Why healthcare’s medical device challenges will never be addressed in isolation – SC Media
The governments push for threat sharing and collaboration, with the uptick in alerts directed to the healthcare sector, are a welcomed shift in the longstanding efforts to curtail cybersecurity challenges with overall awareness and cyber posture in the industry.
But awareness doesnt always translate into a viable solution, particularly when it comes to tackling the minutiae of medical devices. Due to the sheer complexity of the device ecosystem, resource constraints, and knowledge gaps, even the largest health systems struggle to solve the risk management challenges.
I think medical devices and biomed in general are really kind of the redheaded-stepchild of healthcare organizations because they're complex, and nobody really knows how to deal with them, said Ben Denkers, CynergisTeks chief innovation officer.
Consider the FBI alert on legacy medical devices, which resounded the bullhorn on risks associated with leveraging legacy tech in devices directly tied to patients. For many in healthcare, the messages rang familiar: groups like CHIME have long-warned of patch management issues and the impossibility of a real-time inventory in the healthcare environment. Similarly, the recommendations were rather vanilla: basic blocking and tackling at the end of the day.
Certainly, such reminders do no harm encouraging some healthcare entities to leverage technology as a safeguard to defend against a specific threat or to reduce overall risk. But some argue that the challenges facing many providers cant be boiled down into a singular problem or solution, and that the current assessment of risk could leave a vulnerable market unable to see the forest through the trees.
SC Media spoke to Denkers about this quandary, and how the market can better address multiple and sometimes conflicting hurdles to cybersecurity.
When the onslaught of ransomware attacks against healthcare began in 2016, the rallying cry was that there was no silver bullet to solve cybersecurity challenges. The sentiment remains, for both overall infrastructure and device security vulnerabilities.
As its likely always been in healthcare, the crux of its issues is actually a combination of resource and knowledge constraints, which are needed to truly have an effective security and privacy program, Denkers explained. Providers need a combination of people, processes, and technology to have a successful privacy and security program, even before its applied to a specific area like medical devices.
If you don't have enough resources, it's going to be problematic. If you don't have the right technology, you're going to have issues. And if you don't have the right processes to make sure all of those are working and effective, it doesn't do you any good, said Denkers.
That's the problem. It's not a singular issue of, hey, we don't have the right technology to stop the attack, he continued. Let's say, magically, you can wave your wand and put in some sort of endpoint protection on all the medical devices. Great. But what happens if you don't have the people to monitor the alerts or have to deal with a device being compromised? It doesn't really do you any good.
That means that even when a problem is identified, it still cant be remediated without the effective processes or controls. And if the problem persists, it can create downstream effects when the device remains in use, which could still cause patient safety impacts.
Further, if hospital leadership doesnt know how to use the actual security technology, its not going to do a whole lot, said Denkers. Others are struggling without the resources to manage or monitor the tools, or even tweak them to make it effective in the environment.
I've had countless conversations with individuals at healthcare organizations, and similarly where they've invested a lot of money in technology for it to sit in the corner because they don't have the resources or the know-how, or the physical resources to take the device and implement it, he added.
And they certainly don't have the resources to validate that it's working. Medical device security is important, it absolutely is. But you're also talking to organizations that probably, I would venture to guess, don't even have endpoint protection.
Some resource issues are financially driven; organizations dont have the money to make investments in the technology stack, or afford to hire the right people. Hiring challenges also persist for rural providers, who may not be able to physically get people into the organization.
Many rural hospitals face staffing challenges based on location alone, he said. Healthcare is facing all of these problems, not just with medical devices and the higher level of risk due to the direct attachment to care. But if you really start to unpeel the layers, you'll start to see that healthcare in general still isn't isn't necessarily the poster child for security and privacy programs.
Denkers posed an important question: if a car manufacturer had vehicles on the road that generally did what they were supposed to do, but passengers were at risk due to a faulty airbag, or malfunctioning brakes, what would happen? The manufacturer would be forced to make changes.
The reason why we're having to deal with these problems is because [medical devices] weren't properly developed from the beginning, he mused. It all starts with the software development life cycle, and where does SDLC start? It's whoever is developing the product or the solution.
If issues aren't properly vetted at the beginning of the development cycle, risks emerge. As Denkers sees it, it's the responsibility of the vendor to have a better product.
It's a snowball effect: you're never really actually going to catch up because it's just going to continue to get worse and worse and worse every time you have outdated software or end-of-life hardware and products.
It's interesting, those types of risks wouldn't be accepted in any other organization. But for some reason, we're dealing with people, which arguably have the highest rates of consequences, and it's okay, said Denkers.
The FBI alert was likely intended to reflect the current threats facing vulnerable platforms, warning that bad actors are increasingly using unpatched medical devices to gain a foothold on the network.
But the alert should instead serve as a guidepost: An exploit could ultimately impact the integrity and confidentiality of data, or even worse, cause disruptions in operational functions and impact patient safety.
Use this as a compass or a North Star, Denkers recommended, and review the guidance to verify just how well medical devices are being protected. Many in healthcare are in situations where they think they have certain safeguards in place, or some version of recommended safeguards, inadvertently miss the most important element amid the noise.
As Denkers plainly puts it, The question then really becomes: How effective is that control?
An entity may have endpoint protection or access controls, but be unaware of potential gaps in the environment, or unclear whether tools adequately address vulnerabilities. Some organizations generally don't have a mechanism in place to validate how effective controls are whether it be people, processes, or technology, he explained.
Segmentation is one of those areas where an entity might decide to separate certain devices from the main network, but then management of those devices is handled by another department. They set security and forget it. But as noted by Denkers, if they're connected to the network, they're still connected to patients.
And such oversights bring grave consequences. If a device or supporting infrastructure were to be compromised, and the device needs the internet to function or access certain portions of the environment, the medical devices cant function for patient care.
Depending on the organization's requirements, there can be many downstream effects from general compromises on the IT environment that become problematic quickly.
See the original post here:
Why healthcare's medical device challenges will never be addressed in isolation - SC Media
- Bluesky Gives Users More Control Over their Notifications - Social Media Today - July 8th, 2025 [July 8th, 2025]
- Spin Control: Media struggles after Trump swears with cameras rolling - The Spokesman-Review - July 8th, 2025 [July 8th, 2025]
- Beyond banks and brokers: All about decentralized finance (DeFi) - Britannica - July 8th, 2025 [July 8th, 2025]
- The Future of Crypto Payroll Security: Bitchat and Decentralized Messaging - OneSafe - July 8th, 2025 [July 8th, 2025]
- Paradigm leads $11.5 million funding round in Kuru Labs, a decentralized exchange blending CLOBs and AMMs - The Block - July 8th, 2025 [July 8th, 2025]
- Decentralized Payroll: The Future of Work - OneSafe - July 8th, 2025 [July 8th, 2025]
- Jack Dorsey tests Bitchat decentralized messaging without internet - Cointelegraph - July 8th, 2025 [July 8th, 2025]
- CrossFis Haley Cromer on Bridging Traditional Finance and Web3 for a Decentralized Future - BlockTelegraph - July 8th, 2025 [July 8th, 2025]
- India's Crypto Tax: Navigating New Norms with Decentralized Solutions - OneSafe - July 8th, 2025 [July 8th, 2025]
- Turkey Tightens Its Grip on Crypto: What It Means for Decentralized Exchanges - OneSafe - July 8th, 2025 [July 8th, 2025]
- Spheron and AIxBlock Unite to Democratize Decentralized AI - CoinTrust - July 8th, 2025 [July 8th, 2025]
- The Role of Web3 in Shaping NFT Marketplace Opportunities - Vocal - July 8th, 2025 [July 8th, 2025]
- BNB Adds Centralized Features, But Lightchain AI Adds Decentralized Incentives That Drive New Demand - Modern Diplomacy - July 8th, 2025 [July 8th, 2025]
- Taiko and Nethermind Partner to Enhance Ethereum Rollup Infrastructure - Blockchain News - July 8th, 2025 [July 8th, 2025]
- The Rise of Decentralized Stablecoins: Can They Replace Centralized Counterparts in 2025? - Vocal - July 8th, 2025 [July 8th, 2025]
- On MSNBC's Deadline: White House, Angelo Carusone highlights how Trump is losing control of narrative dominance due to "fractures" in... - July 8th, 2025 [July 8th, 2025]
- Assembly Control Transforms Programmatic Advertising with Revolutionary Brand Safety Platform - Stock Titan - July 4th, 2025 [July 4th, 2025]
- Now, United States Border Control Scrutinizes Social Media: For The Travelers To The United States from France, Spain, and Beyond, Here Is All You... - July 4th, 2025 [July 4th, 2025]
- Assembly Launches 'Assembly Control' to Elevate Brand Safety, Suitability, and Campaign Performance in Programmatic Media - Macau Business - July 4th, 2025 [July 4th, 2025]
- Breaking the Studio Social Media Blackout: Caylee Cowan Takes Creative Control and Financial Freedom with Fanfix - Silicon UK - June 28th, 2025 [June 28th, 2025]
- Aleema's control over PTI social media makes her all-powerful within Imran-founded party - Geo News - June 26th, 2025 [June 26th, 2025]
- Tuenti social media co-founder takes control of Puerto Bans bullring with plans to demolish it - Sur in English - June 20th, 2025 [June 20th, 2025]
- InMobi Advertising Unveils Mobile-First Curation Platform Empowering All Media Buyers with Precision, Transparency, and Control - Passionate In... - June 20th, 2025 [June 20th, 2025]
- Trump takes control of media cycle with travel ban, Harvard visa restriction, Biden investigation policy spree - Washington Examiner - June 7th, 2025 [June 7th, 2025]
- Pushed Out and Unfiltered: Joy Reid, Misogynoir, Media Control,and the Fear of a Black Womans Voice - Daily Kos - June 7th, 2025 [June 7th, 2025]
- GitGuardian urges shift to machine identity control - SC Media - May 11th, 2025 [May 11th, 2025]
- Opinion: Its time to lose control - Main Street Media of Tennessee - May 8th, 2025 [May 8th, 2025]
- Opinion | How a Professional Bully Is Winning Control of the Media - Common Dreams - April 30th, 2025 [April 30th, 2025]
- Social Media, Social Control, and the Politics of Public Shaming - - Political Science Now - April 21st, 2025 [April 21st, 2025]
- Tariff saga creates a meme war on social media, making it difficult for brands to 'control the message' - Digiday - April 21st, 2025 [April 21st, 2025]
- Conservatives are limiting media access to Poilievre. Is it helping or hurting him? - CBC - April 12th, 2025 [April 12th, 2025]
- Robert W. McChesney, who warned of corporate media control, dies at 72 - Editor and Publisher - April 10th, 2025 [April 10th, 2025]
- FCC Commissioner Anna Gomez Sounds Alarm Over Trump Administrations Absolute Pattern of Censorship and Control - Variety - April 10th, 2025 [April 10th, 2025]
- 'Attack lined up': Grenon says he offered compromise but believes NZME board has 'no interest' - NZ Herald - April 8th, 2025 [April 8th, 2025]
- Russia seeks full control of partially occupied Ukrainian regions in talks with US, media reports - Kyiv Independent - March 26th, 2025 [March 26th, 2025]
- Navigating the digital world without letting it control you. - Psychology Today - March 25th, 2025 [March 25th, 2025]
- ANZ Digital Padlock to give customers real-time control in fight against fraud and scams - ANZ - March 25th, 2025 [March 25th, 2025]
- Trump Handpicking Reporters and Bezos Partisan Shift: A Trend in Media Control - MSN - March 13th, 2025 [March 13th, 2025]
- Spains New Media Law Sparks Fears of Censorship and State Control - The European Conservative - March 5th, 2025 [March 5th, 2025]
- We dont feel we have control: How social media algorithms have warped our attention spans - MSNBC - March 3rd, 2025 [March 3rd, 2025]
- White House takes control of the press pool covering Trump - Reuters - March 3rd, 2025 [March 3rd, 2025]
- White House takes control of the press pool covering Trump - Reuters - March 3rd, 2025 [March 3rd, 2025]
- We dont feel we have control: How social media algorithms have warped our attention spans - MSNBC - March 3rd, 2025 [March 3rd, 2025]
- Reuters and Associated Press among outlets barred from Trumps first cabinet meeting - Semafor - March 3rd, 2025 [March 3rd, 2025]
- Reuters and Associated Press among outlets barred from Trumps first cabinet meeting - Semafor - March 3rd, 2025 [March 3rd, 2025]
- White House seizes control of press pool, will decide which outlets cover events with president - POLITICO - March 3rd, 2025 [March 3rd, 2025]
- White House seizes control of press pool, will decide which outlets cover events with president - POLITICO - March 3rd, 2025 [March 3rd, 2025]
- Epson And Show Sage At USITT 2025 Showcasing New 4K Projection With New Media Server And Control Tech - Live Design - March 3rd, 2025 [March 3rd, 2025]
- Epson And Show Sage At USITT 2025 Showcasing New 4K Projection With New Media Server And Control Tech - Live Design - March 3rd, 2025 [March 3rd, 2025]
- White House takes control of picking media who cover Trump - El Paso Inc. - March 3rd, 2025 [March 3rd, 2025]
- White House takes control of picking media who cover Trump - El Paso Inc. - March 3rd, 2025 [March 3rd, 2025]
- Trump administration to take control of media access at White House - New Straits Times - March 3rd, 2025 [March 3rd, 2025]
- USAID spent millions of dollars to promote media control through Internews which is linked to India based Factshala - Organiser - February 16th, 2025 [February 16th, 2025]
- Inaccurate reporting on foot and mouth disease controls - Defra in the media - February 16th, 2025 [February 16th, 2025]
- Russian forces take control of two settlements in eastern Ukraine, Media - APA - February 16th, 2025 [February 16th, 2025]
- TikTok's woes in the United States highlight the 'Godfather' battle to control social media - ABC News - February 5th, 2025 [February 5th, 2025]
- Jesse Watters: Air traffic control was "unable to meet their own DEI quotas, and thats what is leading to staffing shortages" - Media... - February 5th, 2025 [February 5th, 2025]
- Hive to launch Beeblade Nexus media control engine - Installation and AV Technology Europe - January 27th, 2025 [January 27th, 2025]
- Pakistan introduces law allowing government to block platforms, imprison users for spreading 'disinformat - The Times of India - January 27th, 2025 [January 27th, 2025]
- This little media control button is the gadget I can't live without - MSN - January 22nd, 2025 [January 22nd, 2025]
- Effective role of media is a must for tobacco control, experts say - bdnews24.com - January 22nd, 2025 [January 22nd, 2025]
- Effective media role vital for tobacco control: Experts - United News of Bangladesh - UNB - January 22nd, 2025 [January 22nd, 2025]
- How Government & Legacy Media CONTROL What We Think - iHeartRadio - January 9th, 2025 [January 9th, 2025]
- SNL kinda banned this 1998 'Schoolhouse Rock' parody warning about corporate media control - Upworthy - December 30th, 2024 [December 30th, 2024]
- Palestinian Authority: Jews Lied About Oct. 7 Because They Control the Media - Algemeiner - December 30th, 2024 [December 30th, 2024]
- NDCs control of major media houses gave them edge in 2024 polls Bawumia - Adomonline - December 22nd, 2024 [December 22nd, 2024]
- Hallmark Insights to Tackle the Debate on Social Media Management and Control in Organizations - PC Tech Magazine - December 14th, 2024 [December 14th, 2024]
- Rupert Murdochs bid to change familys trust over Fox News media empire control is rejected - Washington Times - December 10th, 2024 [December 10th, 2024]
- Rupert Murdoch loses battle to control succession to his media empire - The Guardian - December 10th, 2024 [December 10th, 2024]
- Journalist Abducted in Guinea Amid Military's Increasing Control Over Media - Oneindia - December 5th, 2024 [December 5th, 2024]
- Aleppo and Idlib Under Opposition Control, With Eyes on Hama - The Media Line - December 5th, 2024 [December 5th, 2024]
- Remilekun Dosumu takes the helm as Head of Media Buying & Control at PHD Nigeria - Marketing Edge - December 5th, 2024 [December 5th, 2024]
- Media reports US Republicans regaining control of House of Representatives - MENAFN.COM - November 14th, 2024 [November 14th, 2024]
- Social media misinformation is scaring women about birth control - STAT - November 5th, 2024 [November 5th, 2024]
- The (Lack Of) Science Behind Social Media Claims Of Weather Control - Forbes - October 14th, 2024 [October 14th, 2024]
- No, the government is not controlling the weather. "It's so stupid, it's got to stop," Biden says - CBS News - October 14th, 2024 [October 14th, 2024]
- Column: Media tries to control the narrative | Aiken Standard - The Post and Courier - October 12th, 2024 [October 12th, 2024]
- DoubleVerify To Introduce Pre-Screen Content Control On Meta, Strengthening Brand Safety, Suitability, Media Performance - Business - October 12th, 2024 [October 12th, 2024]
- Android Auto 13.0: Paving the way for enhanced media control - MSN - October 11th, 2024 [October 11th, 2024]
- Unveiling Android Auto 13.0: Paving the way for seamless media control - MSN - October 11th, 2024 [October 11th, 2024]