
▶ 2:11:17Yes, they do. How many people is it going to take? How much money we got to Is that a question? Yes, sir. Yeah. Uh, so this is a people and process problem. And there are what I'll say is this. Inside healthc care, we have been underresourced as a as a national system to manage the problem. Okay.
▶ 2:11:43So you haven't had any cooperation with SISA or you know we've had we've had cooperation with SISA with HHS with FDA. There's there's many agencies that are involved in this. You got NSA right? We have not had any specific dialogue. You got the cyber center of excellence command. That's the military. So no no connection there.
▶ 2:12:05So one one of the things I mentioned in my written testimony is the the connection to the national security apparatus to critical infrastructure has been a bit disconnected. Our connectivity is through our sector risk management agencies. So health and human services and CISA those have been the two main uh entry points into the dialogue. Okay. So might this be a means and methods Yes.
▶ 2:12:32I I think that we we need to do a better job of sharing information and sharing intelligence back and forth between That's just what I was told in a meeting a week ago. Yeah. The other thing I was told is we're we're playing defense. Yes. Just defense. We're not going on the offense trying to stop these people from doing what they're doing. Uh we're just, you know, we're just sitting back playing defense and everybody it's it's a threat to everyone.
▶ 2:13:01every business, financial institutions, you name it. And obviously in health care, lives are at risk. I mean, don't you think we need to figure this out and quit blaming each other for whatever we're doing? I mean, the in the definition of insanity is doing the same thing over and over again and expecting a different a result. It is it's insane to me that we sit here and say we can't figure this out.
▶ 2:13:27Should we have one group that does this and does it very well and is respected around the world? Right now, we just we just look totally exposed. Would any of the panel disagree with me on that? So, why don't we look for solutions rather than blaming Elon Musk or President Trump or whoever and say, "Let's get together and fix this problem. I'm ready to do it and we need your help." Okay.
▶ 2:13:57and we need to fix this thing. And with that, Mr. Chairman, I yield back. The gentleman yields. The chair now recogniz recognizes gentle lady from Colorado, Miss Gette, for five minutes for her questions. Thank you so much, um, Mr. Chairman, and you know, um, they say everything's been said, but it hasn't been said by everybody. And, and I apologize for coming in late. I'm the ranking Democrat on the House Subcommittee.
▶ 2:14:23We're having, I'm sure you've all heard, we we're having a hearing downstairs right now, and the hearing downstairs right now is supposedly on the reauthorization of user fee legislation to smooth the path of over-the-counter monograph drugs to market. So, we have this hearing up here in O and I today around um uh patient safety with medical devices and cyber security. And then we have the one downstairs.
▶ 2:14:49And we really do feel like we're fiddling while Rome is burning today in the US House of Representatives Energy and Commerce Committee because last week Elon Musk and his youthful Doge employees announced they were going to slash and burn uh HHS um agencies including the FDA. And then today 35 people showed up to work and they couldn't get in. And so that's that's what we've all been talking about.
▶ 2:15:18And the reason we're talking about it is because as someone who's been on this committee and worked on these agencies for almost 30 years now, I know Congress, article one of the constitution, friends, Congress has the legal authority to authorize and to oversee these agencies. All of us are for efficiency. All of us want to eliminate waste, fraud, and abuse.
▶ 2:15:47But when you just willy-nilly cut 3,500 employees, it is going to not only fundamentally affect your ability to regulate industries like medical devices, it's also going to fundamentally undermine patient health and safety.
▶ 2:16:09And so um you know they they said that um that the layoffs that they were having of the 20% of employees at FDA uh would would just would not be regulators but in fact it's going to be people who are helping this agency perform its duties. And so I just want to um ask all of you I I just want to ask all of you going down the line u this simple question.
▶ 2:16:39Will a reduction of the effort of of the experts at the um harm patient safety and innovation in device security? Yes or no? I'll start with you Dr. Damoth. It is likely Mr. Decker. We would have to study it.
▶ 2:17:00You do you think that reducing the experts that regulate medical devices and and cyber technology could actually hurt could actually help? It has the potential to. Okay. I'd like you to supplement. Would you investigate it? Please supplement your answer to show me how it could help. Miss Jump. Yes. Mr. Dr. Fu. Yes. So, so all of you except for Mr.
▶ 2:17:27Deckers, who's going to do a study, think that reducing the experts could potentially harm safety and innovation. Now, um I I would like to uh also say that that uh when the chairman of the full committee, Mr. Guthrie, was downstairs in the other hearing, uh Congressman Palone and I asked him if he would please um utilize this committee's broad jurisdiction and have an oversight hearing.
▶ 2:17:55And given the fact that four of the five witnesses today at this hearing have just told me that patient safety and innovation in device security could be undermined by these actions. I think this is urgent and I would renew our request to have this hearing and I would request to have this hearing before the April recess. And with that I yield General lady yields.
▶ 2:18:20Just for clarification on the question she asked, does the entire US health care system and all of its medical device manufacturers depend entirely on the expertise of HHS to protect us from attacks? Mr. Danf. Uh, no, but in so well that's that's all I just wanted a clarification. The chair now recognizes the gentleman from uh Ohio, Mr. Roelly, for five minutes for his questions.
▶ 2:18:51Well, thank you, chairman. Um, once again, the answer is never just throw more money at it. We see what happened in England with the health care system. The answer on the opposition side is throw more money at it. I'm more concerned about the bluecollar rural county hospitals. I've lost two in my district. The rest of them are not doing well at all. And so, I just think that I need to address that. So, we have so many different aspects of it. So, I'm going to move to Mr. Garcia. Mr.
▶ 2:19:20Garcia, what are the biggest challenges to rural hospitals right now in implementing FDA and federal cyber security guidelines? It seems like with the $36 trillion deficit that America is functioning in, these rural hospitals cannot look to the federal government for any assistance at all. And I know like whether it's in a lot of things that happen in the state of Ohio, we do shared cost where perhaps some are like East Liverpool Hospital with Marietta Hospital with the one that's in St. Claire'sville.
▶ 2:19:48A lot of times they share different services as far as expertise. But as far as the cyber security aspect of it, we have hospitals that are actually helping the most uh needy people in my district in particular, which is rural America. These guys are not watching CNN and Fox News all day. All they're doing is making honest day work, honest day pay, and they want a hospital they don't have to drive to Pittsburgh or Columbus to get to.
▶ 2:20:12So, how can we move forward where the rubber meets the road, where we actually talk about tangible things that going to help our constituents instead of talking about fairy dust? What can be done to make a better cyber security with these medical devices that are inside my district? Thank you for that question, um, Congressman.
▶ 2:20:29um the restraints on rural critical access uh FQC health systems, it's all for resources, expertise and workforce. Um those are severely lacking in those health providers that are operating at zero to negative margins.
▶ 2:20:50Next week, I expect we will be releasing a white paper with findings and recommendations of a series of interviews we did with um executives of underserved uh resource constrained health systems across the country, 30 states, 40 executives um asking what are your needs? What are your stress points in cyber security? Who's in charge? And if you are to be held to a higher standard of cyber security, what's going to be meaningful support for you?
▶ 2:21:21Is it going to be grants, subsidies, more funding? Is it going to be training? What's going to help your constituents, your underserved providers meet their cyber security requirements so that they protect patient safety? So, that's coming out next week. So, thank you for the question. Well, you're spot on. I I actually have talked to three of the hospitals in my district about this very thing and they were wondering if there's ever going to be like a a blueprint or a guideline if they are under cyber security tax. You have to realize a lot of the IT guys are very limited that are in the brick and mortar at the moment.
▶ 2:21:50What is the action plan? You know, how do they move forward? What's the best way to approach it? And it sounds like you're sort of getting there. Absolutely. And one of our biggest challenges with the sector coordinating council is that we have produced now almost 30 best practices on how to do cyber security better. Mr. Decker was the co-chair of um an initiative that created the health industry cyber security practices or hiccup volume one is specifically for small rural critical accesses.
▶ 2:22:20This is what you need to do. It's the top 10 cyber security controls. Our challenge is to get those resources out to those stakeholders who need them. We need to not only lead that horse to water, but get it to drink. And the water is the cyber security practices and the horse is the entire healthcare ecosystem. The most refreshing answer I've heard today. Thank you so much, sir. With that, I yield my time back to the chair. Gentleman yields. Chair now recognizes gentle lady from Texas, Miss Fletcher, for five minutes for her questions.
▶ 2:22:50Well, thank you so much, uh, Mr. Chairman, and thank you to all of our witnesses. I'm glad to be here to hear from you this morning and I apologize for missing some of the earlier testimony. I was in another hearing where we were also um talking about um some challenges in our um in our health sector and at FDA in particular.
▶ 2:23:08Um, and I know though that many of my colleagues have already uh mentioned during the hearing this morning um their concerns about not only efforts to protect cyber security um but also uh to protect the American public at large um and the proposed cuts and changes that we're seeing at the Department of Health and Human Services.
▶ 2:23:30Um just this morning as we have been sitting in hearings today uh I'm sure you all have heard um as we have we've gotten multiple reports that um people are lined up outside of HHS uh around the block uh at the building that's just down the street uh swiping their badges to see if they are still employed. Um those folks are apparently uh going in and if your badge swipes green, you're fine and you can go on in and if it's red, you've been fired.
▶ 2:23:58Uh that's what we're seeing happening and I am alarmed that what we're seeing from Secretary Kennedy, from President Trump, um is really undermining the government's essential function of keeping us safe, not only through these devastating staffing cuts, but by cancing important meetings of experts um who regularly advise the FDA and other agencies whether it is on um whether it is on all kinds of topics and issues and programs or whether it is on cyber for security.
▶ 2:24:29I know that uh just I guess February, so not last month anymore, but um President Trump signed an executive order ending the advisory committee on long COVID um and health equity hasn't stopped there. It's been reported they're considering ending an additional nine advisory committees at the CDC uh including those that focus on the prevention and treatment of HIV, uh viral hepatitis and sexually transmitted infections.
▶ 2:24:52And as I understand it, FDA made FDA's medical device reviewers need to have the opportunity to consult with an array of adviserss to handle um the workload and that a single reviewer or team can't be experts in every single specialty required to properly assess every um every application without ex without outside expertise. And so my questions are um really to be directed at you Dr. Fu.
▶ 2:25:22Um because I want with the time that we have left, just about two and a half minutes, if you could just talk to us about situations that you might have seen at the FDA where outside experts were brought in to advise the agency on a specific issue or device application and how that enhanced decision- making and then um kind of the correlary to that just because we're down to about two minutes is if the FDA lays off the workforce that consults with reviewers on medical device cyber security and safety, what will be the effect on the review process?
▶ 2:25:51Could you cover those topics with the time we have left? When you say bring in outside experts, do you mean hire or I'm not Could you clarify? Just consultation with outside experts for and you can tell me better. You're you are the expert, not me. But that's my understanding that that you have the opportunity to consult with others who might have particular expertise on either the devices or um the conditions that are sought to be addressed. Well, FDA had been trying to convince me for 10 years to join. So, they they got me for a short time period.
▶ 2:26:21Uh, one of the things I appreciate about the agency is that they would hold stakeholder meetings, public forums to get all all input, whether it be patient uh, uh, input from patients on how they feel about medical device security and how it impacts uh, how they feel about their treatments and diagnosis to uh, holding I believe uh, Michelle mentioned just hundreds of people in a room primarily medical device manufacturers coming together to not just listen but actually give input on what they would like to see in these processes
▶ 2:26:51and what are the problems they're seeing to manufacture these devices to to reach the public um and and sell uh usually to hospitals. So I I think bringing in experts there's a small number that become employees at FDA. It's a very small team on cyber security and FDA. Uh and what you will find though is that they try to use these uh public events to bring in and with HSCC and and other organizations of that nature.
▶ 2:27:18The international medical device regulators forum uh is another force multiplier uh to help globally uh bring more harmony to the regulations so that companies don't have to uh think cyber in 10 different dialects. And just with the time I have left, what will happen at the FDA if the workforce that facilitates those discussions is laid I don't know what will happen.
▶ 2:27:43I don't I think it it takes many years for an individual in that kind of position to build up their expertise in Rolodex to really understand how to bring things together. And that's that's not the kind of thing you're going to learn from a textbook. So, uh you you can't simply post on LinkedIn. We need someone with 20 years experience doing this. It's it's might not be possible to replace. Thank you very much. I've gone over my time, so Mr. Chairman, I yield back. Gentle lady yields.
▶ 2:28:13Gentleman uh the chair now recognizes gentleman from Idaho, Mr. Fulture, for five minutes for his questions. Thank you, Mr. Chairman. Mr. Garcia, during your verbal testimony, you made a statement that surprised me a little bit, and it was that the medical device uh security uh in the industry, medical industry, if I understood you correctly, was the most targeted for cyber attacks. Did I get that right? The entire health care ecosystem, not just medical devices. Okay. So, uh why why health care?
▶ 2:28:41I mean, we hear about the the um banking, right? Uh power grids. What is it about the healthcare industry that creates that target? Yeah, I came from financial services before this and and at that time 15 years ago banking was the biggest target because that's where the money is. Um but then they started out spending the criminals.
▶ 2:29:02Um the problem with health care is first off it is a widely distributed uh multiaceted ecosystem that has a lot of touch points, a lot of vulnerabilities. Secondly, um there is less money to spend against cyber threats. Um and thirdly, it's easy money. When you have a ransomware attack, if you are a hacker and you ransom a hospital, you are forcing the decision on the hospital.
▶ 2:29:30Should I pay the ransom and continue to uh treat patients or should I not and run the risk of not treating patients andor going out of business? That's why Okay, that makes sense. I, you know, it's sad state of affairs, but makes sense. Mr. uh Mr. Decker, question for actually a couple questions for you. You uh as uh you noted during your uh uh testimony, some recommendations.
▶ 2:29:57One is um uh recommending that that hospitals join a cyber security working group, right? Um how would they go about doing that? and and uh if if if my hospitals in Idaho wanted to do that, how would that happen? Uh well, luckily our executive director is at the table here, Greg Garcia.
▶ 2:30:18So the the health sector coordinating council cyber security working group is the place where owners and operators of healthcare industries, hospitals, clinics, uh medical device manufacturers and so forth can freely join this organization and participate in the collaboration. and we have about 470ome organizations that are members of that. But that's only a scratch of the surface of what represents the actual totality of privately owned critical infrastructure of healthcare.
▶ 2:30:43You also mentioned uh the previous law signed by President Trump, the Cyber Security Act of 2015. This brings up a question that I want to ask you having to do with regulations. Um it's always a fine line for Congress to walk when you put regulations in place. You don't you want to serve a good purpose, but you don't want to be obstacles. Would you talk about that for a minute?
▶ 2:31:06How do we how do we walk that fine line, improve the regulations, but not make them obstacles to progress? Yeah, we actually have an answer, an an answer that we've been working on for the last eight years. The the law that was signed in, public law 116 321, it took uh the health industry cyber security practices publication, Hiccup, Greg referenced it earlier. I put it into my written testimony and it it embedded it as a recognized cyber security practice.
▶ 2:31:34What it did was it incentivized the organ the the healthcare industry to adopt that and if you adopt it then the regulators have to consider that during any enforcement action. So it's a carrot into the into the process there. It wasn't a stimulus. It wasn't a financial uh stimulus into the hospitals but it was a way to say this is the path forward. How we built that that the health industry cyber security practices document was a part of the consortium of the uh of the critical infrastructure policy advisory committee.
▶ 2:32:04Uh that is the HSCC the health sector coordinating council and the government coordinating council coming together working together to say these are the most important and impactful practices that are necessary. Everybody agrees and when everybody agrees it's very easy to say that should actually be the thing that we should then all do. Okay. Thank you for that. Mr. Garcia, same question. Any further comment on that regular? Well, I would just like to do a public service announcement to the Health Sector Coordinating Council. Health sector council.org is where your constituents can go uh to join the organization.
▶ 2:32:34Um we do not charge dues. Um and we welcome um any and all healthcare regulated organizations to assist uh in our collective mission. Thank you for that. Uh Mr. Deckerville got 30 seconds left, but any any comments you'd like to make regarding uh the uh clarity of federal cyber security standards? Yeah.
▶ 2:32:55So we actually built with with Hiccup uh just last year we put together the cyber security performance goals which was a again a jointly uh provided effort which defined what needs to be done to protect against this resiliency attack these ransomware attacks the ways that we know the adversaries are breaking in and how that connects to hiccup and and the whole how-to guide frame uh those we we need to be specific and clear when it comes to these standards and we've again like I said we've built them.
▶ 2:33:25All we need to do is just capitalize on them. Thank you, Mr. Decker. Mr. Chairman, yield back. Gentleman yields. Chair now recognizes the gentle lady from Michigan, Miss Dingle, for five minutes for her questions. Thank you, Mr. Chairman, and thanks for um holding this hearing today.
▶ 2:33:42As you've all heard from everybody talking, what's considered a medical device can be broad and include items ranging from a scalpel to a novel mechanical heart pump first used in my district at the University of Michigan.
▶ 2:33:57Innovation in medical devices is essential for our health care systems ability and to continue treating Recently, I held a round table of researchers at the University of Michigan who receive NIH funding who are very concerned about what disruptions in funding will mean for research and breakthroughs. They told me that one hiccup or brief pause in funding can push progress back for 40 years. Life-saving clinical trials trials are on hold.
▶ 2:34:27Brain cancer research funding's been cut by 30% and these are just examples. Without funding, the medical community is unable to prepare the next generation of health professionals. They can't hire or promote staff, and they're looking at more layoffs.
▶ 2:34:44As we discuss the importance of medical device research and innovation, we've got to support the great minds and teams who are protecting our devices from the next generation of cyber attacks and In addition to next generation of attacks, we all are dismayed at the next generation of firings at the FDA. Trump administrations creating tremendous uncertainty by firing then rehiring the FDA workforce.
▶ 2:35:11As you know, on February 24th, Doge fired 700 employees and then had to rehire many of them back after realizing that they were important safety expert experts. And then last week, Secretary Kennedy announced a plan to cut 3,500 employees from the FDA. Firing key drug safety officials in the name of efficiency is shortsighted and it's not the way our health care system should be run and it risks American safety. Dr.
▶ 2:35:41Damop, how is firing FDA safety employees an effective way to spur innovation and protect against cyber crime? I am uncertain as to the scope of effects that those firings would have other than to mention what I previously stated is that it would likely impact the ability for the FDA to um quickly and effectively measure and keep medical devices accountability at the point of submission.
▶ 2:36:09It's been pretty mentioned on the rest of the panel as well that their function in postmarket guidance when a device is found to be vulnerable is also not to be overstated. It could potentially impact that as well. Thank you. We're all worried. Now, I want to turn my attention to electronic medical records. Different companies contract with health systems to create a complex web of providers that can transmit health records, hospital records.
▶ 2:36:35However, there are concerns that sometimes the systems are blocking the necessary spread of information. This information blocking negatively impacts patient health and the quality of care that patients receive. The efficient exchange of electronic health information is critically important to ensure that patients and providers alike have access to the most up-to-date information when making important health care decisions.
▶ 2:37:01Unfortunately, according to data reported by the Office of National Coordinator for Health Information Technology, there have been thousands of claims of information blocking that have been submitted since April 2021. My home state of Michigan, there were 14,32 patients impacted in 13 health systems. Dr. Fu, what is being done to address information blocking and what can Congress do to ensure all organizations play fairly?
▶ 2:37:32So, I think electronic health records are uh really important topic and it's one that I've studied in the past. Uh although different from medical devices and different regulatory authorities uh what you're referring to his or health in information exchanges were a major part of some of the ONC efforts from about 10 years ago. uh and it has improved uh health information exchange to some extent but I too even as a patient have encountered this where it's been impossible to get records uh across certain administrative boundaries.
▶ 2:38:02Uh I'm not sure what to do about it in in that particular space. It's it's not an area where I'm actively working at the moment. Um but uh I I know that in the past it was more incentive system based uh and then as the meaningful use uh evolved uh into more penalties uh it um uh was was when my knowledge dropped off in that space. So um I'm I'm not sure the full answer to that question. Well, I'm out of time. I had one more question.
▶ 2:38:29But you would agree that we got a problem there and we need to be addressing it. It's certainly a personal problem to me. I think it goes much broader. Thank you, Mr. Chairman, and I yield back. Gentle lady yields. U chair now recognizes gentleman from Pennsylvania, the vice chairman of the full committee, Mr. Joyce, for five minutes for his questions. Thank you, Chairman Palmer and Ranking Member Clark for holding this important hearing and for our panel for testifying with us here today.
▶ 2:38:57As with many other sectors, as technology has advanced, our health care system has become increasingly dependent on a variety of interconnected devices. The ability of medical devices to connect to and communicate across networks yields tremendous benefits in terms of the availability of real time accurate health data. This data is critical in improving patient outcomes and efficiency of care while ultimately with the goal to hopefully lower costs.
▶ 2:39:26With widespread interconnectivity in such a critical and sensitive system as health care, we must be especially cognizant of the potential cyber security risks. I recall when I started my training as an intern at John's Hopkins in internal medicine, we made home visits. We were given a map of East Baltimore. Today, these same young interns go out and do these home visits, but they have connectivity.
▶ 2:39:50They have ability to take their devices with them and they don't have to be looking at a map to find out where the patient is they're going to visit, but they bring sensitive data with them on their devices. I would like to focus on some of the risks that exists as the health professional and patient level when dealing with potential vulnerable legacy medical devices. Dr. Dr.
▶ 2:40:11Damoth, as a physician and as an educator, do you feel that medical students and residents are receiving the adequate education and training regarding the potential cyber security risk of the devices that they utilize each and every day? To my knowledge, there is not a standardized curriculum at any medical school across this country regarding the risks of digital healthcare up to including cyber security. Should there be? That is a uh interesting question.
▶ 2:40:39I personally believe so that we should be equipping our next generation of clinicians with that knowledge. Um it is a hard thing. It would be argued that uh medical school is dense with enough information. Anatomy, physiology, pharmarmacology, those types of topics are often cited as being um should be optional electives. My personal belief is that we can't practice modern medicine without these technologies. We better equip our clinicians with the knowledge of what happens when they fail so they can still effectively care for their patients.
▶ 2:41:07The modern generation of clinicians, in my opinion, are not capable of safely caring for patients without things like the electronic health record, connected medical devices, and the old guard of doctors that were capable of caring for patients before the digital age are on their way out. How can we better prepare that next generation of physicians to be aware of that legacy medical device to malfunction or to be targeted should that you talked about medical students and your knowledge of an inadequate preparation of that. What about residencies?
▶ 2:41:38What about fellowships? Shouldn't that continue? Shouldn't that be the basis and then build on that basis? That's a great question. I think it needs to continue throughout the entire medical education uh cycle, if you will. They the only education I'm familiar of with residents and fellows, for instance, has to do with utilizing the electronic health record and protecting data, letting them know that if they violate HIPPA, for instance, that they could be fired or too late then. It's too late.
▶ 2:42:02if we're making individuals aware after the uh defect has already occurred, we need to be proactive and I think we can both agree on that. I agree. Mr. Garcia, you referenced in your testimony how continuing decreases in Medicare physician reimbursement impact the ability of doctors to upgrade or to replace vulnerable medical technology.
▶ 2:42:24Especially for physicians in rural areas that I represented and practice, declining reimbursement can ultimately make it unsuccessful to keep the doors open to keep that access for the patients who need them the most and the potential costs of more secure medical devices or the consequences of cyber attack occur in rural areas. Well, with this in mind, Mr.
▶ 2:42:48Garcia, would you agree that for the healthc care cyber security to be improved, it is important for physicians to be adequately compensated? Absolutely. Um, Congressman, uh, we have advocated that um, we need positive incentives for better cyber security across all um, health care systems. And uh, you know what better than reimbursement? Follow the money.
▶ 2:43:14If you have a positive incentive that says if you do better in cyber security, if you can replace your aging medical devices, um we will uh improve your reimbursement. It's that simple. I think you really nailed it when you talk about how important cyber security is. It's important across all sectors, but it's incredibly important when it comes to patients lives and when those lives are at stake.
▶ 2:43:37Moving forward, I am confident that this committee will be a leader in allowing doctors to be better informed and properly reimbursed so that they can be partners in improving cyber security for their patients and within their profession. Thank you, Mr. Chairman, and I yield. Gentleman yields. Seeing there are no further members wishing to ask questions, I would like to thank our witnesses uh again for being here today.
▶ 2:44:04Uh, I ask unanimous consent to insert in the record the documents included on the staff hearing documents list without objection. So ordered. Pursuant to committee rules, I remind members that they have 10 business days to submit additional questions for the record and ask that the witnesses submit their responses within 10 days upon receipt of the questions. Without objection, the subcommittee is adjourned.
▶ 2:44:48I wanted to cyber security for the clinician video series that he's the star of that should be part of I Thank you.
▶ 2:45:23Thank you. I appreciate the chairman's