Cybersecurity vulnerabilities in medical devices: a complex environment and multifaceted problem

被引:122
作者
Williams, Patricia A. H. [1 ]
Woodward, Andrew J. [1 ]
机构
[1] Edith Cowan Univ, Secur Res Inst, Ehealth Res Grp, Perth, WA, Australia
关键词
cybersecurity; security; safety; wireless; risk; medical devices;
D O I
10.2147/MDER.S50048
中图分类号
R318 [生物医学工程];
学科分类号
0831 ;
摘要
The increased connectivity to existing computer networks has exposed medical devices to cybersecurity vulnerabilities from which they were previously shielded. For the prevention of cybersecurity incidents, it is important to recognize the complexity of the operational environment as well as to catalog the technical vulnerabilities. Cybersecurity protection is not just a technical issue; it is a richer and more intricate problem to solve. A review of the factors that contribute to such a potentially insecure environment, together with the identification of the vulnerabilities, is important for understanding why these vulnerabilities persist and what the solution space should look like. This multifaceted problem must be viewed from a systemic perspective if adequate protection is to be put in place and patient safety concerns addressed. This requires technical controls, governance, resilience measures, consolidated reporting, context expertise, regulation, and standards. It is evident that a coordinated, proactive approach to address this complex challenge is essential. In the interim, patient safety is under threat.
引用
收藏
页码:305 / 315
页数:11
相关论文
共 40 条
[31]  
spectrum.ieee.org, 2011, MED DEV VULN HACKS R
[32]  
spectrum.ieee.org, 2014, FEDS PROBE CYBERSECU, P1
[33]  
U.S. Food and Drug Administration, 2014, FDASIA HLTH IT REP P
[34]  
U.S. Food and Drug Administration Center for Devices and Radiological Health, 2014, CONT PREM SUBM MAN C
[35]  
United States Food & Drug Administration, 2014, IS PROD MED DEV
[36]  
US Federal Bureau of Investigation Cyber Division, 2014, HLTH CAR SYST MED DE
[37]  
US Food and Drug Administration, 2011, UND BARR MED DEV QUA
[38]  
Whitman M., 2010, MANAGEMENT INFORM SE
[39]  
Williams Patricia A H, 2008, Health Informatics J, V14, P211, DOI 10.1177/1081180X08092831
[40]  
wired.com, 2014, ITS INSANELY EASY HA