The House Energy and Commerce Oversight and Investigations Subcommittee April 1 discussed cybersecurity threats in legacy medical devices during a hearing. The subcommittee heard from experts on the dangers of outdated devices as the hardware can last several years longer than software.

“Our patients depend on millions of medical devices — many of them aging, machines — to deliver life-saving care,” said Christian Dameff, M.D., emergency physician and co-director for the Center for Healthcare Cybersecurity at the University of California San Diego Health. “The cybersecurity of our legacy medical devices thus becomes a literal matter of life and death."

Erik Decker, vice president, chief information security officer at Intermountain Health, discussed the current state of cyberthreat adversaries as well as the state of medical device security programs.

“The primary concerns with attacks against medical devices are related to patient safety and national security,” Decker said. “Additionally, they can be used for conduits for further attack against an organization. Though there have been no known public attacks against medical devices to cause harm to a patient, the studies and research have shown that such an attack is possible.”

Other witnesses for the hearing included Greg Garcia, executive director of the Health Sector Coordinating Council Cybersecurity Working Group; Michelle Jump, chief executive officer of MedSec; and Kevin Fu, professor from the department of electrical and computer engineering at the Khoury College of Computer Sciences at Northeastern University.

Related News Articles

Headline
A Health-ISAC (Information Sharing and Analysis Center) bulletin released Oct. 1 warns of a recently released LockBit 5.0 ransomware variant that poses a…
Headline
Fernando Martinez, Ph.D., chief digital officer at the Texas Hospital Association, shares how Texas and the THA are building regional resilience through cyber…
Headline
The federal government shut down Oct. 1 following a failed Senate vote on the House-passed continuing resolution to fund the government by midnight Sept. 30.…
Headline
Microsoft Sept. 16 announced it had disrupted a growing phishing service that had targeted at least 20 U.S. health care organizations. The company said it used…
Headline
The FBI Sept. 12 released an alert warning of malicious activities by cybercriminal groups UNC6040 and UNC6395, which the agency said are responsible for an…
Headline
The Cybersecurity and Infrastructure Security Agency, National Security Agency and international agencies Sept. 3 released joint guidance outlining a “software…