How to Strengthen Medical Device Cybersecurity

265 views
•
February 28, 2020
by
RSAC Cybersecurity
YouTube video player
How to Strengthen Medical Device Cybersecurity

TL;DR

Medical device cybersecurity requires security planning before release, coordinated vulnerability handling after release, and safeguards that reflect how hospitals will deploy connected products. Manufacturers should consider FDA safety expectations, healthcare customers’ HIPAA obligations, privacy protections, IT security risks, and the unusually long service lives of legacy devices when designing and operating a robust security program.

Transcript

Uh, I have the great pleasure of introducing, uh, our panelists. I'm gonna let them introduce their own names so I don't mess up. But it turns out they're gonna be talking about medical device cybersecurity, which I think is a thing that we can all agree we want them to get right. So, uh, now I'm going to, uh, let them give their own names, but ple... Read More

Key Insights

  • FDA considers cybersecurity relevant to medical device safety because security weaknesses can directly affect how safely devices operate. Its role focuses on device safety, while privacy and broader hospital IT security introduce additional responsibilities that manufacturers and healthcare providers must address.
  • Pre-market cybersecurity guidance provides strong suggestions for integrating security considerations into medical devices before market release. Manufacturers should treat this stage as an opportunity to build security into product design rather than waiting for vulnerabilities to emerge after deployment.
  • Post-market cybersecurity guidance addresses how manufacturers should prepare for and respond to vulnerabilities after devices have entered use. Recommended practices include establishing coordinated vulnerability disclosure programs so external researchers can report problems and work with manufacturers toward appropriate resolution.
  • Public participation can shape FDA cybersecurity guidance because manufacturers, researchers, vendors, and other stakeholders can submit comments and attend workshops. The panel encourages community involvement because the resulting recommendations can substantially affect company operations and the delivery of cybersecurity products to device manufacturers.
  • HIPAA can influence device design even when it does not regulate a medical device manufacturer as such. Healthcare providers need products they can use consistently with their own security obligations, including protections for electronic health information and documented security risk analyses.
  • Encryption and access management are important design considerations for devices that store information or connect to hospital networks. Manufacturers should be prepared to explain how their controls address required and addressable safeguards, including why an alternative measure may be reasonable when a particular standard is not met directly.
  • Connected medical devices can become network entry points for attackers even when they do not maintain the patient data emphasized by traditional privacy governance. Effective risk management must therefore account for device safety, information privacy, and the security of the wider hospital network.
  • Legacy medical devices present a difficult cybersecurity problem because devices may remain in the market for ten or twenty years. Their long lifespans extend the period during which manufacturers and healthcare organizations must confront vulnerabilities, implementation constraints, and potential effects on patient care.

Install to Summarize YouTube Videos and Get Transcripts

Explore YouTube Video Summarizer or Get YouTube Transcript Extractor

Questions & Answers

Q: How should manufacturers approach medical device cybersecurity?

Manufacturers should integrate cybersecurity considerations before a device reaches the market and maintain the ability to handle vulnerabilities after deployment. They should also consider how healthcare providers will use the product, whether it stores information or connects to hospital networks, and whether controls such as encryption and access management support customer security obligations and patient safety.

Q: What is the difference between pre-market and post-market cybersecurity guidance?

Pre-market guidance addresses security considerations before a medical device is released, when manufacturers can integrate protections into product design and prepare for market entry. Post-market guidance concerns devices already deployed and recommends ways to receive, assess, communicate, and resolve vulnerability reports. The latter includes coordinated vulnerability disclosure programs for working with external security researchers.

Q: Why does FDA treat cybersecurity as a medical device safety issue?

FDA recognizes that cybersecurity can directly affect the safety of medical devices. A vulnerable connected product may create consequences beyond lost information, including effects on patient care. Because FDA is responsible for device safety, it has spent approximately five or six years working with researchers, manufacturers, and other stakeholders on this complex security problem.

Q: What is coordinated vulnerability disclosure for medical devices?

Coordinated vulnerability disclosure is a structured process through which external researchers can communicate discovered vulnerabilities to medical device manufacturers and work toward appropriate resolution. FDA's post-market recommendations include adopting such a program so manufacturers are prepared to receive and handle reports after devices have been fielded, rather than responding without an established process.

Q: How does HIPAA affect medical device manufacturers?

HIPAA does not necessarily regulate medical device manufacturers as such, but it regulates healthcare providers that may purchase and deploy their products. Manufacturers should therefore consider whether hospitals can use a device in a way that satisfies their security and risk-analysis obligations, particularly when the product stores electronic health information or connects to healthcare networks.

Q: What security controls should connected medical devices include?

Manufacturers should consider encryption, access management, and the broader set of safeguards relevant to protecting electronic health information. They should have credible answers for required and addressable protections. When an addressable standard is not met directly, they should be able to explain why an alternative measure is reasonable in light of how hospitals will use the product.

Q: Why are medical devices a risk to hospital networks?

Connected medical devices can become entry points for attackers when deployed on hospital networks. This risk can exist even if a device does not maintain the type of patient data emphasized by privacy and security rules. Hospitals and manufacturers must therefore address not only data protection, but also device vulnerabilities, network exposure, and potential consequences for patient care.

Q: Why are legacy medical devices difficult to secure?

Legacy medical devices are challenging because many products remain on the market for ten or twenty years. Such long lifespans create an extended period in which vulnerabilities, network threats, and implementation difficulties may need attention. The issue is especially concerning for connected devices because weaknesses can create entry points or potentially affect patient care long after release.

Summary & Key Takeaways

  • FDA treats cybersecurity as a medical device safety issue and has pursued a whole-of-community approach involving manufacturers, researchers, and other stakeholders. Its pre-market guidance encourages manufacturers to integrate security considerations before products reach the market, while its evolving post-market guidance addresses vulnerability reporting, coordinated disclosure, remediation, and organizational readiness after deployment.

  • Medical device manufacturers must consider requirements beyond direct FDA oversight. HIPAA may not regulate manufacturers merely because they make devices, but healthcare providers purchasing those products must protect electronic health information. Manufacturers should therefore design encryption, access management, and other safeguards that help hospitals conduct security risk analyses and use devices appropriately.

  • Connected medical devices create overlapping concerns involving patient safety, privacy, and hospital IT security. Even devices that do not maintain data can contain vulnerabilities or provide attackers with network entry points. Long product lifespans make legacy devices especially challenging because security risks and implementation responsibilities can persist for ten or twenty years.


Read in Other Languages (beta)

Share This Summary 📚

Explore More Summaries from RSAC Cybersecurity 📚