Live data from Hacker News

It’s Easy to Hack Hospital Equipment

wired.com

51–60 of 65 posts

Re: It’s Easy to Hack Hospital Equipment

#51

To be a dash risk managementy about it; (Risk of being hacked) x (severity of being hacked) (Risk of being hacked): Small. (Severity of being hacked): Very negative, but localised most likely to a single machine, set of machines, or hospital. (Risk of Software not Delivered): Pretty high if we go super-security. We are on a budget. There is competition. Who is paying for it? (Severity of not delivered): Failure to cu…

What are the chances that someone would actually doing the hacking? I don't see any monetary reason to do so. Maybe that's one reason why we haven't seen many reports of people hacking medical devices?

Bob is on a medical device. It take readings (which it hides from him) and provides medication at a rate which is set by someone else.

Every few weeks / months Bob needs to see a doctor w o enters a password, retrieves the data, and makes changes to the settings.

Bob feels that the $DISEASE community can help him interpret the data and tweak the settings and Bob could then reduce doctor visits to once every six months.

Ann is an undisclosed drug addict and wishes to hack her morphine pump to supply more than she is currently getting.

Etc

Re: It’s Easy to Hack Hospital Equipment

#52
post #23

Earlier quoted context omitted.

TL&DR Regulations need to require interoperability and cross-platform with medical records and images. As a "Cancer Dad" the electronic medical records and images that are closed and inaccessible between my local hospital where we got our chemotherapy and the Children's Hospital where we did our major surgeries was mind blowingly crazy. I had to drive my bone cancer child 2.5 hours to use their equipment because ther…

As somebody working in healthcare integration, this may be small consolation, but it that's getting better. The HITECH act[1] (which was part of the stimulus package in 2009) has gone a long way in getting the industry moving. One of the core deadlines we're scrambling to meet at the moment at my hospital is actually data interchange between facilities, including a portal that allows patients to access their records…

Out of curiosity, which HL7 CDAs (and which levels) do you support, and how much lift is it to set up import/export for a new provider or institution?

I'm pessimistic that we'll be able to achieve true level 3 interoperability, even though the basic ontologies (e.g., SNOMED, LOINC, etc) are in place. I'd love to hear that you're having a good experience, though.

Re: It’s Easy to Hack Hospital Equipment

#53
post #10

Earlier quoted context omitted.

I think you have to always assume that people can't be trusted to do the right thing when it comes to lives of others. The FDA has to employ policies which gives us a reasonable confidence that a vendor's device/test/whatever is safe and effective. Disclaimer: I have worked on FDA cleared medical devices my entire career.

I think most of the time you can trust people to do the right thing when it comes to the lives of others, when the right thing is sufficiently clear, when the fact that it involves the lives of others is sufficiently salient, and when there are not enormous incentives to do otherwise.

I'm not sure you took my meaning. Even if what you say is true, a regulating body must view everyone with skepticism. They have to walk into an audit/filing review with a "prove it to me" attitude else risk doing real harm to people.

Re: It’s Easy to Hack Hospital Equipment

#54

To be a dash risk managementy about it; (Risk of being hacked) x (severity of being hacked) (Risk of being hacked): Small. (Severity of being hacked): Very negative, but localised most likely to a single machine, set of machines, or hospital. (Risk of Software not Delivered): Pretty high if we go super-security. We are on a budget. There is competition. Who is paying for it? (Severity of not delivered): Failure to cu…

Whilst true, I can with 100% certainty, state that no-one in the medical profession, or the procurement people in the hospitals ever did that calculation. NICE (the UK's no-you-cant-spend-ten-million-of-taxpayers-money-per-patient-on-a-drug-to-extend-their-life-by-six-weeks agency which gets it in the neck for such things) might be able to take on such a calculation - but I bet you anything even if they did that calc…

They don't need to do the calculation because their intuition already leads them to the right decision. This is just economics. What is the payoff for the evildoer hacking a pacemaker? Oh right, he's a contract killer? Too many movies for you. It's just more profitable to replace the payment processing app with your own payment skimming app at some big store.

Re: It’s Easy to Hack Hospital Equipment

#55

To be a dash risk managementy about it; (Risk of being hacked) x (severity of being hacked) (Risk of being hacked): Small. (Severity of being hacked): Very negative, but localised most likely to a single machine, set of machines, or hospital. (Risk of Software not Delivered): Pretty high if we go super-security. We are on a budget. There is competition. Who is paying for it? (Severity of not delivered): Failure to cu…

What are the chances that someone would actually doing the hacking? I don't see any monetary reason to do so. Maybe that's one reason why we haven't seen many reports of people hacking medical devices?

Collateral damage from a poorly designed worm would be one thing I'd worry about. We've seen multiple vector attacks, I could imagine one gaining a foothold within the network and another component of the attack interfering with medical devices.

Re: It’s Easy to Hack Hospital Equipment

#56

Earlier quoted context omitted.

What are the chances that someone would actually doing the hacking? I don't see any monetary reason to do so. Maybe that's one reason why we haven't seen many reports of people hacking medical devices?

It could be done as a murder for hire, or as a terrorist event. It's possible some hackers would do it 'for the lulz' or maybe they just want to test out a hack and accidentally go to far, though these are more unlikely. And there is also extortion, maybe you find everyone that has a vulnerable pacemaker, and demand they pay you or else you stop their heart. Criminals are clever, if they find a way to attack people t…

I know they can do it, but how many times has it been tried or actually reportedly been done?

Re: It’s Easy to Hack Hospital Equipment

#57
post #53

Earlier quoted context omitted.

I think most of the time you can trust people to do the right thing when it comes to the lives of others, when the right thing is sufficiently clear, when the fact that it involves the lives of others is sufficiently salient, and when there are not enormous incentives to do otherwise.

I'm not sure you took my meaning. Even if what you say is true, a regulating body must view everyone with skepticism. They have to walk into an audit/filing review with a "prove it to me" attitude else risk doing real harm to people.

I don't know that that's wrong. The two views are certainly compatible.

Re: It’s Easy to Hack Hospital Equipment

#58
post #52

Earlier quoted context omitted.

As somebody working in healthcare integration, this may be small consolation, but it that's getting better. The HITECH act[1] (which was part of the stimulus package in 2009) has gone a long way in getting the industry moving. One of the core deadlines we're scrambling to meet at the moment at my hospital is actually data interchange between facilities, including a portal that allows patients to access their records…

Out of curiosity, which HL7 CDAs (and which levels) do you support, and how much lift is it to set up import/export for a new provider or institution? I'm pessimistic that we'll be able to achieve true level 3 interoperability, even though the basic ontologies (e.g., SNOMED, LOINC, etc) are in place. I'd love to hear that you're having a good experience, though.

Honestly, that end of things is kind of out of my element; I'm mostly involved in the message plumbing side of things.

Our actual HIE integration has been contracted out to Relay Health/McKesson. They're promising the world, but we're not far enough along for me to say whether they'll actually deliver at this point.

Re: It’s Easy to Hack Hospital Equipment

#59

“Many hospitals are unaware of the high risk associated with these devices,” I assure you that while this is the hospital's official stance, many people within the hospital are well aware of the shoddy software on their medical devices and the risks they pose. There are so many opportunities for disruption of every aspect of the healthcare system (from the equipment itself, that this article addresses, to the electro…

I agree. I led a team that added network connectivity to one of our high-value medical instruments and one of the highest hurdles to cross wasn't technical: it was getting the hospitals' IT departments to buy in. They are rightfully paranoid about anything connected to their network. Both for the security of the device itself (it stores thousands of patient test records) and the possibility of it being hostile to the rest of the network.

tl;dr: Buyers may not care, but hospital IT certainly does.

Re: It’s Easy to Hack Hospital Equipment

#60
post #18
post #15

Earlier quoted context omitted.

I almost wonder what a completely reimagined vertically integrated health care system would look and cost like.

Can you explain what you mean by "vertically integrated" in this context?

I mean from every check-in to every release/death, all patient data is collected, tracked. All tests automatically end up in the patient file and every device a patient is hooked up to is part of the same "system". Spend time on an EKG? Every heart beat becomes part of this package. Every shot, every weigh-in, every blood pressure test. This should also tie in to inventory systems etc.

Got the sniffles? The system shows you get them every year at this time, and that it's atypical of any other tracked infectious outbreak, but correlates to three cyclical natural events including a yearly mold growth that it turns out you're allergic to.

End up incapacitates in the ER? System automatically notes your allergies and past medical history, allowing the ER folks to give you one pain medicine instead of the other one that will kill you. While you're there, all the respirators, etc. all get logged. Take 5 units of blood from 3 donors? All their histories are tracked and fed into your treatment in-case some blood-born illness they suffer from but passed screening shows up in your case.

Blood test shows an abnormality? You get automatic trendlines showing either a progression of this abnormal result (blood sugar continues to get lower) or a weird spike, this way your doctor isn't just working off of one data point like usual.

Every x-ray, cat scan etc. all get stored for later reference. The first cat scan your oncologist takes might not be the first cat scan she can refer to if you have one in your file?

Right now, at least in the U.S., and with different insurances every year (meaning my doctor might change every year), I have to really go out of my way just to make sure my shot records follow me. Within one provider they do an okay job of tracking my medical history and getting x-rays from the x-ray machine to the wall mounted display in the evaluation room, but the moment I need to go to a hospital I'm pretty much filling out my history again by hand and from memory.

Vertically integrated means dumping your medical history into Watson to see if some emergent patterns point to some underlying chronic illness you aren't even aware of and don't have notable symptoms yet.

Post reply on HN