Events Calendar

Mon
Tue
Wed
Thu
Fri
Sat
Sun
M
T
W
T
F
S
S
30
31
2
4
5
10
11
12
13
14
15
20
21
22
23
24
25
26
27
12:00 AM - Arab Health 2020
29
1
2
5th International Conference On Recent Advances In Medical Science ICRAMS
2020-01-01 - 2020-01-02    
All Day
2020 IIER 775th International Conference on Recent Advances in Medical Science ICRAMS will be held in Dublin, Ireland during 1st - 2nd January, 2020 as [...]
01 Jan
2020-01-01 - 2020-01-02    
All Day
The Academics World 744th International Conference on Recent Advances in Medical and Health Sciences ICRAMHS aims to bring together leading academic scientists, researchers and research [...]
03 Jan
2020-01-03 - 2020-01-04    
All Day
Academicsera – 599th International Conference On Pharma and FoodICPAF will be held on 3rd-4th January, 2020 at Malacca , Malaysia. ICPAF is to bring together [...]
The IRES - 642nd International Conference On Food Microbiology And Food SafetyICFMFS
2020-01-03 - 2020-01-04    
All Day
The IRES - 642nd International Conference on Food Microbiology and Food SafetyICFMFS aimed at presenting current research being carried out in that area and scheduled [...]
World Congress On Medical Imaging And Clinical Research WCMICR-2020
2020-01-03 - 2020-01-04    
All Day
The WCMICR conference is an international forum for the presentation of technological advances and research results in the fields of Medical Imaging and Clinical Research. [...]
International Conference On Agro-Ecology And Food Science ICAEFS
2020-01-06    
All Day
The key intention of ICAEFS is to provide opportunity for the global participants to share their ideas and experience in person with their peers expected [...]
RW- 743rd International Conference On Medical And Biosciences ICMBS
2020-01-07 - 2020-01-08    
All Day
RW- 743rd International Conference on Medical and Biosciences ICMBS is a prestigious event organized with a motivation to provide an excellent international platform for the [...]
International Conference On Nursing Ethics And Medical Ethics ICNEME
2020-01-08 - 2020-01-09    
All Day
An elegant and rich premier global platform for the International Conference on Nursing Ethics and Medical Ethics ICNEME that uniquely describes the Academic research and [...]
International Conference On Medical And Health SciencesICMHS-2020
2020-01-09 - 2020-01-10    
All Day
The ICMHS conference is an international forum for the presentation of technological advances and research results in the fields of Medical and Health Sciences. The [...]
12th Annual ICJR Winter Hip And Knee Course
2020-01-16 - 2020-01-19    
All Day
Make plans to join us in Vail, Colorado, for the 12th Annual Winter Hip And Knee Course, the premier winter meeting focused on primary and [...]
3rd Big Sky Cardiology Update 2020
2020-01-17 - 2020-01-18    
All Day
ABOUT 3RD BIG SKY CARDIOLOGY UPDATE 2020 Following the success of the 2nd edition, I am pleased to invite you to the “3rd Big Sky [...]
A4M India Conference
2020-01-18 - 2020-01-20    
All Day
ABOUT A4M INDIA CONFERENCE Taking place for the first time in New Delhi, India, this two-day event will serve as a foundational course in the [...]
International Conference On Oncology & Cancer Research ICOCR-2020
2020-01-19 - 2020-01-20    
All Day
The ICOCR conference is an international forum for the presentation of technological advances and research results in the fields of Oncology & Cancer Research. The [...]
Arab Health 2020
2020-01-27 - 2020-01-30    
All Day
ABOUT ARAB HEALTH 2020 Arab Health is an industry-defining platform where the healthcare industry meets to do business with new customers and develop relationships with [...]
12th International Conference on Acute Cardiac Care
2020-01-28 - 2020-01-29    
All Day
ABOUT 12TH INTERNATIONAL CONFERENCE ON ACUTE CARDIAC CARE Acute Cardiac Care has been undergoing a substantial transformation in recent years as the population ages and [...]
30 Jan
2020-01-30 - 2020-01-31    
All Day
The ICMHS conference is an international forum for the presentation of technological advances and research results in the fields of Medical and Health Sciences. The [...]
Annual Lower and Upper Canada Anesthesia Symposium 2020 (LUCAS)
2020-01-31 - 2020-02-02    
All Day
ABOUT ANNUAL LOWER & UPPER CANADA ANESTHESIA SYMPOSIUM 2020 (LUCAS) On behalf of the Departments of Anesthesia of McGill University, Queen’s University, and the University [...]
RF - 577th International Conference On Medical & Health Science - ICMHS 2020
2020-02-02 - 2020-02-03    
All Day
577th International Conference on Medical & Health Science - ICMHS 2020. It will be held during 2nd-3rd February, 2020 at Berlin , Germany. ICMHS 2020 [...]
ISER- 747th International Conference On Science, Health And Medicine ICSHM
2020-02-02 - 2020-02-03    
All Day
ISER- 747th International Conference on Science, Health and Medicine ICSHM is a prestigious event organized with a motivation to provide an excellent international platform for [...]
Events on 2020-01-08
Events on 2020-01-09
Events on 2020-01-16
Events on 2020-01-17
Events on 2020-01-18
A4M India Conference
18 Jan 20
Haridwar
Events on 2020-01-27
Arab Health 2020
27 Jan 20
Dubai
Events on 2020-01-28
Events on 2020-01-30
Events on 2020-01-31
Latest News

Temporary hospitals are rife with cybersecurity vulnerabilities

Temporary hospitals are rife with cybersecurity vulnerabilities

The COVID-19 outbreak has led to a series of rapidly established medical-treatment units the world over, which will be utilizing remote-care devices that lack proper protection. The situation gives hackers more opportunities to perpetrate attacks. They could also infiltrate these devices to steal a patient’s personal health information, causing complications for both the users of these devices and the healthcare providers themselves.

Temporary medical units carry a unique set of vulnerabilities due to the fact they are remote and sit outside of a defense-in-depth architecture. Because of the very nature of their purpose – to care for patients in a time of crisis – IT security is naturally lower on the priority list.

“They are being set up quite quickly with constrained budgets, and the budget for those is not on IT, it’s on PPE, patient care, getting testing set up, everything a center should be focused on during this crisis,” Tom Burt, corporate vice president of Microsoft Customer Security & Trust, told Healthcare IT News.

He explained that some immediate steps healthcare organizations can take include making sure software is updated and fully patched – what Burt calls the “number one hygiene” measure they can do to make sure they are resilient – as well as enabling two-factor authentication for every account that has access to the pop-up center’s system.

Because ransomware and phishing attacks are the most common types of cyberattacks on healthcare systems, Burt also recommends ensuring the system is backed up offline, and going through practice exercises.

“If you are a victim of ransomware, you want to make sure you get your system back up and running as quickly as possible so you don’t have to pay the criminals to get your data back,” he said.

While he noted the transmission of the data from a temporary facility to a home facility like the CDC or WHO is not particularly vulnerable, what he has seen is state actors looking for the most vulnerable point in a communications network.

Those state actors may focus on those temporary facilities as vulnerable points, and if they can successfully infect that facility, they can use that control over a device to further communicate with another organization.

“That communication would then appear to be legitimately coming from the pop-up facility, and it’s easier to get the recipient to click on the link and get themselves infected,” he said.

To that end, Microsoft recently expanded the availability of its AccountGuard security service program to help healthcare organizations defend themselves against cyberattacks from nation states.

The company has also rolled out a series of services to help bolster security during the outbreak, including advisories on protection from COVID-19-related phishing attacks.

Administrators already fight on a daily basis to patch, upgrade and maintain physical systems within predefined facilities, and these systems are available 24/7, 365 days a year, which means there is a constant routine to maintain security hygiene.

“On the other hand, temporary medical units are impossible to maintain for the reason they are not often employed,” Travis Volk, technical vice president at Radware, explained. “Because these weaker networks are also connected to broader medical organizations, it increases the potential entry points for hackers seeking to infiltrate a hospital.”

He noted it’s also true that using wireless connectivity opens a localized opportunity for hackers to monitor traffic over air and increase the odds of identifying legitimate credentials to simplify their access.

Natali Tshuva, CEO and cofounder of IoT cybersecurity company Sternum, said it’s the rapid deployment of these temporary medical units that concerns her the most.

“Because we are establishing these units so quickly, there simply is not enough time to build the proper IT infrastructure to protect the overall network, either via an effective firewall or through other cybersecurity measures,” she said.

Furthermore, the vast majority of these temporary medical units will be highly dependent on connected medical devices due to the demands of remote care, monitoring devices and infrastructure like smart beds.

These medical IoT devices rarely have any embedded security and remain particularly vulnerable, Tshuva noted, and pointed out healthcare organizations came into this pandemic facing an uphill struggle.

Now, as they must establish these temporary medical centers to battle the consequences of the pandemic, the cybersecurity risks are further heightened.

“If we were not in the midst of a pandemic, defense measures established by broader medical organizations would have more of a fighting chance to stop malicious parties from being able to initiate attacks against medical devices within hospitals, as these devices would be in a controlled environment,” she explained. “But these temporary medical units leave the connected medical environment more exposed than ever before.”

Caleb Barlow, CEO of cybersecurity firm CynergisTek, pointed out that in addition to temporary facilities, there are now hundreds of thousands of remote-healthcare workers who are not working directly with patients but have access to providers, patient data, and financial data, and are on the same email system.

“Gaining access to the remote worker is one thing, but now using that access to get into the hospital’s resources creates a situation that, frankly, no provider was prepared for,” he said.

“Added to the quick deployment in less than ideal circumstances, you now have users who have most likely not been fully trained on new devices, new networks and a new set of login credentials in many cases.”

Barlow explained that in a remote medical facility, when a physician is accessing the electronic healthcare records, the endpoint and the network are totally unknown.

In many cases, these remote facilities are in stadiums or convention centers running on the network in that location, which likely lacks the network-security provisions that one would normally expect.

“The endpoint is also unknown, and might be a shared computer, personal workstation or a rented laptop,” he said. “The only layer of security left are the access credentials and, simply put, if the bad guy has those, then they are likely inside the EHR.”