healthsystemcio.com

healthsystemCIO.com is the sole online-only publication dedicated to exclusively and comprehensively serving the information needs of healthcare CIOs.

  • About
    • Our Team
    • Advisory Panel
    • FAQs/Policies
    • Podcasts
    • Social Media
    • Contact
    • Privacy & Data Protection Policy
    • Terms of Service
  • Advertise
  • Partner Perspectives
  • Subscribe
  • Webinars
    • 10/12-Fighting Insider Breaches
    • 10/17-Improving Patient Communications
    • 10/25-Medical Device Security
    • 10/26-Being Audit-Ready
    • On-Demand Webinar Library

  • About
    • Our Team
    • Advisory Panel
    • FAQs/Policies
    • Podcasts
    • Social Media
    • Contact
    • Privacy & Data Protection Policy
    • Terms of Service
  • Advertise
  • Partner Perspectives
  • Subscribe
  • Webinars
    • 10/12-Fighting Insider Breaches
    • 10/17-Improving Patient Communications
    • 10/25-Medical Device Security
    • 10/26-Being Audit-Ready
    • On-Demand Webinar Library

Are Medical Devices a Blind Spot for Healthcare Cybersecurity?

04/12/2023 By Joey Meneses Leave a Comment

Joey Meneses, CTO, Akron Children’s Hospital

The importance of medical device cybersecurity cannot be overstated. Medical devices are increasingly connected to the internet and hospital networks, which makes them vulnerable to cyberattacks. A cyberattack on a medical device can have serious consequences, ranging from the theft of patient data to the compromising of patient care.

Often, the management of medical device cybersecurity is not a primary concern of a clinical engineering team in a healthcare organization due to the following factors:

  • Clinical engineering teams are primarily focused on scheduled maintenance and bench repairs.
  • Clinical engineering professionals may lack IT and cybersecurity skills.
  • Only general attributes from medical devices are captured and documented in the Computerized Maintenance Management System (CMMS). Core network and cybersecurity attributes are not maintained in the CMMS.
  • Clinical engineering policies, procedures, and processes are not aligned to manage cybersecurity risks.
  • Lack of coordination and/or siloed structure between IT and clinical engineering.
  • Original Equipment Manufacturers (OEMs) have unique methods of sharing the availability of a validated or approved mitigation for medical devices impacted by a vulnerability, plus there is no industry-wide standard or regulations for releasing validated patches in a reasonable time. This creates a unique challenge for healthcare organizations to track the timely availability of a patch or other mitigations.

The advancement in healthcare technology has not only increased the dependency of integrated medical devices on the network but also provided bad actors with other entry points for cyberattacks due to weak security controls or unpatched vulnerabilities on medical devices.

There are several ways to mitigate the risk of a cyberattack on medical devices:

  • Conduct Risk Assessments
  • Implement Strong Authentication
  • Regularly Update and Patch Devices
  • Segment Networks
  • Encrypt Data
  • Train Staff
  • Regularly Test Systems
  • Implement Incident Response Plans

Assessment of medical device cybersecurity requires a strong collaboration between IT and clinical engineering. By working together, both departments can develop a cybersecurity strategy and improve the lifecycle management of medical devices. This joint effort can empower healthcare organizations to protect against cyberattacks while contributing to its primary mission: safe and reliable patient care.

This piece was written by Joey Meneses, Chief Technology Officer at Akron Children’s Hospital.

Share

Related Posts:

  • Tackling the Toughest Problem in Healthcare IT Security: Medical Devices
  • Real-World Management of Medical Devices
  • Medical Devices and "Blind Spots": How True Visibility Can Change the Game
  • What CIOs Need To Know About Securing Medical Devices
  • Valley Medical Taps Sunquest

Filed Under: Columns, Cybersecurity, Device Management, Featured, Patient Safety Tagged With: Akron Children's Hospital, Joey Meneses

Share Your Thoughts Cancel reply

You must be logged in to post a comment.

To register, click here.

Partner Sponsors

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 


 

 

 

 

Copyright © 2023 HealthsystemCIO.com.