中文

Four steps to reduce cybersecurity threats from legacy medical devices

The U.S. FDA implemented new regulations last year to strengthen cybersecurity oversight of medical devices, but legacy devices remain a challenge. Experts recommend that hospitals reduce risks through four steps: identifying devices, understanding vulnerabilities, network segmentation, and shutting down devices when necessary.

2024-09-235views
Four steps to reduce cybersecurity threats from legacy medical devices

The U.S. Food and Drug Administration (FDA) implemented a comprehensive set of new regulations last year to strengthen cybersecurity oversight of medical devices, as cyber attackers continue to target hospitals. However, regulators and cybersecurity experts are still working to address a specific threat: legacy medical devices.

Hospitals and health systems across the country are filled with medical technology running outdated or soon-to-be-outdated software, leaving gaps in institutions' cyber defenses. Although devices are rarely the direct target of cyber attacks, unsupported legacy medical devices can still be affected by attacks on hospital networks, potentially forcing critical equipment to shut down and endangering patient safety.

"There is always a constant tension between securing devices, preserving the economics of older equipment, and prioritizing patients who urgently need network-connected devices," said John Riggi, national advisor for cybersecurity and risk at the American Hospital Association.

In 2023, the FDA's Center for Devices and Radiological Health (CDRH) implemented new regulations and guidance aimed at minimizing cybersecurity risks in medical devices. The new rules prioritize stricter cybersecurity requirements before devices hit the market, as well as more comprehensive monitoring standards after product release. Experts praised these regulations for ushering in a new era where cybersecurity finally receives the attention it deserves.

One key initiative is ensuring that devices entering hospitals do not quickly become obsolete, and requiring manufacturers to develop specific plans for monitoring, updating, or patching older software.

However, solutions remain elusive for the vast number of devices currently in hospitals running outdated and unsupported software. Nastassia Tamari, director of the CDRH's medical device cybersecurity division, told MedTech Dive in March that no one knows how many legacy devices are in hospitals due to a lack of reliable data. Tamari explained that legacy devices are currently one of the biggest problems facing the industry, and "there is no answer yet."

Some legacy devices are critical to patient care, so hospitals cannot simply shut them down as a security measure. At the same time, some unsupported devices are expensive, and hospitals cannot simply purchase new machines after software becomes outdated.

"This is a big problem," said Ty Greenhalgh, healthcare lead at cybersecurity company Medigate by Claroty. "It's so complex... understanding the problem itself is difficult, let alone the solution."

MedTech Dive spoke with cybersecurity experts about how medical device manufacturers and hospitals can reduce the risks posed by legacy devices. Here are the four steps they recommended:

1. Identify devices

Cybersecurity experts say the first step in addressing the legacy device problem is for hospitals to identify how many devices are connected to their networks. This can be complex due to the sheer number of potential connected devices.

"A large number of systems connected to hospital networks today are largely unmanaged, or even if managed, they are quasi-managed by facilities or third parties," said Richard Staynings, chief security strategist at computer and cybersecurity company Cylera. "The first thing we need to do—and this is something the healthcare industry is doing very poorly right now—is to understand what is connected to our networks."

While the first step may seem simple, it can be burdensome for individual vendors, regulators, and device manufacturers. Claroty's Greenhalgh said identifying connected devices, including legacy machines, is "almost impossible." Hospitals may have hundreds of thousands of devices connected to their networks, ranging from medical devices to IT systems, phones, and laptops. Greenhalgh explained that even after discovering a specific machine is connected to the network, identifying it can be complex because devices like imaging machines may appear as "Windows devices" rather than medical devices.

"The problem is not as clear-cut as people would like," Greenhalgh added. "But we are making progress."

Once devices are identified, the hospital's network needs continuous monitoring to detect new devices, threats, and determine whether patching or updates are needed.

2. Understand vulnerabilities

The next step is understanding the risks that network-connected devices may pose. Some machines may need patch updates, or immediate updates when operating systems are no longer supported, while others may already be outdated with no patches available.

Understanding where vulnerabilities lie is crucial so facilities can prepare for emergencies, especially for medical devices used to treat or diagnose patients. Ransomware or other forms of cyber attacks can spread laterally through hospital systems, disabling medical equipment such as CT scanners and MRI machines, as well as other functions that rely on the facility's network.

"Some legacy technology lacks basic security features such as data encryption and transmission encryption. Some don't even have passwords, or use hardcoded passwords that you can find in technical manuals on the internet," said Riggi of the AHA, who served in cybersecurity roles at the FBI for over five years. "These devices still work as designed. They were designed to be durable... It's the operating systems and software that are outdated or full of vulnerabilities."

Software bills of materials (SBOMs) are one tool that medical device manufacturers can use to help vendors understand what updates or patches a device may need, enabling them to better understand potential vulnerabilities. An SBOM is a list of all the software components that make up a device.

Detailed SBOMs provided by device companies can also help hospitals identify machines connected to their networks and patch or update them when needed, said Anura Fernando, chief security advisor and global head of medical device security at UL Solutions. Fernando added that SBOMs can trigger conversations between device manufacturers and hospitals about whether machines are vulnerable and what controls are in place to manage those risks.

"Some legacy technology lacks basic security features such as data encryption and transmission encryption. Some don't even have passwords, or use hardcoded passwords that you can find in technical manuals on the internet."
— John Riggi, national advisor for cybersecurity and risk at the American Hospital Association

Under regulations implemented last year, the FDA now requires manufacturers to provide SBOMs for devices. While some have praised this as an improvement over previous standards, experts emphasize that manufacturers still need to ensure devices are as secure as possible before selling them and should not use patching as a development crutch.

"Once you understand how they work, you can start locking down these devices in ways that allow for improved cybersecurity," said Cylera's Staynings. "Let's assume we can never patch legacy devices—some can, some can't—but assume the worst case so we can protect patient safety as well as the integrity and security of healthcare networks."

3. Use network segmentation

After identifying legacy devices and understanding potential risks, some devices may pose enough of a threat that they need to be isolated on their own network, a process called network segmentation. This step is a security measure that prevents cyber threats on the network from reaching vulnerable devices, or prevents threats from spreading if a device is compromised.

Network segmentation is a critical strategy because cyber attacks can spread rapidly, leaving no time to protect machines during or after an attack.

"Malware can spread laterally through the network, and before you know it, the entire hospital is paralyzed," Staynings said. "Ambulances are diverted, patients are transferred by medical helicopters to other nearby facilities, and the cost of recovery and rebuilding quickly reaches millions of dollars."

Segmentation does not always mean the machine is completely shut down. Greenhalgh explained that segmented machines can still connect to other machines that are part of the system. For example, an imaging workstation needs to communicate with three or four other machines to function, and these can be segmented in a way that allows them to communicate with "clinically relevant" devices. Administrators can then continue to monitor the machine's behavior, communicate with the medical device company, and take action when needed.

Vulnerable legacy devices can also be "air-gapped," completely disconnected from the network. UL Solutions' Fernando said air-gapping allows software to continue running and can extend a machine's lifespan beyond its support period. Fernando noted that air-gapped devices can still be compromised through USB connections and storage sticks, but "if you implement strong access controls and physical security policies for air-gapped devices, then you should be able to avoid" many pitfalls.

"There is always a constant tension between securing devices, preserving the economics of older equipment, and prioritizing patients who urgently need network-connected devices."
— John Riggi, national advisor for cybersecurity and risk at the American Hospital Association

4. Disconnect devices

Finally, if a device poses too much risk even after segmentation, or has been compromised by a cyber attack, hospitals can disconnect it completely from the network and internet. However, this is not always an easy decision. Deciding to disconnect a medical device requires weighing the threat's risk against its necessity for patient care, and replacing the device is costly.

AHA's Riggi called disconnecting devices the "last resort." If a machine must be disconnected, hospitals need contingency plans, which may include transferring patients to other facilities. They must also communicate with medical device manufacturers to implement controls.

"We need to focus on how to care for patients for 30 days or more without technology, because that's the average time we see ransomware victims—hospitals—take to at least recover their core systems," Riggi added.

No matter how well risks are managed, or how new regulations address the problem, outdated and unsupported machines will always challenge the market because software ages and technology continues to advance. Complicating the issue is the involvement of multiple parties. Device companies develop and manufacture products, hospitals monitor devices and are responsible for connected networks, and various regulatory agencies oversee different aspects of the healthcare industry—all of which need to work together to defend against cyber attacks.

Experts believe that despite new regulations, efforts are still needed to address current challenges, especially strategies for legacy machines currently in hospitals. Riggi said stricter regulation would help, but "it may take a generation to retire all the old legacy technology."