Patient critical – healthcare’s cybersecurity pulse

August 2019 News & Events, Information Security, Healthcare (Industry)

The healthcare industry has become one of the leading cybersecurity attack vectors worldwide.

Case 1 – The patient and his family appeared horrified. What had begun as a seemingly routine medical examination had turned into a nightmare. The man appeared healthy but had complained of persistent headaches. The CT scan showed what was diagnosed to be a massive tumour on the brain. Declining surgery, he still managed to get a substantial disability pay-out from his insurers who were unaware of his brilliance at writing computer programs.

Craig Rosewarne

Pending his nomination he undertook a thorough medical check-up and was declared fit as a fiddle. A month later he collapsed at a fundraising function and died of a major arterial embolism in the brain. The underworld rejoiced.

Do the above case scenarios sound strange? Not if one considers that researchers in Israel recently announced that they’d created a computer virus capable of adding or removing images of tumours into CT and MRI scans, malware designed to fool doctors into misdiagnosing low- to high-profile patients. This short video is scary yet fascinating:

The healthcare industry has become one of the leading attack vectors worldwide for several reasons. Firstly, it maintains huge amounts of highly sensitive patient data, a juicy target for hackers who can use it for financial gain, humiliation or revenge. Access to a medical database would allow a miscreant to alter medical records, delete them or hold them hostage using ransomware.

Secondly, medical institutions are far more likely to accede to ransomware demands when patients’ lives are at stake. The healthcare industry increasingly relies on IoT (Internet of Things) technology that’s connected to the Internet, which ranges from patient records and lab results to radiology equipment. Even catering and down to maintenance of the hospitals are impacted. The 2017 WannaCry ‘epidemic’ caused chaos in the healthcare industry, the UK in particular being hard hit. Many institutions were found to still be running their systems on outdated, end-of-life, unpatched Windows XP devices.

Healthcare lags far behind other industries, experts say, unlike the financial sector, in the way it protects its information technology infrastructure. A healthcare failure can end with injury or even death, unlike finance which may involve a slap on the wrist or a fine.

Not a matter of when or if…

Medical institutions are being bombarded with malicious attacks every day. Many do not even know that they are already infected as many viruses can lay dormant or continue to seek new backdoors until activated. Advanced Persistent Threats (ATPs) are sometimes only discovered 18 months after breaching the system. Another major problem is that most medical personnel do not know what system devices are running on. Many service providers have gone out of business and patches, when provided, are often not implemented. Many small medical facilities do not have the budget for a full-time IT team and those in rural areas are at greater risk, especially if they are connected to the main urban centres. The country cousins can infect their city slickers – remember, everything is connected.

What other dangers do the health industries and medical devices face? Pacemakers have been proven to be easily hackable. The device can be instructed to speed up, slow down, behave in an erratic fashion or even shut down. ECGs, scanners and X-rays may give false readings or simply be unavailable. Hospitals’ and clinics’ emergency power generators can be disabled, preventing any tests, operations, etc. during a mains outage, which are a common occurrence here in sunny South Africa.

Why is the health industry lagging behind other enterprises? Low budgets play a major part, but the lack of awareness regarding the enormity of the threats from governments, decision makers down to grass-level employees is extremely worrying. The perceived attitude that no-one would be so callous as to attack a medical establishment and endanger human lives or cause fatalities is pervasive. Many hackers don’t care. The monetary rewards far outweigh any feelings of guilt or remorse.

There is a pulse, but it is very weak.

Share this article:
Share via emailShare via LinkedInPrint this page

Further reading:

Pentagon appointed as Milestone distributor
Elvey Security Technologies News & Events Surveillance
Milestone Systems appointed Pentagon Distribution (an Elvey Group company within the Hudaco Group of Companies) as a distributor. XProtect’s open architecture means no lock-in and the ability to customise the connected video solution that will accomplish the job.

SMART Estate Security returns to KZN
Nemtek Electric Fencing Products Technews Publishing Axis Communications SA OneSpace Editor's Choice News & Events Integrated Solutions IoT & Automation
The second SMART Estate Security Conference of 2024 was held in May in KwaZulu-Natal at the Mount Edgecombe Estate Conference Centre, which is located on the Estate’s pristine golf course.

From the editor's desk: Just gooi a cable
Technews Publishing News & Events
      Welcome to the 2024 edition of the SMART Estate Security Handbook. We focus on a host of topics, and this year’s issue also has a larger-than-normal Product Showcase section. Perhaps the vendors are ...

Secutel wins OSPA Award for Outstanding New Security Product
Secutel Technologies News & Events Access Control & Identity Management
[Sponsored] Secutel Technologies’ NoKey Access Control solution won the Outstanding New Security Product category at the 2024 OSPAs in South Africa. The awards were presented at Securex 2024 where all category finalists were recognised for their contribution to the security industry.

ONVIF launches new working groups for cloud, metadata and audio
News & Events Surveillance
ONVIF, the global standardisation initiative for IP-based physical security products, is announcing the formation of three new working groups to tackle standardisation work in cloud connectivity, audio, and advanced metadata.

Inaugural Gallagher Security Johannesburg networking roadshow
Gallagher News & Events
Held at Johannesburg’s Foghound Coffee Company in Midrand from 11 to 12 June, security industry professionals gather at the inaugural Gallagher Security Johannesburg Networking Roadshow.

Trend Micro launches first security solutions for consumer AI PCs
Information Security News & Events
Trend Micro unveiled its first consumer security solutions tailored to safeguard against emerging threats in the era of AI PCs. Trend will bring these advanced capabilities to consumers in late 2024.

Dallmeier receives ISO 27001 certification
Dallmeier Electronic Southern Africa Surveillance News & Events
Dallmeier has received ISO 27001 certification for its Information Security Management System (ISMS). The international standard for information security management ensures that companies meet the highest standards of data protection and data security.

AI and ransomware: cutting through the hype
AI & Data Analytics Information Security
It might be the great paradox of 2024: artificial intelligence (AI). Everyone is bored of hearing it, but we cannot stop talking about it. It is not going away, so we had better get used to it.

Local manufacturing is still on the rise
Hissco Editor's Choice News & Events Security Services & Risk Management
HISSCO International, Africa's largest manufacturer of security X-ray products, has recently secured a multi-continental contract to supply over 55 baggage X-ray screening systems in 10 countries.