Manufacturer Disclosure Statement for Medical Device Security
A standardized form by which device manufacturers disclose security characteristics to healthcare delivery organizations.
Definition
The Manufacturer Disclosure Statement for Medical Device Security (MDS2), maintained by the Healthcare Information and Management Systems Society (HIMSS) and aligned to IEC 80001-2-2, is a standardized questionnaire that manufacturers complete to disclose a connected device's security characteristics - authentication, encryption, audit controls, malware protection, network configuration, patch policy - to hospital procurement and security teams.What this means in practice
MDS2 sits at the manufacturer-HDO handoff and is one of the highest-leverage documents a security program produces. A well-completed, current MDS2 directly accelerates hospital procurement; a stale or incomplete MDS2 stalls deals. Mature MedTech teams maintain MDS2 as a living document tied to each release.- •Treating MDS2 as a marketing document - overstating capabilities backfires in operator audits.
- •Letting MDS2 go stale across releases.
- •Not aligning MDS2 to MDS2-2019 (the current version) - older versions miss key security characteristics.
Frequently asked questions
Cross-references
See also
Closely related context worth reading.
Related terms
Grouped by themeEditor's picks
· Hand-selected related conceptsAn industry-developed reference framework from the Healthcare Sector Coordinating Council for end-to-end MedTech cybersecurity.
International standard for risk management of IT networks that incorporate medical devices.
The federal statute that gives FDA explicit premarket authority over cybersecurity for cyber devices.
More in Cybersecurity
· Same categoryAAMI/ANSI standard establishing requirements for medical-device cybersecurity activities throughout the lifecycle.
AAMI Technical Information Report providing MedTech-specific guidance on cybersecurity risk management.
AAMI Technical Information Report on post-market security risk management for medical device manufacturers, the operational companion to TIR57.
Unauthorized remote control of an implanted neurostimulator (e.g., DBS) to alter stimulation parameters and harm a patient.
Primary references
3 sources- 1
HIMSS MDS2VerifiedHIMSShimss.org
- 2
IEC TR 80001-2-2VerifiedISO/IECiso.org
- 3
HSCC - Health Sector Coordinating CouncilVerifiedHSCChealthsectorcouncil.org
Inline markers like [1] jump to the matching reference above.