Securing medical devices against cyberattacks or malware outbreaks and safeguarding protected health information (PHI) stored on devices or exchanged between a device and the provider’s network is a growing challenge for clinical engineers and hospital information technology (IT) professionals. 1 This article will analyze two general trends with regard to their impact on a medical device security strategy: first, the increased exposure and vulnerability through the growing number of devices connected to a network, and, second, the changes in the cyberthreat landscape. Threats are becoming more prevalent, complex, and sophisticated, and are being driven by a cybercrime culture that is moving away from sensationalism to targeted attacks based on financial motivation. 2 A medical device, in the context of this article, is any network-connected system used in patient care in a hospital, private office, home, or other healthcare setting, and which, due to its usage model, operating system, configuration, and network communications, can be exposed to cyberthreats—for example, through a permanent or intermittent network connection or through “sneakernet,” a term that describes the transfer of electronic information by physical means, such as a USB or universal serial bus, device.
Read full abstract