Medical devices, whether an insulin pump inside a diabetic's body or a diagnostic scanner in a hospital, come seeded with cybersecurity vulnerabilities that are becoming more widely known every day.
Some flaws cough patient health information or allow a hacker to spy on a hospital network. In April, hackers tried to crash the Boston Children's Hospital computer system, and last week the Homeland Security Department disclosed a serious security glitch in a machine that safeguards dangerous drugs in hospitals.
Hackers may even attack a patient by switching off an implanted device or causing it to dump a payload of drugs into a patient. "To most people this sounds like fantasy, but we know that this threat is real," Jason Lay, manager of cyberthreat information at the U.S. Health and Human Services Department, said at a public workshop Tuesday in Arlington, Va.
Some of these "cybervulnerabilities" have been known for years, but progress to fix them has been sluggish and uneven. On Tuesday, officials with the Food and Drug Administration aimed to jump-start the conversation by kicking off a two-day gathering of experts from hospitals, devicemakers and computer-security firms for the first national workshop on improving cybersecurity in medical devices.
"I think everyone has a role to play, but frankly, everyone needs to step up. That's what we're not seeing so far," Kevin McDonald, clinical information security director at the Mayo Clinic, said Tuesday at the workshop.
Mayo, it turns out, is among a handful of hospital systems nationally that have staked out aggressive stands on device security.
Last year the Rochester-based provider quietly hosted its own internal "hackathon," in which system employees and outside experts were asked to put about 40 medical devices through the paces and uncover vulnerabilities. New flaws were found, which in some cases led to "deeper dives" with manufacturers to fix the problems. "For the most part, the vendors have been receptive to working with us," said another Mayo employee, chief security analyst Debra Bruemmer, in a panel discussion at the workshop.
The hospital system also starts detailed discussions about cybersecurity with device companies during early purchase-agreement negotiations, which may help aid hospitals nationally by raising the profile of the issue among devicemakers, Bruemmer said.