WSGR logoWSGR logo
WSGR logo
  • Experience
  • People
  • Insights
  • About Us
  • Careers

  • Practice Areas
  • Industries

  • Corporate
  • Intellectual Property
  • Litigation
  • Patents and Innovations
  • Regulatory
  • Technology Transactions

  • Capital Markets
  • Corporate Governance
  • Corporate Life Sciences
  • Derivatives
  • Emerging Companies and Venture Capital
  • Employee Benefits and Compensation
  • Energy and Climate Solutions
  • Executive Advisory Program
  • Finance and Structured Finance
  • Fund Formation
  • Greater China
  • Mergers & Acquisitions
  • Private Equity
  • Public Company Representation
  • Real Estate
  • Restructuring
  • Shareholder Engagement and Activism
  • Tax
  • U.S. Expansion
  • Wealthtech

  • Special Purpose Acquisition Companies (SPACs)

  • Environmental, Social, and Governance

  • AI and Data Center Infrastructure
  • Energy Regulation and Competition
  • Project Development and M&A
  • Project Finance and Tax Credit Transactions
  • Sustainability and Decarbonization
  • Transportation Electrification

  • U.S. Expansion Library and Resources

  • Post-Grant Review
  • Trademark and Advertising

  • Antitrust Litigation
  • Arbitration
  • Board and Internal Investigations
  • Class Action Litigation
  • Commercial Litigation
  • Consumer Litigation
  • Corporate Governance Litigation
  • Employment Litigation
  • Executive Branch Updates
  • Government Investigations
  • Internet Strategy and Litigation
  • Patent Litigation
  • Securities Litigation
  • State Attorneys General
  • Supreme Court and Appellate Practice
  • Trade Secret Litigation
  • Trademark and Copyright Litigation
  • Trial
  • White Collar Crime

  • Advertising, Promotions, and Marketing
  • Antitrust and Competition
  • Committee on Foreign Investment in the U.S. (CFIUS)
  • Communications
  • Data, Privacy, and Cybersecurity
  • Export Control and Sanctions
  • FCPA and Anti-Corruption
  • FDA Regulatory, Healthcare, and Consumer Products
  • Federal Trade Commission
  • Fintech and Financial Services
  • Government Contracts
  • National Security and Trade
  • Payments
  • State Attorneys General
  • Strategic Risk and Crisis Management
  • Tariffs, Customs, and Import Compliance

  • Antitrust and Intellectual Property
  • Antitrust Civil Enforcement
  • Antitrust Compliance and Business Strategy
  • Antitrust Criminal Enforcement
  • Antitrust Litigation
  • Antitrust Merger Clearance
  • European Competition Law
  • Third-Party Merger and Non-Merger Antitrust Representation

  • Anti-Money Laundering
  • Foreign Ownership, Control, or Influence (FOCI)
  • Team Telecom

  • AI in Healthcare
  • Animal Health
  • Artificial Intelligence and Machine Learning
  • Aviation
  • Biotech
  • Blockchain and Cryptocurrency
  • Clean Energy
  • Climate and Clean Technologies
  • Communications and Networking
  • Consumer Products and Services
  • Data Storage and Cloud
  • Defense Tech
  • Diagnostics, Life Science Tools, and Deep Tech
  • Digital Health
  • Digital Media and Entertainment
  • Electronic Gaming
  • Fintech and Financial Services
  • FoodTech and AgTech
  • Global Generics
  • Internet
  • Life Sciences
  • Medical Devices
  • Mobile Devices
  • Mobility
  • NewSpace
  • Quantum Computing
  • Semiconductors
  • Software

  • Offices
  • Country Desks
  • Events
  • Community
  • Our Diversity
  • Sustainability
  • Our Values
  • Board of Directors
  • Management Team

  • Austin
  • Boston
  • Boulder
  • Brussels
  • Century City
  • Hong Kong
  • London
  • Los Angeles
  • New York
  • Palo Alto
  • Salt Lake City
  • San Diego
  • San Francisco
  • Seattle
  • Shanghai
  • Washington, D.C.
  • Wilmington, DE

  • Law Students
  • Judicial Clerks
  • Experienced Attorneys
  • Patent Agents
  • Business Professionals
  • Alternative Legal Careers
  • Contact Recruiting
Manufacturers of Instruments Routinely Used in In Vitro Diagnostics Should Carefully Consider FDA's Recent Cybersecurity Guidance
Alerts
December 4, 2018

High throughput sequencers, including next generation, or NGS, sequencers; polymerase chain reaction, or PCR, machines; flow cytometers; and other instruments are routinely used in conducting in vitro diagnostic assays. Many of these devices are interoperable—i.e., are capable of exchanging and using information across medical and non-medical networks, or the internet.

NGS sequencers are especially powerful as diagnostic medical devices:

"Most IVDs [in vitro diagnostics] detect only a single or a defined number of substances to diagnose one or several specified conditions. In contrast, NGS tests are capable of detecting the over 3 billion bases in the human genome, and in doing so identify the approximately 3 million genetic variants an individual may have. A single use of an NGS test could enable the diagnosis of any one, or more, diseases or conditions a patient presents with. NGS tests can also help to predict a patient's risk for developing certain conditions. Because it is possible to sequence the whole genome, it is not necessary to know what variant one wishes to identify prior to running and successfully interpreting an NGS test—a concept which is very different from how traditional IVDs are used."1

The use of NGS sequencers, as diagnostic medical devices, coupled with their interoperability, makes them potential targets for a medical device hack. We previously published an article about medical device hacking associated with more traditional medical devices (such as implantable cardiac devices), and the hack's consequences and potential ramifications. Traditional medical device manufacturers are, in our experience, generally aware of—and take steps to mitigate—cybersecurity risks associated with their products. But instruments like NGS sequencers can be medical devices, and these instruments can therefore be subject to different degrees of U.S. Food and Drug Administration, or FDA, regulation. And a hack of these instruments, functioning as medical devices, can directly result in harm to patients.

Recently, we summarized the FDA's draft guidance "Content of Premarket Submissions for Management of Cyber Security in Medical Devices" (the guidance). A key driver for the FDA's issuing the guidance is that cyber security incidents have "rendered medical devices and hospital networks inoperable" and that the "need for effective cybersecurity to ensure medical device functionality and safety has become more important…"2

The guidance defines two Tiers of cybersecurity risk. Medical devices have a Tier 1 risk if: 1. the device is capable of connecting to another medical or non-medical product network, or the internet; and 2. a cybersecurity incident affecting the device could directly result in harm to patients.3Examples of Tier 1 devices include connected or connectable: implantable cardioverter defibrillators, pacemakers, left ventricle assist devices, brain stimulators, dialysis devices, infusion and insulin pumps.4The second Tier, or Tier 2, is a device for which the criteria for a Tier 1 device are not met.

All of the above Tier 1 examples (e.g., pacemakers) are what would be thought of as traditional medical devices. But the incorporation of instruments such as interoperable NGS sequencers into IVDs, in the event of a hack, could result in delaying vital diagnostic outcomes or changing vital diagnostic results. In other words, a hack could directly result in harm to patients. So these interoperable instruments used in IVDs can be Tier 1 cybersecurity risks.

This takes on significant importance because of the sheer number of labs performing IVDs, and the sheer number of tests issuing from these labs. By one estimate, the commercial medical and diagnostic laboratory industry in the U.S. consists of about 17,000 establishments (single-location companies and units of multi-location companies) with combined annual revenues of about $50 billion. Medical labs account for about 65 percent of diagnostic industry revenue.

By another estimate, in 2018, about 75,000 genetic testing units, or GTUs, were actively marketed by Clinical Laboratory Improvement Amendments (CLIA)-certified laboratories in the U.S., and about 15 new GTUs per day are being offered. Thus, hacks on NGS instruments used in IVDs could directly and significantly harm large numbers of patients nationwide. Which brings us back to the guidance.

A significant part of the guidance is devoted to helping to ensure a device can be trustworthy. The guidance states that trustworthy devices: 1. are reasonably secure from cybersecurity intrusion and misuse; 2. provide a reasonable level of availability, reliability, and operation; 3. are reasonably suited to performing their intended functions; and 4) adhere to generally accepted security procedures.5Trustworthiness is one of several considerations that instrument manufacturers should keep in mind.

As general considerations: manufacturers of interoperable instruments used in IVDs should think carefully about how and where their instruments will be used. One strategy for possibly controlling how an interoperable instrument can be used is employment of a label license. Also, where warranted, awareness of and compliance with FDA regulations are important. Designing devices to be used in IVDs as trustworthy devices should be carefully considered. And contingencies in the event of a hack should be put into place before the occurrence of an actual hack.

For questions regarding this alert, the guidance, or FDA's regulation of the cybersecurity risk of medical devices, please contact Vern Norviel or David Hoffmeister, or any member of the patents and innovations or FDA regulatory groups.


1"Optimizing FDA's Regulatory Oversight of Next Generation Sequencing Diagnostic Tests"—Preliminary Discussion Paper, at 2. Available at: https://www.fda.gov/downloads/MedicalDevices/NewsEvents/WorkshopsConferences/UCM427869.pdf.
2The guidance, at 4.
3Id., at 10.
4Id.
5Id.

Contributors

  • Vern Norviel
  • David M. Hoffmeister
  • people
  • insights
  • about us
  • careers
  • Binder
  • Alumni
  • Mailing List Signup
  • Client FTP Portal
  • Privacy Policy
  • Terms of Use
  • Accessibility
WSGR logo
Twitter
LinkedIn
Facebook
Instagram
Youtube
Copyright © 2026 Wilson Sonsini Goodrich & Rosati. All Rights Reserved.