Editor's Note: This article is the second in a series of reports continuously focusing on cybersecurity risks in medical devices.

Medical device manufacturers and hospitals share the responsibility of protecting devices from cybersecurity threats and collaboratively managing patient safety risks. However, despite both parties acknowledging the shared responsibility for cybersecurity, device security continues to be a casualty of the gap between hospitals and medical device companies—a divide that often leads to mutual blame and sometimes a lack of coordination. The consequence is that patients may face life-threatening risks due to outdated and unprotected medical devices.

If cybersecurity risks throughout a device's entire lifecycle are not effectively controlled or managed, it could lead to patient harm, such as illness, injury, or even death caused by treatment delays or compromised device availability and functionality. The risk landscape is particularly severe as the U.S. Food and Drug Administration (FDA) seeks to increase transparency regarding device vulnerabilities.

Blame and disagreements between hospitals and medical device companies are most pronounced in defending against the growing threat of hacker attacks on legacy medical devices. Hospitals argue that many legacy devices were not designed with security in mind, and as end users, they bear a far heavier burden than device manufacturers in trying to protect these devices. The American Hospital Association (AHA) wants the FDA to mandate that manufacturers provide lifelong support for medical devices.

John Riggi, AHA's senior advisor for cybersecurity and risk, claims that most medical devices used in hospitals are legacy devices relying on operating systems like Windows 7, for which Microsoft no longer provides security patches and updates. Complicating matters further, a health system may have tens of thousands of devices from hundreds of manufacturers connected to its network, posing an overwhelming cybersecurity challenge for healthcare organizations already tasked with protecting traditional IT assets.

According to cybersecurity firm Sensato, each medical device has an average of 6.2 vulnerabilities, and the FDA has issued recall notices for critical devices such as pacemakers and insulin pumps due to known security issues; meanwhile, over 40% of medical devices are already at the end of their lifecycle and cannot receive security patches or upgrades.

Earlier this month, the Cybersecurity and Infrastructure Security Agency (CISA) issued an alert about critical vulnerabilities in Siemens software originally released in 1993, which could affect millions of medical devices from multiple manufacturers. Siemens has released updates for some affected products and advised users of unpatched devices to take countermeasures, but according to CISA, it did not specify other specific workarounds or mitigations. Although no known attacks have specifically targeted these vulnerabilities, CISA stated that hackers could potentially disrupt the operation of critical medical devices such as anesthesia machines and bedside monitors. The FDA has required all manufacturers to assess their products' exposure to the Siemens software vulnerabilities.

Nick Yuran, CEO of security consulting firm Harbor Labs, stated that some affected medical devices may have been in clinical use with these vulnerabilities for nearly 30 years, calling it "another wake-up call" for the medical device industry regarding hidden risks in legacy devices. Meanwhile, many hospitals lack an accurate understanding of their medical device inventory, making it impossible to protect devices from hackers.

A recent survey by the Ponemon Institute found that only 36% of healthcare organizations believe they can effectively track the location of all medical devices, while only 35% say they know when device suppliers' operating systems reach end-of-life or become outdated. When technology reaches end-of-life, it means "the end of security," said Rob Suárez, Chief Information Security Officer at Becton Dickinson, adding that the cost of upgrading a large inventory of legacy devices is extremely high.

"It is very important for medical device manufacturers and healthcare providers to work closely together to plan necessary upgrades into procurement cycles," Suárez said. However, this is a huge challenge—especially for large health systems that must deal with numerous legacy devices frequently moving within hospitals, noted AHA's Riggi. Clinicians often move these devices to different patient areas, connect them to the network, and then disconnect them, which is far from the best way to track devices.

"Sometimes suppliers say, 'The solution is to buy new equipment.' That is simply not financially feasible, especially given that many hospitals and health systems are heavily burdened by COVID-19 and financial pressures," Riggi said. "We have many devices that, in many cases, we cannot afford to replace."

Although the FDA has issued postmarket guidance requiring device companies to ensure device security, the AHA believes manufacturer support is often insufficient, forcing hospitals to develop their own device security controls, many of which are expensive, inefficient, and not scalable. Hospitals have "historically been 'thrown over the wall' by manufacturers," who tell them "the responsibility is on you" once devices operate behind the healthcare network and firewalls, said Vidya Murthy, Chief Operating Officer of medical device cybersecurity firm MedCrypt. Murthy, who previously served as a senior manager of cybersecurity at BD, believes the device security demands facing hospitals have accumulated to the point where healthcare organizations are "collapsing under the pressure"—not just tracking devices, let alone patching vulnerabilities.

"I think about the breadth that hospitals have to manage," Murthy said. "It's not just the variety of devices, but also the sheer volume. Some manufacturers focus on making a single device and dedicate cybersecurity personnel specifically to it, yet vulnerabilities still exist. Expecting hospitals to develop that level of expertise for every device is an unrealistic expectation."

Product Lifecycle Challenges

To help hospitals, the FDA released a discussion paper in July, following a 2018 report that set goals for strengthening and improving cybersecurity processes related to the servicing of legacy devices used in healthcare settings beyond their intended lifecycle. The FDA noted that original equipment manufacturers (OEMs) "have regulatory obligations for safety issues beyond security supportability," but individual components such as operating systems and other third-party software components may no longer be supported before a healthcare organization's procurement cycle—or healthcare organizations may choose, for financial reasons, to continue using devices after their lifecycle ends. The FDA warned that these unpatched medical devices will become increasingly vulnerable to cyberattacks over time and called on OEMs to strengthen communication with healthcare organizations when they can no longer provide software upgrades and patches to address device cybersecurity risks.

The agency recommended that manufacturers and healthcare organizations establish "responsibility agreements" for devices that may be maintained within acceptable performance specifications but carry increasing cybersecurity risks the longer they are used. However, John Gomez, CEO of Sensato, believes there is a "misunderstanding of responsibility" in device security, where, fairly or not, the burden falls heavily on hospitals rather than device manufacturers. "I'm not downplaying the responsibility of device manufacturers. But ultimately, when devices come within the hospital's walls, they must realize they bear responsibility. Patient safety and security are the hospital's responsibility," said Gomez, whose company has an agreement with the FDA to share information on medical device and healthcare cybersecurity vulnerabilities.

Gomez believes manufacturers have "stepped up their efforts" in providing patches for legacy devices, while MedCrypt's Murthy thinks most device manufacturers are "trying to be good corporate citizens" by issuing updates and providing hospitals with information about legacy devices still in the field. However, hospitals are sometimes discouraged or even prohibited by manufacturers from patching devices themselves, and for good reason, said Erik Decker, Chief Information Security Officer at Intermountain Healthcare, during a virtual cybersecurity summit hosted last month by device company BD. "You can't just patch a device and assume it will solve the problem, because the patch might actually cause harm," Decker said. "It might not work properly or may not have undergone quality checks, and from a patient safety perspective, it could have its own consequences."

Robert Smigielski, a cybersecurity engineer at device company B. Braun Medical, believes healthcare organizations may not necessarily know how to handle all third-party software vulnerability information, especially given that hospitals must track hundreds or even thousands of devices. "We know the situation. We are medical device manufacturers. We have to know if operating systems are outdated. We plan for that—but do customers need to know?" Smigielski said. "We know hospitals are still running Windows 7, and they are helpless about it. So, how does this help them? They can't actually do anything about it."

Intermountain's Decker emphasized that healthcare organizations also have their own responsibilities in device security. "We implement devices. During clinical use, we must manage and maintain them. That is our obligation," Decker said. Although MedCrypt's Murthy sympathizes with the security demands facing hospitals, she believes that for legacy devices no longer supported but still used by healthcare organizations, responsibility should shift from manufacturers. "If hospitals choose to keep such outdated devices on their networks, well past when they should have been retired, they must accept and understand the risks that come with that," Murthy said.

Mandating Lifelong Support

Hospitals complain that they are forced to protect legacy devices, such as medical imaging equipment, which may last for decades, throughout their useful lives, while many mitigation measures—such as firewalls, network segmentation, and offline devices—do not fully address security issues and may impact clinical workflows and patient care. The finalized postmarket cybersecurity guidance explains the FDA's current expectations for maintaining the security of deployed devices. However, there is currently no legal requirement (premarket or postmarket) that explicitly mandates device manufacturers to address cybersecurity issues.

"One of the fundamental principles is security by design and providing devices with the capability for continuous updates. Lifelong support for devices is another area where we hope more manufacturers will step up," Riggi said. The FDA, in its congressional budget justification for fiscal year 2021 at HHS, stated it is seeking to require devices to have the capability for timely updates and patches. "Once devices enter the hospital environment, hospitals need to know what security vulnerabilities exist and which ones can be patched," Riggi said.

Suzanne Schwartz, Director of the Office of Strategic Partnerships and Technology Innovation at the FDA's Center for Devices and Radiological Health (CDRH), told MedTech Dive that the agency holds a similar view. CDRH is developing a holistic framework to consistently communicate medical device vulnerabilities. The FDA wants new postmarket authorities to require device companies to adopt policies and procedures for coordinated disclosure when vulnerabilities are identified. Schwartz specifically emphasized the importance of public disclosure by medical device companies when they learn of cybersecurity vulnerabilities, so that users can understand when devices may be vulnerable and receive guidance on mitigating risks.

BD's Suárez said the company is committed to transparency in informing customers and the industry about newly discovered vulnerabilities in its medical devices. Earlier this year, BD claimed to be the first device company authorized as a Common Vulnerabilities and Exposures (CVE) Numbering Authority, a program sponsored by CISA aimed at providing customers with accurate and timely information about product vulnerabilities. "You can't protect what you don't know about. That's why transparency is crucial for everyone in the healthcare technology ecosystem... truly understanding the issues with third-party components used in medical devices, assessing the risk, and then communicating that risk to customers," Suárez said.

Although some device companies have engaged in coordinated vulnerability disclosure (CVD), the FDA's Schwartz believes that currently only a few medical device industry participants treat it as a best practice. CVD, currently included in the FDA's postmarket guidance, is a core principle to help hospitals "be better prepared and have the tools to respond to issues as they arise," Schwartz said. However, Schwartz argued that making CVD part of additional legislative authority would "create a level playing field—right now it's more voluntary." This voluntary approach between the FDA and manufacturers has been insufficient because whether device manufacturers comply is discretionary, Riggi argued. "It's not binding. We want some of these guidelines to be mandated through regulation."

However, Zach Rothstein, Vice President of Technology and Regulatory Affairs at AdvaMed, said the FDA's postmarket cybersecurity guidance is binding on manufacturers, while insisting that device companies and hospitals share responsibility throughout a device's useful life. "This is a legacy device area where AdvaMed and AHA are more likely to be on different sides," Rothstein acknowledged during BD's virtual cybersecurity summit last month. "Legacy issues are complex, and no one is satisfied with them today."

Nevertheless, the AHA believes that device companies have long sold legacy devices to hospitals, and manufacturers have little incentive to address security issues in their installed product base. That is why the hospital lobbying group is pushing the FDA to clarify that security measures to protect legacy devices are required, not optional, and that postmarket cybersecurity is binding. The FDA's recent "Medical Device Safety Action Plan" states that the agency plans to consider new premarket authorities requiring manufacturers to build capabilities into product design for updating and patching device security and to provide software bills of materials (SBOMs) to identify third-party components in devices, enabling end users to better manage cyber risks. The plan also includes considering new postmarket authorities requiring manufacturers to adopt policies and procedures for coordinated disclosure when vulnerabilities are identified.

However, the FDA has not yet implemented these requirements for manufacturers, and cyber threats to legacy medical devices continue to grow. AHA's Riggi ultimately wants to see regulatory obligations for device manufacturers, similar to how the automotive industry is regulated. "Automakers have an obligation to provide ongoing support and correct potential safety and other defects throughout a vehicle's entire lifecycle," Riggi concluded. "There are regulatory requirements for automotive safety features. We don't let the auto industry decide on its own whether to implement seat belts, airbags, and recalls."