Why healthcare’s medical device challenges will never be addressed in isolation – SC Media
The governments push for threat sharing and collaboration, with the uptick in alerts directed to the healthcare sector, are a welcomed shift in the longstanding efforts to curtail cybersecurity challenges with overall awareness and cyber posture in the industry.
But awareness doesnt always translate into a viable solution, particularly when it comes to tackling the minutiae of medical devices. Due to the sheer complexity of the device ecosystem, resource constraints, and knowledge gaps, even the largest health systems struggle to solve the risk management challenges.
I think medical devices and biomed in general are really kind of the redheaded-stepchild of healthcare organizations because they're complex, and nobody really knows how to deal with them, said Ben Denkers, CynergisTeks chief innovation officer.
Consider the FBI alert on legacy medical devices, which resounded the bullhorn on risks associated with leveraging legacy tech in devices directly tied to patients. For many in healthcare, the messages rang familiar: groups like CHIME have long-warned of patch management issues and the impossibility of a real-time inventory in the healthcare environment. Similarly, the recommendations were rather vanilla: basic blocking and tackling at the end of the day.
Certainly, such reminders do no harm encouraging some healthcare entities to leverage technology as a safeguard to defend against a specific threat or to reduce overall risk. But some argue that the challenges facing many providers cant be boiled down into a singular problem or solution, and that the current assessment of risk could leave a vulnerable market unable to see the forest through the trees.
SC Media spoke to Denkers about this quandary, and how the market can better address multiple and sometimes conflicting hurdles to cybersecurity.
When the onslaught of ransomware attacks against healthcare began in 2016, the rallying cry was that there was no silver bullet to solve cybersecurity challenges. The sentiment remains, for both overall infrastructure and device security vulnerabilities.
As its likely always been in healthcare, the crux of its issues is actually a combination of resource and knowledge constraints, which are needed to truly have an effective security and privacy program, Denkers explained. Providers need a combination of people, processes, and technology to have a successful privacy and security program, even before its applied to a specific area like medical devices.
If you don't have enough resources, it's going to be problematic. If you don't have the right technology, you're going to have issues. And if you don't have the right processes to make sure all of those are working and effective, it doesn't do you any good, said Denkers.
That's the problem. It's not a singular issue of, hey, we don't have the right technology to stop the attack, he continued. Let's say, magically, you can wave your wand and put in some sort of endpoint protection on all the medical devices. Great. But what happens if you don't have the people to monitor the alerts or have to deal with a device being compromised? It doesn't really do you any good.
That means that even when a problem is identified, it still cant be remediated without the effective processes or controls. And if the problem persists, it can create downstream effects when the device remains in use, which could still cause patient safety impacts.
Further, if hospital leadership doesnt know how to use the actual security technology, its not going to do a whole lot, said Denkers. Others are struggling without the resources to manage or monitor the tools, or even tweak them to make it effective in the environment.
I've had countless conversations with individuals at healthcare organizations, and similarly where they've invested a lot of money in technology for it to sit in the corner because they don't have the resources or the know-how, or the physical resources to take the device and implement it, he added.
And they certainly don't have the resources to validate that it's working. Medical device security is important, it absolutely is. But you're also talking to organizations that probably, I would venture to guess, don't even have endpoint protection.
Some resource issues are financially driven; organizations dont have the money to make investments in the technology stack, or afford to hire the right people. Hiring challenges also persist for rural providers, who may not be able to physically get people into the organization.
Many rural hospitals face staffing challenges based on location alone, he said. Healthcare is facing all of these problems, not just with medical devices and the higher level of risk due to the direct attachment to care. But if you really start to unpeel the layers, you'll start to see that healthcare in general still isn't isn't necessarily the poster child for security and privacy programs.
Denkers posed an important question: if a car manufacturer had vehicles on the road that generally did what they were supposed to do, but passengers were at risk due to a faulty airbag, or malfunctioning brakes, what would happen? The manufacturer would be forced to make changes.
The reason why we're having to deal with these problems is because [medical devices] weren't properly developed from the beginning, he mused. It all starts with the software development life cycle, and where does SDLC start? It's whoever is developing the product or the solution.
If issues aren't properly vetted at the beginning of the development cycle, risks emerge. As Denkers sees it, it's the responsibility of the vendor to have a better product.
It's a snowball effect: you're never really actually going to catch up because it's just going to continue to get worse and worse and worse every time you have outdated software or end-of-life hardware and products.
It's interesting, those types of risks wouldn't be accepted in any other organization. But for some reason, we're dealing with people, which arguably have the highest rates of consequences, and it's okay, said Denkers.
The FBI alert was likely intended to reflect the current threats facing vulnerable platforms, warning that bad actors are increasingly using unpatched medical devices to gain a foothold on the network.
But the alert should instead serve as a guidepost: An exploit could ultimately impact the integrity and confidentiality of data, or even worse, cause disruptions in operational functions and impact patient safety.
Use this as a compass or a North Star, Denkers recommended, and review the guidance to verify just how well medical devices are being protected. Many in healthcare are in situations where they think they have certain safeguards in place, or some version of recommended safeguards, inadvertently miss the most important element amid the noise.
As Denkers plainly puts it, The question then really becomes: How effective is that control?
An entity may have endpoint protection or access controls, but be unaware of potential gaps in the environment, or unclear whether tools adequately address vulnerabilities. Some organizations generally don't have a mechanism in place to validate how effective controls are whether it be people, processes, or technology, he explained.
Segmentation is one of those areas where an entity might decide to separate certain devices from the main network, but then management of those devices is handled by another department. They set security and forget it. But as noted by Denkers, if they're connected to the network, they're still connected to patients.
And such oversights bring grave consequences. If a device or supporting infrastructure were to be compromised, and the device needs the internet to function or access certain portions of the environment, the medical devices cant function for patient care.
Depending on the organization's requirements, there can be many downstream effects from general compromises on the IT environment that become problematic quickly.
See the original post here:
Why healthcare's medical device challenges will never be addressed in isolation - SC Media
- Netanyahu's Government Moves to Stifle Journalism and Take Control of the Israeli Media - Haaretz - November 7th, 2025 [November 7th, 2025]
- Media bill wont give government direct editorial control, but risks putting press in biased, moneyed hands - The Times of Israel - November 5th, 2025 [November 5th, 2025]
- Likud ministers contentious media regulation bill passes first reading in Knesset - The Times of Israel - November 5th, 2025 [November 5th, 2025]
- From CBS to TikTok, US media are falling to Trumps allies. This is how democracy crumbles | Owen Jones - The Guardian - October 31st, 2025 [October 31st, 2025]
- Denmark reportedly withdraws Chat Control proposal following controversy - therecord.media - October 31st, 2025 [October 31st, 2025]
- Opinion | Crypto and Trump Corrupted America - The New York Times - October 26th, 2025 [October 26th, 2025]
- After internal struggle, Colorados Libertarians look to pivot. It could impact Congress. - The Denver Post - October 26th, 2025 [October 26th, 2025]
- Argentina goes to polls amid economic crisis and Trump interference - The Guardian - October 26th, 2025 [October 26th, 2025]
- Five things to know about Argentina's pivotal midterm election - Purdue Exponent - October 26th, 2025 [October 26th, 2025]
- Milei promised to drain Argentinas swamp. Now hes sinki... - The Observer - October 26th, 2025 [October 26th, 2025]
- After Tunisian shipwreck kills 40, archbishop urges world to tackle migration crisis - Catholic News Agency - October 26th, 2025 [October 26th, 2025]
- Migrant prison farce proves the system is out of control - The Telegraph - October 26th, 2025 [October 26th, 2025]
- Labour blasted as 'too weak' to deport small boat migrants while pressure mounts on Keir Starmer to adopt Rwanda-style plan - GB News - October 26th, 2025 [October 26th, 2025]
- France backing away from pledge to intercept migrant boats, sources tell BBC - BBC - October 26th, 2025 [October 26th, 2025]
- Migrants abandon children on Spanish holidays so they can claim asylum - The Telegraph - October 26th, 2025 [October 26th, 2025]
- Ireland is making a dangerous mistake on immigration - The Telegraph - October 26th, 2025 [October 26th, 2025]
- Migrant sent back to France in one in, one out deal returns to UK - The Independent - October 26th, 2025 [October 26th, 2025]
- Syrian migrant with 'deep voice and receding grey hair' is ruled to be a child - GB News - October 26th, 2025 [October 26th, 2025]
- Stop lecturing migrant hotel protesters, Dublin is more proof of this total betrayal - Adam Brooks - GB News - October 26th, 2025 [October 26th, 2025]
- 'It's a FARCE!' Tom Harwood up in arms while Labour 'takes the mickey' with 'one in, one out' scheme - GB News - October 26th, 2025 [October 26th, 2025]
- Secret report reveals Home Office culture of defeatism on migration - The Telegraph - October 26th, 2025 [October 26th, 2025]
- Lammy: Catching migrant shows one in, one out is working - The Telegraph - October 26th, 2025 [October 26th, 2025]
- Migrant guilty of murdering woman with screwdriver - The Telegraph - October 26th, 2025 [October 26th, 2025]
- If UK controlled its own borders, killer illegal migrant would never have been here - Rakib Ehsan - GB News - October 26th, 2025 [October 26th, 2025]
- Mark White's Migration Monitor: The small boats farce continues - and the next act looks even darker - GB News - October 26th, 2025 [October 26th, 2025]
- Epping migrant STILL on the loose as David Lammy admits Ethiopian sex offender is 'at large in London' - GB News - October 26th, 2025 [October 26th, 2025]
- Cal State Invited Tech Companies to Remake Learning With A.I. - The New York Times - October 26th, 2025 [October 26th, 2025]
- Artificial intelligence (AI) - The Guardian - October 26th, 2025 [October 26th, 2025]
- Banking and Finance Symposium to Address AI, Technology Issues - University of Mississippi | Ole Miss - October 26th, 2025 [October 26th, 2025]
- AI Is Even Putting Animal Actors Out of Work - Futurism - October 26th, 2025 [October 26th, 2025]
- Impacts of artificial intelligence (AI) in teaching and learning of built environment students in a developing country - Taylor & Francis Online - October 26th, 2025 [October 26th, 2025]
- 3 Top Artificial Intelligence (AI) Stocks Ready for a Bull Run - The Motley Fool - October 26th, 2025 [October 26th, 2025]
- Israel playing catch-up in AI after two years of war - JNS.org - October 26th, 2025 [October 26th, 2025]
- Why Analysts See Alibabas Growth Story Changing With Cloud and AI Driving New Optimism - Yahoo Finance - October 26th, 2025 [October 26th, 2025]
- The AI Bubble Is Poised to Burst, Yet the Next One Is in the Works - 36Kr - October 26th, 2025 [October 26th, 2025]
- Beyond Chips: AI Infrastructure Spending Is Projected to Hit $490 Billion -- Who Benefits Most? - Yahoo Finance - October 26th, 2025 [October 26th, 2025]
- Jordan to lead MSUs AI efforts in new role, Willard named interim VP for research, economic development - Mississippi State University - October 26th, 2025 [October 26th, 2025]
- Artificial Intelligence and Medical Translation: An Editorial on the Ethical Considerations for Emerging Technologies in Dermatology - Cureus - October 26th, 2025 [October 26th, 2025]
- Scientists spent years teaching a robot to play sports. It's still terrible - BBC Science Focus Magazine - October 26th, 2025 [October 26th, 2025]
- There is no life: Kupiansks slow demise reflects the fate of cities on Ukraines frontline - The Guardian - October 26th, 2025 [October 26th, 2025]
- Ukraines Coalition of the Willing Has the Wind at Its Back - The New York Times - October 26th, 2025 [October 26th, 2025]
- Russia arrests Ukrainian biologist for backing curbs on Antarctic krill fishing - The Guardian - October 26th, 2025 [October 26th, 2025]
- Six metres below ground: inside the secret hospital treating Ukrainian soldiers injured by Russian drones - The Guardian - October 26th, 2025 [October 26th, 2025]
- Jet-powered bombs and planes-turned-missiles: Ukrainian and Russian militaries improvise and adapt in a battle of wits - CNN - October 26th, 2025 [October 26th, 2025]
- 3 Years Ago It Was a Casting Agency. Now It Has $1 Billion in Drone Contracts. - The New York Times - October 26th, 2025 [October 26th, 2025]
- Russia targets Kyiv with drones, killing 3 and wounding 29 - ABC News - Breaking News, Latest News and Videos - October 26th, 2025 [October 26th, 2025]
- More than Tomahawks: what Ukraines soldiers say they actually need - The Kyiv Independent - October 26th, 2025 [October 26th, 2025]
- Ukraines ingenuity alone will not be enough to win the war - The Independent - October 26th, 2025 [October 26th, 2025]
- After War Turned Their Fields Into Frontlines, Ukraines Farmers Return to Reclaim Them - UNITED24 Media - October 26th, 2025 [October 26th, 2025]
- Turkey urges US to act after accusing Israel of breaching Gaza ceasefire - Sky News - October 26th, 2025 [October 26th, 2025]
- President Erdoan visits Oman, his last stopover in the Gulf | Daily Sabah - Daily Sabah - October 26th, 2025 [October 26th, 2025]
- Erdoan to meet with DEM Party delegation on terror-free process | Daily Sabah - Daily Sabah - October 26th, 2025 [October 26th, 2025]
- Erdoan renews call for UN reform over Gaza in 80th anniversary message | Daily Sabah - Daily Sabah - October 26th, 2025 [October 26th, 2025]
- Foreign media: Russia reiterated its stance on full control of Donbas to the US last weekend - Bitget - October 23rd, 2025 [October 23rd, 2025]
- Health Ministry and PAHO Host Media Session on Upcoming National Tobacco Control Bill - Love FM Belize - October 19th, 2025 [October 19th, 2025]
- Ask Lucas: My teens social media obsession is out of control - Cleveland.com - October 17th, 2025 [October 17th, 2025]
- Molding the Message - China Media Project - October 17th, 2025 [October 17th, 2025]
- From clicks to curation: How publishers can reclaim control of the media ecosystem - Digiday - October 15th, 2025 [October 15th, 2025]
- Orbans Propaganda State in Hungary Is Starting to Show Cracks - The New York Times - October 15th, 2025 [October 15th, 2025]
- How Chioma Ikeh is helping small businesses take back control of their social media - Businessday NG - October 13th, 2025 [October 13th, 2025]
- Germany will not support 'Chat Control' message scanning in the EU - The Record from Recorded Future News - October 11th, 2025 [October 11th, 2025]
- Media: IDF will control 53% of Gaza in the first phase of the agreement - Baku.ws - October 11th, 2025 [October 11th, 2025]
- Rob Reiner Says U.S. Will Become an Autocracy if Trump Is Allowed to Control the Media and Commandeer the Election: We Have a Year to Stop Him -... - October 7th, 2025 [October 7th, 2025]
- Rob Reiner Warns Trump Wants "Control Of Media" To Steal 2026 Election - Deadline - October 7th, 2025 [October 7th, 2025]
- Move over Murdochs, the Ellisons are the new family dynasty shaking up US media - BBC - September 30th, 2025 [September 30th, 2025]
- How Trumps TikTok Deal Could Change the Future of US Media - TODAY.com - September 30th, 2025 [September 30th, 2025]
- Meghan Markles Media Battles: Control, Conflicts, and the Struggle for Credibility - vocal.media - September 28th, 2025 [September 28th, 2025]
- Trump announces deal to put TikTok under control of US investors - ABC News - Breaking News, Latest News and Videos - September 28th, 2025 [September 28th, 2025]
- President Tebbounes Media Exchange: Inflation Control, Electoral Reform, and a Drive Toward Modernization - - September 28th, 2025 [September 28th, 2025]
- Raptors GM Bobby Webster meets with the media ahead of first season with full team control - Toronto Star - September 28th, 2025 [September 28th, 2025]
- Murdochs TikTok? Trump offers allies another lever of media control - The Guardian - September 25th, 2025 [September 25th, 2025]
- Even legacy media admit left-wing violence is out of control - The Heartlander - September 25th, 2025 [September 25th, 2025]
- Capture the Media, Control the Culture? - The American Prospect - September 23rd, 2025 [September 23rd, 2025]
- Whats actually in the Media Control Act? - Maldives Independent - September 23rd, 2025 [September 23rd, 2025]
- Power Play: Murdochs, Ellison, and Dell Join Forces for TikTok Bid - International Business Times UK - September 23rd, 2025 [September 23rd, 2025]
- Jimmy Kimmel and the MAGA strong-arming of American media - Media Matters for America - September 19th, 2025 [September 19th, 2025]
- Abbreviated Pundit Roundup: Controlling the media controls the message - Daily Kos - September 19th, 2025 [September 19th, 2025]
- The 31-day sprint: a timeline of the "media control law" - Maldives Independent - September 19th, 2025 [September 19th, 2025]
- Trump Admin Says Framework Reached for U.S. Owners to Take Control of TikTok - Gizmodo - September 17th, 2025 [September 17th, 2025]
- "We have a prime ministerial republic"/ Media: Changes to the Constitution, control of the Assembly and the opposition - cna.al - September 17th, 2025 [September 17th, 2025]