One day, robots could take the place of physicians and surgeons, performing more accurate diagnoses and complex procedures. With Artificial Intelligence, you could program their “bedside manner” and even their gender according to the individual patient’s preferences and needs. Geriatrics, pediatrics, etc., could deal with particular patients accordingly.
Despite the benefits this may present, it’s pretty scary to imagine what a hacker might cause one of these practitioners to practice.
While that day is not here (at least 100% yet) the Internet of Medical Things is a reality now and securing them is a challenge that needs to be addressed now.
A recent ZingBox survey revealed that 70 percent believe that traditional security solutions are sufficient enough to secure the Internet of Medical Things (IoMT) devices. IoMT devices are usually wearable or monitors that connect to the healthcare facility’s network. IoMT devices still work the same way as the more obvious vulnerable assets like laptops and smartphones: they receive and send data but have no interface like computers or phones.
“The survey results demonstrate the current state of confusion and misconceptions abound in the healthcare industry on how best to secure connected medical devices,” ZingBox CEO and Co-Founder Xu Zou said in a statement. “The need to gain a deeper understanding of the unique individual personalities of IoT devices remains a foreign concept to many. Unfortunately, you need to understand the device personalities to gain accurate visibility and protection.”
“IoT technology presents special challenges to a healthcare organization’s ability to protect itself from both insider threats as well as external cyber-attacks across a wide range of attack vectors, as demonstrated by the most recent WannaCry ransomware and NotPetya wiperware attacks,” Zou continued. “As these attacks continue to step to the forefront, companies deploying IoT devices need to be more cognizant than ever of their security measures.”
ZingBox calculated that 76 percent of Healthcare IT executives believe that any device connected to their network is secure against outside attacks. The reality is that employing the same security measures for laptops, cannot detect irregular or malicious activity to cause, for example, an infusion pump to malfunction, a monitor screen to show bogus normal data, creating a life threatening condition.
“The results of the survey were sobering in terms of the risks the healthcare community faces,” said May Wang, CTO and Co-Founder of ZingBox. “This is a tremendous opportunity to raise awareness of healthcare organizations regarding their perception of security and their need to consider modern techniques such as cloud, machine learning and real-time remediation across an organization’s entire IoT footprint.”
“IoT requires a more thorough approach to constantly monitor for deviations in behavior and provide alerts for suspicious behavior.”
In order to secure IoMT devices, providers should note:
1.What is the device doing ?
2.How is it connected to the network?
3.Does the device store data on it?
4.Is the data Private or Privileged Personal Healthcare Information (PHI)?
5.Will it be sending and/or receiving signals?
6.If the device is stolen can it be traced back to the data source?
7.Who can access the device and how?
8.Is the data encrypted so that the information cannot be deciphered while monitoring or in the event that the device is lost or stolen?
HIPAA (The Health Insurance Portability and Accountability Act) now requires that security protocols be in place to detect abnormal behavior from IoMT devices.
To avoid sanctions and fines, and above all to protect the health and lives of their patients, all healthcare providers must secure all of their network connected assets.
IoMT devices send and receive signals that change whenever a patient’s condition becomes life threatening or needs immediate attention. The visibility and control that an organization has over its network will affect its ability to respond to cyberattacks and detect the potential threats created by connected IoMT assets.
Ron Benvenisti
CyVision Technologies, Inc
