Live data from Hacker News

It’s Easy to Hack Hospital Equipment

wired.com

1–10 of 65 posts

Re: It’s Easy to Hack Hospital Equipment

#2
“Many hospitals are unaware of the high risk associated with these devices,”

I assure you that while this is the hospital's official stance, many people within the hospital are well aware of the shoddy software on their medical devices and the risks they pose. There are so many opportunities for disruption of every aspect of the healthcare system (from the equipment itself, that this article addresses, to the electronic medical records systems, to more structural aspects of the healthcare system as a whole), but literally none of the incentives for practitioners and hospital administrators are properly aligned to make it possible. I'd love to work with a company trying to break into these markets if they had a plausible route to entry.

Re: It’s Easy to Hack Hospital Equipment

#3
Scary, but this isn't surprising at all. What the hardware does in these cases is more important than the software that runs it. Couple that with devices that sell in relatively small quantities for high cost, and you get undertested, unstressed software.

Re: It’s Easy to Hack Hospital Equipment

#6

“Many hospitals are unaware of the high risk associated with these devices,” I assure you that while this is the hospital's official stance, many people within the hospital are well aware of the shoddy software on their medical devices and the risks they pose. There are so many opportunities for disruption of every aspect of the healthcare system (from the equipment itself, that this article addresses, to the electro…

I agree with you - I'm sure there are people within the healthcare system who are aware of the situation but are probably not in a position to do anything about it. I'd also guess that this is one of those things where nothing will be done until there's a high-profile "incident". Security will probably end up being reactionary at first.

Re: It’s Easy to Hack Hospital Equipment

#7
Although vendors often tell customers they can’t remove hard coded passwords from their devices or take other steps to secure their systems because it would require them to take the systems back to the FDA for approval afterward, Erven points out that the FDA guidelines for medical equipment includes a cybersecurity clause that allows a post-market device to be patched without requiring recertification by the FDA.

These are the same people that have been complaining about how awful it is that the Affordable Care Act imposes a medical device tax. Maybe if they weren't so cavalier about deceiving their customers regulation and certification wouldn't cost as much as it does.

Re: It’s Easy to Hack Hospital Equipment

#10

Although vendors often tell customers they can’t remove hard coded passwords from their devices or take other steps to secure their systems because it would require them to take the systems back to the FDA for approval afterward, Erven points out that the FDA guidelines for medical equipment includes a cybersecurity clause that allows a post-market device to be patched without requiring recertification by the FDA. Th…

I think you have to always assume that people can't be trusted to do the right thing when it comes to lives of others. The FDA has to employ policies which gives us a reasonable confidence that a vendor's device/test/whatever is safe and effective.

Disclaimer: I have worked on FDA cleared medical devices my entire career.

Post reply on HN