Patient critical – healthcare’s cybersecurity pulse

August 2019 News, Cyber Security, Healthcare (Industry)

The healthcare industry has become one of the leading cybersecurity attack vectors worldwide.

Case 1 – The patient and his family appeared horrified. What had begun as a seemingly routine medical examination had turned into a nightmare. The man appeared healthy but had complained of persistent headaches. The CT scan showed what was diagnosed to be a massive tumour on the brain. Declining surgery, he still managed to get a substantial disability pay-out from his insurers who were unaware of his brilliance at writing computer programs.

Craig Rosewarne

Pending his nomination he undertook a thorough medical check-up and was declared fit as a fiddle. A month later he collapsed at a fundraising function and died of a major arterial embolism in the brain. The underworld rejoiced.

Do the above case scenarios sound strange? Not if one considers that researchers in Israel recently announced that they’d created a computer virus capable of adding or removing images of tumours into CT and MRI scans, malware designed to fool doctors into misdiagnosing low- to high-profile patients. This short video is scary yet fascinating:

The healthcare industry has become one of the leading attack vectors worldwide for several reasons. Firstly, it maintains huge amounts of highly sensitive patient data, a juicy target for hackers who can use it for financial gain, humiliation or revenge. Access to a medical database would allow a miscreant to alter medical records, delete them or hold them hostage using ransomware.

Secondly, medical institutions are far more likely to accede to ransomware demands when patients’ lives are at stake. The healthcare industry increasingly relies on IoT (Internet of Things) technology that’s connected to the Internet, which ranges from patient records and lab results to radiology equipment. Even catering and down to maintenance of the hospitals are impacted. The 2017 WannaCry ‘epidemic’ caused chaos in the healthcare industry, the UK in particular being hard hit. Many institutions were found to still be running their systems on outdated, end-of-life, unpatched Windows XP devices.

Healthcare lags far behind other industries, experts say, unlike the financial sector, in the way it protects its information technology infrastructure. A healthcare failure can end with injury or even death, unlike finance which may involve a slap on the wrist or a fine.

Not a matter of when or if…

Medical institutions are being bombarded with malicious attacks every day. Many do not even know that they are already infected as many viruses can lay dormant or continue to seek new backdoors until activated. Advanced Persistent Threats (ATPs) are sometimes only discovered 18 months after breaching the system. Another major problem is that most medical personnel do not know what system devices are running on. Many service providers have gone out of business and patches, when provided, are often not implemented. Many small medical facilities do not have the budget for a full-time IT team and those in rural areas are at greater risk, especially if they are connected to the main urban centres. The country cousins can infect their city slickers – remember, everything is connected.

What other dangers do the health industries and medical devices face? Pacemakers have been proven to be easily hackable. The device can be instructed to speed up, slow down, behave in an erratic fashion or even shut down. ECGs, scanners and X-rays may give false readings or simply be unavailable. Hospitals’ and clinics’ emergency power generators can be disabled, preventing any tests, operations, etc. during a mains outage, which are a common occurrence here in sunny South Africa.

Why is the health industry lagging behind other enterprises? Low budgets play a major part, but the lack of awareness regarding the enormity of the threats from governments, decision makers down to grass-level employees is extremely worrying. The perceived attitude that no-one would be so callous as to attack a medical establishment and endanger human lives or cause fatalities is pervasive. Many hackers don’t care. The monetary rewards far outweigh any feelings of guilt or remorse.

There is a pulse, but it is very weak.


Share this article:
Share via emailShare via LinkedInPrint this page

Further reading:

ONVIF introduces Profile M Release Candidate
Issue 7 2020 , News
ONVIF has introduced its Profile M Release Candidate for standardising the communication of metadata and event handling of analytics for smart applications.

T-Systems and Fortinet launch cyber academy
Issue 7 2020 , News
T-Systems South Africa will be introducing cybersecurity education programmes to create a specialised Cyber Security Academy incorporated into the organisation’s existing ICT Academy.

New cyber-insurance offering
Issue 7 2020, Vox Telecom , News
The first-of-its-kind cyber protection solution from Vox and King Price Insurance will alleviate key business continuity risks for SA companies.

LD Africa partners with Milesight
Issue 7 2020, LD Africa , News
LD Africa is now an approved partner of Milesight’s security and surveillance solutions in South Africa.

Secure cloud VMS in an app
CCTV Handbook 2020, Mobotix , CCTV, Surveillance & Remote Monitoring, News
Mobotix has launched a new cyber-secure cloud video management system that enables complete video management of local cameras via an app.

From the editor's desk: The more things stay the same
CCTV Handbook 2020, Technews Publishing , News
It is rather redundant to say that the surveillance industry is going through significant changes and that there are some incredible advances in technology happening. You can read about a small number ...

New hires at iPulse
Issue 7 2020, iPulse Systems , News
iPulse has welcomed two new employees into its ranks. Shai Weil has been appointed as operations director, while Corneli Botha is the new customer sales liaison.

HID Global acquires Access-IS
Issue 7 2020, HID Global , News
HID Global acquires provider of miniaturised reader devices that combine key technologies for mission-critical markets.

Securing digital transformation
Issue 7 2020 , News
Schneider Electric partners with Fortinet to strengthen ability to secure operations across the business lifecycle and unlock the advantages of a secure IIoT.

Suprema integrates with Paxton’s Net2 access control
Issue 7 2020, Suprema , News
Suprema has announced it has integrated its devices with Paxton’s access control system, Net2.