Categories: AnalysisFeatured

IoT has invaded the healthcare industry and it’s a mess

Healthcare has big risks with connected devices.

I’ve been hanging around with folks during the past week that are thinking about healthcare IoT and security, and it’s pretty grim. I’ll write more on this in the future, but for now, here are a few things that should concern everyone.

I spoke with a security researcher and two hospital CISOs this week who all said they have gear running Windows ME or even Windows 95. Those two operating systems haven’t been patched in years. Yet, in hospitals around the country, infusion pumps, MRI machines and other essential patient gear are running operating systems that have absolutely no support.

Hospitals are now targets for hackers, generally those disabling access in exchange for a ransom. But as any security expert can tell you, these same vulnerabilities could easily be exploited not just for profit, but also to wreck havoc.

Attacking infusion pumps could dump 12 hours worth of medicine into a patient all at once, possibly killing her. A hacked MRI might lead to an essential piece of equipment going offline.

This is the stuff keeping hospital CISOs up at night. For security pros in factories, cities and other areas deploying connected devices, it offers a strong indicator of how essential good IT security will be to their own deployments.

The problems at hospitals stem from several factors other industries also face. There is a rush to connect devices with an eye to improve overall outcomes and lower costs. Their equipment has to last for 15 or 20 years. It’s highly regulated. Profits in many hospitals are razor thin. Technology is not a core expertise. In fact, in small and rural hospitals, a tech expert may not even be on staff.

Any one of these factors will make life for a CISO or someone charged with IT security inside a hospital difficult. All of them combined make the job seem impossible. And yet, it’s not a problem that can be ignored because the stakes are so high.

Many of these same dynamics play out in other industries such as power generation and delivery, automotive, and smart cities deployments. Right now there is a failure to consider security, longevity of support, and a regulatory framework that meets the needs of an interconnected network of connected devices. But we’re adding things to the internet even so.

The healthcare industry is showing us how dangerous that really is.

andrew

Share
Published by
andrew

Recent Posts

Episode 437: Goodbye and good luck

This is the final episode of The Internet of Things Podcast, and to send us…

8 months ago

So long, and thanks for all the insights

This article was originally published in my weekly IoT newsletter on Friday August 18, 2023.…

9 months ago

We are entering our maintenance era

This article was originally published in my weekly IoT newsletter on Friday August 18, 2023.…

9 months ago

IoT news of the week for August 18, 2023

Verdigris has raised $10M for smarter buildings: I am so excited by this news, because roughly eight…

9 months ago

Podcast: Can Alexa (and the smart home) stand on its own?

Amazon's head of devices, David Limp, plans to retire as part of a wave of executives that…

9 months ago

Z-Wave gets a boost with new chip provider

If you need any more indication that Matter is not going to kill all of…

9 months ago