Transcript
Thank you. Appreciate it. So, unique opportunity, I think, to talk to someone in your role, a medical device security engineer for a hospital system. Just want to kind of get some insight into your day-to-day and some of the challenges that you face. So, let's start kind of like with, you know, overall goals for your program and how you approach your role. Yeah, absolutely. So, I am our medical device security engineer. I'm responsible for our medical device security program. There are multiple resources assigned to that program from all assets of the organization, not just clinical engineering. We've got security engineers from the standard IT space that are involved leaders. We've got the radiology department managers and supervisors who get involved in these discussions. And the whole purpose is to secure our medical devices. It's been a tricky process, mainly because medical devices have lots of restrictions. You're not allowed to really install your own software on a lot of them. And all of these, the securing of these devices are usually taken care of through patching or some type of segmentation or even some compensating controls in situations where you have to allow these devices to function on your network because of the need for the organization. So, tell me a little bit about some of the realities in healthcare around medical device security and specifically, you know, some of the risks that are involved because a lot of these devices are either newly connected or just kind of starting to, you know, be connected to the network, to the internet, and so forth for a lot of different reasons, a lot of business reasons, a lot of business reasons that benefit patient care. So maybe talk about some of the risks that are involved with connectivity and some of the hurdles that you have to deal with day-to-day. Yeah, absolutely. I believe until very recently, cybersecurity hasn't been a primary focus when it comes to the vendors who create these types of devices. They're creating them for functionality and for the purposes that our departments and users would need to use them for. But when it comes to connecting them to the network, the cybersecurity side of that tends to take a backseat. So you notice a lot of vulnerabilities on these medical devices. They're not really typically configured from the get-go at purchase to restrict communication to only the ports and protocols that are necessary in order for the device to function. They typically don't lock down any type of USB access or removable media. So all of these things lead to additional risk with these types of systems. They contain patient health information, and because of that, you have to kind of take an extra look at them when it comes to securing those types of devices. And they become an increased target for people to try and exfiltrate data that we don't want them to have. Sure. Maybe we should take a step back, and what are some of these devices that we're talking about specifically? Sure. We've got the whole gamut of devices. We've got MRIs, CTs, nuclear medicine machines. We've got ultrasounds, patient health monitors, even down to your defibrillators are now connected to the network for maintenance purposes and tracking. So a lot of systems that you wouldn't even think need to be connected actually do have a reason to be connected and have a system they communicate with in order to ensure that they're functioning properly and that they're not going to cause harm. And are you ever allowed to push back on the connectivity aspect? I guess what I'm asking is, you understand the risks. How often are you communicating that to decision makers and saying, hey, maybe we should do a further risk assessment or really understand why we're connecting a device, for example? Absolutely. I think part of any good medical device security program starts with a good risk assessment of your devices. So typically, I would assess a device as it's coming in the door. We also have a rolling process to assess devices that we already have that may have not undergone an assessment previously. And based on the results of those assessments, we bring those risks to the leaders who are looking to purchase or use those types of devices. There have been instances where we've found devices too risky to allow them to connect to our network or even to purchase. Those are a little few and far between, but normally we will communicate with our staff the risks. And a decision is made at an executive level whether or not those risks would be accepted or if they're just too strong and we don't want to take on that kind of risk with the device. So, absolutely. And do you see commonalities in some of the risks, whether it's a configuration issue or the underlying platform, if there are vulnerabilities, I mean, can you talk a little bit about that? Absolutely. There are definitely some common factors with medical device risk. One of them is most organizations that sell medical devices want to use their own remote access utilities to support their equipment. They have additional features built into their remote access utilities, typically like telemetry and data collection, mainly around how the device is functioning and if they need to take proactive measures to resolve an issue with functionality. So it's always a challenge to try and get these vendors to use your approved remote access systems. There's been a lot of cases where that just simply can't happen. There have been other cases where we have been told they will use our remote access system, but they'd like their additional data collection technologies that they use for their remote access system to remain in place outside of the remote access process. And do you always have visibility into whatever their remote access tool is? There are certain levels of protection on different devices. Some just aren't very secure off the shelf. And that's part of my assessment for risk is we actually determine what remote access tools these vendors are using. And we ask as part of that assessment whether or not they're willing to use our remote access tool if they've got their own or if they're not even using one. If they need remote access, we tend to push them towards our tool. So in terms of communicating with business leaders, how well-versed are they in the risks? Do you have to kind of tune your messaging to kind of their language, so to speak? There's always a need to stay out of the weeds when you're talking to the users of the appliance. The people looking to purchase these devices, you've got to adjust your language. Make it so that people who aren't familiar with cybersecurity can understand what you're trying to say and the actual concern that you're trying to get across. It is a challenge. A lot of these people have no experience in cybersecurity. So playing a little bit of a translator role is very important. And do you talk in terms of patient care or patient safety when it comes to those interactions? Absolutely. That's usually the driving factor when it comes to risk patient care, patient safety, protecting the patient's information, and ensuring that what we do as an organization isn't going to harm the patient, whether it's physically or with their data footprint. So I'd like to hear more about patching of medical devices from your perspective and your experience. Let's say a critical vulnerability in a patient monitor comes across your desk tomorrow. What happens? I mean, patching isn't entirely in your hands. There's a lot of outside federal approval that has to happen. Just give me a little insight into kind of what happens from your perspective. Yeah, absolutely. If a critical vulnerability was to come across my desk tomorrow, depending on the risk, we would mobilize our clinical engineering team and put in place some kind of action for them to patch or remediate the vulnerability. Depending on the size of the fleet of those devices, that may take some time. They are a limited team with a limited number of resources, and sometimes they might have to touch each and every device themselves. If it's a vendor-managed system where the vendor's doing the maintenance, we would contact the vendor right away, try and schedule a site visit to have them patch the system. And a lot of times, even beyond just patching, these medical devices can have critical vulnerabilities that the device manufacturer just has not approved the patch to resolve yet. So you then have to look into additional compensating controls, micro-segmentation being one of them, securing a device if the vulnerability is related to physical access, securing a device in a secured area behind lock and key or security guards, those types of things. So you've mentioned micro-segmentation a couple of times. Can you share, I assume it's been somewhat successful for you, how you got there? What are some of the challenges? How do you avoid them? So micro-segmentation, with medical devices and the rate of adoption of patches for the manufacturers and the fact that there's vulnerabilities coming out every week, a lot of the times you're chasing your tail trying to patch these vulnerabilities on devices. You'll patch a handful of them and then the next week that number jumps up again. So I believe micro-segmentation is one of the best ways to secure a medical device. You're not always going to be able to patch everything. And limiting what those devices are able to communicate with really goes a long way to securing those types of devices. And so just as kind of a closing thought, what advice do you have for other folks in a similar role that you have in terms of successes and roadblocks and just kind of like maybe a few foundational things that need to be in place to succeed? You've really got to get the right team together. You've got to make sure everybody's on board with securing these devices because if you don't have the right buy-in, then you can find vulnerabilities all day and it might not be important enough to the organization to get them patched. So being a little bit of the squeaky wheel when it comes to this goes a long way, especially when you find technologies like micro-segmentation that are going to help you the most. That is a big lift for an organization and it can sometimes take a long time to convince them that it's even necessary. So you really just got to stay on top of it, explain how important the process of securing these types of devices is, and hopefully eventually you get some buy-in from your organization and they start getting a program together that works for you and your team. All right, great stuff. Thank you, Adam. Thank you.