newsfilter.io
Panel, Conference Presentation

Hacks on Health Care: How to Make a Vulnerable Industry Cyber-Secure

  • Healthcare cybersecurity is characterized as being in critical condition, with reports indicating that 85% of modern healthcare delivery organizations lack a single qualified security person on staff and that incidents causing care delays or ambulance diversions occur weekly.
  • Future trends anticipate that 40% of all Internet of Things devices will be health-related, creating opportunities to reduce costs and improve care through technologies like swallowable biosensors and artificial organs, though this dependence increases exposure to new accidents and adversaries.
  • Regulatory expectations have shifted to require security built into the design of all new devices as part of pre-market guidance, with manufacturers maintaining security throughout the total product lifecycle until obsolescence, while FDA policy acknowledges the necessity of continuous monitoring under the NIST framework.
  • Significant financial barriers exist, with hospitals potentially needing up to $106 million to acquire necessary security tools, a sum that poses challenges for smaller facilities, while the current assessment market is valued at approximately $15 billion and the security technology market at $75 billion.
  • Market risks include the potential for cyber terrorism to leverage vulnerabilities to take human life, a belief that a fatality due to software flaw will eventually occur driving liability expectations, and the risk of a public crisis of confidence causing medical officers to retreat from life-saving technology.
  • Strategic approaches for security involve adopting existing standards like NIST for defense in depth, engaging white hat hackers, and anticipating that compensating controls for legacy devices may lead to diversity, errors, and increased costs.
  • Cyber insurance is projected to play a vital role despite premiums skyrocketing in 2015 due to mispricing, though the sector is currently considered too immature to serve as a primary solution compared to direct security investments.
  • Industry dynamics suggest that device manufacturers will increase R&D investment in security if customers demand it in RFPs, though the development phase for new devices faces lags due to testing, standards, and submission processes.
  • A formal report on healthcare cybersecurity is expected to launch in the next several days following a one-year Congressional Task Force mandate, emphasizing that solutions must be integrated through design, maintenance, and end-of-life rather than relying on single antivirus products.
  • Specific scenarios such as operating room shutdowns due to cyber threats are expected to persist, while the industry moves toward a "Hippocratic Oath for connected medical devices" strategy founded on the assumption that all systems will eventually fail.