Events Calendar

Mon
Tue
Wed
Thu
Fri
Sat
Sun
M
T
W
T
F
S
S
26
27
28
29
30
31
1
2
3
4
6
7
8
10
11
12
13
14
15
17
18
20
21
22
24
25
28
29
30
31
1
2
3
4
5
Food and Beverages
2021-07-26 - 2021-07-27    
12:00 am
The conference highlights the theme “Global leading improvement in Food Technology & Beverages Production” aimed to provide an opportunity for the professionals to discuss the [...]
European Endocrinology and Diabetes Congress
2021-08-05 - 2021-08-06    
All Day
This conference is an extraordinary and leading event ardent to the science with practice of endocrinology research, which makes a perfect platform for global networking [...]
Big Data Analysis and Data Mining
2021-08-09 - 2021-08-10    
All Day
Data Mining, the extraction of hidden predictive information from large databases, is a powerful new technology with great potential to help companies focus on the [...]
Agriculture & Horticulture
2021-08-16 - 2021-08-17    
All Day
Agriculture Conference invites a common platform for Deans, Directors, Professors, Students, Research scholars and other participants including CEO, Consultant, Head of Management, Economist, Project Manager [...]
Wireless and Satellite Communication
2021-08-19 - 2021-08-20    
All Day
Conference Series llc Ltd. proudly invites contributors across the globe to its World Convention on 2nd International Conference on Wireless and Satellite Communication (Wireless Conference [...]
Frontiers in Alternative & Traditional Medicine
2021-08-23 - 2021-08-24    
All Day
World Health Organization announced that, “The influx of large numbers of people to mass gathering events may give rise to specific public health risks because [...]
Agroecology and Organic farming
2021-08-26 - 2021-08-27    
All Day
Current research on emerging technologies and strategies, integrated agriculture and sustainable agriculture, crop improvements, the most recent updates in plant and soil science, agriculture and [...]
Agriculture Sciences and Farming Technology
2021-08-26 - 2021-08-27    
All Day
Current research on emerging technologies and strategies, integrated agriculture and sustainable agriculture, crop improvements, the most recent updates in plant and soil science, agriculture and [...]
CIVIL ENGINEERING, ARCHITECTURE AND STRUCTURAL MATERIALS
2021-08-27 - 2021-08-28    
All Day
Engineering is applied to the profession in which information on the numerical/mathematical and natural sciences, picked up by study, understanding, and practice, are applied to [...]
Diabetes, Obesity and Its Complications
2021-09-02 - 2021-09-03    
All Day
Diabetes Congress 2021 aims to provide a platform to share knowledge, expertise along with unparalleled networking opportunities between a large number of medical and industrial [...]
Events on 2021-07-26
Food and Beverages
26 Jul 21
Events on 2021-08-05
Events on 2021-08-09
Events on 2021-08-16
Events on 2021-08-19
Events on 2021-08-23
Events on 2021-09-02
Latest News

FDA issues cybersecurity alert on GE Healthcare medical devices

FDA issues cybersecurity alert on GE Healthcare medical devices

The U.S. Food and Drug Administration has put out a safety alert concerning GE Healthcare Clinical Information Central Stations and Telemetry Servers, which it says could pose risks to the patients they’re monitoring fda issues cybersecurity alert

FDA issued the safety communication, which concerns cybersecurity vulnerabilities in the devices, following GE Healthcare’s own issuance in November 2019 of a letter informing consumers of the security vulnerabilities in the listed devices, as well as directions to software updates and patches.

The specific security risk concerns a vulnerability within the Clinical Information Central Stations and Telemetry Servers that could allow a hacker to change settings and configurations inside the device, including the ability to silence alarms or otherwise interfere with the patient monitoring capabilities.

“These vulnerabilities might allow an attack to happen undetected and without user interaction,” FDA noted in its communication. “Because an attack may be interpreted by the affected device as normal network communications, it may remain invisible to existing security measures.”

Telemetry servers and clinical information central stations are used mostly in health care facilities for displaying temperature, heartbeat, blood pressure, and other physiologic parameters of a patient.

The listed devices include the ApexPro Telemetry Server and CARESCAPE Telemetry Server running software version 4.2 or earlier, CARESCAPE Central Station (CSCS) version 1 running software 1.x, and CIC Pro Clinical Information Center Central Station version 1, running software versions 4.x and 5.x.

FDA recommends providers work with staff to determine which devices and patients may be affected and take appropriate steps to reduce risk, the agency said, noting that it was thus far unaware of any “adverse events” related to the software vulnerabilities.

GE Healthcare will be issuing a software patch to address the vulnerabilities and will notify affected customers to deploy them when the patches are ready.

In the meantime, the risk posed by the vulnerabilities can be reduced by segregating the network connecting the patient monitors with the GE Healthcare Clinical Information Central Stations and Telemetry Servers from the rest of the hospital network, as described in the GE Healthcare documentation for these devices.

FDA said to use firewalls, segregated networks, virtual private networks, network monitors, or other technologies that minimize the risk of remote or local network attacks.

The safety communication also noted the security risk could be reduced by segregating the devices in question from the rest of the hospital network, as well as through the use of firewalls, virtual private networks and network monitors.

According to research CyberMDX, the common element across these vulnerabilities–beyond the devices they affect and their shared point of discovery–is that they all present a direct path to the device’s compromise, whether by way of illicit control, read, write, or upload capabilities.

Meanwhile, the CEO of third-party risk management specialist Censine, Ed Gaudet, released a statement calling for a fundamental rethink in the way health providers approach risk assessment and third-party medical devices.

“Malicious actors have gotten very good at identifying and exposing weak links in healthcare security,” Gaudet,’s statement noted. “Unfortunately, it’s becoming increasingly common that the weakest link is a third-party medical device.”