MAIN WEAKNESSES AND PROBLEMATICS OF CYBERSECURITY IN MEDICAL DEVICES

Author(s)

Blavatskyi I1, Blavatska O2
1National University Lviv Polytechnic, Computer Technologies, Ukraine, Lviv, Ukraine, 2Danylo Galytskyi Lviv national medical university, Lviv, Ukraine

Presentation Documents

Advancements in healthcare technologies devices help patients to lead lives healthier and happier as they rely on their devices to provide safe reliable care. Devices themselves often rely on computer software to function properly and as more of them are wireless they are increasingly connected somehow to hospitals’ network or other medical devices. But this connectivity costs vulnerabilities for hackers, malwares, viruses and other threats. Cybersecurity found in medical devices is not very advanced at this point. Cybersecurity specialist should take preventative steps to solve this problem. Most common 4 weaknesses in hospital cybersecurity practices are:

1) An incomplete cyber inventory. Many cybersecurity problems aren’t technical. It’s hard to mitigate risk until you have an inventory of your systems. You should be able to enumerate everything that is on your network and identify your cybersecurity risk by device in your computerized maintenance management system.

2) Vendors awareness can make security hard, can take lackadaisical approach to cybersecurity. Advice to put your device on secure network or behind firewall isn’t effective. If vendor doesn’t know about medical device security formulas, you should consider whether he has other deficiencies and would leave open backdoors to potential cyber threats.

3) Number of overwhelming security testing tools. Providers struggle to cope with volume of security testing tools and vulnerability info; they may not know issue to address, how to identify the most important one or even where to start.

4) List of overreliance on segmentation isn’t enough. Network segmentation makes network harder to manage which again adds to workload and makes taking inventory more difficult, despite all these challenges should be monitored.

Security should be designed at development and not add later, when device is already on market. This should be handled by medical device developer witch applied to risk management.

Conference/Value in Health Info

2019-11, ISPOR Europe 2019, Copenhagen, Denmark

Code

PMU11

Disease

Multiple Diseases

Your browser is out-of-date

ISPOR recommends that you update your browser for more security, speed and the best experience on ispor.org. Update my browser now

×