Managing Legacy Medical, OT, IoT Device Risk in Healthcare episode artwork

EPISODE · Jul 25, 2023

Managing Legacy Medical, OT, IoT Device Risk in Healthcare

from Info Risk Today Podcast · host InfoRiskToday.com

While patient safety risks posed by unpatched security vulnerabilities in legacy medical devices often grab headlines, healthcare entities shouldn't underestimate the serious business risks involving other poorly secured IoT and OT gear used in healthcare settings, said Mohammad Waqas of Armis.

Episode metadata supplied by the publisher feed · Published Jul 25, 2023

Embed this episode

NOW PLAYING

Managing Legacy Medical, OT, IoT Device Risk in Healthcare

0:00 0:00
of MATCHES

TRANSCRIPT · AUTO-GENERATED

Hi, I'm Mary Ann Kolbasek McGee, executive editor at Information Security Media Group. Today I'm speaking with Mohamed Wakaz, who is Principal Solutions Architect for Healthcare at Security Firm Armist. So Mo, a recent study by Armist, rated the riskiest medical devices and IoT devices used in healthcare settings. I understand the assessment looked at devices with the greatest number of unpatched vulnerabilities.

What kinds of vulnerabilities went unpatched? And what are the dangers that these vulnerabilities pose to IT systems and data? And did you assess whether or not the devices and unpatched vulnerabilities posed patient safety concerns as well? The types of vulnerabilities that we saw across all the different types of, whether it's IoT, IoT, building management systems and OT systems, they were varying across all the different severities, let's say.

So you, of course, had your load, your mediums highs, and the report they released was quite focused on the critical unpatched CVs that existed. Now, a lot of them were related to things like remote code execution, taking remote control over devices that have the ability to allow attackers to either sift data, steal patient data, even make changes on quite a few of the different types of medical devices. So in one of them, for example, the infusion pumps, it was found that unauthenticated attackers can actually take control and they can actually change the different, let's say, drugs and concentrations that are being delivered by those types of medical devices. So it's really the technical capabilities and severities are pretty well documented when it comes to the necessary security vulnerability database.

But then when we start looking at the business impact, that impacts a whole another realm of risk that we see across healthcare organizations. So then what else did you find when the business risk is considered? Yeah, so when the business risk is considered, it's a lot on the, especially those devices that are directly touching patients, like your infusion pumps, even lab equipment and things of that nature. There's a lot of patient safety related ones that if they were to be exploited can result in, then there's the patient data related ones that there was another vulnerability that was disclosed that impacted Illumina Universal Copy Services that run on lab sequencing devices.

Now, if authenticators or rather if attackers get a hold of that or are able to exploit that vulnerability, what ends up happening is they can actually take patient related data, so patient identification information, understanding who the patient is, what the test is that's running, what the results on those are. So across the board, these are the types of things that we're seeing. And then of course, there's the other types of IoT devices like when you saw IP cameras that were also as part of the Armist Research Report that was released, there's also the potential for privacy issues there as well. And what exacerbates the issue even more is the fact that healthcare networks are pretty old legacy networks that are flat.

And when I say flat, what I mean by that is if one device on the network gets compromised, it can be a computer in the staff break room and an attacker takes control of that, they can very easily pivot over and take control of medical devices, IP cameras, nurse call systems, facility systems. So that's why we're seeing a lot of focus on health organizations now trying to go under a segmentation project, trying to kind of break up their networks and secure them into smaller chunks. So now I do understand you mentioned it also, but I understand that nurse call systems were the top riskiest device. Why?

Well, that was given the, they have the most severe CDEs or unpatched vulnerabilities. And by far, the largest volume, if you will, with almost half of them having those unpatched CDEs. Now, if you look at it from an impact of patient care perspective and the impact it has on it, the nurse ball systems are leveraged to immediately contact and dispatch clinicians and nurses, of course, if there's a adverse event that's impacting a patient. Now, while this is not necessarily a direct patient connected medical device that's monitoring vitals, you can imagine that any type of delay in having that nurse call system engaged or respond or available can lead to negative consequences and potential harm for patients that they're not responding to in an inappropriate amount of time.

And I also understand that infusion pumps were also second riskiest. And what did you find there? Infusion pumps, they have been on the radar. And this isn't the first time the arm is actually disclosed infusion pumps as some of the riskiest medical devices that exist on the network.

They have, in fact, Armist, I believe this was about four years ago, there was also additional research released by Armist, which of the vulnerability urgent 11, which was a set of vulnerabilities that impacted billions of devices across the world in all different types of industries. And this essentially allows attackers to remotely control and get access to a whole plethora of different devices. Now, infusion pumps being one of those types. And as I was mentioning earlier, with the infusion pumps, really the risk is multiplied several fold exponentially, because when taking advantage or taking control of these types of devices, what it will result into is making any types of changes or even bringing those medical devices down, it causes direct impact to somebody who's connected to that actual device.

So that's where a lot of the time when these types of reports are released, it's unfortunate that medical devices, particularly legacy ones that have been developed over the past few decades or so that are still employed in hospitals, it's very difficult to actually patch these types of systems. And that's where it gets really important to understand and embark on that, as I was mentioning, a lot of healthcare organizations are looking to segment these devices off. Because if you can't patch these vulnerabilities, then what's the next best thing you can do is you can control access to it. So a lot of through this podcast, what I've been mentioning is a lot of remotely excubable vulnerabilities.

Well, that vulnerability in terms of risk starts decreasing if the attacker simply can't even access it at device, whether it's on a laptop, on that network that can talk to it or directly jump over to that medical device. So that's why we're seeing a really big surge in order to address these vulnerabilities, a big push on the network segmentation side for healthcare organizations. So when it comes to the legacy devices, where there are certain types of devices that tend to linger longer in these environments, for instance, the nurse call systems, where they hide on the list because you see a lot of those legacy systems that just don't get replaced, or what is the landscape like when it comes to the legacy devices and those risks that you saw? I think it comes down to a few different factors.

The first one being just even being aware of what devices exist with what vulnerabilities. I think there's been quite a bit of focus or new focus placed on medical devices specifically in the past few years where we're starting to see headlines and a lot more reports coming up on medical devices and have been coming out. And what's important, what's important to understand is that the healthcare device ecosystem is actually one of the most diverse across the different industries that exist because you have your enterprise devices, your IOT devices such as IP cameras, digital signage, your TVs, your registration kiosks, your medical devices, infusion pumps, and imaging modalities, lab equipment, but then also your building management systems, your HVAC systems, your support systems, your pneumatic tube systems that help support the delivery of patient care in one way, shape or another. Think of an HVAC system like an AC unit, it's regulating the humidity and temperature levels in an operating room.

If that were to malfunction and humidity levels rise, you're looking at canceled surgeries. So when we're unpacking this, the first and foremost is let's look at medical devices. Now when there's a lot of emphasis put on, hey, you have these 10,000 medical devices, they all have extremely critical vulnerabilities. Now, what are the options we have to actually remediate or mitigate these vulnerabilities?

In a traditional cyber security world where all we're dealing with is laptops and desktops, I would be able to go to windows at Microsoft.com, download the patch and install it. Now with medical devices, what's happening is vendors are either not allowing devices to be patched simply because they don't support it, or because they haven't had the time to certify it yet. So historically, vendors have sold a drug dispensing cabinet running Windows XP, let's say 10, 15 years ago, and it is certified to operate as is. Any changes to that, whether it's changes to configuration, changes to patching, it might not operate how it's supposed to.

So you can imagine the risk being exponentially higher if there's a device that's dispensing drugs to a patient directly into their veins, and something happens, it malfunctioned or acted in a way that it different, there's just way too much risk with that. So what vendors have done is they're selling you that device in an as is configuration. Okay, so Mo, you told me why vendors can't patch it. What's the next option?

Well, vendors sell new medical devices with the newer operating systems. The trick here, though, is that it's very, very cost prohibitive. And I'll give you an example. In my previous life, I worked for a hospital for about 10 years helping build their information security program for the ground up.

And when we went to the pharmacy team and we said, the security team has this massive mandate where we're getting rid of all Windows XP devices and Windows XP being an operating system that's been end of life for almost a decade now. Well, in that case, the vendors that we can't, we had actually upgraded to Windows 7 or Windows 10, we'd have to buy a new device and that device costs $100,000. Now, Mo, your security team is mandating this for me from an operational perspective. This device works exactly how I needed to.

There's no problems with it. It's not broken. It's helping deliver patient care. We have 30 of these across our environment.

So common format, that's $3 million. Mo, will you pay $3 million out of your budget to have these devices replaced? That turns into a very, very different conversation when we start thinking about the cost benefit. And when you were talking about non-medical devices such as HVACs, besides HVACs, what other sort of OT or IoT devices are sometimes overlooked in terms of the risk that they compose there to patients or the IT systems and data?

Usually, almost always overload. Some of the more common ones like your IP cameras, just because they make the news all the time, even if it's, you know, your Nest camera or doorbell or ring system that you have at home, even those making the headlines kind of trigger some type of response from teams to say, we should look at our own IP cameras. But when it comes to HVAC systems, these are the ones that are not front and center. They're not top of mind.

When you think of health care, you think of medical devices. When you're walking through an organization, you're looking at CT scanners, a machine that are very prominent in front of you. A lot of times with the HVAC systems, there are a lot of times the afterthought. And when they're, when they become the afterthought, it's very hard to prioritize replacing them if it's not broken.

And that kind of ties back into the previous point there, where, you know, let's take the nurse call system as an example. It's not a medical device that's directly touching a patient for the purpose of patient care delivery. It works. So if it works, then why should we replace and spend so much money on replacing something that already functions as is when we have other priorities, right?

Hospitals across the world having very limited budgets. And when it comes to HVAC systems, their priorities are also just the availability, just making sure these devices are, their maintenance is done on time and they're up and running. In order for me to rip and replace a massive HVAC system that, that power throughout the entire hospital and organization, that is huge investment of human resources, a huge investment capital. And what's the benefit that I'm getting from it?

It's a very large and complex, multi-million dollar project. What we can do from a security perspective, though, is we can help build in compensating controls so that general these systems are more than not as isolated as it can be. And what we can do is value that they have the compensating cybersecurity controls in place so that they're not talking to other aspects of the network that would otherwise elevate the risk they've posed. Well, thank you very much, Mo.

I've been speaking to Muhammad Wokas. I'm Mary Ann Kolbasak, the GEE of Information Security Media Group. Thanks for joining us.

No similar episodes found.

No similar podcasts found.

Frequently Asked Questions

When was this Info Risk Today Podcast episode published?

This episode was published on July 25, 2023.

Can I download this Info Risk Today Podcast episode?

Yes. Use the download control on the episode player to save the publisher-provided media file.
URL copied to clipboard!