I'm Mary Ann Cobis, Executive Editor at Information Security Media Group. Today I'm speaking with Mike Nelson, who is Global Vice President of Digital Trust at Security firm Digisert. We're going to be discussing the FDA's Expanded Authority to regulate cyber security for medical devices and some other issues involving medical devices. Hi, Mike.
Hey, Mary Ann. So good to have you here. Thanks for coming over for the conversation today. Well, thanks for joining me.
So, Mike, here at HIMS, you're speaking about the FDA's Expanded Authority over medical device cybersecurity. What do healthcare sector entities need to know about medical device cybersecurity, especially when it concerns the FDA and their expectations for new products and what those products should be equipped with? Yeah. It's a great question.
It's been a journey in healthcare. You know, today the landscape of medical devices is very different than it was 10 years ago. Devices are connected. Devices are on the hospital for connecting to a lot of different IT systems, tobacco and gateways, and servers.
Patients are attaching devices to them, diabetes devices, cardiac devices, neurostimulators. And all of those devices today have connectivity and that connectivity creates better patient outcomes. And so, the connectivity is a really good thing, but it also creates more risk. Anytime you have that connectivity, it presents the opportunity for attackers to compromise those devices.
So, over the last decade, the Food and Drug Administration has taken on the burden to help the industry to improve the security posture of where they are. And last year, on October 1st, the FDA finally got the regulatory authority to do more than just encourage it. They now have the authority to deny approvals of medical devices that don't meet certain cyber best practices. And that's a really good thing for the industry.
Because it can give, whether it's a patient using a medical device, a hospital system that's onboarding it and connecting it to their network and the patients that are coming in there, it gives assurance to the industry that, beginning now, devices that are going through the approval process, have to meet those requirements. And so, I'm really encouraged and it's been quite a journey to get where we are today. So, I understand that you describe public key infrastructure or PKI as a connective tissue between compliance and security, so medical device manufacturers can meet regulations and keep their products on the market. What do you mean by that and how is that the case?
Yeah, so, public key infrastructure is a security protection that has been used for a long time. It started, you know, with the public internet and authenticating connections between web servers. But today, as more and more devices and IT systems are connecting, cryptography is used to authenticate connections. It's used to provide strong identity and to have an immutable identity on a device.
It's also used to help encrypt and protect the data that's being transmitted. So, you know, the FDA, the regulations are based on security best practices, things like authenticate your connections and encrypt your data, sign your code, do vulnerability scanning, do risk assessment. A lot of those security best practices are actually rooted in public key infrastructure. And so, having a robust and strong PKI engine that allows you to scale it across your organization to all of the different devices that you're manufacturing, if I'm a large manufacturer, is a really important component.
And so, in order to achieve compliance with the regulations, you have to be doing it. And so, that's where, you know, there's a link between having a strong PKI engine and management practice and achieving compliance because you have to be leveraging that technology. So, what are some of the top issues you see involving medical device identity and why? And what are the manufacturers doing about this?
Are they sort of on the globe with this? Are they needing help? And as the FDA is refusing to accept their submissions of medical devices that are lacking in certain cybersecurity details, any sense of where identity falls into this? Well, you can't do security without identity.
So that's the starting point. And identity doesn't start when a device is onboarded at a hospital. Identity has to start in the design and architecture and build components. So, as you're provisioning software to a device, you need to have a digital identity that then stays with the device through its lifecycle.
That identity allows you to do asset tracking. It allows you to also, from a remote standpoint, and the FDA is requiring this, be able to update the device. You can't do a device update without having proper identity. And so, identity becomes such an important control mechanism to enable all the security things that you need to do.
Without that identity, which can be embedded on a digital certificate so that it sits there, it's impossible to do security well. And where do you see manufacturer struggling when it comes to the identity issue? Yeah. So, the question is, when do you do that?
And we see a lot of manufacturers today provisioning what we call identity certificates or a birth certificate when they're manufacturing the device. They provision on the manufacturing floor or from the cloud, a certificate that has a unique identifier for that device. That identifier then lives with the device until it's decommissioned. And it's used for things like operational updates.
If you need to do an over-the-air update, that certificate is used to one-identify it and then create a secure authenticated connection with whatever server it's communicating with that then allows you to provision that update. We see manufacturers struggling to figure out how to provision, when to provision. A lot of them are like, can we do it once we turn the device on the field or do we need to do it earlier than that? We always encourage manufacturers to think earlier in the life cycle of the device.
The sooner you can get it on, the better control and security protections you're going to be able to have with that device. When it comes to the encryption of patient data from medical devices, what sort of issues are you seeing manufacturers struggling with when it comes to encryption for data at rest, the data in transit from medical devices and are there any devices that are still pre-popular within healthcare settings like just lack encryption? Yeah. Yeah.
We just did a survey on the state of digital trust 2024, I think is the fancy official name. So one of the findings that we had in the survey is that today, now this is industry-wide, not just healthcare, but it reported and discovered that 86% of IoT data is still being transmitted in free text. That's terrifying. I hope that's not the case in healthcare.
I don't believe it is. I believe that that number is smaller in healthcare because of the sensitivity of patient data, but it still is a problem. The manufacturers and the FDA is now requiring this that they use encryption at rest for data that's residing on the device, that they use encryption of data in transit just to make sure that that data is protected. And again, it's best to design and architect that at the beginning.
It's much harder to introduce encryption and security protections to devices that are already on the field, and you have an architect your solution to be able to do that. So now, what are your concerns related to quantum computing and medical devices, particularly looking ahead and how soon are these worries realistic in terms of what entities might be dealing with? Yeah, that certainly is a hot topic right now, and the reason is because quantum computing is it might not be here this year or next year, but it's certainly coming. There are medical devices in the market today, if you walk around the HIMS floor, big pieces of capital equipment.
When a health care and hospital system buys a device like that, they don't rotate those devices every couple years. They can live on a hospital floor for up to 10 to 15 years. I was talking with one of the panelists yesterday, the Cyber Forum, who was the CSO at the hospital. She says, we have an imaging device that we've had in our system for 18 years.
It's a long time. So are we going to have quantum computing in 18 years? Yeah, probably. Right?
And so will we have it in five years? Yeah. So there's debate about the timing of it. But what there's not debate about is the need to be ready for it.
And so with cryptography, you need to think about it from an agility standpoint. So if you're using crypto on a medical device and your device is going to be in the film for five to 10 longer years, you need to be thinking about how you establish resistance for quantum computing. And the way you do that is agility. And the way you achieve that agility is by having the ability to update your device.
So if you can, with a click of a button or a few clicks of a button, communicate with that device, update the credentials, rotate the certificates and the keys to quantum resistant keys, then you're in a position of protection. If you don't have that capability today, you need to start thinking about that. And finally, Mike, what else are you keeping your eyes on right now when it comes to medical device cybersecurity issues? There are plenty of issues.
And there's a wide degree of variation in the maturity of what manufacturers are doing. Some are just getting started. Some have been after it for a lot longer. I tell a funny story several years ago, I was trying to learn how to, I've always been a swimmer, but I love to swim.
And I was like, there was a guy in the Olympics who was 45 years old and he won the goal in the free. And I was like, that's amazing. I might be able to be a Olympic athlete. There's no way I will.
But so I went and I hired a coach. I've been swimming for a long time. And I jumped in the pool and I started to swim. And he's like, you have so many flaws in the way you swim.
Your elbows, your reach, your kick. He's like, you're doing it all wrong. And it was really interesting because I've been swimming for a long time. It was hard for me to change that behavior.
So correlating that to medical device manufacturers were there. They've been making devices for a long time. And they've been making devices without cyber protections for a long time. The biggest thing manufacturers need to do right now is learn how to take on those new muscles, how to use those new muscles of building cyber into the way they design, the way they architect, the way they build, the way they deploy and the way they manage devices once they're in the field.
It's a new muscle. And just like it was hard for me to change my swim stroke, it's hard for manufacturers to have been doing things the same way for a long time to all of a sudden change that introduced new practices. It costs money. It requires new talent.
It requires a lot of things that are really shaking things up for them. And so being intentional, my encouragement, encouragement to manufacturers is to be intentional about building your muscle around cyber and making it part of everything that you do. Make it part of your quality system. Make it part of when you're deploying and making sure that those protections are turned on and are in place and are working.
And then the ongoing management. It has to be embedded through the life cycle of the device. Well, thank you so much, Mike. I've been speaking to Mike Nelson.
I'm Mary Ann Kolbasak-McGhee of Information Security Media Group. Thanks for joining us. Thank you so much, Mary. It's great to be with you today.