March 19, 2018 By David Bisson 2 min read

Current U.K. regulations do not fully consider how poor device security could potentially affect patient privacy and safety in the healthcare sector, according to a new report.

Vulnerabilities and Increased Integration Put Patients at Risk

In a study titled “Cyber Safety and Resilience: Strengthening the Digital Systems That Support the Modern Economy,” researchers from the Royal Academy of Engineering argued that the U.K.’s health device regulations fail to adequately account for digital security as the technology landscape evolves.

“The regulation of health devices and systems has focused on patient safety, albeit not perfectly, but has not fully considered the possible impacts of poor cybersecurity,” the researchers wrote in the report. “As new technologies and systems are created, and the threat environment evolves, vulnerabilities in connected health devices need to be addressed.”

According to the study, both implantable and nonimplantable health devices are prone to vulnerabilities. These weaknesses affect low-power, low-footprint sensors as well as large-scale legacy medical equipment.

At the same time, the researchers observed that healthcare providers’ enterprise systems are integrating more with clinical suppliers and systems. This makes them preferred targets of ransomware and other digital threats.

Improving Health Device Regulations in the UK

Researchers advised U.K. regulators to address these risks by linking data protection standards with digital security best practices. In addition, security frameworks should use clear language to help device manufacturers and other parties easily navigate the regulations.

The report also outlined the following recommendations for securing health devices to ensure patients’ safety:

  • Governance — When applicable, clarify the roles and responsibilities for national and local entities in the U.K.’s National Health Service (NHS).
  • Procurement — Look to other industries to understand supply chain risks. Organizations can use that knowledge to build more trustworthy products and provide customers with information about the security of those items.
  • Design — Seek input from healthcare professionals when creating new systems. Developers need such contributions to learn how health organizations implement their systems.
  • Defense — Explore patch management strategies that account for patient safety and the security of medical devices.
  • Education — Train clinical professionals on digital security and data literacy.

The report’s lead author, Nick Jennings, underscored these recommendations with a plea to build better security into systems from the outset. “We cannot totally avoid failures or attacks,” he said, “but we can design systems that are highly resilient and will recover quickly.”

Many of the recommendations for healthcare also apply to other critical sectors. The researchers noted that it’s important for private organizations to work with the U.K. government to develop relevant sector-specific guidelines.

More from

NIST’s role in the global tech race against AI

4 min read - Last year, the United States Secretary of Commerce announced that the National Institute of Standards and Technology (NIST) has been put in charge of launching a new public working group on artificial intelligence (AI) that will build on the success of the NIST AI Risk Management Framework to address this rapidly advancing technology.However, recent budget cuts at NIST, along with a lack of strategy implementation, have called into question the agency’s ability to lead this critical effort. Ultimately, the success…

Researchers develop malicious AI ‘worm’ targeting generative AI systems

2 min read - Researchers have created a new, never-seen-before kind of malware they call the "Morris II" worm, which uses popular AI services to spread itself, infect new systems and steal data. The name references the original Morris computer worm that wreaked havoc on the internet in 1988.The worm demonstrates the potential dangers of AI security threats and creates a new urgency around securing AI models.New worm utilizes adversarial self-replicating promptThe researchers from Cornell Tech, the Israel Institute of Technology and Intuit, used what’s…

Passwords, passkeys and familiarity bias

5 min read - As passkey (passwordless authentication) adoption proceeds, misconceptions abound. There appears to be a widespread impression that passkeys may be more convenient and less secure than passwords. The reality is that they are both more secure and more convenient — possibly a first in cybersecurity.Most of us could be forgiven for not realizing passwordless authentication is more secure than passwords. Thinking back to the first couple of use cases I was exposed to — a phone operating system (OS) and a…

Topic updates

Get email updates and stay ahead of the latest threats to the security landscape, thought leadership and research.
Subscribe today