Cybersecurity vulnerabilities in medical devices: a complex environment and multifaceted problem

被引:122
作者
Williams, Patricia A. H. [1 ]
Woodward, Andrew J. [1 ]
机构
[1] Edith Cowan Univ, Secur Res Inst, Ehealth Res Grp, Perth, WA, Australia
关键词
cybersecurity; security; safety; wireless; risk; medical devices;
D O I
10.2147/MDER.S50048
中图分类号
R318 [生物医学工程];
学科分类号
0831 ;
摘要
The increased connectivity to existing computer networks has exposed medical devices to cybersecurity vulnerabilities from which they were previously shielded. For the prevention of cybersecurity incidents, it is important to recognize the complexity of the operational environment as well as to catalog the technical vulnerabilities. Cybersecurity protection is not just a technical issue; it is a richer and more intricate problem to solve. A review of the factors that contribute to such a potentially insecure environment, together with the identification of the vulnerabilities, is important for understanding why these vulnerabilities persist and what the solution space should look like. This multifaceted problem must be viewed from a systemic perspective if adequate protection is to be put in place and patient safety concerns addressed. This requires technical controls, governance, resilience measures, consolidated reporting, context expertise, regulation, and standards. It is evident that a coordinated, proactive approach to address this complex challenge is essential. In the interim, patient safety is under threat.
引用
收藏
页码:305 / 315
页数:11
相关论文
共 40 条
[1]  
[Anonymous], 2013, HLTHCARE IT NEWS
[2]  
Archimedes Ann Arbor Research Center For Medical Device Security, 2015, IMPR MED DEV SEC
[3]  
Burleson W, 2012, P 49 ANN DES AUT C 2
[4]  
Clark S. S., 2011, INT ICST C WIR MOB C
[5]  
CNET, 2009, CNET
[6]  
Coles-Kemp L, 2014, ELECTRON J HEALTH IN, V8
[7]  
Craigen D, 2014, TECHNOL INNOV MANAG, P13
[8]   Medical Devices - Balancing Regulation and Innovation [J].
Curfman, Gregory D. ;
Redberg, Rita F. .
NEW ENGLAND JOURNAL OF MEDICINE, 2011, 365 (11) :975-977
[9]   Thinking about Cybersecurity [J].
Dark, Melissa .
IEEE SECURITY & PRIVACY, 2015, 13 (01) :61-65
[10]  
Deloitte Center for Health Solutions, 2013, NETW MED DEV CYB SEC, P16