Cybersecurity of Medical Devices: Is the Software Bill of Materials a Help or a Hidden Danger?
As cyberattacks pose an increasing threat to healthcare organizations, the FDA is pushing medical device manufacturers to provide a Software Bill of Materials (SBOM) to enhance transparency of third-party software components. Supporters believe this helps identify and mitigate vulnerability risks, but industry groups such as AdvaMed worry that SBOMs could be exploited by hackers, increasing device susceptibility. This article reviews the progress, controversies, and future regulatory directions of SBOMs.

For years, the U.S. Food and Drug Administration (FDA) has emphasized the need for medical devices to include a software bill of materials (SBOM) — an electronically readable list of third-party components in a device — to address widespread cybersecurity vulnerabilities.
The push for SBOMs gained significant momentum in May 2021, when U.S. President Joe Biden signed an executive order aimed at strengthening the nation's cybersecurity posture, with one measure focusing on enhancing software supply chain security.executive order, which included a measure to strengthen software supply chain security.
The momentum from that executive order, combined with a multi-stakeholder initiative led by the National Telecommunications and Information Administration (NTIA), a Commerce Department agency, aimed at improving transparency of software components across multiple industries, including medical technology,multi-stakeholder initiative, may have created a turning point for SBOMs.
Kevin Fu, acting director of medical device cybersecurity at the FDA's Center for Devices and Radiological Health (CDRH), told MedTech Dive in June that medical device manufacturers must provide SBOMs to "better understand the exposure to known and future vulnerabilities of third-party software inlegacy devices."
Many older medical devices currently in use — running outdated or insecure software — were not designed with cybersecurity in mind. SBOM supporters argue that without this visibility, healthcare providers like hospitals often don't realize their devices contain components vulnerable to hacking. By standardizing the data-sharing process, device users can better understand what's running on their networks and how to protect it, the core rationale goes.
The FDA has supported the NTIA's SBOM efforts since they began in 2018, helping to develop models, formats, and other outputs that could eventually be used by the National Institute of Standards and Technology (NIST) for its software integrity guidance to implement Biden's executive order.
Suzanne Schwartz, director of the CDRH's Office of Strategic Partnerships and Technological Innovation, told MedTech Dive in August that the agency wants to require medical technology companies to provide SBOMs in premarket submissions ahead of time. The FDA chose to push SBOM requirements in 2021, given Biden's executive order and the growing threat of ransomware and othercyberattacks on healthcare organizations。
"An SBOM sitting only in a manufacturer's records is not helpful; the opportunity for risk mitigation lies in transparency," said the FDA's Schwartz. "Device owners and operators — whether hospitals, healthcare organizations, providers, or patients — should be aware of the SBOM, and this requirement is part of future legislative proposals we are working on."
However, the FDA's intent goes beyond just mandating a list of third-party software components in devices. The Department of Health and Human Services (HHS) fiscal year 2021 congressional budget justification states that the FDA is seeking a statutory requirement to "phase in a cybersecurity bill of materials (CBOM)" that would include, but not be limited to, lists of commercial, open-source, and off-the-shelf software and hardware components that "are or could be susceptible to vulnerabilities." The FDA said a software-focused SBOM would be part of the broader CBOM requirement, which would include managing hardware-centric third-party cybersecurity risks.
Healthcare provider organizations have shockingly low visibility into their own medical devices, leaving them at risk of cyberattacks. A recentsurveyby the Ponemon Institute found that only 36% of respondent groups believed they were effective at knowing the location of all their medical devices, while just 35% said they knew when device vendors' operating systems reached end-of-life or became outdated.
Allan Friedman, former director of cybersecurity initiatives at NTIA and now at the U.S. Cybersecurity and Infrastructure Security Agency (CISA), warned that without a list of third-party components, healthcare providers would find it difficult to know which medical devices are affected and how to implement mitigation strategies once a vulnerability is discovered.
"You can't defend what you don't know."
— Allan Friedman, Cybersecurity and Infrastructure Security Agency
Friedman praised Biden's executive order (which will change federal procurement regulations) for raising the "visibility" of SBOMs and software supply chain transparency, and for "paving the way" for the active standards developed at NTIA over the past three years. When asked if the FDA requiring SBOMs as part of premarket submissions was a good idea, Friedman declined to answer. But he noted that understanding the "inner workings" of medical devices allows healthcare providers to quickly determine if they are affected by newly discovered cyber vulnerabilities.
A roadmap for hackers or defenders?
The SBOM concept is based on third-party component information contained in a machine-readable format that can be easily shared with stakeholders like healthcare providers. But the data could also be accessed and exploited by cybercriminals, potentially making medical devices more vulnerable to attacks. At least, that's a concern within the medical device industry.
"From a common-sense perspective, we want to ensure there are certain guardrails. In the context of releasing SBOMs, they really should be in a secure environment so the public can't easily access them," said Zach Rothstein, vice president of technology and regulatory affairs at AdvaMed.
While NTIA calls this a common misconception and concern, the agency acknowledges it's theoretically possible because "all information is a double-edged sword." The agency argues that "the defensive benefits of transparency far outweigh this common concern, as SBOMs are more like a 'roadmap for defenders'" than a source of dangerously sensitive data for hackers to target medical devices.
The FDA's 2018Medical Device Safety Action Planreminded the industry that the agency was considering requiring companies to develop SBOMs as part of premarket submissions and provide them to healthcare users.
AdvaMed'sformal commentsquestioned the benefits of SBOMs, given the inherent risk of information falling into the wrong hands, and warned of the excessive implementation burden on healthcare providers. The lobbying group also expressed concerns about the lack of proper controls for sharing and maintaining SBOMs, warning that if these electronically readable files were stored in publicly accessible central databases, they could let hackers know what software runs inside devices and put patients at potential harm.
"For a period after a vulnerability is discovered, a device may be at higher risk of exploitation — until the vulnerability is mitigated — if the information contained in an SBOM is obtained by malicious actors," AdvaMed warned. AdvaMed recommended that "access to SBOM information should be restricted, for example, to hospital network operators only," to ensure "appropriate risk management is in place and unintended consequences are mitigated."
NTIA seems open to such access controls and included them in the agency's July-released SBOM minimum elementsguidance. "Many suppliers, including open-source maintainers and providers of widely available software, may see it in their best interest to make SBOM data public. Other organizations, especially in the early stages, may want to keep this data confidential and restrict access to specific customers or users," NTIA said.
Overall, Rothstein said the medical technology industry supports SBOMs "as a general proposition," particularly as a potential solution to help defend older legacy devices against growing cyber threats. But AdvaMed also wants to see uniform standards to ensure device manufacturers provide the same information and "don't have to create 10 different versions to meet SBOM requirements," Rothstein said.
Ultimately, NTIA concluded that if SBOMs are to be successfully implemented across multiple industries, both broad rules and policies and sector-specific flexibility are needed. Friedman acknowledged this fundamental tension: a "one-size-fits-all approach" to SBOMs is "easier to scale, easier to build tools and policies around," while a "sector-specific" approach for industries like medical technology remains to be worked out.
