newsfilter.io
Panel, Conference Presentation

Hacks on Health Care: How to Make a Vulnerable Industry Cyber-Secure

  • Moderator Context: Kim McCleary (Faster Cures/Milken Institute) framed the panel around the intersection of healthcare innovation and cybersecurity, noting that cyber attacks are now equated by business leaders with natural disasters like fires or floods.

  • Hollywood Presbyterian Case Study: Hackers infiltrated a local hospital, extorting $17,000; the attack caused significant operational disruption, including operating room shutdowns and ambulance diversions, highlighting that the cost of downtime far exceeds the ransom amount.

  • BlackBerry R&D Findings: BlackBerry's white-hat hacking team compromised a generic bedside infusion pump in two weeks, achieving root-level control that could only be physically overridden by unplugging the device.

  • Regulatory Shift Trigger: The "I Am the Cavalry" organization demonstrated a fatal flaw in an infusion pump to the FDA; despite no actual patient harm occurring, the FDA mandated a corrective action, establishing a precedent that proof of potential harm is sufficient for regulatory intervention.

  • Market Disparity: While healthcare employs high-level intellect, it lags in security adoption due to a massive volume of legacy devices, a lack of security-savvy personnel compared to the financial sector, and a collaborative culture that is inherently more exploitable than the restrictive security models of banking or intelligence.

  • Data Value: Electronic health records (EHRs) are valued at approximately $100 per record on the black market, significantly higher than credit card data, with a permanent value because medical history cannot be changed like a credit card number.

  • Economic Barrier: Securing a typical 160-bed hospital costs an estimated $106 million in tools alone, creating an impossible financial hurdle for smaller rural facilities (e.g., 24-bed hospitals) to afford basic cyber defenses.

  • Legacy Technology Challenges: Medical devices often remain in use for 10–15 years, frequently running on unsupported operating systems like Windows XP, making patching and security retrofitting technically difficult or impossible.

  • Task Force Findings (HHS): A 20-member Congressional task force identified "critical condition" in healthcare cybersecurity, citing five key truths:

    • Talent Shortage: Approximately 85% of modern healthcare organizations lack a single qualified security professional on staff.
    • Legacy Systems: Widespread use of unsupported, obsolete operating systems that cannot receive security patches.
    • Hyper-Connectivity: Government "meaningful use" incentives forced unrelated devices into flat, unsegmented networks, exposing them nakedly to the internet.
    • Patient Safety Risk: Vulnerabilities can directly interrupt critical care, as seen in diverted ambulances and UK hospital shutdowns.
    • Vulnerability Epidemic: The average device contains over 1,400 known exploitable flaws.
  • Insurance Limitations: Cyber insurance currently covers narrow scopes (e.g., credit card monitoring, legal fees) but rarely covers clinical losses, brand damage, or loss of life; premiums are skewed, and recent ransomware payments (over $1 billion in 2016) often exceeded policy deductibles.

  • Liability Gap: No statutory liability exists for software flaws in the U.S. for the past 30 years, though this is expected to shift following anticipated fatalities, which will force insurers to align products with manufacturers and hospitals.

  • NIST Framework Approach: The NIST cybersecurity framework focuses on identify, protect, detect, respond, and recover, explicitly omitting "prevent" because total prevention is impossible; the goal is continuous risk management and containment.

  • Medical Device "Hippocratic Oath": Proposed standards for connected devices include designing for safety by assumption (systems will fail), logging failures, agile patching, and segmenting networks to isolate breaches.

  • Actionable Recommendations for Stakeholders:

    • FDA/Regulatory: Empower patients and clinicians with security knowledge to facilitate informed decision-making and demand transparency regarding device risks.
    • Innovators/Investors: Leverage the current crisis as a commercial opportunity to develop scalable solutions for cash-strapped, "target-rich" hospital environments.
    • Hospitals/Procurement: Conduct vulnerability assessments (e.g., 90-minute surveys) and mandate specific security requirements in Request for Proposals (RFPs) for new devices.
    • Healthcare Institutions: Integrate cybersecurity into the existing culture of patient safety and implement critical security controls to reduce risk immediately.