Contec and Epsimed Cybersecurity Patch
In an updated safety communication, FDA says Contec has issued a software patch to fix cybersecurity vulnerabilities in certain Contec and Epsimed patient monitors. The agency notice says the patch fully removes networking functionality from the affected monitors, making them usable only for local monitoring.
In a 1/30 safety communication, FDA had called attention to three cybersecurity vulnerabilities in the monitors:
- the monitor may be remotely controlled by an unauthorized user or not work as intended;
- the software on the monitors includes a backdoor, which may mean that the device or the network to which the device has been connected may have been or could be compromised; and
- once the monitor is connected to the Internet, it begins gathering patient data, including personally identifiable information and protected health information and exfiltrating the data outside of the healthcare delivery environment.