Events Calendar

Mon
Tue
Wed
Thu
Fri
Sat
Sun
M
T
W
T
F
S
S
1
2
3
4
5
6
7
8
9
10
14
15
16
17
18
19
20
21
22
24
25
27
31
12:00 AM - EXPO.health
1
2
3
4
11 Jul
2019-07-11 - 2019-07-13    
All Day
2019 Annual Meeting and Scientific Seminar is Oraganized by American College of Neuropsychiatrists/American College of Osteopathic Neurologists and Psychiatrists (ACN/ACONP) and will be held from [...]
Breast Cancer: New Horizons, Current Controversies 2019
2019-07-11 - 2019-07-13    
All Day
Breast Cancer: New Horizons, Current Controversies is organized by Harvard Medical School (HMS) and will be held from Jul 11 - 13, 2019 at Boston [...]
11 Jul
2019-07-11 - 2019-07-12    
All Day
Pediatric Colorectal Scientific Meeting (PCSM) is organized by Intermountain Healthcare Interprofessional Continuing Education (IPCE) and will be held from Jul 11 - 12, 2019 at [...]
12 Jul
2019-07-12 - 2019-07-14    
All Day
Infectious Disease for Primary Care is organized by Medical Education Resources (MER) and will be held from Jul 12 - 14, 2019 at Disney's Contemporary [...]
12 Jul
2019-07-12 - 2019-07-14    
All Day
Dermatology for Primary Care is organized by Medical Education Resources (MER) and will be held from Jul 12 - 14, 2019 at Disney's Grand Californian [...]
12 Jul
2019-07-12 - 2019-07-14    
All Day
Office Orthopedics for Primary Care is organized by Medical Education Resources (MER) and will be held from Jul 12 - 14, 2019 at Bellagio Hotel [...]
13 Jul
2019-07-13 - 2019-07-19    
All Day
Association for Healthcare Philanthropy (AHP) Madison Institute is organized by Association for Healthcare Philanthropy (AHP) and will be held during Jul 13 - 19, 2019 [...]
13 Jul
2019-07-13 - 2019-07-14    
All Day
Red Cells Gordon Research Seminar (GRS) is organized by Gordon Research Conferences (GRC) and will be held from Jul 13 - 14, 2019 at Salve [...]
47th Annual Institute and Conference - "Advancing Nursing Practice: Innovation, Access and Health Equity"
2019-07-23 - 2019-07-28    
All Day
47th Annual Institute and Conference - "Advancing Nursing Practice: Innovation, Access and Health Equity" is organized by National Black Nurses Association (NBNA), Inc. and will [...]
2nd International Conference on  Medical and Health Science
2019-07-26 - 2019-07-27    
All Day
Date: July 26-27, 2019 Melbourne, Australia Theme: Scrutinize the Modish of Medical and Health Science "2nd International Conference on Medical and Health Science" on July [...]
Pediatric and Adolescent Medicine, Pediatric Critical Care, Developmental Pediatrics, and ADHD
2019-07-26 - 2019-08-02    
All Day
Pediatric and Adolescent Medicine, Pediatric Critical Care, Developmental Pediatrics, and ADHD is organized by Continuing Education, Inc and will be held from Jul 26 - [...]
Cosmetic Pearls for the General Dental Practitioner
2019-07-26 - 2019-08-02    
All Day
Cosmetic Pearls for the General Dental Practitioner is organized by Continuing Education, Inc and will be held from Jul 26 - Aug 02, 2019 at [...]
Neuroethology: Behavior, Evolution and Neurobiology Gordon Research Conference (GRC) 2019
2019-07-28 - 2019-08-02    
All Day
Neuroethology: Behavior, Evolution and Neurobiology Gordon Research Conference (GRC) is organized by Gordon Research Conferences (GRC) and will be held from Jul 28 - Aug [...]
Molecular and Cellular Biology of Lipids Gordon Research Conference (GRC) 2019
2019-07-28 - 2019-08-02    
All Day
Molecular and Cellular Biology of Lipids Gordon Research Conference (GRC) is organized by Gordon Research Conferences (GRC) and will be held from Jul 28 - [...]
37th Annual Conference on Pediatric Infectious Diseases
2019-07-28 - 2019-08-02    
All Day
37th Annual Conference on Pediatric Infectious Diseases is organized by Children's Hospital Colorado and will be held from Jul 28 - Aug 02, 2019 at [...]
32nd Annual Summer Seminar in Health Care Ethics & Surgical Ethics
2019-07-29 - 2019-08-02    
All Day
32nd Annual Summer Seminar in Health Care Ethics & Surgical Ethics is organized by University of Washington School of Medicine (UWSOM) Continuing Medical Education (CME) [...]
3-Day Physician Assistant PANCE / PANRE Board Review Course by Certified Medical Educators (CME) - Salt Lake City
2019-07-29 - 2019-07-31    
All Day
3-Day Physician Assistant PANCE / PANRE Board Review Course is organized by Certified Medical Educators (CME) and will be held from Jul 29 - 31, [...]
Four Week Radiologic Pathology Correlation Course (Jul 29 - Aug 23, 2019)
2019-07-29 - 2019-08-23    
All Day
Four Week Radiologic Pathology Correlation Course is organized by American Institute for Radiologic Pathology (AIRP) and will be held from Jul 29 - Aug 23, [...]
Third Annual Philadelphia Trauma Training Conference
2019-07-30 - 2019-08-01    
All Day
Third Annual Philadelphia Trauma Training Conference is organized by Thomas Jefferson University (TJU) and will be held from Jul 30 - Aug 01, 2019 at [...]
IDAA Annual Meeting 2019
2019-07-31 - 2019-08-04    
All Day
International Doctors in Alcoholics Anonymous (IDAA) 70th Annual Meeting 2019 is organized by International Doctors in Alcoholics Anonymous (IDAA) and will be held from Jul [...]
EXPO.health
2019-07-31 - 2019-08-02    
All Day
EXPO.health Schedule July 31 - August 2, 2019 - Location: Boston, MA Join us at EXPO.health (Formerly Healthcare IT Expo – HITExpo) 2019 happening July [...]
01 Aug
2019-08-01 - 2019-08-03    
All Day
UCSF CME: Neurosurgery Update 2019 is organized by The University of California, San Francisco (UCSF) Office of Continuing Medical Education and will be held from [...]
PBI Medical Ethics & Professionalism (ME-22) - Irvine
2019-08-02 - 2019-08-03    
All Day
PBI Medical Ethics & Professionalism (ME-22) is organized by Professional Boundaries, Inc. (PBI) and will be held from Aug 02 - 03, 2019 at Wyndham [...]
The 8th Beijing International Top Health & Medical Exhibition (BIHM)
2019-08-02 - 2019-08-04    
All Day
The 8th Beijing International Private Health and Medical Exhibition will be held at the China International Exhibition Center from August 2nd to August 4th, 2019. [...]
Angiogenesis Gordon Research Seminar (GRS) 2019
2019-08-03 - 2019-08-04    
12:00 am
Angiogenesis Gordon Research Seminar (GRS) is organized by Gordon Research Conferences (GRC) and will be held from Aug 03 - 04, 2019 at Salve Regina [...]
Lung Development, Injury and Repair Gordon Research Seminar (GRS) 2019
2019-08-03 - 2019-08-04    
All Day
Lung Development, Injury and Repair Gordon Research Seminar (GRS) is organized by Gordon Research Conferences (GRC) and will be held from Aug 03 - 04, [...]
Platelet Rich Plasma for Aesthetics Course - Miami (Aug 2019)
Platelet Rich Plasma for Aesthetics Course is organized by Empire Medical Training (EMT), Inc and will be held on Aug 04, 2019 at GALLERYone - [...]
Physician Medical Weight Loss Training (Aug 04, 2019)
2019-08-04    
All Day
Physician Medical Weight Loss Training is organized by Empire Medical Training (EMT), Inc and will be held on Aug 04, 2019 at The Platinum Hotel [...]
Events on 2019-07-11
Events on 2019-07-30
Events on 2019-07-31
IDAA Annual Meeting 2019
31 Jul 19
Knoxville
EXPO.health
31 Jul 19
Boston
Events on 2019-08-01
01 Aug
Latest News

Cloud-connected devices need a fresh scan for security issues

Medical devices increasingly represent a weakness in security for most healthcare organizations, which typically use hundreds of diverse devices from dozens of manufacturers. Equipment ranging from infusion pumps to hospital beds to Bluetooth-enabled devices can be 10 or more years old, working on old, vulnerable operating or application systems, and they’re often in close proximity to patients and essential in providing life-saving treatment.

Because an increasing number of these devices are connected to the cloud, it’s time to take a structured approach to ensuring that security risks are managed closely, said James L. Angle, an information security architect at Trinity Health, a Livonia, Michigan-based Catholic healthcare system. Angle detailed the growing risk of cloud-linked devices’ security risks, as well as an approach for tightening up defenses based on their proximity to patients during his recent HIMSS20 Digital presentation, Managing the Risk for Medical Devices Connected to the Cloud.

Mitigating device security risks should begin before they’re purchased, Angle said. He outlined five “degrees of separation” medical devices can have from patients, and security professionals’ strategy for strengthening security varies among the different categories. They are:

Devices implanted in the patient

1: Devices that touch the patient, such as a blood-gas monitor in an ICU

2: Devices that don’t touch the patient, but take vital measurements, such as a blood pressure monitor

3: Devices that don’t touch the patient, but still provide data vital to proper patient diagnosis

4: Devices that are separate and are more of an operational tool vs. one that’s diagnostic or clinical

Before any devices are purchased, security professionals need to be involved, collecting documents such as the manufacturer’s disclosure statement on medical device security, augmenting those formal statements with additional security questions, Angle said. Based on that information, it’s crucial to conduct a risk assessment and threat assessment.

“Pay special attention to [security] controls that the manufacturers say are in place,” Angle noted. “Look at all the related software, both for the device’s operating system and application system. Some of these devices have database software connected to it. Identify all the connections for the data; know where the data is being processed and where the patient data is being stored – in multiple devices on site, network storage media or in the cloud. Each one of those has different security requirements.”

Various organizations provide a technical framework outlining security postures for devices that handle health information – these include the National Institute of Standards Technology, HITRUST and the International Organization for Standardization. “When you’re doing a control assessment, it’s important to use a recognized framework,” he said.

Contracts for device purchases should ensure that all threats and vulnerabilities are addressed, even though not all of them can be corrected or remediated. For example, contracts should specify how quickly patches are applied to resolve security issues, ranging from two weeks for high-priority patches to four weeks for low-priority fixes.

“A lot of times, vendors will not let you apply the patch to their devices – they want to do it themselves. If it takes them a year to come out and apply the patch, that’s a problem.” Once devices are purchased and in use, it falls to operations management to manage security protection, which is crucial for devices that are managed via cloud services or upload data to the cloud. Different levels of attention are necessary the closer devices are to patients.

For example, implanted devices “present a unique set of issues,” Angle said. “The device on its own typically does not connect directly to the Internet or the cloud – a pacemaker usually does so through another device, for example, like a handheld device that you hold up next to the patient, which then reads information off the pacemaker, which then connects to a base station or a smart device. In that case, you have multiple points to check for security.”

With implanted devices, typical concerns include how the devices accomplish identity and access management, and how the health organization ensures that new vulnerabilities are remediated. IAM is critical on implanted devices because patients can be in settings where devices might be easily accessed and hacked.

Depending on their proximity to patients, medical devices can be difficult to patch, Angle said in outlining challenges for the various degrees of separation from patients. IAM issues are common to almost all types of devices, and it can be difficult to run antivirus programs and apply necessary patches while they are in service.

Manufacturers of some devices don’t allow antivirus software to be installed on them, and they may have weak or no IAM, which makes it difficult to layer on essential security for devices that connect to the cloud. In these cases, devices can be somewhat insulated by segmenting them on the network and controlling the data flow to and from the device, Angle said.

For devices that connect to the cloud, healthcare organizations should collect log files wherever possible and implement a cloud access security broker solution. “What this does is identify all the PHI data going into the cloud and also encrypts the data. Providers also need to assess cloud security, and the Cloud Security Alliance IoT control matrix is a good place to start,” he said.