{"podcast":{"title":"Let's Talk Risk! Podcast","slug":"let-s-talk-risk-podcast-6693844","podcast_index_feed_id":6693844,"rss_url":"https://api.substack.com/feed/podcast/1477050.rss","website_url":"https://naveenagarwalphd.substack.com/podcast","image_url":"https://substackcdn.com/feed/podcast/1477050/ee2039dcd34796f25b1263b7e1659bef.jpg","author":"Where MedTech professionals gain clarity and confidence to navigate complex decisions.","episode_count":173,"summary":"Where MedTech professionals gain clarity and confidence to navigate complex risk, quality, and leadership challenges.","last_synced_at":"2026-07-10T22:17:47.658661+00:00","page_url":"https://stenobird.com/podcast/let-s-talk-risk-podcast-6693844"},"episode":{"title":"Case Study: Why FDA Cybersecurity Expectations Are Really QMS Expectations","slug":"case-study-why-fda-cybersecurity-expectations-are-really-qms-expectations","published_at":"2026-07-10T12:00:00+00:00","page_url":"https://stenobird.com/podcast/let-s-talk-risk-podcast-6693844/case-study-why-fda-cybersecurity-expectations-are-really-qms-expectations","show_page_url":"https://stenobird.com/podcast/let-s-talk-risk-podcast-6693844","url":"https://naveenagarwalphd.substack.com/p/case-study-why-fda-cybersecurity-are-qms-expectations","audio_url":"https://api.substack.com/feed/podcast/206300700/934690b84890a6fbc944c71690b30f6a.mp3","summary":"You cannot bolt cybersecurity onto a medical device at the end of development. FDA’s cybersecurity guidance makes a clear shift: cyber risk is now a quality system issue, a patient safety issue, and a lifecycle management issue. For connected and software-enabled devices, it is not enough to show that the software works as intended. Manufacturers also need to show how cybersecurity risks were identified, controlled, verified, traced to patient harm, and managed after release. In this audio summary, we walk through why FDA’s expectations go beyond submission documentation and why QA/RA teams need to understand the practical connections between SPDF, threat modeling, SBOMs, vulnerability management, postmarket patching, and the medical device QMS. Key highlights covered in the audio: * Why cybersecurity now needs to be treated as part of the medical device QMS * How Section 524(b) changes expectations for “cyber devices” * Why cyber risk needs to connect to patient harm, not just IT vulnerability * How SPDF, threat modeling, architecture views, and testing evidence fit together * Why machine-readable SBOMs and VEX documentation matter for vulnerability management * How postmarket patching, CVD, and cybersecurity management plans create lifecycle obligations Keywords: FDA cybersecurity guidance, medical device cybersecurity, cyber device, SPDF, SBOM, medical device QMS, cybersecurity risk management, patient safety, postmarket cybersecurity. 🎧Click Play above to listen to a brief audio summary about this case and lessons QA/RA and Clinical professionals can apply in practice using the newly released FDA Guidance. Thanks for reading Let's Talk Risk! . If you liked this post, share with others. Note: The audio summary was prepared using Google NotebookLM, an AI-enabled rese…","meta_description":"You cannot bolt cybersecurity onto a medical device at the end of development. FDA’s cybersecurity guidance makes a clear shift: cyber risk is now a quali…","key_points":[],"chapters":[],"topics":[],"duration_seconds":1049,"processing_state":"not_requested","actions":[{"name":"request_transcript","method":"POST","url":"https://stenobird.com/v1/public/podcasts/let-s-talk-risk-podcast-6693844/episodes/case-study-why-fda-cybersecurity-expectations-are-really-qms-expectations/transcription-requests","description":"Idempotently request low-priority transcript generation for this episode."},{"name":"read_markdown","method":"GET","url":"https://stenobird.com/podcast/let-s-talk-risk-podcast-6693844/case-study-why-fda-cybersecurity-expectations-are-really-qms-expectations.md","description":"Read the agent-friendly Markdown representation of this episode resource."}]}}