Industries

Helping clients meet their business challenges begins with an in-depth understanding of the industries in which they work. That’s why KPMG LLP established its industry-driven structure. In fact, KPMG LLP was the first of the Big Four firms to organize itself along the same industry lines as clients.

How We Work

We bring together passionate problem-solvers, innovative technologies, and full-service capabilities to create opportunity with every insight.

Learn more

Careers & Culture

What is culture? Culture is how we do things around here. It is the combination of a predominant mindset, actions (both big and small) that we all commit to every day, and the underlying processes, programs and systems supporting how work gets done.

Learn more

Helping Manufacturers Strengthen Medical Device Security

KPMG LLP helps medical device manufacturers comply with cybersecurity regulations, ensuring patient safety and privacy.

Cybersecurity breaches involving medical devices can have severe consequences, threatening patient safety and privacy. However, securing these devices is complex and resource intensive. The guidelines and regulations for medical device cybersecurity are comprehensive, technical, and regularly updated to address emerging threats and vulnerabilities, making aligning to them a continual process rather than a one-time effort. Healthcare delivery organizations (HDOs) and individual patients continue to drive increasing security requirements for medical device manufacturers, often accelerated by broader healthcare breaches. 

Manufacturers must first navigate the US FDA approval process for medical devices, which requires a rigorous demonstration of safety and efficacy with cybersecurity measures. Section 3305 of the Food and Drug Omnibus Reform Act of 2022 (“FDORA”) added new authorities for the FDA to enable the FDA to require certain cybersecurity information for approval submissions. In September 2023, the FDA updated its pre-market guidance for devices with new guidelines that significantly raised the expectation for cybersecurity. This was followed by a March 2024 draft guidance document from the FDA that proposed additional cybersecurity expectations. 

Beyond the US FDA, there is now a global landscape of dozens of medical device security-relevant regulations that manufacturers must navigate, such as IMDRF guidance, the EU MDR, and China’s CSL. 

With the continuous evolution of cybersecurity standards and practices, manufacturers face the daunting task of ensuring their devices meet and maintain compliance with the latest recommendations and requirements.

How can KPMG help?

To address these challenges, our experienced team of life-science subject matter professionals can help assess your medical device security program and device features and also help you improve processes and technology to better align with the FDA, other global guidance, and customer expectations. We can support you with:

  • Current State Assessments (holistic, regulation-specific, or customized)
  • Strategy, Roadmap, Operating Model, and Business Case Development
  • Coordinated Vulnerability Disclosure (CVD) Program Building
  • Security Reference Architecture Development
  • Software Bill of Materials (SBOM) Support
  • ...and more.

Beyond the above, our team of seasoned medical device security professionals also has insight across the industry and regulatory environment and is happy to be available for knowledge-sharing sessions to keep you informed on the latest developments.

Dive into our thinking:

KPMG PCI Compliance Services

Download PDF

Life Sciences

KPMG can help companies in pharmaceuticals, medical devices, and biotech use automation, artificial intelligence, and data analytics to improve performance and find new opportunities.

Meet Our Team

Image of Adam Brand
Adam Brand
Principal, Advisory, Cyber Security Services, KPMG US
Image of Scott Erven
Scott Erven
Principal, Cyber Security Services, KPMG US

Explore other services tailored to your business

Thank you!

Thank you for contacting KPMG. We will respond to you as soon as possible.

Contact KPMG

Use this form to submit general inquiries to KPMG. We will respond to you as soon as possible.

By submitting, you agree that KPMG LLP may process any personal information you provide pursuant to KPMG LLP's Privacy Statement.

An error occurred. Please contact customer support.

Job seekers

Visit our careers section or search our jobs database.

Submit RFP

Use the RFP submission form to detail the services KPMG can help assist you with.

Office locations

International hotline

You can confidentially report concerns to the KPMG International hotline

Press contacts

Do you need to speak with our Press Office? Here's how to get in touch.

Headline