Site icon Check Point Blog

What Makes IoT Security in Hospitals Different

By Mor Ahuvia, Product Marketing Manager, Security Platforms

Join the webinar: Preventing Attacks on IoT Devices and Networks

Register: AMER | EMEA

When it comes to securing their internet of things (IoT) devices, hospitals struggle with unique challenges. For some healthcare facilities, these challenges have been exasperated with the Covid-19 pandemic due to increased workload and pressure.

What’s at stake? Hint: It’s more than ePHI

Only recently, the DHS Cybersecurity and Infrastructure Security Agency (CISA) issued medical advisories about 21 vulnerabilities in popular medical devices. Most issues have to do with the confidentiality of electronic protected health information (ePHI).

That in itself is a huge issue for victims of medical identity, as well as hospitals required to foot the bill in the breach aftermath, with healthcare organizations facing the highest costs, averaging $6.45 million per incident, or 65 percent higher than the industry average.

But it doesn’t stop at ePHI and remediation costs. One of the vulnerabilities reported by DHS CISA “could allow an attacker to change treatment status information,” and by inference, the course of treatment itself.

What about manipulating dosages administered to patients? Cyber security researchers at CyberMDX have demonstrated that exploiting vulnerabilities in certain devices that provide “mounting, power, and communication support to infusion pumps” could “allow a malicious attacker to completely disable the device, install malware, or report false information. In extreme cases, the attacker could even communicate directly with pumps connected to the gateway to alter drug dosages and infusion rates.”

Why Hospitals are IoT Security Unicorns

So what makes IoT security in hospitals different? Below are salient traits and considerations.

Hardening Hospital Devices and Networks

The good news is that hospitals and healthcare manufacturers can both take preventive measures to minimize their security risk exposure.

At the network level hospitals can:

At the device level, medical device manufacturers can:

Jumpstart your Healthcare IoT Security

Don’t leave your IoT Security to chance. Join Check Point and our partners Medigate for a webinar on 20th July, to learn the healthcare IoT security basics and start your journey to a safer hospital and better-secured patients. You can also read about the joint solution here.

Exit mobile version