中文

Four-Step Strategy: Reducing Cybersecurity Threats of Legacy Medical Devices

As cyberattacks continue to target hospitals, the U.S. FDA implemented comprehensive new regulations last year to strengthen cybersecurity oversight of medical devices, but regulators and cybersecurity experts are still working to address a specific threat: legacy medical devices. Hospitals and health systems across the nation are filled with medical technology running outdated or soon-to-be-outdated software, leaving vulnerabilities in facility network defenses. Experts propose a four-step mitigation strategy: identifying devices, understanding vulnerabilities, network segmentation, and shutting down devices.

2024-09-239views
Four-Step Strategy: Reducing Cybersecurity Threats of Legacy Medical Devices

The U.S. Food and Drug Administration (FDA) implemented comprehensive new rules last year to strengthen cybersecurity oversight of medical devices, as cyber attackers continue to target hospitals. However, regulators and cyber experts are still grappling with a specific threat: legacy medical devices.

Across hospitals and health systems nationwide, a large number of medical technologies still run on outdated or soon-to-be-outdated software, leaving vulnerabilities in facilities' cybersecurity defenses. Although devices are rarely the direct target of cyber attacks, unsupported legacy medical devices can still be affected by attacks on hospital networks, potentially forcing critical equipment to shut down and endangering patient safety.

"There is always a constant tension between securing devices, preserving the economics of older equipment, and prioritizing patients who urgently need connected devices," said John Riggi, national advisor for cybersecurity and risk at the American Hospital Association.

In 2023, the FDA's Center for Devices and Radiological Health (CDRH) implemented new rules and guidance aimed at minimizing cybersecurity risks for medical devices. The new rules prioritize stricter cybersecurity requirements before devices are marketed and more comprehensive monitoring standards after product release. Experts praised these regulations for ushering in a new era where cybersecurity finally receives the attention it deserves.

A key part of this effort includes ensuring devices entering hospitals do not quickly become obsolete and requiring manufacturers to develop specific plans to monitor, update, or patch older software. However, for the large number of devices currently in hospitals running outdated and unsupported software, solutions remain elusive. Nastassia Tamari, director of the medical device cybersecurity division at CDRH, told MedTech Dive in March that due to a lack of reliable data, no one knows how many legacy devices are in hospitals. Tamari explained that legacy devices are currently one of the industry's biggest problems, and "there is no answer yet."

Some legacy devices are critical to patient care, so hospitals cannot simply shut them down as a security measure. At the same time, some unsupported devices are expensive, and hospitals cannot simply purchase new machines after software becomes outdated.

"This is a big problem," said Ty Greenhalgh, healthcare industry lead at cybersecurity company Medigate by Claroty. "It's so complex... it's hard to understand the problem, let alone the solution."

MedTech Dive spoke with cybersecurity experts about how medical device manufacturers and hospitals can mitigate risks posed by legacy devices. Here is their recommended four-step strategy:

1. Identify devices

Cybersecurity experts say the first step in addressing legacy device issues is for hospitals to identify how many devices are connected to their networks. This can be complex due to the sheer number of potential connected devices.

"Today, a huge number of systems are connected to hospital networks, most of which are unmanaged, or even if managed, they are quasi-managed by facilities or third parties," said Richard Staynings, chief security strategist at computer and cybersecurity company Cylera. "The first thing we need to do—and this is something the healthcare industry is doing very poorly right now—is to understand what is connected to our networks."

While the first step may seem simple, it can be burdensome for individual providers, regulators, and device manufacturers. Claroty's Greenhalgh said identifying connected devices, including legacy machines, is "almost impossible." Hospitals may have hundreds of thousands of machines connected to networks, ranging from medical devices to IT systems, phones, and laptops. Greenhalgh explained that even if a machine is discovered connected to the network, identifying the specific machine can be complex because devices like imaging machines may appear as "Windows devices" rather than medical devices.

"The problem is not as clear-cut as people would like," Greenhalgh added. "But we are making progress."

Once devices are identified, hospital networks need continuous monitoring to identify new devices, threats, and whether patches or updates are needed.

2. Understand vulnerabilities

The next step is to understand the risks that network-connected devices may pose. Some machines may need updated patches or immediate updates when operating systems are unsupported, while others may already be outdated with no patches available.

Understanding where vulnerabilities lie is crucial so facilities can prepare for emergencies, especially for medical devices used to treat or diagnose patients. Ransomware or other forms of cyber attacks can spread laterally across hospital systems, disabling medical devices such as CT scanners and MRI machines, as well as other functions that rely on the facility's network.

"Some legacy technology lacks basic security features such as data encryption and transmission encryption. Some don't even have passwords, or have hardcoded passwords that can be found in technical manuals on the internet," said Riggi of AHA, who served in cybersecurity roles at the FBI for more than five years. "These devices still work as designed. They are designed to be durable... but operating systems and software become outdated or full of vulnerabilities."

Software bills of materials (SBOMs) are one tool medical device manufacturers can use to help providers understand what updates or patches a device may need, thereby better understanding potential vulnerabilities. An SBOM is a list of all software components that make up a device.

Detailed SBOMs provided by device companies can also help hospitals identify machines connected to the network and patch or update them when needed, said Anura Fernando, chief security advisor and global head of medical device security at UL Solutions. Fernando added that SBOMs can trigger conversations between device manufacturers and hospitals about whether machines are vulnerable and what controls exist to manage those risks.

"Some legacy technology lacks basic security features such as data encryption and transmission encryption. Some don't even have passwords, or have hardcoded passwords that can be found in technical manuals on the internet."
— John Riggi, national advisor for cybersecurity and risk at the American Hospital Association

Under rules implemented last year, the FDA now requires manufacturers to provide SBOMs for devices. While some have praised this as an improvement over previous standards, experts emphasize that manufacturers still need to ensure devices are as secure as possible before selling them and should not use patches as a development crutch.

"Once you understand how they work, you can start locking down these devices to improve cybersecurity," said Cylera's Staynings. "Let's assume we can never patch legacy devices—some can, some can't—but assume the worst case, so we can protect patient safety and the integrity and security of medical networks."

3. Use network segmentation

After identifying legacy devices and understanding potential risks, some devices may pose enough of a threat that they need to be isolated on their own network, a process called network segmentation. This step is a security measure that prevents network threats from reaching vulnerable devices or prevents threats from spreading if a device is compromised.

Network segmentation is a key strategy because cyber attacks can spread quickly, leaving no time to protect machines during or after an attack.

"Malware can spread laterally across the network, and before you know it, the entire hospital is down," Staynings said. "Ambulances are diverted, patients are transferred by medical helicopters to nearby facilities, and recovery and rebuilding costs quickly reach millions of dollars."

Segmentation does not always mean machines are completely sealed off. Greenhalgh explained that segmented machines can still connect to other machines that are part of the system. For example, imaging workstations need to communicate with three or four other machines to function, and these machines can be segmented to allow communication with "clinically relevant" devices. Administrators can then continue monitoring machine behavior, communicating with medical device companies, and taking action when needed.

Vulnerable legacy devices can also be "air-gapped," meaning completely disconnected from the network. UL Solutions' Fernando said air-gapping allows software to continue running and can extend a machine's life beyond its end-of-support date. Fernando noted that air-gapped devices can still be threatened through USB connections and memory sticks, but "if you implement strong access control and physical security policies for air-gapped devices, then you should be able to avoid" many pitfalls.

"There is always a constant tension between securing devices, preserving the economics of older equipment, and prioritizing patients who urgently need connected devices."
— John Riggi, national advisor for cybersecurity and risk at the American Hospital Association

4. Decommission devices

Finally, if a device poses too much risk even after segmentation, or has been compromised by a cyber attack, hospitals can completely disconnect it from the network and internet. However, this is not always an easy decision. Decommissioning a medical device requires weighing the threat risk against the necessity for patient care, and replacing devices is costly.

AHA's Riggi called decommissioning a "last resort." If a machine must be shut down, hospitals need contingency plans, which may include transferring patients to other facilities. They must also communicate with medical device manufacturers to implement controls.

"We need to focus on how to care for patients for 30 days or more without technology, because that's the average time we see ransomware victims—hospitals—take to at least recover their core systems," Riggi added.

No matter how well risk is managed or how new rules address the problem, outdated and unsupported machines will always challenge the market because software ages and technology continues to advance. Complicating the issue is the involvement of multiple parties: device companies develop and manufacture products, hospitals monitor devices and are responsible for network connections, and various regulatory agencies oversee different aspects of the healthcare industry—all of which need to work together to protect against cyber attacks.

Experts believe that despite new rules, efforts are still needed to address current challenges, especially strategies for existing legacy machines in hospitals. Riggi said stricter regulation would help, but "it may take a generation to retire all old legacy technology."