The Challenges in Keeping Medical Device Software Updated episode artwork

EPISODE · May 6, 2024

The Challenges in Keeping Medical Device Software Updated

from Info Risk Today Podcast · host InfoRiskToday.com

Updating software as new vulnerabilities are discovered persistently remains a top medical device cybersecurity challenge, said David Brumley, a cybersecurity professor at Carnegie Mellon University and CEO of security firm ForAllSecure. Solving this requires a major mindset shift, he said.

Episode metadata supplied by the publisher feed · Published May 6, 2024

Embed this episode

NOW PLAYING

The Challenges in Keeping Medical Device Software Updated

0:00 0:00
of MATCHES

TRANSCRIPT · AUTO-GENERATED

I'm Mary Ann Coba, Executive Editor at Information Security Media Group, today I'm speaking with David Brumley, who is Cybersecurity Professor at Carnegie Mellon and CEO of software security firm for all secure. We're going to be discussing cyber security issues involving medical devices. So David, as you speak to device makers and sort of survey the medical device landscape, what is your sense of the challenges that medical device makers are having in terms of including in their product submissions to the FDA, the kinds of cyber details that the FDA now expects? What do you think is giving device makers most difficulties?

The FDA really recently increased the scrutiny for cyber security, which is an absolutely good thing. And it's really started, you know, late last year in July where they had some draft guidance that came out and was ratified this year. So I think what device manufacturers struggle with is wrapping their heads around this. Medical device manufacturers have increased the amount of wireless, Bluetooth, and internet connectivity for their devices.

We know that those are attack vectors, but typically they've looked at this as only a safety issue as opposed to a cyber security issue, and that's sometimes surprising to people who aren't familiar with regulations that there's a difference. But the manufacturers traditionally have looked at quality assurance for safety purposes, but that didn't mean they couldn't be hacked. And so now they're trying to figure out how do they adapt those same safety protocols to make the devices more secure against offensive cyber security attacks. So David, overall, what sorts of issues do you see as most concerning when it comes to cyber security shortcomings in medical device products that are on the market today that you hope will be addressed as new products are reviewed by the FDA during the pre-market submission process?

The biggest thing that I think that we get hope for is increasing the cadence of updates. The legacy traditional approach, and this is only a few years ago, was when you built a medical device, you got it certified and it kind of stayed that way forever. And of course, we all have software updates for our phones or computers. We know that's not really how things work anymore.

And so that's what I see as kind of the biggest challenge of their focusing is how can we get those updates to devices as new vulnerabilities are detected, as we find new issues in our software, while still maintaining that same high quality of care. So when it comes to the software updates, what are the challenges? Is it a matter of sort of the logistical challenges that entities don't want to pull medical devices off line because they're needed by patients and when do we update software? What kinds of challenges do you see?

I think the biggest one right now is regulatory and what is going to be enough to make sure that they're abiding by regulations and that they can get these devices with patients. So if you think about it, we've all had software updates that are broken our computers. They obviously can't have that. It's not so much timing.

It's that making sure that hey, they tested it and lab it works fine. But then when it goes out into the real world, something breaks and being able to come up with a cycle that make sure that doesn't happen. Give me advice for medical device makers when it comes to the software updates and in terms of early on in the development lifecycle that for seeing that if we need to do updates, we can make it as easy as possible. Or is that really something so that it's hard to predict because you never know what vulnerabilities might be later discovered?

Everyone wrestles with the problem that you don't know what vulnerabilities are going to be later discovered. What the big shift is, is to think about how rapidly we can get those updates out. Because again, it's this legacy approach. The idea traditionally from these manufacturers and the entire mindset, the entire culture that's built into the companies making these is our devices are safe.

And safety is very much like it's going to work even if the person is hit by lightning, like the battery is not going to explode, things like that. Cybersecurity is another ball game entirely. The challenge is that immediately when you start saying, hey, your devices may be at risk, they're going to say, no, no, they're safe. And there's this entire culture shift to get people, the entire teams, thinking in terms of cyber security isn't a one and done thing.

You can't predict all the different things that are going to happen. What we can predict is the need to rapidly iterate and to get those out to customers. So it's a culture shift, especially around regulation. And the reason I keep focusing on regulation is that sets the bar about what's going to be put into patience, right?

Like if you don't get regulatory approval, it's just not going to go out. Are there certain categories of medical devices you find most concerning when it comes to this cybersecurity risk? Anything that has over the air updates or connectivity is a big one. We're seeing this a lot in diagnostics.

And this is by the way, Mary, I'm kind of personal to me. I'm a cancer survivor. And so I've gone through surgery, radiation, and far too many doctors appointments with connected devices. If you've ever had one of these scans, you know that you're in a big machine and that machine is connected to a technician who can view the scan.

All that information, of course, gets thrown over the internet or through the medical to the hospital's network so the doctor can pull it up on their system. Software texts can remotely log in. All these devices are increasingly connected. Just to get information out there and to make it so people can consume information in the right way, but it also greatly expands the attack surface.

And we've seen cases where bad guys break into medical devices and they didn't even know it was a medical device. It just happened to be vulnerable. And they were on it because they used an off-the-shelf exploit to get there. Now, when it comes to the challenges involved in securing some of the AI and machine learning enabled devices that are being developed or already in use, what are some of the challenges?

Are the challenges any different than the more traditional sorts of devices in use that don't necessarily rely on AI or machine learning? I don't know that there's a huge difference in security. I mean, one of the cool things about AI is it's repeatedly shown to offer high-quality diagnostic information to people. And so I have the most trust for it there.

Being able to review medical records and attack cancers that might have been missed from a radiologist. Things like that. It's really good. I think one of the challenges that we face more is on the privacy end of these.

How do we train these models in a way that we provide high accuracy without also making patient information? This is also attention with the concept that we know that more personalized healthcare is more effective, but the more personalized that also means that you need more personal information. And so how do you weigh all these pros and cons? It's less of a cybersecurity, more of a privacy, conundrum there, I think.

So David, you mentioned that you use the medical imaging or the big devices that patients go into to get scanned and for tests, and then that data is then shared with doctors, and the technician can see it, and so on and so forth. But we also hear a lot about remote monitoring patients at home being monitored either by full-fledged medical devices, but maybe they're also wearables that they're not necessarily under the FDA's regulatory umbrella. What sorts of issues do you see now in potentially emerging when it comes to cybersecurity and remote monitoring, whether it's, again, a full-fledged sort of FDA approved device versus a more consumable wearable, what are some of the issues? I think there's obviously the issue about increased connectivity, where when people go home, that also means the hospital has to be able to reach in to gather that diagnostic data.

And of course, you're going to open it up to the manufacturers getting more data. So beyond cybersecurity, there's also increased privacy concerns. This is a huge area. We also run into an issue where most of the cybersecurity standards really focus on things that are used for direct patient diagnostic and critical life safety issues.

The more wearables you get in, you kind of get into this gray zone of it's not necessarily diagnostic in itself, and so you're going to use more off-the-shelf software potentially as a lower security bar, but that in turn can make it easier to break into. So you have this tension. I think the stuff that we absolutely need to work because it's life critical, people do a lot of work on. But what we're seeing is this increase of non-life critical stuff that just improves health care, and that's just held to a lower bar.

So, David, you had said earlier about FDA's concern is, you know, it's number one concern is patient safety. But as we know, a cyber incident involving a medical device not only presents possible patient safety issues, but it could also bring compromises into the hospital's network, data compromises, that sort of thing. How do you weigh that in terms of, you know, if you were security, are you already taking care of the patient safety concerns, or are there like two sets of issues when it comes to cybersecurity, patient harm versus data compromise or disruption? How does this all play out?

Well, no doubt we have to put patient safety first. You have to make sure those medical devices aren't creating risk for the patient because they're getting treatment for something. Data compromise is something that we have a number of methods to deal with. First, we don't want it to happen, right?

It's always bad when it happens. But what we're seeing is a rise of things like ransomware, and you can often pay these people off. Like no one is going to die because of ransom. You do end up in a negative feedback cycle where if a hospital pays off a ransomware attack, well, where they're going to get that money from, of course, the rates are going to have to go up.

And so it does affect the cost of health care, which affects patient care. But I think if you're going to put a prioritization, you always have to focus on the person that you know that's getting like critical treatment and making sure they're safe. And when we hear so much about ransomware attacks on hospitals and often on their vendors, what is most concerning to you about keeping those medical devices either segmented or protected against whatever else might be going on in the environment that might spread to the medical devices? I mean, it's a really difficult problem.

I mean, hospitals have traditionally taken this segmentation approach. We're going to build firewalls to try to segment things. And that just hasn't traditionally worked very well. It's like trying to build a dam in New Orleans, right?

It may work temporarily, but not for very long. If you think about it, you have a huge number of people who have access to medical and patient data. And these people are all working from different workstations. And just to single slip up on one of those can cause a cybersecurity incident.

Beyond that, the very nature of health care means that we have to collaborate with between doctors, different institutions and different devices. And so you have this right ecosystem of everyone needs to share information and that information is super important to protect. And you're also dealing with the people who are sharing it aren't cybersecurity experts. And finally, David, in terms of further steps that the FDA might consider taking to help promote the development and the use of more secure medical devices, any suggestions beyond what they've been doing so far?

I do. I've caught a lot of thought into this. You know, as someone where this is again near and dear to my heart, the FDA issues guidance, which is really upper and lower bounds about what you should do. There are general policy guidelines about the sorts of activities you should be conducting, but not how you go about doing them.

And in cybersecurity, how you do things is super important, saying that you should have a documented process for tracking new cybersecurity risks and your devices is what the FDA says. I mean, anyone can come up with a process to document stuff. It could be an Excel spreadsheet, for example. The real nuts and bolts of these are what sort of techniques are you employing to check the software?

How are you doing this to make sure when you change things that doesn't break? And then how do you deliver this quickly? And so a lot of what we've been doing, both in research and practice, is trying to build up reference architectures for these sorts of things that go beyond the generic advice and say, here's a system that number of cybersecurity experts have looked at. And if you use the system, you should be safe.

Well, thank you very much, David. I've been speaking to David Bromley. I'm Mary Ann Cobissette McGee of Information Security Media Group. Thanks for joining us.

No similar episodes found.

No similar podcasts found.

Frequently Asked Questions

When was this Info Risk Today Podcast episode published?

This episode was published on May 6, 2024.

Can I download this Info Risk Today Podcast episode?

Yes. Use the download control on the episode player to save the publisher-provided media file.
URL copied to clipboard!