Medtronic approaches patient privacy and device security as part of a holistic security management framework that includes people, products, IT systems, data, and facilities. To effectively manage the proliferation of wireless connectivity in our medical devices, facility operations and computer networks we centralize security management through a Global Privacy and Security Office and an Executive Security Governance Committee.
Our global processes and procedures address risk assessment, governance, training and awareness, technology assessment, vendor management, government and industry relations, and product development and metrics. To drive awareness and understanding of our privacy and security practices, Medtronic has a Global Privacy and Data Protection Policy and a Global Electronic Resource Use Policy available in multiple languages. In 2012, the company initiated global biennial data protection and privacy training for employees and contractors who have frequent access to Medtronic computers.
In addition, Medtronic conducts real-time monitoring of released products, including vulnerability assessments, privacy testing and code reviews and recently launched a global incidence response management initiative to ensure rapid, succinct and consistent response to possible incidents.