• Skip to main content

DistilINFO LifeSciences

Weekly round up from Life Sciences Industry.

  • Publications
    • Home
    • DistilINFO HealthPlan
    • DistilINFO HospitalIT
    • DistilINFO IT
    • DistilINFO Retail
    • DistilINFO POPHealth
    • DistilINFO Ageing
    • DistilINFO Life Sciences
    • DistilINFO GovHealth
    • DistilINFO EHS
    • DistilINFO HealthIndia
    • Subscribe
    • Submit Article
    • Advertise
    • Newsletters

Medical Device Cybersecurity Will Be Rubbish For 20 More Years

Share:

August 27, 2019

“Everything with a power point is probably connected, or will be shortly,” says Christopher Neal, chief information security officer (CISO) of Ramsay Health Care.

“Increasingly that connectivity is critical to patient care,” he told the Gartner Security and Risk Management Summit in Sydney on Monday.

Even if those connected devices aren’t transmitting patient medical data, increasingly they’re conveying information about their own health.

Yet those medical devices can be incredibly vulnerable.

Want to publish your own articles on DistilINFO Publications?

Send us an email, we will get in touch with you.

Neal saw this first-hand in the medical village at the DefCon cybersecurity conference earlier this month. Hackers were let loose on the kind of equipment you’d expect to find in hospital patient rooms.

“The most fun I saw was [when] a guy sat down at an ultrasound machine,” he said.

“Within about 30 seconds of connecting he had shell, unrestricted Powershell access to that system through a vulnerability in the file manager that’s on the platform.”

The US Food and Drug Administration (FDA) has been issuing cybersecurity guidelines for several years. Australia’s Therapeutic Goods Administration (TGA) issued its own Medical device cyber security guidance for industry last month.

“There’s good guidance, but any systems built with that guidance are probably three to four years away from market, and most of this gear’s built to last 10 to 15 years,” Neal said.

“Anything you’re buying today has not been built secure-by-design, most likely. This is a problem that’s going to live in healthcare for another 15 to 20 years.”

YOU CAN’T SECURE IT IF YOU DON’T KNOW IT’S THERE

Ramsay is Australia’s largest operator of private hospitals, with 30,000 staff and around 9,500 beds. Their set-up seems typical for a health care provider.

When he started there, Neal found a “not wonderful understanding of where IT systems are at, what’s connected”. There were “varying levels of support and understanding” of what devices are in place, with no centralised fixed asset list.

Each hospital also runs as its own entity, with its own chief executive officer. That works against consistency across the organisation.

While the architecture of the corporate network is flat, each hospital’s medical networks are meant to be compartmentalised using DMZ networks.

“If you don’t know about it you can’t secure it,” Neal said, so he launched a project to map all the devices across the organisations 74 hospitals.

A trial run with three hospitals took three months to complete, so clearly automation was needed. Neal chose the Forescout device visibility and control platform.

“Did we find a lot more equipment with default credentials, default configuration, sitting not on the corporate network but in those DMZs? Yes, we found a lot of that,” he said.

“I see visibility as the foundation to being able to start stitching things together.”

Ramsay isn’t ready to move to a zero trust model for cybersecurity, however. Being able to make that move “depends on IT maturity more generally, how the organisation broadly sees and values IT”.

According to Neal, at Ramsay “there’s an IT and organisational maturity that’s a long way off”.

“For a very mature IT organisation, you can probably get it done in two or three years,” he said.

“Looking to do it any faster than that in any large-ish organisation you’re more likely to break things than fix them.”

Date: August 27, 2019

Source: ZDNet

Coffee with DistilINFO's Morning Updates...

Sign up for DistilINFO e-Newsletters.

Just a little bit more about you...
PROCEED
Choose Lists
BACK

Related Stories

  • Roche’s Spark takeover looks even more distant as FTC review delays againRoche’s Spark takeover looks even more distant as FTC review delays again
  • Germany’s Wingcopter Raises $22M for Distribution of COVID-19 VaccinesGermany’s Wingcopter Raises $22M for Distribution of COVID-19 Vaccines
  • RO Powers Local Physician Search with Ribbon Health’s API, NIH Taps MDClone’s Data Platform and More Digital Health DealsRO Powers Local Physician Search with Ribbon Health’s API, NIH Taps MDClone’s Data Platform and More Digital Health Deals
  • Germany Introduces Digital Supply Act to Digitalise HealthcareGermany Introduces Digital Supply Act to Digitalise Healthcare
  • DBV pulls peanut allergy filing after FDA faults data detailsDBV pulls peanut allergy filing after FDA faults data details
  • Epitel Raises $12.5M for Wearable Seizure Detection SystemEpitel Raises $12.5M for Wearable Seizure Detection System
  • Parse Biosciences Acquires BiomageParse Biosciences Acquires Biomage
  • Covalon Announces Successful Completion of Operational Integration of AquaGuard Acquisition amid Continued Business ProgressCovalon Announces Successful Completion of Operational Integration of AquaGuard Acquisition amid Continued Business Progress

Trending This Week

Sorry. No data so far.

About Us

DistilINFO is media company that publishes Industry news, views and Interviews. We distil the information for you – saving time and keeping you up to date on your interest areas.

More About Us

Follow Us


Useful Links

  • Subscribe
  • Contact
  • Advertise
  • Privacy Policy
  • Terms of Service
  • Feedback

All Publications

  • DistilINFO HealthPlan Advisory
  • DistilINFO HospitalIT Advisory
  • DistilINFO IT Advisory
  • DistilINFO Retail Advisory
  • DistilINFO POPHealth Advisory
  • DistilINFO Ageing Advisory
  • DistilINFO Life Sciences Advisory
  • DistilINFO GovHealth Advisory
  • DistilINFO EHS Advisory
  • DistilINFO HealthIndia Advisory

© DistilINFO Publications