How to Protect Connected Medical Devices

137 views
•
November 8, 2011
by
RSAC Cybersecurity
YouTube video player
How to Protect Connected Medical Devices

TL;DR

Connected medical devices should be treated as network nodes whose failures can produce physical consequences, not merely financial losses. Hospitals need clinical engineering and IT teams to collaborate, inventory wireless frequencies, manage devices remotely, and account for long service lives, open networks, delayed patches, unexpected integrations, and infections introduced by loaned equipment.

Transcript

Okay. Whenever you're ready. My name is Adrian Turner. I'm CEO of Machina Corporation, and, uh, we are a leading device security software vendor. Uh, what we're here to talk about today is, um, connected medical devices, uh, some of the security concerns and issues associated with connecting medical devices, as well as some of the countermeasures. ... Read More

Key Insights

  • Medical devices are increasingly CPU-based, software-driven, network-capable, and wireless, replacing an earlier environment dominated by standalone equipment, custom circuitry, proprietary networks, and wired connections. This transition makes each device another node whose weaknesses can affect the wider hospital network.
  • Remote patient monitoring extends the hospital into patients' homes, where connected devices must be remotely managed and secured. Their communications may cross more open networks than traditional hospital systems, creating risks beyond the controlled clinical environment in which many devices historically operated.
  • Connected-device threats arise partly because equipment can be integrated into systems that manufacturers did not anticipate. A medical device may remain deployed for five to seven years while its operating environment and the surrounding IT threat landscape change rapidly.
  • Automated systems of systems can reduce direct human involvement as devices exchange data and support care processes. This connectivity increases the significance of security weaknesses because a compromised component may influence other systems, communications, or automated clinical workflows.
  • Medical-device breaches can produce physical consequences in addition to privacy or financial harm. Researchers demonstrated that an implanted cardiac device could reveal personal information, be shut down, and deliver shocks at will through a radio-based attack.
  • Healthcare networks can become collateral damage rather than deliberate targets. A botnet attack disrupted intensive-care computers, operating-suite doors, and hospital paging, while the same botnet also damaged Department of Defense computers in Germany.
  • Regulatory requirements can conflict with the speed of cybersecurity response. After the Conficker virus infected thousands of MRI machines, hospitals were required to wait ninety days before applying a patch, illustrating the tension between necessary medical regulation and rapidly changing threats.
  • Radio interference can function like a denial-of-service attack when it disrupts device operation or communication. Hospitals therefore need IT and clinical engineering teams to inventory and manage frequencies used by telemetry, RFID readers, cell phones, pagers, televisions, and other wireless equipment.

Install to Summarize YouTube Videos and Get Transcripts

Explore YouTube Video Summarizer or Get YouTube Transcript Extractor

Questions & Answers

Q: How should hospitals secure connected medical devices?

Hospitals should treat every connected medical device as a node on the wider network and protect it accordingly. Security planning should cover device inventory, remote management, open-network communications, wireless-frequency use, software vulnerabilities, and unexpected system integrations. Clinical engineering and IT must work together because these systems combine conventional computing risks with life-critical monitoring, alarms, and care functions.

Q: Why are connected medical devices vulnerable to attack?

Connected medical devices are vulnerable because many were deployed without common security measures and may operate for five to seven years while networks and threats evolve. Devices are also being connected to systems their manufacturers did not necessarily anticipate. Wireless access, software-based designs, remote monitoring, automated data exchange, and communications across open networks create additional opportunities for compromise or disruption.

Q: What risks do wireless medical devices create?

Wireless medical devices face both hostile attacks and ordinary radio interference. Interference may prevent proper operation or communication, making it comparable to a denial-of-service attack. Hospital environments contain telemetry systems, RFID readers, cell phones, pagers, televisions, and other transmitters, so their frequencies require careful inventory and management to protect security, signal quality, and bandwidth allocation.

Q: Can a medical-device cyberattack harm a patient physically?

A medical-device cyberattack can create physical consequences when it disrupts monitoring, alarms, treatment, or an implanted device. Researchers from three American universities demonstrated a radio attack on an implanted defibrillator or pacemaker that extracted personal information, shut the device down, and delivered shocks at will. Hospital attacks also disrupted intensive-care computers, operating-suite doors, and paging systems.

Q: Why must clinical engineering and IT collaborate?

Clinical engineering and IT must collaborate because modern medical devices increasingly resemble conventional IT systems while remaining responsible for life-critical functions. IT typically approaches downtime as a mission-critical problem with financial costs. Clinical engineering must also consider whether a patient can be monitored or whether alarms will function. Securing connected care therefore requires both technical and clinical perspectives.

Q: How can outdated software affect hospital equipment security?

Outdated software can leave hospital equipment exposed when patches are uncertain, discouraged by manufacturers, or delayed by regulation. In one cardiology monitoring case, a Microsoft patch existed, but the manufacturer recommended against using it because of confusion about the appropriate patch. Disconnecting the system reduced its utility because the catheterization laboratory was remote. Conficker also infected thousands of MRI machines.

Q: How can loaned medical equipment infect a hospital network?

Loaned medical equipment can arrive with malicious software already present and spread the infection after being connected to the hospital network. The transcript describes a portable ultrasound device loaned to a hospital with a virus already installed. Once connected, the virus propagated throughout the network, showing why equipment introduced from outside requires security attention before network access.

Q: Why do long medical-device life cycles increase security risk?

Medical devices may remain in service for five to seven years, during which their networks, integrations, and threat environments can change substantially. A device designed for one context may later connect to systems the manufacturer never anticipated. Because equipment deployed today will remain active years later, its security must account for future exposure rather than only current operating conditions.

Summary & Key Takeaways

  • Medical devices are shifting from standalone hardware on proprietary wired networks to CPU-based, software-driven systems with network and wireless capabilities. Their integration into hospital IT systems creates new security dependencies, while remote patient monitoring extends communications into homes and across more open networks that require remote management and protection.

  • Two threat levels shape the connected-device problem. Individual devices may be placed into environments their manufacturers did not anticipate during product development, especially across service lives of five to seven years. Multiple connected devices can also form automated systems of systems in which data and care processes proceed with less human involvement.

  • Documented incidents affected emergency-room computers, hospital phone systems, intensive-care computers, operating-suite doors, paging systems, patient records, MRI machines, and prescription-monitoring records. Researchers also demonstrated control over an implanted cardiac device. These examples show that healthcare breaches can compromise privacy, interrupt operations, spread unintentionally, and create physical consequences.


Read in Other Languages (beta)

Share This Summary 📚

Explore More Summaries from RSAC Cybersecurity 📚