Secondary Market Medical Device Security Risks episode artwork

EPISODE · Aug 10, 2023

Secondary Market Medical Device Security Risks

from Info Risk Today Podcast · host InfoRiskToday.com

Legacy infusion pumps commonly available for purchase on the secondary market often contain wireless authentication and other sensitive data that the original medical organization owners failed to purge, warned researcher Deral Heiland, citing a recent study conducted by security firm Rapid7.

Episode metadata supplied by the publisher feed · Published Aug 10, 2023

Embed this episode

NOW PLAYING

Secondary Market Medical Device Security Risks

0:00 0:00
of MATCHES

TRANSCRIPT · AUTO-GENERATED

I'm Marianne Kolbesak-McGee, Executive Editor at Information Security Media Group. Today I'm speaking with Daryl Highland, who is Principal Security Researcher for IoT at security firm Rapid7. We're going to be discussing a recent research report that Daryl and his team put together involving legacy infusion pumps that are still used in healthcare sector settings. So Daryl, I understand that you examined infusion pump models that are no longer being manufactured, but they are believed to be in use at many medical institutions globally.

Please describe briefly what you looked at, and what did you find? So about two years ago, I decided I was going to spin up a research project that kind of focused on medical-based technology. So I reached out to some contacts, and they'd recommended maybe taking another look at infusion pumps. So I started looking at them, and I think later last year, we published some vulnerabilities we found on the Baxter.

But during this whole process, I noticed that the devices that I was purchasing on secondary market actually were containing configuration data from their previous environment they were in. So that's where the whole project spun up. Is this a bigger systemic issue? What's the potential impact to hospitals and organizations that are using these devices and decommission them without cleaning them properly?

So Daryl, with that said, what were the most concerning findings when you started digging around in these infusion pumps? And why were those findings concerning? What sorts of either patient safety and or data security risks do these issues pose? I think the biggest issue that this proposes is if an organization decommissions the device, and it goes off into the big black hole secondary market for people to purchase, and somebody that would be nefarious would decide to purchase these devices, and they could gain access to, let's say, the Wi-Fi credentials or Active Directory credentials or whatever is actually stored on this.

That in itself gives them potential data that could be used to breach an organization. And not only just breach an organization, but the networks that these typically tie into are the health medical networks. These are the networks where critical care patients are located and other medical technology is located. So if those organizations or those networks become breached, it becomes a potential issue of safety, health, and concern.

So Daryl, in terms of the average age of the infusion pumps that you examined, how old were these devices? And any estimates on how many of these devices could still be in use today for patient care? I think the devices I looked at were manufactured anywhere from 10 to 15 years ago. In a number of those cases, the devices were manufactured for a long period of time, and they were just updated and upgraded to new software versions and things like that, which kind of typically takes place for easy decade before organizations or vendors will actually start manufacturing new technology.

With that said, a lot of the hospitals, similar to the old T-Scada thing, they want to get their money's worth. When they buy these things, they buy thousands of them in some cases, and they'll keep them in place for 10, 15 years. Other organizations that may not have the resources, smaller hospital chains, things like that, may actually keep them longer, or they may actually buy these things. So you could buy these things on secondary market and refurbish them.

So you could go through and often these organizations have their own teams that do maintenance, support, and certifications of their actual devices. So these things can be bought for spare parts or to be completely refurbished and reused within an organization. So they can have a long, very long shelf life. And I think recently, I actually was in an organization or a hospital location where I actually saw these things that I've looked at still in use.

So it's not uncommon for these to have a very long life. How many are out there? I really can't answer that. That would be kind of the question to go talk to like manufacturers and go, hey, how many of these devices did you ever produce?

And then try to estimate from there. So you mentioned that the devices had configuration data on them. Were there any sorts of like vulnerabilities that you store on these products that maybe were, you know, known but not patched? And if they did, again, if they're on the secondary market, they're purchased and they're used again, does that pose potential issues?

And who would buy these sort of used devices? Yeah, when it comes to that, obviously, if you're purchasing things on secondary market, you may not be updating or patching these devices that you're using. So if you go out to any of the vendors that we talk about and look at vulnerabilities that have been published over the last, you know, eight, nine, 10 years on these devices, and it's a number of them, you could actually come to the conclusion that if you're not patching and upgrade devices you bought off secondary market, there is a high probability that you're actually installing not only the devices that are containing potential vulnerabilities and may be exploitable. I know we worked with Baxter last year and disclosed like four vulnerabilities on those devices.

So if you purchase these devices on secondary market and didn't update them or patch them to the latest software that Baxter's released to fix these issues, then you have vulnerable devices on your network. So with the devices that you examined for this particular study, Baxter devices, were there a mix from other vendors? Any particular popular models that were looked at? I decided to look at three of the popular models.

I was looking at the Elleris Series pumps, the PC8015 model pumps. I looked at the Baxter Sigma Spectrum, and I also looked at the Hospira Plum devices as examples. And those are all easily available on secondary market. And again, in terms of the secondary market, you know, who tends to buy there?

Are they, is it mostly then the researchers who are kind of examining the equipment? Or are they, you know, maybe smaller clinics that have these sorts of devices in their environments now? One breaks down, they want to replace it, or they need parts, or, you know, who buys these? What I'm thinking of is typically probably not researchers.

I mean, it's a good source for researchers. It's where I went out there and I expect a number of my research counterparts in the community that want to look at medical devices are going to go to secondary market and try to buy the latest versions they can get that are used and cheap. But what I see is these devices will probably be in resold for spare parts and for smaller clinics or organizations, or even large organizations that still have them in use. Because, you know, with a good trained staff, these can easily be refurbished and recertified to be safe to be used.

So Daryl, with that said, what is your advice to healthcare sector entities that either have these legacy infusion pumps still in use for patient care, or they purchased them because they need parts, they need replacements? Aside from replacing these pumps with newer devices, what steps should these organizations be taking to better address the sort of issues that you found? With the issues I found, I'm kind of like bringing this forward as a cradle to grave issue. Organizations, and not just these pumps, but all embedded medical technology.

Because I assure you, I found it on these three devices. I'd expect that this is way wider spread across all embedded technologies that can integrate into the network. And the whole cradle to grave thing is, is an organization needs to plan ahead. When we go to purchase any kind of technology, we need to figure out how we're going to maintain its security, how we're going to patch it.

And at the end of life, how are we going to remove our data before we decommission it? And also in that cradle to grave thing, hey, if we're just leasing these devices, how do we set up contractual agreements as the technology is coming in so we can solve these problems as it's going out the door also? And that's kind of the big story, I think, is, and as part of this research project, I did have a chance to talk to several medical organizations specifically on this topic. And typically, this is not necessarily on the radar screen.

They buy these devices, they use them. And at the end of life, they're out the door they go. And often they have no idea what may be happened to these devices, especially the leased devices. So having that cradle to grave solution processes and policies in place, I think it's critical for an organization to protect itself.

And finally, Daryl, I know you examined infusion pumps for this particular study. What other legacy medical devices commonly found in healthcare settings are most concerning to you in terms of security risk and that sort of legacy factor that we were just discussing? What other kinds of devices should be getting more attention? Typically, I think of this as an embedded device issue, because if we step back a few years, you remember all the stories about hard drives.

Companies were selling equipment that had hard drives. People were buying them off the internet, pulling all this data out of there. We're in a different age now. These devices don't necessarily have hard drives, but they have flash memory chips.

And these flash memory chips are no different than a hard drive. They're just really small and they're on those boards that can easily pull this data. So being able to take care of that issue and not deal with these devices to solve that problem, we need to think about all medical devices. Often I think of everything from health monitoring systems that want to keep heart rates and all that type of stuff.

Often these things connect to the network. So they send data to the back-end management systems. We may look at the devices that are breathing, you know, that we just went through with COVID. All of these types of devices may actually be tied to the network and contain data and integrate into those networks.

So it's any technology that integrates into the environment that could contain access creds, active directory creds, Wi-Fi credentials, or patient information or

No similar episodes found.

No similar podcasts found.

Frequently Asked Questions

When was this Info Risk Today Podcast episode published?

This episode was published on August 10, 2023.

Can I download this Info Risk Today Podcast episode?

Yes. Use the download control on the episode player to save the publisher-provided media file.
URL copied to clipboard!