As ransomware attacks against hospitals and health systems escalate incomplexity,healthcare organizations are facing one of their biggest cybersecurity challenges—how to defend legacy medical devices against new cyber threats.

Many legacy medical devices currently used by healthcare organizations were designed and manufactured long before the medical device industry began seriously considering cybersecurity features. Many older devices still in operation today run outdated or insecure software, hardware, and protocols, with no built-in network protection from the outset, leaving healthcare organizations vulnerable and putting device manufacturers' reputations and financial stability at risk.

Despite the cybersecurity risks, the number of networked medical devices in hospital networks is still growing rapidly.According to IBM, the number of connected medical devices—devices connected to the internet—is expected to grow from 10 billion to 50 billion over the next decade.

"Devices that are 10 to 15 years old were never designed with networking in mind," said David Finn, executive vice president of cybersecurity consulting firm CynergisTek and former CIO of Texas Children's Hospital. "Anything connected to the internet is going to be at risk."

Worse, legacy devices are running operating systems like Windows XP, for which Microsoft no longer provides security patches and updates.

"That's a 20-year-old system. But some large medical devices can last that long and still function perfectly from a medical standpoint," acknowledged Zach Rothstein, vice president of technology and regulatory affairs at AdvaMed.

IoT security company Forescout, in its2020 Device Security Report,predicted that healthcare organizations will have to deal with medical devices running legacy operating systems for the foreseeable future.

"The proportion of devices running completely unsupported operating system versions has not changed, remaining at a constant 0.4% between 2019 and 2020. This includes now-obsolete Windows operating systems such as Windows XP and Windows Server 2003," the report noted, suggesting that the legacy operating system problem will persist.

The report noted that while this proportion is low, the most affected systems are often critical devices supporting clinical care in healthcare organizations, such as insulin pumps and ventilators.

Marc Schlessinger, senior associate at watchdog ECRI, said medical device security is often one of the weakest links in healthcare organizations, calling legacy devices a particularly thorny area because they have known vulnerabilities that cannot be patched.

Chris Gates, product security director at medical device engineering firm Velentium, believes "you can't always retrofit security measures, especially for legacy devices—I've directly returned checks to clients and told them this can't be fixed."

Schlessinger said that just last year, he saw older devices in hospitals running on Windows 98, even though Microsoft stopped all support for that operating system back in 2006. Such operating system issues are particularly common in aging medical imaging systems.

"But you won't find a hospital willing to quickly replace a $1.5 million MRI or CT device just because of an outdated operating system,"Schlessinger said. Instead, he recommends that healthcare organizations adopt best practices for managing security risks, including isolating networked medical devices from the hospital network where possible.

At the same time,Schlessinger acknowledged,disconnecting devices from the hospital network is often not practical because doing so could disrupt clinical workflows critical to patient care.

Gates of Velentium, who defines legacy medical devices as those that cannot meet current cybersecurity standards, believes the U.S. needs to phase out devices that are "highly insecure" and have been in hospitals for 20 years or more. "Let's clear out the deadwood," he said.

However,with healthcare organizations facing many competing priorities, limitedfinancial and human resources are the main obstacles to fixing vulnerabilities in legacy medical devices, as both replacing and repairing these devices are cost-prohibitive.

The problem is that security analysts and regulators are "too busy chasing potential vulnerabilities in new devices to pay attention to medical systems that have been in clinical use for years," said Mike Rushanan, medical security director at consulting firm Harbor Labs. Hackers, on the other hand, are different—he believes they have the resources and patience to continuously discover new cybersecurity vulnerabilities.

Hospitals and device manufacturers clash over liability and regulations

Cybersecurity experts insist that identifying and classifying medical devices running legacy operating systems is critical to risk mitigation, recommending network segmentation for devices that cannot be retired or patched, limiting access to only critical information and services.

However, the American Hospital Association hasarguedthat, for example, upgrading devices from Windows 7 to Windows 10 should be considered an expected event by device manufacturers and part of planned maintenance at reasonable cost.

The AHA believes that although the FDA has issued premarket and postmarket guidance to device manufacturers on how to ensure system security, "manufacturers lack the incentive to address security issues in their installed product base." The hospital organization insists that regulators must make clear that security measures to protect legacy devices are mandatory, not optional.

"The FDA should take a leadership role in setting expectations that manufacturers proactively reduce risk by building security into products through design, providing security tools to end users, and updating and patching devices as new intelligence and threats emerge," the AHA said.

The FDA'sguidanceissued in 2016 outlined the steps manufacturers must follow to protect medical devices from cyberattacks. In that document, the agency clearly stated that cybersecurity risk management is a shared responsibility of all stakeholders, including medical device manufacturers and healthcare providers.

AdvaMed's Rothstein said the FDA's postmarket cybersecurity guidance is binding on manufacturers, but device companies and hospitals share responsibility for maintaining device security over their useful life.

Complicating matters, the long useful life of legacy medical devices makes protecting them more difficult because the cybersecurity landscape is constantly evolving, with new vulnerabilities and threats emerging all the time.

Under FDA rules, manufacturers of newer devices must disclose vulnerabilities when discovered. What worries cybersecurity experts is that many vulnerabilities in legacy devices have yet to be discovered.

Evolving threats

At-risk legacy devices can become easy targets for cybercriminals, who can use them as entry points into hospital networks and ultimately gain access to the valuable patient data they covet, reaping direct financial rewards through ransomware attacks or profiting indirectly by selling stolen information.

"These are financially motivated intruders who go after the low-hanging fruit. And the healthcareindustry happens to be a relatively easy target," said Kevin Fu, acting director of medical device cybersecurity at the FDA's Center for Devices and Radiological Health, at the Food and Drug Law Institute's annual meeting last month.

"Everything is hackable," Fu declared, noting that medical devices infected with ransomware may fail to perform critical clinical functions properly, potentially leading to patient harm.

Although medical devices such as infusion pumps are used to provide life-sustaining treatment,to ECRI's knowledge, no hacker has yet harmed a patient by altering device settings.

Even so,IBM last yeardiscovered a cybersecurityvulnerabilitythat could allow hackers to remotely control insulin pumps and alter patients' medication dosages.

So far, hackers seem more focused on financial gain than on harming patients.

"They haven't gone after patients yet, but that doesn't mean it won't happen,"Schlessinger said. "If hackers wanted to actually harm patients, IV infusion pumps and ventilators would be two types of devices they could easily target."

The FDA's Fu warned that as more medical device companies use the cloud and rely on it for real-time device functionality, the industry is likely to see cybersecurity incidents escalate into patient safety issues.

"Ransomware strikes at the very heart of usability. It renders devices completely inoperable," Fu said.

That possibility is becoming more real as ransomware attacks against healthcare have evolved into an epidemic.

According toThe Wall Street Journal,an Eastern European cybercrime gang called Ryuk has attacked at least 235 U.S. hospitals and inpatient psychiatric facilities since 2018, earning more than $100 million through ransomware attacks. Some ransomware gangs avoid targeting healthcare organizations out of concern for patient safety. However, Ryuk and other gangs have no such qualms.

"Things out there are getting really bad. The adversaries are more sophisticated than they were a year ago," Fu said at the FDLI conference, citing the Conti ransomware group, which has targeted at least 16 U.S. healthcare and emergency networks, prompting the FBI last month toissue an alert.

Fu admitted that when faced with the massive problem of legacy devices and their inherent cybersecurity vulnerabilities, he doesn't know what the answer is.

For now, Gates said the FDA is playing the "long game," essentially allowing legacy devices to reach the end of their useful life and then be replaced by newer, more secure products that comply with the agency's latest cyber regulations—hopefully before hackers exploit their vulnerabilities and cause harm to hospitals and their patients.

"It's a really thorny issue," AdvaMed's Rothstein acknowledged, noting that given the rapid pace of technological iteration, any medical device brought to market will quickly be considered legacy. "We'll never completely get rid of this problem," he said.