Medical Device Security Moving in ‘Right Direction’: Article
An online article in Healthcare IT News says FDA and the medical device industry “are moving in the right direction” on medical device security, “fueled by the open dialog and FDA guidance on disclosures.” The article notes that medical device vendors reported 400% more vulnerabilities per quarter since FDA released its 2016 cybersecurity guidance. MedCrypt CEO Mike Kijewski says the increase in disclosures is potentially a sign of growing compliance and may also reflect a maturity in security risk assessments. “This may actually be a good thing, showing that medical device vendors are starting to take cybersecurity seriously,” Kijewski told the newsletter.
When considering whether FDA is doing “enough,” the article says the question is hard to answer definitively. “We’re not there yet, but we’re moving in the right direction,” it says.
Kijewski says that “much progress has been made in the last two to four years and our industry is on a trajectory that suggests we’ll have significantly more secure devices in the future than we did in the past.”
The need to continue to make progress, the article says, was shown by McAfee researchers who demonstrated at DEF CON in Las Vegas how easy it was for them to hack into medical devices and modify patient vitals in real-time by mimicking data sent from medical equipment clients to central monitoring systems.
Kijewski says the FDA guidance could be more detailed to help direct “vendors toward security features that would mitigate more complicated vulnerabilities.” For now, the article says, healthcare organizations need to improve patch management policies to ensure that, at the bare minimum, disclosed vulnerabilities are closed off to unauthorized access