Cyber Security Challenges in Healthcare IoT Devices

The recent Vectra 2019 Spotlight Report on Healthcare indicates that the proliferation of healthcare internet-of-things (IoT) devices, along with a lack of network segmentation, insufficient access controls and reliance on legacy systems, has created an increasing attack surface that can be exploited by cyber criminals determined to steal personally identifiable information (PII) and protected health information (PHI) in addition to disrupt healthcare delivery processes.
Protecting patient medical, insurance and personal information must be a top priority. However, to best protect that data, security professionals need a better understanding of the types of cyber threats they are dealing with. That was the purpose of the report, which was published in April 2019.
In addition, the report has identified gaps in policies and procedures that can result in errors by healthcare staff. In fact, the findings of the report are in line with those of the Verizon 2019 Data Breach Investigations Report (DBIR) for the healthcare industry, which indicates that the majority of breaches are associated mostly with internal actors (59%) than with external ones (42%). This means that human errors pose a bigger risk in healthcare, most often in the form of misdelivery, which Verizon describes as sending something intended for one person to a different recipient. Misdelivery is followed by publishing errors, disposal errors, loss and misconfiguration.
Before digging into the report findings, it is important to understand the challenges the modern healthcare environment faces.
Saving lives and treating patients is the top priority for healthcare organizations, and they can’t afford to have their systems down to be patched, even for just a few hours. Sustaining 24/7 operations is critical for all healthcare organizations. Consequently, outdated systems and software have become common, and many healthcare legacy systems lack essential cybersecurity controls. The truth is that in an emergency a lot of well-planned protocols, procedures, security controls and training are being ignored by medical personnel trying to save a human life.
Medical IoT devices offer new ways to monitor patients and equipment while improving care and lowering costs. But many of these smart devices have unknown security protections. Connected medical devices – from Wi-Fi enabled infusion pumps to smart MRI machines – increase the attack surface of devices sharing information and create security concerns including privacy risks and potential violation of privacy regulations.
In addition to the above, most hospitals don’t have network segmentation of IoT from other devices. The result is that any device that is introduced locally can end up having a global organizational impact especially due to the lateral movement of patient medical and sensitive information across devices and departments. The security problem becomes more threatening because of the procurement procedures of medical devices. Security isn’t often included in the device acquisition or implementation phases, and it is usually an add-on feature. The lack of embedded security features increases the risk of human error, which can be anything from poor system configuration to the absence of audit logs, unauthorized access control or even a lack of processes surrounding the device’s use.
The device problem isn’t just about medical IoT. Medical facilities also allow BYOD (bring your own device), and many of those devices are considered non-compliant. Often bringing in their own personal devices are physicians employed by outside, independent medical groups which work on-site at multiple hospitals and medical students at teaching hospitals who have access to critical healthcare information for academic purposes. Even if there are proper policies in place regulating the use of personal devices, violation of policies occurs unintentionally by staff focused on providing the optimal patient care.


