MOU 225-26-008
MEMORANDUM OF UNDERSTANDING BETWEEN THE REGENTS OF THE UNIVERSITY OF CALIFORNIA, SAN DIEGO AND THE U.S. FOOD AND DRUG ADMINISTRATION CENTER FOR DEVICES AND RADIOLOGICAL HEALTH
I. Purpose
The Regents of the University of California on behalf of its San Diego campus (“UCSD”) and the United States Food and Drug Administration (“FDA”)’s Center for Devices and Radiological Health (“CDRH”) have a shared interest in encouraging the identification, mitigation, and prevention of cybersecurity threats to medical devices. FDA and UCSD are each referred to herein individually as a “Party” and collectively as the “Parties.” This Memorandum of Understanding (“MOU”) establishes the terms for collaboration to promote this shared interest.
II. Background
The FDA promotes and protects the public health by ensuring the safety, efficacy, and security of drugs, biological products, veterinary products, medical devices, and radiological products, and the safety and security of foods and cosmetics. The FDA administers the Federal Food, Drug, and Cosmetic Act. (see generally, 21 U.S.C. § 301 et seq.) and certain sections of the Public Health Service Act (see, e.g., 42 U.S.C. § 262), among other statutes. Among its duties, the FDA approves premarket applications for medical products, conducts inspections of manufacturing facilities, and monitors postmarket adverse events. The FDA also initiates civil and criminal litigation to enforce applicable laws and regulations.
CDRH is responsible for ensuring that patients and healthcare providers have access to safe and effective medical devices. To advance patient care, medical devices are becoming increasingly interconnected and interoperable. However, interconnected devices also increase cybersecurity risks which, if exploited, may affect device performance. CDRH is committed to enhancing patient safety by mitigating cybersecurity risk throughout the lifecycle of medical devices. This includes monitoring, identifying, and addressing cybersecurity vulnerabilities in medical devices once they are on the market. CDRH works collaboratively with industry, healthcare organizations, academic institutions, and government entities to address cybersecurity risks to medical devices.
The UCSD Center for Healthcare Cybersecurity (“CHC”) is a multidisciplinary research, education, and advocacy program dedicated to addressing emerging cybersecurity threats in healthcare. By integrating clinical expertise with technical innovation, the CHC develops real-world solutions that protect patient safety, enhance hospital resilience, and strengthen the security of medical systems. Cyber threats in healthcare go beyond IT infrastructure—they disrupt hospital operations, delay critical treatments, and put lives at risk. The CHC was established to ensure that hospitals, clinics, and medical systems can withstand and recover from cyber incidents without compromising patient care.
Through collaboration with healthcare institutions, industry leaders, and government agencies, the CHC is creating a proactive, adaptable, cybersecurity ecosystem that evolves with emerging threats. Working at the intersection of medicine, cybersecurity, and technology, the CHC is redefining how healthcare organizations prepare for and respond to cyber risks.
III. Goals of Collaboration
The goals of this MOU are to establish, develop, and expand a framework of cooperation between FDA and UCSD to enhance collaboration and communication regarding the identification, mitigation, and prevention of cybersecurity threats to medical devices. This MOU provides a framework for coordination and the principles and procedures by which mutually beneficial opportunities, projects, and activities between the Parties shall take place.
IV. Responsibilities
1. UCSD Responsibilities: As part of this collaborative partnership, the CHC will provide expertise and collaborative assistance within the domain of healthcare cybersecurity to support pre-competitive regulatory science initiatives. Such activities may include, but are not limited to: delivering lectures or workshops for FDA staff; hosting or deploying clinical cybersecurity simulation exercises; engaging in joint vulnerability discussions to explore potential patient safety implications of cybersecurity risks identified through CHC's research and expertise; supporting the conceptualization of future collaborative, data-driven research projects of mutual interest; sharing research data or outcomes through the transmission of materials or leadership research briefings; hosting FDA staff or fellows in experiential learning programs organized and administered by the CHC; and participating in joint panels or academic presentations.
2. FDA Responsibilities: As part of this collaborative partnership, CDRH will provide subject matter expertise and collaborative assistance within the domain of medical device and healthcare cybersecurity to support broad, pre-competitive regulatory science initiatives. Such activities may include, but are not limited to: participating in lectures or workshops developed in coordination with CHC; engaging in clinical cybersecurity simulation exercises hosted or deployed by CHC; contributing to joint vulnerability discussions to explore potential patient safety implications of cybersecurity risks; collaborating on the conceptualization of future data-driven research projects of mutual interest; receiving and engaging with research data or outcomes shared through the transmission of materials or leadership research briefings; facilitating the placement of FDA staff or fellows in experiential learning programs organized and administered by the CHC; and participating in joint panels or academic presentations. All activities undertaken by CDRH pursuant to this MOU will be conducted in accordance with applicable federal laws, regulations, and policies.
3. Each Party will establish a principal point of contact to facilitate the actions carried out under this MOU.
V. General Provisions
1. This MOU represents a broad outline of the Parties’ intention to collaborate in areas of mutual interest. All activities that may be undertaken by this MOU are subject to the availability of personnel, resources, and funds. This MOU does not affect or supersede any existing or future understandings or arrangements between the Parties and does not affect the ability of the Parties to enter into other understandings or arrangements related to this MOU. This MOU does not create binding, enforceable obligations against any Party. This MOU and all associated agreements will be subject to the applicable policies, rules, regulations, and statutes under which FDA and UCSD operate.
2. This MOU is neither a fiscal nor a funds obligation document. Any endeavor or transfer of anything of value involving reimbursement or contribution of funds between the parties to this MOU will be handled in accordance with applicable laws, regulations, and procedures. Such endeavors will be outlined in separate agreements that shall be made in writing by representatives of the parties and shall be independently authorized by appropriate signatory authority. This MOU does not provide such authority. Each party shall be fiscally responsible for their own portion of work performed under the MOU.
3. The Parties will not, as a part of the activities covered by this MOU, share any non-public information, including (1) confidential commercial information, such as the information that would be protected from public disclosure pursuant to Exemption 4 of the Freedom of Information Act (FOIA); (2) personal privacy information, such as the information that would be protected from public disclosure pursuant to Exemption 6 or 7(c) of the FOIA; or (3) information that is otherwise protected from public disclosure by Federal statutes and their implementing regulations (e.g., Trade Secrets Act (18 U.S.C. § 1905)), the Privacy Act (5 U.S.C. § 552a), other Freedom of Information Act exemptions not mentioned above (5 U.S.C. § 552a(v)), the Federal Food, Drug, and Cosmetic Act (21 U.S.C. § 301 et seq.), and the Health Insurance Portability and Accountability Act (HIPAA), Pub. L. 104-191).
4. It is understood that neither party to this MOU is the agent of the other and neither is liable for the wrongful acts or negligence of the other. To the extent permitted by applicable law, each party shall be responsible for its negligent acts or omissions and those of its officers, employees, agents or students (if applicable), howsoever caused.
VI. Liaison Officers
For UCSD
Technical:
Jeff Tully, MD
Co-Director, UC San Diego Center for Healthcare Cybersecurity
UC San Diego Center for Healthcare Cybersecurity Atkinson Hall
9500 Gilman Drive #0436 Room 4605
La Jolla CA 92093-0436
jtully@health.ucsd.edu
Administrative:
Shannon Prior
Program Management Officer, UC San Diego Center for Healthcare Cybersecurity
UC San Diego Center for Healthcare Cybersecurity Atkinson Hall
9500 Gilman Drive #0436 Room 4605
La Jolla CA 92093-0436
sprior@health.ucsd.edu
For FDA
Suzanne Schwartz, MD, MBA
Director, Office of Strategic Partnerships and Technology Innovation
Center for Devices and Radiological Health
U.S. Food and Drug Administration
10903 New Hampshire Avenue
Building 66, Room 5434
Silver Spring, MD 20993
301-796-6937
Suzanne.Schwartz@fda.hhs.gov
or
Nastassia Tamari, MS
Associate Director
Division of Medical Device Cybersecurity
Office of Readiness and Response
Office of Strategic Partnerships and Technology Innovation
Center for Devices and Radiological Health
Food and Drug Administration
10903 New Hampshire Avenue
Silver Spring, MD 20903
(240) 687-0904
nastassia.tamari@fda.hhs.gov
Each Party may designate new liaisons at any time by notifying the other Party's administrative liaison in writing. If, at any time, an individual designated as a liaison under this MOU becomes unavailable to fulfill those functions, the Parties will name a new liaison within two (2) weeks and notify the other Party through the designated administrative liaison.
VII. Term, Termination, and Modification
1. This MOU, when accepted by all participating Parties, will have an effective period of performance of five (5) years from the date of the latest authorized signature.
2. The provisions of this MOU may be modified only by written amendment signed and dated by the duly authorized signatory for each Party.
3. This MOU may be terminated by either Party for any reason by providing written notice to the other Party at least thirty (30) days prior to the desired termination date. This MOU may be terminated immediately upon the mutual, written agreement of the Parties.
IN WITNESS WHEREOF, the parties hereto have executed this agreement as of the last written date below.
APPROVED AND ACCEPTED FOR
U.S. FOOD AND DRUG ADMINISTRATION:
/s/
Michelle Tarver, M.D., Ph.D.
Director
Center for Devices and Radiological Health
Date: 09/02/2026
APPROVED AND ACCEPTED FOR
THE REGENTS OF THE UNIVERSITY OF CALIFORNIA
ON BEHALF OF ITS SAN DIEGO CAMPUS:
/s/
Rebecca Hollingsworth
Senior Contract Officer
Date: 08/31/2026