Computer Viruses Are "Rampant" on Medical Devices in Hospitals
technologyreview.com
technologyreview.com
I work in medical equipment R&D and understand criticality. I have personally used competitors systems and am freaked out by their security problems. "Want to see how to infect this system? Plug this thumb drive in. The OS is set to autorun. Or, lets just plug a keyboard in and hit CTRL-ALT-DEL open the task manager and lookie here, full access to the system as an admin user. Plug a network cord in... the C drive is fully shared all permissions. Well, at least the drive is RAIDed so that any malice that happens to this device has a failover backup. facepalm"
My devices run Windows Embedded and they are locked down hard so that no unauthorized access. You aren't getting into the bios. You aren't getting into a permanent part of the file system. You aren't getting access via the usb port unless it is exactly what we want. Something on the system changes and fails a checksum test, we will know and the system will not allow usage. Our service people are the only ones allowed to make those types changes.
There are replies on this post and the article seem to have a strong anti-Windows for the sake of being anti-Windows sentiment and shows an extreme lack of understanding on software and hardware configurations. "Herp-Derp Window$ BAD, use Linux". Windows itself is not inherently bad. I would make the same statement if someone just went with a full stock release of Ubuntu on a medical device.
Most medical devices use Windows Embedded, not a full Windows install, and developers should strip it down to the bare essentials that they need, set up the write filter protection and lock their system down tight and anyone that gives a care about their patients would overprotect above the FDA guidance.
If you want sensitive patient data you go after the servers that receive and store data from the devices, or data entry computers. Hell, most desktops in hospitals contain sensitive patient information and malware is already on all of those because people are clicking on the 'INSTALL A VIRUS SCANNER ON MY PC' banner ads and admins are too lazy to lock down desktops.
If anyone ever had the technical skill to sabotage medical device just to hurt or kill someone, it would be an extremely rare event.
The real danger comes from automated malware that trawls networks or is attached to media and overwhelms or disables medical devices by accident. Malware that's just trying to find a home for a botnet can spread like wildfire and cause all kinds of havoc and is much more likely to be on the device right now.
Alas, medical device manufacturers (like most 3rd-party vendors) design their product to the barest specifications of their customers. If the customer doesn't ask for security or a hardened OS, they aren't going to go out of their way to make it so.
With a medical device, you don't just worry about the intentionally malicious viruses that try to extort money via fake virus ads or steal record. You must make sure that the system operates as the system is supposed to operate. If in the middle of surgery, your system crashes because some virus tries to link in to a DLL load because the surgeon loaded their profile to the system with an infected usb stick, you have a problem. Imagine that you had a laser on to cut something and now it isn't getting a command to stop from the system. Guess what will happen?
It doesn't need to be an intentional sabotage, unintentional does damage quite well. If your product has security issues, you don't just lose customers, you injure people.
Many times a malware infected system can cause minor but significant annoyances like sluggishness to random reboots. Thanks to a rich malware ecosystem, these systems are almost always based on Windows. So, I don't think that the anti-Windows sentiment is unwarranted. The visitors themselves see the ominous Blue Screen of Death on screens from time to time.
Having seen that, I can't say I'm surprised that medical computers of all kinds are full of malware. For all I know, I might have carried a computer virus from the hospital onto the doctor's office computer myself! I saw no sign of that, and the viewing software looked legit (even if it was clunky and hard to use) but viruses that attach to legitimate programs and hide from the user are not new. I hope this changes soon.
While a PNG for sure is adequate for your doctor to see a fracture of your bone or joint, it might be completely unusable for someone who wants to do quantitative analysis: How big is a babies head in a ultrasound? How dense is some bone material for planning radiation therapy?
In these cases the correct metadata is very important. It might of course possible to add it to the PNG standard, but DICOM is already there, and it's established.
And: In theory your doctor would only need one compliant viewer program, but in practice the "export data" functionality of a certain device will burn a DVD that includes the vendor's recommended viewer program.
Same department had a tech that would only come down to look at the computers if our pretty staffer was there. When she left, he refused to come down.
Simply put, most people are lazy until they get smacked by the invisible hand. In the medical field, the invisible hand has been tied up by the government.
So you get doctors and nurses who hate computers and computer-based solutions reflexively because a few more clicks, or minor Windows-cruft-based annoyances are just irritants for an intake clerk, but often tip the scales of "what's faster and more effective" for nurses and doctors back toward pen-and-paper.
Those workers tend to have UX needs that run more toward mobile users [1] and medical software is very rarely designed to meet those needs.
And the general aversion to computers -- again, in my experience -- is an act. Honestly saying they hate a given system has political costs and asking for changes again takes time (they rarely have to spare) to define and follow-through. But saying they simply aren't proficient with computers often has no such costs and can be very effective in getting overhead tasks pushed off to other workers.
This is also why you see those same types of users take so quickly and eagerly to the new wave of stripped-down mobile companion apps. They don't necessarily want to carry a tablet instead of a clip-board. They just really want to use a focused-task, minimal, responsive interface instead of another windows enterprise UI.
All of that is to say: Hospitals do care about IT. They just have a not-altogether-unique situation where the people who would most benefit from computerization rarely make time to see the projects done to their specifications and the overhead in 'typical' enterprise solutions can make-or-break feasibility. [2]
[1] half-seconds count. size of click targets counts. data unrelated to the current task is wasteful noise. etc.
[2] law and cpa firms can be similar, due the inaccessibility of the partners, the political situations and the resistance to anything that introduces overhead they can't bill for. These places, not unlike hospitals, often only see successful technology projects when they're limited to improving the speed/accuracy of administrative groups.
Why are these devices connected to a network, let alone the internet?
Why are these devices running windows? Don't get me wrong I run it too, but that doesn't mean it makes sense on something like this.
Edit: External media connectivity is typically used for updates. It's much more convenient to have a USB port that will use an off-the-shelf mass storage device than a JTAG and a custom programmer.
- Increasingly health monitors are on a network so that all the stats of a ward can be displayed at a central nursing station. The alternative is to turn the beeper really loud so that nurses at the station can hear it go off. In the case of (as an example) children, these monitors go off regularly - especially at night. The warning beeps are usually not a big deal but they do wake up both child and parent (whom often sleep at the hospital with the child). Oxygen Sat monitoring in particular has a high false-positive during regular monitoring on children. To ease the burden of parent, child and nurse these monitors are connected to a network and remotely monitored by nursing staff. This allows nurses to weed out false positives without waking everyone up.
- These networks should not be on the internet, I agree. But I can see low budgets (why run so many wires when one will work?!) and less-than-competent IT (also related to budgets) causing these networks to be connected to the internet.
They're on the internet because it's convenient. The vendor has a support contract (so they can keep pulling money out of the hospital) which allows them to do software updates or maintenance without having to visit the site. Which they almost never do, anyway.
It's mindboggling that this is the quality one can expect from a $30,000 software package covering -three- seats in 2012.
I'm not sure if that's still possible these days, considering windows server weights in disk space and memory than an usual device should ever require... Maybe someone has first-hand / more up to data information about it?
And no, we didn't offer security updates (although Microsoft did provide some infrastructure to do this). This was a hardware company, the idea of providing anything other than consumables and spare parts was quite alien.
[1] The original plan was to use Linux, but we needed to connect various hardware that only came with Windows drivers...
I think the other issue here is liability -- if the manufacturer provides a "security update" and subsequently causes an error which kills a patient, it's the manufacturer's fault. Whereas if there's malware on the device, then it's the hospital's fault for not keeping the device clean.
Plus, there's a great deal of vendor lock-in in the medical devices industry, so I wouldn't expect to see hospitals suddenly adding devices from $NEW_VENDOR which bothers to spend the extra money to write security updates and spend millions getting them recertified.
Medical device manufacturers are for-profit entities looking to make a profit. If using Windows makes it easier to make a profit then they'll use it. If that's problematic to society, from a security perspective, then regulations should be put in place to put make security costs impact the manufacturer's bottom line.
Personally, I'd like to see pentesting as part of device certification requirements.
I learned a valuable lesson, though: don't work for companies that would rather save face than know about serious issues. I've also tried to be slightly more tactful since then. :P