After Russia invaded Ukraine last week, U.S. hospitals and medical device companies are on high alert for cyberattacks from Russian-backed hackers who may target U.S. critical infrastructure, experts say.

Although cybersecurity threats, including ransomware, facing the healthcare and medical technology industries have increased during the pandemic, the conflict has further raised the threat level.

Nick Yuran, CEO of medical device security consulting firm Harbor Labs, who spent 10 years as a Russian-language intelligence analyst in U.S. intelligence before entering the private sector, believes that given the "talent and resources" of state-backed actors like Russia, the damage to the U.S. healthcare system could be catastrophic.

"We typically think of energy and finance as the most high-profile targets in state-sponsored cyberattacks, but attacks on healthcare infrastructure can be equally destructive," Yuran said. "Targeted cyberattacks against military medical organizations, such as the Military Health System or Department of Veterans Affairs facilities, could be intended as military operations. But there is no guarantee that such attacks will not inadvertently spill over into civilian healthcare due to the sharing of vast public resources and assets."

However, the American Hospital Association (AHA) released acybersecurity advisoryon February 23, shortly after Russia's invasion of Ukraine, warning that U.S. hospitals and healthcare systems could be "directly" targeted by Russian-backed cyber actors, while also potentially becoming "incidental victims or collateral damage of malware or destructive ransomware deployed by Russia, which could inadvertently penetrate" healthcare organizations.

Chris Gates, director of product security at medical device engineering firm Velentium, said the world has seen Russia usedata-wiping malwarein Ukraine, accompanied by ransomware, "which seems like a 'kitchen sink' type of tactic." Gates believes "such tools can easily exceed their intended target scope," affecting hospitals and medical devices.

The first ransomware attack targeting medical devices occurred during the global WannaCry attack in 2017, whichsuccessfully encrypted hospital radiology equipmentdrives, exposing the vulnerability of medical technology. The WannaCry ransomware infected hundreds of thousands of computers in at least 150 countries, including the UK's National Health Service (NHS), where the attack froze hospital computers and shut down emergency rooms. North Korea is widely believed to be behind the attack.

"If a cyberattack begins, no one can be sure how far the impact will spread, but in the past we've seen that the impact is often broader than expected and not necessarily limited to the target," Mac McMillan, CEO of cybersecurity consulting firm CynergisTek, wrote in an email. He cited the WannaCry attack as an example.

"Once they start, these things are not always easy to control," McMillan said.

Mike Rushanan, medical security director at Harbor Labs, believes Russian-backed malware could exhibit the same characteristics as worms like WannaCry, which spread beyond their intended targets, affecting a wide range of Internet of Things (IoT), consumer, and hospital IT devices, as well as related medical systems and healthcare services.

"Russian state-backed actors certainly have the capability to launch similar types of attacks, and even if healthcare is not the primary target, hospitals could be negatively affected, potentially putting patients at risk," Rushanan said. "I think any state-sponsored hacking would be indirect. Malware would spread via worms... It would be difficult to attribute directly to Russia."

Last month, the Cybersecurity and Infrastructure Security Agency (CISA), the Federal Bureau of Investigation (FBI), and the National Security Agency (NSA) released ajoint advisoryoutlining Russian state-sponsored cyber operations, including common tactics, techniques, and procedures.

CISA subsequently released its own"Shields Up" alertearlier this month, aimed at conveying a heightened national cybersecurity posture to better protect U.S. critical infrastructure, including healthcare.

"While there are no specific or credible cyber threats to the U.S. homeland at this time, Russia's unprovoked attack on Ukraine, which involves cyberattacks on Ukrainian government and critical infrastructure organizations, could impact organizations both within and beyond the region, especially in light of sanctions imposed by the U.S. and allies," CISA said.

Kevin Fu, acting director of cybersecurity at the FDA's Center for Devices and Radiological Health, said in arecent speechthat attacks on healthcare facility networks are causing medical devices to "go down," putting patient lives at risk.

"State and organized crime—real threat actors—are causing harm, compromising the safety and effectiveness of medical devices," Fu warned in late September at the AdvaMed 2021 MedTech conference, when the Wall Street Journal reported the first allegedhospital death due to ransomware

Legacy and connected devices

Although the AHA did not specifically mention medical devices in its cybersecurity advisory on Russia last week, the hospital organization has warned for years about the challenges of defending olderlegacy devicesthat were not designed with security in mind when responding to increasingly sophisticated and cunning hacker threats. To make matters worse, the number of connected medical devices used in hospital networks is rapidly increasing, making them vulnerable to cyberattacks.

According to the FDA, medical device manufacturers (MDMs) have a responsibility to "remain vigilant" in identifying cybersecurity risks and harms associated with their devices, while healthcare delivery organizations (HDOs) should assess their cybersecurity and protect their hospital systems.

The problem is that device security remains avictim of the gap between hospitals and medical technology, which often leads to finger-pointing between the two stakeholders and sometimes a lack of coordination.

However, Velentium's Gates said that in conversations with MDMs and HDOs over the past few weeks, before Russia's invasion of Ukraine, he was "encouraged" that both stakeholder groups seemed to be taking the Russian hacker threat seriously.

"Remove Ukrainian and Russian offices from direct connections to the organization. Implement their 'playbook' to achieve a more secure posture. That's all that can be done," Gates noted. "As this war heats up and other countries get drawn in, what would Putin consider the right response? Since the reasons for this war seem illogical, I expect his continued actions to reflect that. There are more questions than answers right now."

The FDA has not yet issued an alert about potential cybersecurity threats to medical devices following Russia's invasion of Ukraine, nor has it provided recommendations for reducing cyber risks and vulnerabilities.

The agency, in an email response to MedTech Dive, said it "respectfully declines to comment at this time on the impact of the Russia-Ukraine conflict on device security."

Nevertheless, the FDA'scybersecurity webpagenotes that medical devices are "increasingly connected to the internet, hospital networks, and other medical devices to provide features that improve healthcare and enhance the ability of healthcare providers to treat patients," but these "same features also increase the potential cybersecurity risks," making device protection "particularly challenging," while calmly pointing out that "threats and vulnerabilities cannot be eliminated."

Regulator ECRI last monthreleased its annual reporton the top medical technology hazards, finding that cyberattacks are the top concern for patient safety with medical devices in 2022, while noting that all healthcare organizations face cybersecurity incidents.

The organization specifically emphasized that this is a patient safety issue, noting that incidents could threaten network-connected medical devices and data systems.

So far, ECRI has not received reports from its members, primarily providers, about attacks related to current cybersecurity concerns. Nor has it seen specific recalls or alerts from medical device manufacturers. However, the organization still recommends that hospitals and device manufacturers remain vigilant.

"We haven't seen them come to us saying 'we've been attacked,'" said Chad Waters, senior program officer at ECRI. "Everyone should remain vigilant and monitor logs in their organizations. Do what you've always been supposed to do, just make sure you're actually doing it."

Specifically, ECRI said hospitals should develop emergency response plans that consider medical devices, including ensuring that if devices lose functionality due to cascading effects of disruptions, facilities still have means to provide care. Communication channels also need to remain open, and manufacturers should monitor for potential vulnerabilities, flagging them to providers who purchase their devices as well as potential fixes.

Medical device manufacturers should also watch for potential impacts upstream in their supply chains. For example, if they rely on vendors for network management or cloud service providers, they should ensure those vendors remain vigilant and update security practices, said Juuso Leinonen, ECRI's chief program officer.

Many companies also have programmers, hosting sites, call centers, and technical support in Ukraine, wrote CynergisTek's McMillan. As these entities are disrupted, it could affect the companies they support.

"Attacks on infrastructure can also pose risks to organizations as their ability to communicate with supply chains is disrupted," McMillan wrote. "We've already seen this in the Kaseya, Colonial Pipeline, JBS Foods, and most recently Kronos attacks."

Rob Suárez, chief information security officer at Becton Dickinson, believes hospitals and health systems, as well as medical device manufacturers and external partners, "need to be extra vigilant and on high alert for potential cyberattacks," because "everything we do ultimately comes down to the patient."

Suárez noted that CISA's "Shields Up" alert earlier this month provides "actionable guidance to strengthen cybersecurity, from verifying endpoint protection on critical systems to addressing known vulnerabilities, monitoring for anomalous activity, and confirming the latest offline backups to ensure resilience."

BD's security chief also recommends that hospitals and health systems take additional steps to guard against cyberattacks, including using strong network and system access controls, placing critical services behind separate firewalls, and disabling unnecessary accounts, protocols, and services.

"We always advise hospitals and health systems to train staff to maintain extra vigilance. For example, restrict system access to authorized personnel only, and enable employees to recognize and report suspicious activity, including social engineering and phishing attacks. Raising cybersecurity awareness across the organization helps protect patients from potential cyber threats," Suárez said.

However, Velentium's Gates believes that not only medical device manufacturers and healthcare delivery organizations could be affected by Russian-backed hacker attacks. Cyberattacks on hospitals could also disrupt their mission-critical service providers, as the AHA has suggested, Gates said.

"I don't think anyone can 'stand aside' from intentional or unintentional consequences. So it's not just service providers, but all suppliers. And the overall supply chain is already in a pretty bad state, so it doesn't take much for shortages to become a real problem," Gates added.

Elise Reuter contributed reporting to this article.