I'm Marian Kolbeseck-McGee, Executive Editor at Information Security Media Group. Today I'm speaking with Professor Kevin Fu, who is Director of the Archimedes Center for Healthcare and Medical Device Cybersecurity at Northeastern University in Boston. Kevin is also former Acting Director of Medical Device Security at the Food and Drug Administration. Welcome, Kevin.
Thanks, Marianne. Great to be back on your program. Always a pleasure to speak with you. So, Kevin, the Archimedes Center is hosting a workshop in late April, early May in New Orleans that is focused on some of the most pertinent issues involving medical device cybersecurity.
What are the top challenges that you're seeing concerning medical device cybersecurity that you'll be tackling at the event, and who is the target audience? Archimedes at Northeastern University is holding us in New Orleans, and we call it Healthcare Security Week. And so it begins on April 30 with training for the audience of healthcare delivery organizations and medical device manufacturers, as well as any other stakeholders who work within the use or deployment or manufacture of medical devices or pharmaceutical production systems, where high availability is of key concern and resiliency of the overall systems. So that's the audience that's going to this particular event, and I don't think you'll be surprised to hear that one of the top issues of discussion is ransomware preparedness.
So that's sort of the number one thing on everybody's mind because of what's going on at Change Healthcare. But we work more on the left of whom and understanding how to design out these problems in the first place. And so there's also quite a bit of emphasis on the technology, policy, and processes and coordination so we can get out in front of Ransomware 4.0. So, Kevin, you mentioned ransomware, and another buzzword we've been hearing a lot about is AI, and AI and machine learning-enabled medical devices.
What are some of the cybersecurity issues that concern you the most when it does come to AI and machine learning-enabled medical devices? What stands out about these kinds of medical devices from a cybersecurity risk or vulnerability perspective? Machine learning and AI holds huge promise for healthcare, especially digital health. You can imagine it not only as more of an encyclopedic resource, but also in the future a diagnostic resource to help either with cognitive support or in the direct diagnosis of disease.
But it's definitely in the early stages. I could go on for hours about some of the list of Silicon Valley companies that have tried and failed in the past. But this one, I think, finally we've reached the point where it might actually work. Now, getting to your question, but what about the risks?
The risks abound, because any time you're using AI or machine learning, there is an opportunity for an adversary to manipulate the input or to manipulate the training set to do untoward things. Machine learning and AI does not make decision-making the same way human does. Humans have intuition, machine learning as algorithms, and they often use shortcuts to make their decisions. It might seem like it's really smart.
For instance, it might identify a stop sign and tell you, hey, look, it says stop ahead. But the human might be thinking, oh, it's red, and it's an octagon. But the computer vision algorithms might be thinking, hey, I see a pixel at this one location, and whether or not this pixel is red is always associated with stop signs. So I'm just going to look at this one pixel.
And so, of course, if an adversary changes that one pixel, then it can muck with machine learning. So there are these similar risks when using AI or machine learning or computer vision in health care for diagnosis or perhaps in the future even therapies. But I think in my own view, though, I view AI and machine learning as a very important tool for the future of health care. But we just have to be realistic that we can't ignore cybersecurity.
We can't just speak words about it. But we actually have to focus on the threat modeling, which is what we teach on day one of our training when Adam Shostak will be teaching threat modeling. We have to teach about how you stand up security programs that take into account these qualitatively different risks. And that's what Michelle Jumpa is going to be talking about, the regulatory side of how to stand up a cybersecurity program within a health care organization.
So, Kevin, we're also seeing advancements in robotic devices that are used in that is including robotic surgical gear. What are some special cybersecurity considerations that threaten or pose risks for robotic medical devices and what sorts of things besides surgical? Again, I just want to preface my response with I think robotic surgery and the use of robots in health care is really important for helping patients to lead more normal and healthy lives. But, again, we can't simply give lip service to cybersecurity.
It's no longer kids in the basement just trying to have tomfoolery. But these are nation state backed and organized crime that are financially or politically motivated to cause mayhem. So it doesn't take a whole lot of science fiction thinking to already imagine what could possibly go wrong. A robot doing surgery moving in the wrong direction or even something more simple, a robot becoming unavailable in the middle of a procedure because of some kind of cybersecurity threat such as ransomware that brings down a cloud that it's connected to or a piece of malware that causes some of the software to behave outside of what it should be doing.
There's also, in my view, a risk that has not yet come to pass in the real world, but I suspect it will in the coming short number of years. And that is the integrity property. So ransomware cuts to the availability property as well as privacy property in that it can cause devices to be unavailable to deliver patient care. And FDA has come down quite publicly on record that they consider this harm.
And legally, when it's considered harm, all sorts of regulatory systems kick in. So availability is something we're used to, but integrity is a whole other class of challenge. So imagine a piece of ransomware can get in and just subtly change things that the robot is thinking, what direction to go, how quick to go, how often to make an incision. These are things that are going to be harder to detect and are going to cause more subtle problems.
Or flipping a couple of bits in a patient's record to change not what the program in the robot is, but how the program in the robot decides what to do. So there are all sorts of risks. And this all begins with step one, threat modeling. So, Kevin, as you know, we also see a lot of consumer wearable health devices that might not necessarily fall under the regulatory authority of the FDA.
We also see remote monitoring and other telehealth sorts of devices. Many of these devices and applications really kind of took off during COVID. What are some of your top cyber concerns involving these types of technologies? Great, that's a great question.
So I would divide this question up into at least two different areas. One is personal health, which is generally not regulated by FDA, but is regulated by other entities, such as the proposed cyber trust mark coming out of the SCC. And then there are clearly FDA regulated devices, such as remote diagnosis of disease. So it gets into these, of course, gray areas of state and federal law.
So let me get to the digital health devices first. Again, digital health devices have great potential. I think already the anecdotal evidence is showing how it's helping individuals to create more personalized health improvement plans, everything from fitness, step counters to exercise regimes and personal assistance. I think there's a lot of opportunity there.
I think we have a lot of classic risks there of confidentiality. So, for instance, just classic malware and intrusions that have been going on for over 30 years. But now getting into these systems that have much more personal data about individuals poses some especially significant risks, privacy of the individuals. And so you're going to see some of these topics regulated by most likely the new cyber trust mark, where there are certain expectations of cybersecurity engineering before this mark is available to a device.
This is in the very early stages in the U.S. government, but has already gone through a public comment period with the FCC. Now, on the side that gets much more closest to things like medical devices or simply the practice of medicine, there's telehealth, right? So telehealth, I think, is a real game changer in a positive way.
So it's almost like bringing back the ability to have the house call from your family doctor, right? I don't know anyone who gets house calls from a family doctor anymore unless it's telehealth. And so now you can get much more rapid response rather than going to an emergency room, but you can do it from the safety of your home to really triage some of these clinical diagnoses. Now, that's going to get into, I think, a few of the basic risks, force it relies on cloud technology.
And so that's why at Archimedes, we have an event and speakers from some of the major cloud service providers. For instance, both Google and Amazon's cloud services divisions are sending people to talk about how they work with the life sciences and medical device companies to ensure high availability and other security properties of the cloud behind a lot of these services. But just imagine if we had a change healthcare event for telehealth. You can probably imagine there are a few different software providers who create these telehealth platforms.
And what if one of them goes down? Will we have a national outage of telehealth? What happens in 10 years when we shift to no longer optional telehealth, but everybody either de facto standard doing telehealth and it becomes unavailable? What do we do?
So, again, this gets back to classic threat modeling of step one before we can even begin to understand, well, what mitigating approaches do you deploy to ensure the resiliency of these approaches? At the other extreme would be actual future therapies using telehealth services. So there are some devices of this nature, and there's definitely a lot in the works. But you can imagine a future where the physician is able to actually engage in the therapies, whether it's involving administration of drugs or it could be changing settings of a device.
But doing this remotely brings up an extremely different class of risks. The hospital setting, although there are risks, it is a relatively controlled environment. I wouldn't call it an innately safe environment, but it's definitely more controlled. You have clinicians nearby.
You have healthcare professionals that something should go wrong. At the home, you have children running amok. You may have a cat crawling across your medical device. There are all sorts of uncontrolled situations.
And it's much harder to maintain the security of the system remotely. And so we're going to have to rethink a lot of the threat modeling. And, you know, this does mean we're going to have to go back to if we have a device that's designed for use in the hospital, we have to think about what new controls need to be put in place such that it can remain highly available, still safe and effective, despite the qualitatively different cybersecurity risks at home. So, Kevin, you mentioned the FCC.
What are you watching in terms of the FDA and regulatory developments this year involving medical device cybersecurity? Well, it's been a real flurry of activity of FDA guidances over the past year, both regulatory guidances with statutory authorities. So just to remind your listening community, there is the finalized, what many of us call the pre-market cybersecurity guidance, also has a much longer name of quality system regulations for cybersecurity considerations for pre-market. This is basically what manufacturers are expected to do to receive a positive review, pre-market review of the medical device, to get permission to market it in the United States.
It's much more detailed now. Everything about software bill materials, which we have speakers on in New Orleans, to things like penetration testing and vulnerability management. Another big activity, which is only a couple of weeks old, is the draft guidance from the FDA on how they plan to carry out their new statutory authorities known as Section 524B. Section 524B refers to a section of law that was passed about a year ago where the FDA is now required to regulate cybersecurity medical devices.
So it's no longer just optional. It's no longer just guidance, but it's required by law. So they've proposed their guidelines of what they plan to do, and it's very much in line with the previously published pre-market guidance. But the 524B section does require special attention to software bill materials, F-BOMs.
So it's no longer optional. FDA is required to collect these software bill materials. And it also goes into much more detail on what is regulated for cybersecurity in the medical device space. And so there's this term called a cyber device.
And this is something that's extremely important, especially for medical device manufacturers, because I think a lot of manufacturers misunderstand and think that they're not part of the cyber device. They might say, well, oh, we don't run Windows on this device. We don't have any software. Well, that's not the definition of a cyber device.
The definition has to do is if it has the potential to connect to the Internet, not whether it does connect to the Internet by design, but whether it could be even manipulated to connect to the Internet. And so that casts a very wide scope of devices. So, for instance, if there's a Bluetooth module in it, whether or not it is used, whether or not it is enabled doesn't matter. But because it's there, that is now considered a cyber device, according to the draft guidance from the FDA for Section 524B.
And let me just have one more comment. To draw attention to this, Archimedes is actually holding what we call a fun run, a 524B run, a 5.24-kilometer run in New Orleans on May 2. So for any of the runners out there, we hope you'll join us as we run down Bourbon Street and along the Mississippi River to draw attention to this important guidance. Well, thank you so much, Kevin.
I've been speaking to Professor Kevin Fu. I'm Marianne Colbissette McGee of Information Security Media Group. Thanks for joining us. Thank you.