I'm Mary Ann Kolbasakmiki, executive editor and information security media group. Today I'm at him speaking with Dr. Benoit Desjardins, who is professor of radiology and medicine at the University of Pennsylvania. We're going to be discussing some of the latest trends in cybersecurity related to medical devices and IOT, but also AI.
So Benoit, you've been participating in several sessions at HIMS, including one on the cybersecurity challenges involving medical devices, IOT, medical IOT, and OT. What are you seeing in the healthcare sector these days that are most concerning to you when it comes to securing these devices? Well, one of the problems is that, well, there's many problems obviously, medical, the medical environment, you know, includes many, many, many medical devices. If we look at Penn, we have, you know, tens of thousands of medical devices.
And a lot of them are kind of like legacy devices, so they're devices that have been around for many years. I mean, right now cybersecurity is a big topic, but many years ago, a few decades ago, people weren't concerned about that. And so when they designed medical devices, the goal was to make the medical device as best as they could for the purpose of patient care. And they didn't even think about cybersecurity because that was just not on the horizon at the time.
And so these hospitals all around the country have legacy devices all over. And these devices have no provision for security whatsoever except, say, the provision that comes with, say, if the device uses an operating system, so for example, you have a scanner, MRI scanner. These scanners are, you know, use computers and then to run software, but these computers typically will run Windows or Unix or something like that. So there will be some security based on the fact that these operating systems have some integrated security or patches that are distributed several times a year and then there's upgrades.
But a lot of the software in those devices are kind of like, you know, end of life. They run on very, very old operating systems. And you can't really patch those anymore. It's been completely obsolete, like Windows 7 and stuff like that.
It's still stuff or Windows XP, it's still devices that use that. The reason they're not upgraded across the board is because of money. I think I heard recently in a conversation that, you know, a person in charge of, you know, all medical devices at an institution, a big institution said, we would love to upgrade the OS and all our devices, but it would cost $800,000 just to upgrade the stuff. And this was not like, you know, a big academic hospital.
Small hospitals, they can't afford that. And so they run obsolete technology from a security point of view. It's still really, really good to offer patient care. I mean, these things very often, they're useful computation or measurements or stuff like that.
It doesn't need fancy advanced software to do the basic, you know, stuff for patient care. But from a cyber security point of view, it's completely unprotected and obsolete. It's a big problem. So now the FDA has been taking action to get the newer medical devices to have more cyber security features, more cyber security issues in mind.
And this pertains mostly to the new products that are getting submitted. But when it comes to other sorts of IoT and OT devices and healthcare that are less regulated, what do you worry about? Besides the medical devices that are OT or IoT that are less regulated or most concerning and why? So I mean, the FDA, like for example, the new regulations that came up last year from the Omnibus bill essentially forces vendors to address specific cyber security problems with for any newly submitted medical devices in terms of assurance of security and then, you know, post-sale maintenance of security and then kind of a bill of materials and stuff like that.
But there's many other devices that are not necessarily medical devices that really matter from a cyber security point of view. Just look at, you know, the air conditioning system in the hospital. I mean, if this goes down as a problem or elevators, if the elevator goes down and the patient in transit from, you know, the emergency to the OR and gets stuck in the elevator because the elevator got, you know, subjected to a cyber attack is a big problem. These are not regulated whatsoever.
And sometimes, you know, some of these systems provide entry points to hackers to hack into bigger hospital system. There's many, you know, very, very interesting examples, not necessarily in healthcare, but you might have heard there was this casino in Vegas that got hacked a couple of years ago and the hackers got in through the operating system of a fish tank. So they hacked the fish tank and they got into the system and they hacked the casino and was able to, you know, steal money and stuff like that. So it's, you know, anything connected to the internet is vulnerable and a cyber criminal will essentially not necessarily target specific devices.
They're going to hack a bunch of IP addresses, identify vulnerabilities of a bunch of IP addresses. If an IP address comes up as unprotected, they don't know what that IP address serves, but it could be like a fish tank or could be air conditioning or could be some minor device, but it provides an entry point to hackers to get into hospital systems and after that, once they get in, then they just have to move laterally or try to increase their privileges to be able to get full access to the system. But the entry point is very important and you need to protect every single one of those entry points and that means everything medical or non-medical that is connected to the internet that could provide an entry point to a major hospital hack and it's, you know, most of these devices are not really regulated by the FDA or anything related in terms of medical cybersecurity because it's just not even on their horizon in terms of, you know, attention. They're just there.
Their vulnerabilities that exist and it will stay there forever. So what's your advice to health care entities because they're kind of stretched thin now when it comes to the cyber security, resources, the talent, the budgets, you know, so on and so forth. You know, they're struggling with the medical devices. What should they be doing in terms of giving more attention to the OT and these other IoT sorts of devices that are just as vulnerable as anything else in the environment?
Well, it's a difficult problem because everybody in health care is stressed to the max in term of the amount of work that they have to do and the resources that they have to do that work, not just doctors but, you know, IT guys and everybody else. And at some point you've got to make, you know, decisions and choices of what to prioritize and they can prioritize everything. So they have to try to identify the biggest problem that they might have at the institution in terms of, you know, say, open access from the outside and focus on that. And they can do that and very often they do that by hiring firms like cyber security firms like Kevin Johnson who was on my panel, he's a professional hacker who gets hired to try to hack into hospitals and essentially he will identify the networks in the hospital and he will try to run software that scans IP addresses and ports to identify anything that might be vulnerable and he doesn't know which ones are medical devices, which ones are air conditioning, which ones have nothing to do with health care.
They just identify the vulnerabilities and hospitals should definitely take advantage of these outside resources to assess the security of their system because, you know, these systems are really fast, involve tens of thousands of devices. So you need somebody from the outside who's kind of like a hacker except he's a good guy and so these, you know, companies exist and they're in place to be able to help identify the vulnerability and then help patch them. So that's a way that it can use to prioritize what to work on in terms and what are the biggest security vulnerabilities but I mean any hospital or any company will never be fully secure from hackers because essentially there's new vulnerabilities that are discovered almost every week and sometimes you know you have a system that's been super secure for last few decades and then you say yeah that's not going to get hacked ever and the next week they find this vulnerability and every single system involving that software element becomes vulnerable all across the world and you just hope that they're going to go after some other hospital system before your system before you can patch the stuff and so it's a resources that help hospitals prioritize what to work on. So now you're also doing a lot of work around AI and looking ahead I know that AI has already been used in radiology for quite a while, imaging systems to help doctors maybe see something that they didn't see otherwise what is most promising to you when it comes to opportunities of AI in healthcare particularly when it comes around radiological medicine, imaging that sort of thing.
So AI is the future of radiology and we've known that for many years. In fact at Geoffrey Hinton a prominent fodder of deep learning predicted in 2016 that AI would simply completely replace all radiologists within five years and we should stop training radiologists. No it was way off because it was 2015 and then you know there's still plenty of radiologists and they're busier than ever but it was nothing to be off in its prediction it was off in its timing because if you look at what's happened in terms of development since say 2021 so five year you know after his deadline has passed there's been massive advances in AI discussions in radiology and then you know the introduction of LLM's large language models like that it's really a revolution in many aspects of medicine and so we see a future where these systems will be powerful enough to potentially eventually replace radiologists but right now we'd like to focus on developing AI that would help ease the burden of radiologists to in terms of their work like we have to do so much work right now it's ridiculous and a lot of work is cut work you have to do like you know measurements of nodules and then match the nodule in the chest city with the nodule in the private chest city and see whether it's grown or gotten better or whatever and yeah I can do that easily so we need that implemented like you know yesterday to make to ease our burden and so that should be a priority to kind of you know have AI handle all the scotwork all the measurements so that we can free up our time where it matters more from a radiologist point of view which is you know you look at all the measurements and everything and then you provide a global interpretation that is clinically relevant with respect to the conditions of the patient so that is what we should be spending all our times on as radiologists but right now we spend maybe like you know 10% of our time on that because 90% of our time involves doing a scotwork and it's a problem and AI is a potential to affect or influence every single step of the imaging pipeline from the recommendation of which study to order depending on what the patient has all the way to you know report generation that's going to be a report intelligible to patients so not necessarily an advanced radiology term but you take say the report generated by the radiologist and say okay well let's translate that into something that a patient who hasn't really finished high school could understand and so AI has a role in this so every single point in imaging pipeline including interpretation of images and stuff like that and it's being used quite a bit and there's many areas where it's making a difference like for example at our institution we have AI software that runs on a scanner so that if a patient gets a scan an MRI of the head to try to determine whether the patient just had a stroke usually in the old days you know you do the exam the MRI exam takes you know maybe like half an hour or whatever and after that the images get sent to the radiologist radiologists reads a bunch of images of which like thousands of images images oh yeah there's a stroke now these days there's AI software running on the scanner and then as images are acquired one after the other the AI software analyzes the images live you know as they are acquired and as soon as the AI software is able to see that yep there is evidence of a stroke in that patient and it immediately triggers an alarm so that the stroke team gets alerted and says well he lives this bring make sure that we have like you know trouble attacks and the anti-correlation ready so that even before the patient finishes the scan everything is ready so that you know they can get him out of the scanner now that we know that there is a stroke and you don't need to you know completely entire exam and just deal with it and treat the patient so that helps a lot it's AI can speed things up considerably and in cases where it really matters say for example strokes or identification of you know bleed somewhere in the body after an accident AI is going to be very very useful there because it's going to have the speed and we'll be able to handle many patients at the same time or as a radiologist and do one at a time and next time and from a less optimistic perspective anything about AI and healthcare that worries you whether it comes to you know the cyber security or the use of AI by cyber attackers or what what most worries about AI in healthcare if it's not properly vetted or used by you know the adversaries for instance well there's many issues related to AI I think of course there's a bunch of security issues and like we'll go on into that but that's I think one thing that's really important to consider is you know trying to determine when AI will be truly ready to be used to kind of like you know replace or really help the radiologist from a diagnostic point of view and recommendation point of view and right now we're not at that point here AI just really you know software out there it's not that great it picks up a few things that can pick up a pneumothorax on the chest playing film or and it's good for strokes but it's it lacks depth so it's really really good at recognizing pattern and say oh yeah that looks like a pneumothorax you know and then you let's trigger an alarm saying write a patient as a pneumothorax but we need more development but not not more of the way that things are being developed right now like if you look at large language models okay these are very very very powerful system and they can produce fantastic results and they're gonna be used more and more in healthcare but the problem is that these systems are just a compilation of you know hundreds of terabytes of internet data that's kind of regurgitated into something that's more palatable but there's no like real brain power there it's just like a summary that's presented in a way that kind of might address a specific problem without thinking too much about that so it's gonna be a point where AI is gonna seem good enough to be able to diagnose stuff by itself but we need to make sure that it really is good enough by having a couple of safeguards in the system such as one that's very important is explainability and there's a lot of work going on that is like if an AI system comes up with a diagnosis and say well you know we think this is that explain yourself why do you say that this is likely this diagnosis and the AI will system will say well yeah because of that that that that that feature but a problem is that a lot of the systems don't work like that don't think about images the way the radiologists do they just it's just simple very very fast pattern recognition it says I've seen that before in many other cases here's why and so there needs to be an entire other layer that needs to be developed to like large language models as well as many other AI aspects where it involves like you know deeper reasoning typically reasoning you know involving anatomy involving pathology involving physiology and then bring everything together so that the system can make a diagnosis that's not based on just simple recognition of pattern but on on detinking involving petro physiology and symptoms and possible things that are really possible in the context of that specification and there's going to be a point where we're going to think well is AI ready or not and we're going to have to make sure that these mechanisms are in place to prove that AI is really ready to replace doctors and that's not going to be easy because of the way this is the AI systems are designed right now they just say it's no real deep reasoning we need to develop the second layer of the reasoning but as people have started thinking about that but it's difficult but in this progress this is how the field is going forward well thank you very much and while I'm speaking to Dr. Benoit Desjardins, I'm Marianne Kobasek McGee of Information Security Media Group.
Thanks for joining us.