Cybersecurity Vulnerabilities in 2 Patient Monitors
An FDA safety communication says that cybersecurity vulnerabilities in certain Contec and Epsimed (relabeled Contec) patient monitors may put patients at risk after being connected to the Internet. The communication says these three vulnerabilities have been identified:
- the patient monitor may be remotely controlled by an unauthorized user or not work as intended;
- the monitors’ software includes a “backdoor” that may mean that the device or the network to which the device has been connected may have been or could be compromised; and
- once the monitor is connected to the Internet, it begins gathering patient data, including personally identifiable information and protected health information, withdrawing the data outside of the healthcare delivery environment.
“These cybersecurity vulnerabilities can allow unauthorized actors to bypass cybersecurity controls, gaining access to and potentially manipulating the device,” the agency says. “FDA is not aware of any cybersecurity incidents, injuries, or deaths related to these cybersecurity vulnerabilities at this time.”
The notice says a vulnerable device could be exploited to (1) deny access to the device, causing it to crash and be unable to work as intended, and (2) take over the device to remotely control it to perform unexpected or undesired actions, such as corrupting the data.