Most hospitals and healthcare providers are “not even close” to meeting the FDA’s medical device cybersecurity standards, according to new research. In a blog post on Monday, popular VPN provider PIA published its findings on major threats to health data.
PIA’s research provides insights into the current state of cybersecurity in the US healthcare sector.
“Unfortunately, the growing cybersecurity risks for medical devices hasn’t increased healthcare’s attention to security,” stated Kristen Hassel, Information Systems Specialist and the author of the blog post.
“Many providers have inadequate budgets for development or testing and don’t provide necessary updates to the software, primarily because they never planned for it when first developing the devices and software,” Hassel added.
Medical Devices are Prime Targets for Cyberattacks
Medical devices include a wide range of devices that contain a person’s medical data, such as CT, MRI, ultrasound, and X-ray machines, as well as other hospital machines connected to an IT network. Personal devices like smartwatches and smartphones, which collect medical data, also fall into this category.
These devices amass a lot of medical data that is very valuable to malicious actors. Couple this fact with a poor cybersecurity landscape, and these devices become prime targets for malware, data theft, and device hijacking.
According to Hassel, the use of CMDs (custom-made devices) and unsecure legacy equipment (both hardware and software) contribute heavily to the issue. Many CMD manufacturers do not take global cybersecurity rules seriously, despite the threat of fines and damages to patents.
“While CMDs give patients more freedom in terms of where and when medical treatments and monitoring can happen, they raise serious concerns over the privacy challenges associated with transmitting large amounts of patient information,” Hassel says. “Attacks on CMDs can put a patient in danger and even cause fatalities. Without proper management, cybersecurity incidents can easily result in unintentional device malfunctions or delay necessary treatments.”
For example, the FDA issued a call-back for over 460,000 electronic pacemakers after they found a vulnerability allowing third parties to interfere with its functions. Similarly, in 2020 the FDA learned about an RCE (remote code execution) vulnerability in clinical information servers used in healthcare environments.
Section 524B: FDA’s New Medical Device Cybersecurity Requirements
Manufacturers must set up security incident response teams, provide timely updates and patches, and include post-development cybersecurity planning. However, a combination of budgetary restraints of healthcare providers and a lack of initiative from manufacturers means many vulnerabilities continue to exist.
However, US regulators have taken note of the problem. The FDA amended the Federal Food, Drug, and Cosmetic Act in March by adding Section 524B. The changes require manufacturers to meet higher cybersecurity standards for new devices (those made after March 2023).
The new requirements will include:
- Submitting plans for monitoring, identifying, and addressing potential cybersecurity threats to the FDA.
- Providing information on potential threats and vulnerabilities to the Agency.
- Release mandatory updates and patches to prevent cyberattacks.
Failing to abide by Section 524B can result in fines for both hospitals and manufacturers. The latter can also have their patents refused.
These new requirements place a heavy burden on hospitals and healthcare providers, which may be unfeasible. There will be huge costs associated with replacing legacy devices, constantly updating their tools, and maintaining an inventory of all devices connected to their hospital network.
Measures to Improve Network and Medical Device Security
The US healthcare sector is a regular target of ransomware and data leaks. Despite the FBI and CISA publishing regular advisories and other government measures, ransomware attacks did not decline in the country last year.
It is important to encrypt medical data to protect it from malicious third parties. You can anonymize the medical data transmitted by your smartwatch and other wearables by installing a VPN on your router.
