FDA Seeks Feedback on Potential Regulation of GenAI Medical Devices – The HIPAA Journal
FDA Seeks Feedback on Potential Regulation of GenAI Medical Devices – The HIPAA Journal
FDA Seeks Feedback on Potential Regulation of GenAI Medical Devices
The U.S. Food and Drug Administration (FDA) has issued a discussion paper on considerations for the regulation of Generative AI (GenAI)-enabled medical devices. As a regulator of all medical devices, the FDA is considering whether new regulations are required for GenAI-enabled medical devices to ensure patients are provided with timely access to safe and effective devices.
GenAI-enabled medical devices have the potential to transform patient care, yet the devices may introduce unique risks compared to traditional software and artificial intelligence (AI)-enabled medical devices. Current regulatory frameworks, such as those used for traditional medical devices, may not be appropriate for GenAI-enabled devices, which present unique challenges and risks.
The devices have unique characteristics and behaviours, including the capability to produce variable outputs, which change over time as the devices incorporate continuously learning systems. GenAI devices can accept open-ended inputs, and it is not feasible to test the full range of inputs and assess outputs using traditional premarket testing methodologies. The FDA notes that many devices are built on general-purpose foundation models, which have been developed by third parties that have varying levels of transparency into training data, architecture, and evaluation methods. As such, specific behaviors and errors are difficult to attribute to the underlying model used by the devices.
While GenAI-enabled devices offer a wide range of benefits over and above what can be gained from traditional and AI-enabled medical devices, the characteristics that provide those benefits also present unique risks. For instance, GenAI systems may misinterpret or distort data, filling in knowledge gaps with plausible but invented information (confabulations), such as associating a symptom with the wrong condition. There is also a risk of hallucinations – the generation of false facts – on which output is based and presented as fact. GenAI tools may provide outputs that are plausible and sound authentic to end users, which may be questionable at best and potentially dangerous to health.
Get The FREE
HIPAA Compliance Checklist
Immediate Delivery of Checklist Link To Your Email Address
Please Enter Correct Email Address
Your Privacy Respected
HIPAA Journal Privacy Policy
The discussion paper, published by the FDA’s Center for Devices and Radiological Health (CDRH) – Considerations for the Regulation of Generative AI-Enabled Medical Devices: Discussion Paper and Request for Feedback – delves into the challenges associated with premarket evaluation and postmarket monitoring of GenAI-enabled medical devices. The aim of the paper is to guide discussion and focus feedback ahead of the potential development of guidance and future regulations. No decision has been made about whether FDA regulation is required, or areas where guidance may be necessary. The feedback obtained in response to the discussion paper will guide future FDA decisions, including new methodologies for premarket evaluation and the postmarket assessment of the performance of GenAI-enabled medical devices to ensure they remain safe and effective throughout the entire product lifecycle.
The paper discusses the possibility of competency-based testing of GenAI-enabled medical devices for premarket evaluations, using an approach modelled on medical training, licensure examinations, supervised practice, periodic reevaluation, and public reporting, and device benchmarking to assess whether a device demonstrates the necessary clinical knowledge, analytic capabilities, safety behavior, communication, and generalizability to support reasonable assurance of safety and effectiveness of the device for its intended use. Potentially, clinical confirmation will be required, as a competency-based approach may not fully assess performance in a clinical setting.
The FDA anticipates a risk-based approach will be necessary for regulation, taking into consideration the intended use and device characteristics. For instance, certain action-directing functions may be classed as higher risk than functions that provide non-directive information, as well as agentic AI systems capable of autonomous actions.
The FDA said it wishes to work collaboratively with the full range of stakeholders to develop efficient, scientifically sound, and least burdensome approaches to the premarket evaluation and postmarket monitoring of GenAI-enabled devices. Feedback on the discussion draft is requested from medical device manufacturers, clinicians, researchers, and the general public by October 19, 2026.
The post FDA Seeks Feedback on Potential Regulation of GenAI Medical Devices appeared first on The HIPAA Journal.
HHS Updates Security Risk Assessment Tool – The HIPAA Journal
HHS Updates Security Risk Assessment Tool
The HHS has released an updated version of the Security Risk Assessment (SRA) Tool (v3.7). The tool is ideally suited for small- and medium-sized entities to guide them through the risk analysis process, help them identify risks and vulnerabilities to electronic protected health information (ePHI), and comply with the risk analysis implementation specification of the Security Management Process standard of the HIPAA Security Rule.
The SRA Tool was developed by the Department of Health and Human Services Office of the National Coordinator for Health Information Technology (ONC) in collaboration with the Office for Civil Rights (OCR). The downloadable tool was first released in March 2014 to help small- and medium-sized HIPAA-regulated entities navigate the risk analysis requirement of the HIPAA Security Rule.
The tool guides regulated entities through the process of conducting and documenting risk analyses, the aim of which is to identify potential weaknesses and gaps in security policies and all risks and vulnerabilities to ePHI. Only by conducting a comprehensive and accurate risk analysis will HIPAA- regulated entities be able to identify all risks and vulnerabilities to ePHI. If risks and vulnerabilities remain unknown, regulated entities will not be able to take the necessary steps to reduce them to a low and acceptable level and comply with the Risk Management standard of the HIPAA Security Rule.
The SRA Tool has received many upgrades over the years to improve usability and add compliance features. The latest release –September 2026 –includes content improvements in questions, responses, and education, expanding the tool to make it more comprehensive and ensure it remains relevant in an evolving cybersecurity environment.
Get The FREE
HIPAA Compliance Checklist
Immediate Delivery of Checklist Link To Your Email Address
Please Enter Correct Email Address
Your Privacy Respected
HIPAA Journal Privacy Policy
Key updates include the addition of new technologies that have been adopted by regulated entities; a new assessment-scope question to ensure that risk assessments account for every location that creates, receives, maintains, or transmits ePHI; new remote access and telework questions; modernization of the asset inventory to cover technologies that practices are now using; and an update to the system-activity logging question to reflect the varied systems used by regulated entities. The new version also includes updated software libraries, bug fixes, and tweaks in response to feedback to make the application and Excel workbook easier to use.
OCR Actively Enforcing Risk Analysis and Risk Management Compliance
HIPAA-regulated entities have long struggled with conducting risk analyses, and 12 years after the tool was first released, OCR still frequently identifies noncompliance in this area. OCR often finds that risk analyses have never been completed, that they are incomplete or inaccurate, or that there is a lack of documentation of risk analysis processes and procedures.
Widespread noncompliance with this vital Security Rule implementation specification prompted OCR to launch a new risk analysis enforcement initiative in 2024 to encourage and improve compliance. To date, OCR has imposed 14 financial penalties under this initiative, which remains a key enforcement priority for OCR. Further, the planned update to the HIPAA Security Rule, which now has a July 2027 proposed release date, will increase the risk analysis requirements further.
The risk analysis is only the first step in the risk management process. HIPAA-regulated entities must ensure that the identified risks and vulnerabilities are managed effectively and reduced to a low and acceptable level. At the 2026 NIST/OCR conference, Safeguarding Health Information: Building Assurance through HIPAA Security 2026, OCR Director Paula Stannard explained that many regulated entities appear to be confusing risk management with the cybersecurity performance goals (CPGs) issued by OCR in January 2024.
While the CPGs can be adopted by regulated entities to improve their security posture and prevent cyberattacks and data breaches, simply implementing those measures does not satisfy the risk management requirements of the HIPAA Security Rule. The risk management standard requires specific risk management measures to be implemented to address the risks and vulnerabilities identified by the risk analysis.
OCR has confirmed that the risk analysis enforcement initiative has been expanded to cover risk management. In addition to requiring evidence showing that an accurate and comprehensive risk analysis has been conducted, OCR requires evidence that identified risks have been subjected to a HIPAA-compliant risk management process. OCR wants to ensure that regulated entities are acting on the results of their risk analyses and are taking appropriate actions to reduce risks and vulnerabilities to ePHI.
The post HHS Updates Security Risk Assessment Tool appeared first on The HIPAA Journal.
Orthanc DICOM Server Vulnerability Can Lead to Denial of Service – The HIPAA Journal
Orthanc DICOM Server Vulnerability Can Lead to Denial of Service
A high-severity vulnerability has been identified in Orthanc DICOM Server that could be exploited by an authenticated remote attacker to write past the end of a heap allocation and crash an Orthanc process in a denial-of-service attack.
Orthanc DICOM Server is a free-to-use, standalone, open-source, lightweight DICOM server that is used in both clinical and research environments. It can complement or act as a gateway to existing PACS systems, and was developed to improve interoperability and workflow efficiency.
An integer overflow in a specified pitch and buffer-size computation results in a heap out-of-bounds write when Orthanc decodes a specially crafted PNG or JPEG image file, causing a crash and denial-of-service condition.
The vulnerability is tracked as CVE-2026-87020 and has been assigned a CVSS v3.1 base score of 8.1 and a CVSS v4.0 base score of 7.2. The vulnerability was identified by penetration tester Andrej Tomci, who reported the issue to the Cybersecurity and Infrastructure Security Agency.
Get The FREE
HIPAA Compliance Checklist
Immediate Delivery of Checklist Link To Your Email Address
Please Enter Correct Email Address
Your Privacy Respected
HIPAA Journal Privacy Policy
The vulnerability affects all Orthanc DICOM Server prior to 1.13.0. Orthanc has fixed the vulnerability in version 1.13.0. and later versions. Users are advised to verify the installed Orthanc DICOM Server version and download the latest version if a vulnerable version is in use. It is also recommended to restrict network access to Orthanc instances to trusted hosts only.
The post Orthanc DICOM Server Vulnerability Can Lead to Denial of Service appeared first on The HIPAA Journal.
