We use cookies to understand how you use our site and to improve your experience. This includes personalizing content and advertising. To learn more, click here. By continuing to use our site, you accept our use of cookies. Cookie Policy.

Features Partner Sites Information LinkXpress hp
Sign In
Advertise with Us
IBA-Radcal

Download Mobile App




Cyber Security Blunders Rife in Hospital Networks

By HospiMedica International staff writers
Posted on 07 Jul 2014
Many hospital networks are leaking valuable information to the internet, leaving critical systems and equipment vulnerable to hacking.

Researchers at Essentia Health (Duluth, MN, USA) set out to scan the internet to determine how many vulnerable medical devices were directly connected to the internet, as opposed to simply being connected to internal networks accessible via the internet. More...
The review followed a two-year investigation into the security of all medical equipment maintained by the Essentia, a healthcare facility operator that runs 100 facilities, including clinics, hospitals, and pharmacies, in four US states.

In that investigation, the researchers encountered drug infusion pumps that could be remotely manipulated to change dosages delivered to patients; Bluetooth-enabled defibrillators that could be manipulated to deliver random shocks to a patient’s heart or prevent a medically needed shock from occurring; and temperature settings on refrigerators storing blood and drugs that could be reset to cause spoilage. In some cases data leaking to the internet from every computer and device on a hospital’s internal network, which could allow hackers to easily locate and map systems to conduct targeted attacks.

The researchers found that the data leaks were the result of network administrators enabling Server Message Block (SMB), on computers facing the internet and configuring it in such a way that allows data to broadcast externally using port 445. SMB is a protocol commonly used by administrators to help quickly identify, locate, and communicate with computers and equipment connected to an internal network. With SMB, each system is assigned an ID number or other descriptor to help distinguish, say, the PC in a doctor’s office from surgical systems in an operating room or testing equipment in a laboratory.

In at least one case, a large health care organization was reporting 68,000 systems connected to its network, including at least 488 cardiology systems, 332 radiology systems, and 32 pacemakers,. At this and every other facility that was leaking data, the problem was an internet-connected computer that was not configured securely. Quite often, the researchers found, these systems also were using unpatched versions of Windows XP still vulnerable to an exploit used by the Conficker worm six years ago. The findings were presented at the Shakacon Information Technology (IT) Security Conference, held during June 2014 in Honolulu (HI, USA).

“SMB problem is just one security issue that health care organizations are facing. The problems exist because the security teams at these organizations are too often focused solely on checking off boxes to meet government regulations for protecting data, while failing to conduct penetration testing and vulnerability maintenance to really test their systems and secure them the way the security teams at banks and other financial organizations do,” said study presenter Scott Erven, head of information security for Essentia Health, who conducted the study together with Shawn Merdinger, an independent security researcher and analyst.

“We started running organization searches to identify hospitals, clinics, and other medical facilities and we quickly realized this is a global health care organization issue - thousands of organizations [that are leaking this information] across the world,” added Erven in an interview with Wired magazine. “In this case, the vulnerability could be easily fixed by simply disabling the SMB service on external-facing systems or reconfiguring it so that it only broadcasts data internally on the hospital’s local network instead of broadcasting it out to the internet for hackers to see.”

Related Links:

Essentia Health



Gold Member
STI Test
Vivalytic Sexually Transmitted Infection (STI) Array
Antipsychotic TDM Assays
Saladax Antipsychotic Assays
Ultrasound Needle Guidance System
SonoSite L25
Adjustable Mobile Barrier
M-458
Read the full article by registering today, it's FREE! It's Free!
Register now for FREE to HospiMedica.com and get access to news and events that shape the world of Hospital Medicine.
  • Free digital version edition of HospiMedica International sent by email on regular basis
  • Free print version of HospiMedica International magazine (available only outside USA and Canada).
  • Free and unlimited access to back issues of HospiMedica International in digital format
  • Free HospiMedica International Newsletter sent every week containing the latest news
  • Free breaking news sent via email
  • Free access to Events Calendar
  • Free access to LinkXpress new product services
  • REGISTRATION IS FREE AND EASY!
Click here to Register








Channels

Critical Care

view channel
Image: The 3D-printed microneedle patch boosts live-virus vaccine delivery (Photo courtesy of IIS/University of Tokyo)

3D-Printed Delivery System Enhances Vaccine Delivery Via Microneedle Array Patch

The COVID-19 pandemic underscored the need for efficient, durable, and widely accessible vaccines. Conventional vaccination requires trained personnel and cold-chain logistics, which can slow mass immunization... Read more

Surgical Techniques

view channel
Image: The AI-based approach identifies lipid regions matched well with histopathology results (Photo courtesy of Hyeong Soo Nam/KAIST)

AI-Based OCT Image Analysis Identifies High-Risk Plaques in Coronary Arteries

Lipid-rich plaques inside coronary arteries are strongly associated with heart attacks and other major cardiac events. While optical coherence tomography (OCT) provides detailed images of vessel structure... Read more

Patient Care

view channel
Image: The revolutionary automatic IV-Line flushing device set for launch in the EU and US in 2026 (Photo courtesy of Droplet IV)

Revolutionary Automatic IV-Line Flushing Device to Enhance Infusion Care

More than 80% of in-hospital patients receive intravenous (IV) therapy. Every dose of IV medicine delivered in a small volume (<250 mL) infusion bag should be followed by subsequent flushing to ensure... Read more

Business

view channel
Image: Medtronic’s intent to acquire CathWorks follows a 2022 strategic partnership with a co-promotion agreement for the FFRangio System (Photo courtesy of CathWorks)

Medtronic to Acquire Coronary Artery Medtech Company CathWorks

Medtronic plc (Galway, Ireland) has announced that it will exercise its option to acquire CathWorks (Kfar Saba, Israel), a privately held medical device company, which aims to transform how coronary artery... Read more
Copyright © 2000-2026 Globetech Media. All rights reserved.