Safe and Secure? Healthcare in The Cyberworld
Martha Vockley · Biomedical Instrumentation & Technology · 2012
Network vulnerabilities are putting patient confidentiality and safety— fundamental ethical and legal tenets in healthcare—at risk. As healthcare becomes increasingly intertwined with information technology (IT), hackers, viruses, and system glitches have the potential to disrupt medical devices and undermine the security of private information. Consider the sensitive information that has been exposed by data breaches alone every year, potentially affecting millions of patients:1–4And consider the potential impact of data breaches on patients and their families, a threat that's underscored by the federal government's push for the widespread use of electronic health records. “In the last 14 months, both of my parents have had their health records breached—from different healthcare facilities,” says Derek Brost, chief security officer at eProtex, a data security company based in Indianapolis, IN, that specializes in the hidden risks of connected medical devices.“It's ridiculous how casually some healthcare facilities are handling people's private medical information,” Brost says. “And also, oftentimes, that ties to your financial information. My parents are retired. They're in a position where they're starting to get a lot more medical treatment. This could have a big impact on their end-of-life care treatment options if their personal, medical, and financial information was in any way compromised.”Patient confidentiality isn't the only risk. Security breaches of medical technology networks sometimes compromise patient care and safety. If a network or a networked medical device is hit by a security breach, it can take down vital healthcare services, and related business services, along with it. And sinister attacks on portable and implantable medical devices, while hypothetical now, have the potential for increased growth and threats in the future. If the threat follows the trajectory that cybersecurity in other industries has taken, it could ramp up significantly in the not-too-distant future.Equally alarming, many healthcare organizations “don't know what they don't know” about their susceptibility to security breaches. In fact, many only realize their vulnerability after an incident occurs.In terms of threats to the functioning of devices, some security experts over the past year have said they have successfully hacked into wireless medical devices, taking control, for example, of insulin pumps. Manufacturers say they take such claims seriously and are ramping up encryption efforts.Several interrelated factors are making medical technology networks more vulnerable both to malicious attacks from hackers around the world and to internal security threats, whether accidental or intentional.Two major developments over the past year concern security expert Axel Wirth:Earl Reber, executive director of eProtex, adds a third development:More networked medical devices and more devices that capture electronic protected health information. “Just as it becomes more dangerous to drive as more cars get on the road, we have that same increase in traffic on networks,” Reber says. “Statistically, to give you an idea, one of the first hospitals we performed services in had about 0.7 networked medical devices per hospital bed. Now, we see an average of close to, and in many cases just over, two medical devices per hospital bed. And even at that very first hospital, we tracked it and it's up to over 1.34 to 1.4 medical devices per bed in the short span of two years, from 2009 to 2011. That's a significant increase.”This increase in networked medical equipment means that if there is a hacking incident or other security breach, traffic on the network can slow down and interrupt healthcare services and productivity. Moreover, the increasing use of mobile devices, from smartphones to tablets to portable storage devices, adds complexity to network security in healthcare.“The risk of patient and/or user harm from connected or networked devices in the healthcare environment will depend on the specific hazard that has occurred—for example, loss,” says Leanne Cordisco, healthcare IT program manager, education services, at GE Healthcare. “The risks are the same for wired and wireless devices, but the causes of those risks vary greatly between the two. Medical devices providing real-time patient data through the network, for either centralized or remote clinical review, are particularly vulnerable to network disruptions, which may interfere with and adversely impact patient care.”Finally, the risk profile for medical technology is affected by regulations from the U.S. Food and Drug Administration (FDA), the Health Insurance Portability and Accountability Act (HIPAA), and the U.S. Department of Health and Human Services Office of Civil Rights, among others. Whereas hackers and malware—such as computer viruses, worms, Trojans, spyware, and botnets—can move at lightning-fast speed, adaptations to safeguard medical equipment and networks from security breaches can take time.Taken together, here's the bottom line: The “bad guys” are more adept at trolling for valuable information they can turn into a profit. Off-the-shelf software can make medical devices and networks easy to prey upon—or harm inadvertently. With more medical technology connected to networks, and more sensitive information collected and dispersed, protection is more difficult—and security breaches can be more severe.The use of off-the-shelf software offers a prime example of the “collateral damage,” in Wirth's words, that can occur from security breaches. Off-the-shelf software, such as operating systems, browsers, and databases, is becoming more popular because it is familiar to people and thus easier to use, it facilitates connectivity and interoperability, and it is less expensive than developing proprietary software.“Our data show that 40 to 50% of networked medical devices rely on Windows-based systems, about 30 to 40% percent are based on Linux or Unix systems, and about 10 to 20% percent are still proprietary operating systems written for specific companies or specific devices,” Reber says.One problem is with software “patches” or updates. Software companies regularly push out patches to protect against the latest malware or other security or software glitches. Business and personal users can install these updates quickly and easily and get on with their work.Medical technology manufacturers, however, might have to go through an FDA review process before they can give their customers the go-ahead to install the updates to ensure that the update does not impact the safety and functionality of the device. “If I'm a manufacturer, because of that rigorous process, I am challenged to release security patches quickly, I'm more or less behind, depending on the efficiency of my release processes,” Wirth says. “I can't just say, today is Tuesday, I get a new set of patches from Microsoft and I start distributing them. I have to test them first on my device. I need to make sure those changes to the operating system don't impact behavior and functionality of the system and then I can tell my customers, ‘Yes, you can now deploy this operating system.’ That means that medical devices, from an operating system patch level, often are months, if not years, behind where the operating system manufacturer is—meaning that there is a huge, gaping security hole.”That gaping security hole could bring healthcare organizations to their knees. Malware can be introduced into an organization in many ways, Wirth says, be it via mobile data carriers or users' desktops and laptops. But, because they are connected to the network, they can pass the virus on to medical devices that are not as robustly “inoculated” against infection. But, because they are connected to the network, they can pass the virus on to medical devices that are not as robustly “inoculated” against infection.If a virus spreads to medical equipment, its effect can ripple across entire departments and beyond. Many hospitals, for example, prefer to procure a particular type of medical technology, such as imaging equipment for a catheterization lab, from a single vendor. That vendor keeps all of its equipment on the same patch or configuration level. “As soon as one device in that cath lab gets infected, then the same device in all other labs are at risk of getting infected,” Wirth says. “All of sudden, before you know it, your entire interventional cardiology is shut down.” Other networked medical devices, or other IT equipment that is not up-to-date with patches, can “catch” the spreading virus as well. “You have a virus gone rampant throughout your hospital because it is being spread from medical device to medical device.”Thus, while an initial virus or other security breach might not target medical equipment, it can result in broad “collateral damage.” Security breaches can impact patient care and safety, if treatment is delayed or diverted, as well as staff morale and productivity. They also can result in financial loss from equipment downtime, which can range from hours to days, or repairs from outside service providers.Security breaches in healthcare are particularly challenging for another reason. If a business or home computer becomes infected with a virus, the first action for troubleshooting is to disconnect it from the network, and disconnect similar equipment that might be prone to the same virus. But it's difficult for a healthcare facility to disconnect every similar piece of medical equipment, especially if that equipment is essential for patient care or even life support.Equally troubling is the installation of unauthorized software updates, which eProtex's Reber and Brost have encountered. Some company representatives will “unofficially” tell customers that they can install software patches without any negative effects.“A gamma camera is a great example we've run across in the field where it was being infected with viruses,” Reber says. “There was a patch that wasn't applied, and wasn't authorized to be applied, but the manufacturer's tactical service rep said to go ahead and put the patch on. As soon as we put the patch on, we found out that a gamma camera uses 22 ports to transmit its information. That patch restricted the operating system to a maximum number of open ports of eight. And so, the gamma camera could no longer transmit data in a timeframe that it could work within, and the camera failed in its operation.” That exposed the patient to radiation without producing a usable image and it slowed down the diagnostic process.In one case, a computed tomography (CT) scanner in an emergency room became infected with a virus, forcing staff to divert a patient to another department for imaging. “In an emergency department, you're usually talking about a trauma patient,” Reber says. “You have to divert that patient to a different department and kick other patients off the equipment. That's a potential patient safety issue.” Another downside to events on equipment like this is that healthcare institutions may not have extra or backup units available.Such scenarios concern Reber, an attorney, for another reason: the potential liability issues. “My biggest nightmare as an attorney is being the defense attorney for the first time that a patient is misdiagnosed because a medical device either has a virus or, worse yet, had antivirus or other unauthorized software put on it and contributed to a misdiagnosis or a mistreatment,” he says.While external cybercrime is a real threat, security risks abound inside healthcare organizations as well. Even healthcare organizations with strong protection, through firewalls and other technologies, face internal risks. Points of vulnerability include:Physicians and other healthcare staff like to access their e-mail and patient records from their homes or on the road—and in their facilities. “Potential risks associated with smartphones and tablet computers such as iPads are increasing with each new application and product generation that is released,” Cordisco says. “No longer can these devices be viewed as a secondary form of display or data system. Rather, clinicians are relying upon them as the primary information source with increasing frequency and, as such, the risks to patient care can be greater if the manufacturer does not take this expanded use into consideration.”For example, people can inadvertently send or receive files from their personal e-mail accounts, which are easier to breach than their institutional accounts. Plus, these devices are easily lost or stolen. Any files on the device, and automated login and password information to access information, can be retrieved and potentially abused.Legal and financial issues associated with data breaches like these concern Kenneth Maddock, vice president of healthcare technology management and telecommunications services at Baylor Health Care System. “We have to be concerned about this because as an organization we're going to be evaluated on it from a legal and ethical standpoint. We had a device stolen, and fortunately we were able to wipe the hard drive clean quickly. But you still have to report it in a specific amount of time and take steps such as offering those affected credit counseling. You can get enormous fines if it is deemed that you aren't doing enough. And above all you want to protect patient information because it's the right thing to do.”As the “bring your own device” trend reaches healthcare, this vulnerability will increase. Personal devices are harder to control than devices issued and configured by healthcare organizations, but even hospital-issued devices can never be 100 percent secure. “Any mobile device that can be used outside of the hospital to access patient records—if not properly managed and protected—can lead to a privacy breach,” Wirth says.Right now, Windows- and Android-based mobiles with open architectures are easier to attack, and incidents against these devices are on the rise. Apple's iOS operating system for iPads and iPhones is “relatively well architected and relatively safe,” Wirth says. But he cautions that hackers likely are trying to find ways to change that.“Lots of times, we've seen clinicians bring in devices that they want to use that IT hasn't reviewed or approved yet,” Brost adds. “The concern I have is around data security—if a clinician loses that device or forgets it or he forgets which e-mail account he's using. He meant to send the e-mail over his hospital account and selected his personal account. These are creating breaches that just weren't a possibility before because you had to physically sit down at a hospital on a computer, physically access the database and patient records. You didn't have remote access and portable computing access. The change has happened faster than the security and privacy offices have been able to keep up with.”The Open Security Foundation's datalossdb.org website tracks incidents of data breaches resulting from vulnerabilities like these in healthcare and other industries. Figure 2 shows the breakdown of security incidents by vector.6Potential compromises of patient confidentiality, care, and safety, the collateral damage that can result from data breaches, are disturbing. Deliberately harming patients on networked or wireless medical devices would be far worse.That possibility rattles healthcare security experts. Medtronic in 2011 announced it would conduct an “in-depth risk/benefit analysis” after reports that one of the company's insulin pumps is vulnerable to hackers.7 The fear is that hackers could gain remote access to the pump and reprogram it to deliver a potentially lethal dose of insulin.Researchers at Massachusetts Institute of Technology and the University of Massachusetts, Amherst, meanwhile, have demonstrated that it is possible to hack into wireless, implantable medical devices, such as pacemakers, heart defibrillators, cochlear implants, and neuro-stimulators, and reprogram them in ways that could harm patients.8Wirth emphasizes that these are “hypothetical” scenarios. “This has all occurred in a lab setting—but repeatedly, and for different kinds of devices,” he says. “This could be a problem in the future in a riskier scenario because of where those devices are, inside the patient, and what function they have, which is typically sustaining or at least life supporting. If you think about it, it's really scary.”Baylor's Maddock echoes that thought. While there is no evidence that these kinds of adverse events are occurring, healthcare technology managers need to keep them on their radar screen. “The real problem is we just don't know what we don't know,” Maddock says. “Anytime you add a technology you at least have to start thinking about the types of potential failures. While the primary responsibility is on the manufacturers to harden the devices against potential attack, we do have a role. This is a new and evolving area of technology and I'm not sure that those within healthcare technology management are asking the right questions yet.”As healthcare organizations integrate more networked medical equipment and implement electronic medical records, managing security and safety risks will become increasingly important.Robust risk management is the first line of defense, a point recognized by various stakeholders with the development of ANSI/AAMI/IEC 80001-1, a standard which deals with IT networks incorporating medical devices.“Risk management is an ongoing process for all networked devices used in healthcare, whether as a ‘traditional’ medical device that uses stand-alone software or as a medical device with extended connectivity including Internet access, such as tablet computers and smartphones,” Cordisco says. “Risk management starts long before the device is put on the market and continues until it is decommissioned. Part of risk management includes appropriate protections for medical devices with web access against possible breaches of device security.”Risk management should consider the risks to patient safety and data security. Both are important. Healthcare organizations might want to supplement their regular risk management activities with these steps recommended by security experts:Finally, a special caution: Smaller healthcare facilities and doctors' offices are especially vulnerable to medical technology security risks. These facilities typically do not have a dedicated IT or health technology management staff to safeguard patient data or medical devices. And they are easier targets of physical break-ins and thefts.