It’s Easy to Hack Hospital Equipment
wired.com
wired.com
I assure you that while this is the hospital's official stance, many people within the hospital are well aware of the shoddy software on their medical devices and the risks they pose. There are so many opportunities for disruption of every aspect of the healthcare system (from the equipment itself, that this article addresses, to the electronic medical records systems, to more structural aspects of the healthcare system as a whole), but literally none of the incentives for practitioners and hospital administrators are properly aligned to make it possible. I'd love to work with a company trying to break into these markets if they had a plausible route to entry.
Got the sniffles? The system shows you get them every year at this time, and that it's atypical of any other tracked infectious outbreak, but correlates to three cyclical natural events including a yearly mold growth that it turns out you're allergic to.
End up incapacitates in the ER? System automatically notes your allergies and past medical history, allowing the ER folks to give you one pain medicine instead of the other one that will kill you. While you're there, all the respirators, etc. all get logged. Take 5 units of blood from 3 donors? All their histories are tracked and fed into your treatment in-case some blood-born illness they suffer from but passed screening shows up in your case.
Blood test shows an abnormality? You get automatic trendlines showing either a progression of this abnormal result (blood sugar continues to get lower) or a weird spike, this way your doctor isn't just working off of one data point like usual.
Every x-ray, cat scan etc. all get stored for later reference. The first cat scan your oncologist takes might not be the first cat scan she can refer to if you have one in your file?
Right now, at least in the U.S., and with different insurances every year (meaning my doctor might change every year), I have to really go out of my way just to make sure my shot records follow me. Within one provider they do an okay job of tracking my medical history and getting x-rays from the x-ray machine to the wall mounted display in the evaluation room, but the moment I need to go to a hospital I'm pretty much filling out my history again by hand and from memory.
Vertically integrated means dumping your medical history into Watson to see if some emergent patterns point to some underlying chronic illness you aren't even aware of and don't have notable symptoms yet.
In essence, the laws are structured under the (not necessarily wrong) assumption that the consumer is too stupid to identify snake-oil. All an incumbent has to do to block a newcomer to the market is make a hard-to-deny snake-oil accusation.
As a "Cancer Dad" the electronic medical records and images that are closed and inaccessible between my local hospital where we got our chemotherapy and the Children's Hospital where we did our major surgeries was mind blowingly crazy.
I had to drive my bone cancer child 2.5 hours to use their equipment because there was an issue with the image file format. So I had to give my child enough pain killers to knock out a grown adult just so we could get the same pictures we could get 5 miles down the road.
The HITECH act[1] (which was part of the stimulus package in 2009) has gone a long way in getting the industry moving. One of the core deadlines we're scrambling to meet at the moment at my hospital is actually data interchange between facilities, including a portal that allows patients to access their records for themselves.
I realize that doesn't help your situation now, but with Medicare penalties looming for not getting that sort of exchange in place, things are starting to happen quickly in an industry that tends to move at a snail's pace.
http://en.wikipedia.org/wiki/HITECH_Act#Electronic_Health_Re...
I'm pessimistic that we'll be able to achieve true level 3 interoperability, even though the basic ontologies (e.g., SNOMED, LOINC, etc) are in place. I'd love to hear that you're having a good experience, though.
Our actual HIE integration has been contracted out to Relay Health/McKesson. They're promising the world, but we're not far enough along for me to say whether they'll actually deliver at this point.
tl;dr: Buyers may not care, but hospital IT certainly does.
(Risk of being hacked) x (severity of being hacked) << (Risk of software not delivered) x (severity of not delivered).
(Risk of being hacked): Small.
(Severity of being hacked): Very negative, but localised most likely to a single machine, set of machines, or hospital.
(Risk of Software not Delivered): Pretty high if we go super-security. We are on a budget. There is competition. Who is paying for it?
(Severity of not delivered): Failure to cure at every hospital for every machine.
So, yes, there is a cost, but the benefit of ignoring security, for some sets of numbers on the above, could conceivably exceed it.
NICE (the UK's no-you-cant-spend-ten-million-of-taxpayers-money-per-patient-on-a-drug-to-extend-their-life-by-six-weeks agency which gets it in the neck for such things) might be able to take on such a calculation - but I bet you anything even if they did that calculation every machine maker would treble their security departments anyway.
This is only possible because there was no pressure to deploy secure systems. Now there is, and after the first death from a hacked pacemaker, the outcry will be heard from the moon.
Isn't the problem that there will always be a way to kill people, even remotely without touching them (sniper, poison mail, gas bomb, massive microwave in a van that you park next to them, ...). You perhaps don't want to make it easy but it's also not necessarily sensible to waste money on an arms race that you'll never win.
Similarly we don't have enclosed station platforms (in the UK) despite people having been pushed in front of trains in the past.
For the train comparison, it's the difference between pushing a guy on the rails and derailing a train remotely by accelerating it remotely through a curve and disabling the manual controls.
What's the value to the user of a networked pacemaker? Maybe a lower price? There would be better ways for it to 'speak' to a network to collect data, I should think.
Fewer surgeries to get to the physical device and change settings. Therefore, longer life expectancy.
This bug might be a feature.
Strict air gaps would be desirable.
But my basic tenant is that we / society has an acceptable balance of risk and benefit. Maybe not a rational one but one that is understood by most people. For cars it's pretty high on the risk tolerance. For medical drugs it's really low. For computer hacking it's low too - cf Aaron Schwartz. I would say that medical devices combine low risk tolerance of drugs and low risk tolerance of hacking - making the spectre of hacked implanted devices front page news.
I expect it will be pretty simple to defeat however - only allow networking of a device over near field radio (RFID style). that way there is no remote access in a body, and do a similar thing for any robots or monitors - the only way to connect a surgical robot to the Internet is with a doctors own personal RFID - tcpip convertor, that he takes away with him or is counts back into stores next to the nurses. Massively dropping the risk ratio with a few simple rules.
we can do this - we just need to be sensible about it
Ps Westminster and canary wharf do have enclosed tube platforms so people cannot jump / be pushed. Because we cannot have bankers or politicians delayed by poverty stricken depressives ...
http://www.investopedia.com/university/behavioral_finance/
(note the article is in several sections)
Every few weeks / months Bob needs to see a doctor w o enters a password, retrieves the data, and makes changes to the settings.
Bob feels that the $DISEASE community can help him interpret the data and tweak the settings and Bob could then reduce doctor visits to once every six months.
Ann is an undisclosed drug addict and wishes to hack her morphine pump to supply more than she is currently getting.
Etc
Certainly it could be the case that the benefit exceeds the risk, but if such calculations were made, they may need to be reevaluated.
Wow, just wow.
If someone ever hacks an active surgery robot it's going to be Saw meets Snow Crash, and not in a good way.
Some of the ones I deal with are also running those XPs with old IE versions, 6 & 7. This is because they bought, then never upgraded, systems that won't run right with newer browsers.
These are the same people that have been complaining about how awful it is that the Affordable Care Act imposes a medical device tax. Maybe if they weren't so cavalier about deceiving their customers regulation and certification wouldn't cost as much as it does.
Disclaimer: I have worked on FDA cleared medical devices my entire career.
Worst case, these exploits will suddenly be used to disable or cripple hospitals in case of dirty wars and terrorist campaigns. If the latter is still a problem.
It'll continue to be a mess for years to come, the introduction of new medical hardware and software is slow and I don't know how they plan to handle already deployed items. But not exactly for the reasons you state.
http://www.ebay.com/sch/i.html?_trksid=m570.l3201&_nkw=infus...
=> 49.99$ is not _that_ hideously high.
Weak default passwords on the web interface is just the icing on the cake, the low-hanging fruit. The entire networking stack is likely to be riddled with unpatched vulnerabilities for anyone to exploit.
Relative obscurity and physical security are probably the only things that stand between hospital equipment and certain disaster.
Even then, you can pop on a pair of scrubs and avoid most scrutiny. Keycard systems are there, but those aren't difficult. Sometimes the operating area doesn't have cameras and the area surrounding the 2 million dollar daVinci machines are deserted.
I can confirm this.
I can also confirm that those daVinci machines are way less impressive looking in person than they are plastered on roadside billboards. :)
A lot. I know we have telemetry systems that are all XP based. Granted, they're on a separate VLAN that doesn't touch the public internet or the rest of our internal network, but there are still physical security concerns there.
>Weak default passwords on the web interface is just the icing on the cake, the low-hanging fruit. The entire networking stack is likely to be riddled with unpatched vulnerabilities for anyone to exploit.
A major problem in healthcare is that vendors tend to use generic credentials for support purposes.
Airgaps are really hard to do correctly, as they have so many single points of failure.
http://en.wikipedia.org/wiki/SCADA
I've seen a couple that used unencrypted UDP with bitfields representing the state of solenoids. Imagine what sending a series of all '1' and all '0' packets would do in terms of damage and panic.
Also interesting to think about is if these devices are getting hacking and people are blaming it on malfunctions.
It used to read like the actual title: "It’s Insanely Easy to Hack Hospital Equipment"
IF he has an opinion on the difficulty to hack topic there is a comment section. The op is not a comment section for mods