FDA Warns of Computer Software Vulnerabilities in Laboratories
Federal regulators are sounding the alarm about potential vulnerabilities in computer software used in laboratories, with FDA officials expressing concerns about systems that cannot detect or prevent data tampering. Pharmaceutical companies are being warned to ensure that their computer systems can detect and track changes to laboratory records, a crucial aspect of maintaining data integrity.
Key Takeaways:
- FDA officials have identified at least three instances in the past year where computer systems failed to issue reports indicating that laboratory records had been altered.
- According to Jean Blackston Hill, a regulatory pharmaceutical chemist at the FDA, only authorized personnel, such as systems administrators and their backups, should be able to delete data.
- Hill recommends that firms create security levels, with details documented in a written policy, to restrict access to laboratory data.
- Inspectors will examine firms' procedures to prevent overwriting of data files, and vendors selling software that cannot be overwritten may be subject to closer scrutiny.
- Electronic signatures in the lab are not currently an FDA concern, but firms should have written policies holding individuals accountable for actions taken under their electronic signatures.
- Software validation requires documented evidence to ensure that the software will consistently meet its predetermined specifications.
- The FDA recommends that firms create their own software validation programs from scratch to meet their specific needs, rather than relying on vendor-provided software validation packages.
- Macro programs created by users within vendor-provided software must be validated both within and outside the software, according to FDA guidelines.
Statistics:
- 21 CFR Part 11 is the FDA regulation governing electronic signatures and records.
- At least three firms have been found to have computer systems that could not detect or prevent alteration of laboratory records in the past year.
- FDA inspectors will examine firms' procedures to prevent overwriting of data files.
- Less than 10% of software sales are for GMP (Good Manufacturing Practice) environments.
Sources:
- FDA, "Regulatory Procedures Manual" Section 1.256.1, (no date provided)
- Institute for International Research, presentation by Jean Blackston Hill, June 29 (no date provided)