Medical device security



Similar documents
HL7 EHR to PowerSoftMD Visit Import Specifications

What is Really Needed to Secure the Internet of Things?

LIS Interfaces: Basics, Implementation and Pitfalls

Considerations for using the Web for Medical Device Applications

20/20 Integration Guide

HL7 Interface Specification. HL7 Interface 1.2

AUTHORED BY: George W. Gray CTO, VP Software & Information Systems Ivenix, Inc. ADDRESSING CYBERSECURITY IN INFUSION DEVICES

Hong Kong Information Security Outlook 2015 香 港 資 訊 保 安 展 望

Presented By: Holes in the Fence. Agenda. IPCCTV Attack. DDos Attack. Why Network Security is Important

CDM Hardware Asset Management (HWAM) Capability

Notable Changes to NERC Reliability Standard CIP-010-3

Information Security Services

The Internet of Things (IoT) Opportunities and Risks

Medical Device Security Health Group Digital Output

Incident Response. Six Best Practices for Managing Cyber Breaches.

Medical Device Security Health Imaging Digital Capture. Security Assessment Report for the Kodak DR V2.0

Introduction to Epic Bridges. Empowering Extraordinary Patient Care

HL7 Interface Specification Merge LabAccess v. 3.6

Computer Networks & Computer Security

Overview of Network Security The need for network security Desirable security properties Common vulnerabilities Security policy designs

Medical Device Security Health Imaging Digital Capture. Security Assessment Report for the Kodak CR V4.1

Running head: USING NESSUS AND NMAP TOOLS 1

The Internet of Things Risks and Challenges

Medical Device Security Health Imaging Digital Capture. Security Assessment Report for the Kodak Capture Link Server V1.00

Healthcare Cybersecurity Perspectives from the Michigan Healthcare Cybersecurity Council

HL7 & KMEHR. A comparison. Medical informatics AJ 2013/2014. Authors: Tessa Borloo Nele Pien

NURSING INFORMATICS. Nikole L. Farmer, MSN, RN, PMP September 6, 2014

Bring Your Own Internet of Things: BYO IoT

INTRUSION DETECTION SYSTEMS and Network Security

Web of Things Architecture

Digital Pathways. Penetration Testing

Security Awareness For Server Administrators. State of Illinois Central Management Services Security and Compliance Solutions

When a student leaves this intensive 5 day class they will have hands on understanding and experience in Ethical Hacking.

IoT Security: Problems, Challenges and Solutions

Medical Device Security Health Imaging Digital Capture. Security Assessment Report for the Kodak Medical Image Manager (MIM) Version 6.1.

Utility Telecom Forum. Robert Sill, CEO & President Aegis Technologies February 4, 2008

BLACKJACKING: SECURITY THREATS TO BLACKBERRY DEVICES, PDAS, AND CELL PHONES IN THE ENTERPRISE

What is Quantified Self (QS)?

Securing the Internet of Things WHITEPAPER

EHS Privacy and Information Security

HL7 Format and Electronic Sharing

Belmont Savings Bank. Are there Hackers at the gate? 2013 Wolf & Company, P.C.

UMA in Health Care: Providing Patient Control or Creating Chaos?

Access is power. Access management may be an untapped element in a hospital s cybersecurity plan. January kpmg.com

MEDICAL DEVICE Cybersecurity.

10 best practice suggestions for common smartphone threats

D* SEE SAP DIR DIGITAL SIGNATURE LOG FOR APPROVER NAME AND DATE OF APPROVAL

Too Critical To Fail Cyber-Attacks on ERP, CRM, SCM and HR Systems

Privacy Policy Version 1.0, 1 st of May 2016

Building a Security Operations Center. Randy Marchany VA Tech IT Security Office and Lab marchany@vt.edu

Windows Remote Access

Cybersecurity Implications in the US Chemical Industry. Modernization and Greenfield Opportunities

Dr. György Kálmán

IoT Security: Problems, Challenges and Solutions

Course Content Summary ITN 261 Network Attacks, Computer Crime and Hacking (4 Credits)

GE Healthcare. MAC 2000 ECG Analysis System Streamlined for your hospital

WISE-4000 Series. WISE IoT Wireless I/O Modules

How-To Guide: Cyber Security. Content Provided by

A M D DA S 1. 0 For the Manageability, Virtualization and Security of Embedded Solutions

Automotive Ethernet Security Testing. Alon Regev and Abhijit Lahiri

Privacy, Security, and Trust with Federated Identity Management

An Independent Member of Baker Tilly International

A method for handling multi-institutional HL7 data on Hadoop in the cloud

IRON-HID: Create your own bad USB. Seunghun Han

Build Your Own Security Lab

HIPAA: Bigger and More Annoying

IT HEALTHCHECK TOP TIPS WHITEPAPER

Patch and Vulnerability Management Program

Locking down a Hitachi ID Suite server

Medical Device Software

Cyber Security 2014 SECURE BANKING SOLUTIONS, LLC

Cyber Liability. Michael Cavanaugh, RPLU Vice President, Director of Production Apogee Insurance Group Ext. 7029

DATA SECURITY HACKS, HIPAA AND HUMAN RISKS

Privacy Policy. Introduction. Scope of Privacy Policy. 1. Definitions

DMZ Gateways: Secret Weapons for Data Security

Early Evaluation Center

Learn Ethical Hacking, Become a Pentester

Facilitated Self-Evaluation v1.0

The State-of-the-State of Control System Cyber Security

Bluetooth Health Device Profile and the IEEE Medical Device Frame Work

Cyber Security nei prodotti di automazione

Bridging the gap between COTS tool alerting and raw data analysis

Transcription:

Medical device security -- Anirudh Duggal Disclaimer: The views in the presentation are entirely my own and do not reflect the views of my employer.

Before we begin Thank you HITCON Specially thank the organizing team Jal, Pineapple, Turkey, Shanny, Shang and all the people whom I ve troubled till now

About me Senior Software Engineer at Philips health tech anirudhduggal@gmail.com Sustainability enthusiast Interested in medical devices, IOT devices and hardened OS Part of Null community

Nullcon CFP is out!

Agenda What is a medical device? Range of medical devices Medical record value and breaches Challenges Besides challenges Hl7 messaging

What is a medical device? A medical device is an instrument, apparatus, implant, in vitro reagent, or similar or related article that is used to diagnose, prevent, or treat disease or other conditions, and does not achieve its purposes through chemical action within or on the body (which would make it a drug) -- wiki

Range of devices Cost: 5 2$ (50% off) Fits in pocket Cost: can reach up to 3 million $ Size: about the size of a truck (don t ask the weight ;) )

And the memory A simple DIY device A hospital data center

And. Patient monitors Insulin monitors Pacemakers Heart rate devices smart bands Home monitoring solutions

Rapid Innovation Everyone wants mobility (patient, doctors, nurses, clinicians) Diagnostics Big data analysis Information gathering

Why hospitals and medical devices? Easy targets Many entry points Good payoff Medical records

The impact of an attack Privacy Financial a medical record fetches 32x a credit card record Physical?

Lets take a case study

Analyzing a hospital scenario

A typical hospital scenario Other systems Other hospitals Doctor's PC / Secretary PC Patient monitors LAN / WIFI/ Bluetooth/ EMR (electronic medical record) Doctor's Mobile/ Nurse mobile

A typical patient monitor Other peripheral devices Lan / WiFI TCP / IP EMR Serial ports USB HL7

Diving into medical devices They have an OS (sometimes ) They have connectivity ( Fuzzers ;) ) They do have logical errors Protocols Compare the low end devices to IOT infrastructure Can crash / misbehave Known to have APT s discovered in them Trapx discovered a APT recently google

Potential entry points Wifi / Lan Serial ports USB - Firmware The sensors Keyboard / mouse Firewire Protocols

Challenges with these devices Patching Servicing Uptime Cost Longevity

Technical issues observed on the ground Lack of encryption between the devices Lack of skilled personnel

From a manufacturer perspective Support 10 years and counting! How do you define a device to be vulnerable? Security a joint exercise between hospitals and the vendors

From a hospital perspective If it works its all good Cybersecurity needs more investment and skilled individuals Vendors should take care of all security issues why will someone attack a hospital computer go hack NASA we are doctors, not cyber warriors

Hospitals need to understand Cybersecurity!= more money BUT Cybersecurity == better functioning Risks of a cyber attack Patching is a problem, but absolutely worth it Having IDS / IPS Say no to outdated infrastructure (this is changing rapidly )

Securing these devices Having a policy in place cybersecurity policy anyone? DO NOT CONNECT THESE DEVICES TO THE INTERNET unless intended Make sure the systems are patched Know your hospital ( public and private networks anyone? )

Policies / agencies in place FDA HIPAA

$100 to $50,000 per violation (or per record), with a maximum penalty of $1.5 million per year for violations of an identical provision

My opinion We need better regulations - now! Awareness A working group towards security (lets take things global too ) More research on the APT and exploits

What is HL7? Healthcare level standards Most popular in healthcare devices (HL7 2.x) Quite old designed in 1989 FHIR is the next gen

HL7 2.x Most popular HL7 version New messages / fields added

HL7 (only for v2 messaging and CDA) HL7

Things to know MSH message header segment defines the delimiters e.g. MSH ^~\& The primary delimiter is and sub delimiters in the order they are present after The standards define the message structure not the implementation

An HL7 message MSH ^~\& MegaReg XYZHospC SuperOE XYZImgCtr 20060529090131-0500 ADT^A01^ADT_A01 01052901 P 2.5 EVN 200605290901 200605290900 PID 56782445^^^UAReg^PI KLEINSAMPLE^BARRY^Q^JR 19620910 M 2028-9^^HL70005^RA99113^^XYZ 260 GOODWIN CREST DRIVE^^BIRMINGHAM^AL^35209^^M~NICKELL S PICKLES^10000 W 100TH AVE^BIRMINGHAM^AL^35200^^O 0105I30001^^^99DEF^AN PV1 I W^389^1^UABH^^^^3 12345^MORGAN^REX^J^^^MD^0010^UAMC^L 67890^GRAINGER^LUCY^X^^^MD^0010^UAMC^L MED A0 13579^POTT ER^SHERMAN^T^^^MD^0010^UAMC^L 200605290900 OBX 1 NM ^Body Height 1.80 m^meter^iso+ F OBX 2 NM ^Body Weight 79 kg^kilogram^iso+ F AL1 1 ^ASPIRIN DG1 1 786.50^CHEST PAIN, UNSPECIFIED^I9 A

MSH ^~\& MegaReg XYZHospC SuperOE XYZImgCtr 20060529090131-0500 ADT^A01^ADT_A01 01052901 P 2.5 EVN 200605290901 200605290900 PID 56782445^^^UAReg^PI KLEINSAMPLE^BARRY^Q^JR 19620910 M 2028-9^^HL70005^RA99113^^XYZ 260 GOODWIN CREST DRIVE^^BIRMINGHAM^AL^35209^^M~NICKELL S PICKLES^10000 W 100TH AVE^BIRMINGHAM^AL^35200^^O 0105I30001^^^99DEF^AN PV1 I W^389^1^UABH^^^^3 12345^MORGAN^REX^J^^^MD^0010^UAMC^L 67890^GRAINGER^LUCY^X^^^MD^0010^UAMC^L MED A0 13579^POTT ER^SHERMAN^T^^^MD^0010^UAMC^L 200605290900 OBX 1 NM ^Body Height 1.80 m^meter^iso+ F OBX 2 NM ^Body Weight 79 kg^kilogram^iso+ F AL1 1 ^ASPIRIN DG1 1 786.50^CHEST PAIN, UNSPECIFIED^I9 A

Message header information Message type / event type Patient identifier MSH ^~\& MegaReg XYZHospC SuperOE XYZImgCtr 20060529090131-0500 ADT^A01^ADT_A01 01052901 P 2.5 EVN 200605290901 200605290900 PID 56782445^^^UAReg^PI KLEINSAMPLE^BARRY^Q^JR 19620910 M 2028-9^^HL70005^RA99113^^XYZ 260 GOODWIN CREST DRIVE^^BIRMINGHAM^AL^35209^^M~NICKELL S PICKLES^10000 W 100TH AVE^BIRMINGHAM^AL^35200^^O 0105I30001^^^99DEF^AN PV1 I W^389^1^UABH^^^^3 12345^MORGAN^REX^J^^^MD^0010^UAMC^L 67890^GRAINGER^LUCY^X^^^MD^0010^UAMC^L MED A0 13579^POTT Patient name ER^SHERMAN^T^^^MD^0010^UAMC^L 200605290900 OBX 1 NM ^Body Height 1.80 m^meter^iso+ F OBX 2 NM ^Body Weight 79 kg^kilogram^iso+ F AL1 1 ^ASPIRIN DG1 1 786.50^CHEST PAIN, UNSPECIFIED^I9 A Physician name

MSH ^~\& MegaReg XYZHospC SuperOE XYZImgCtr 20060529090131-0500 ADT^A01^ADT_A01 01052901 P 2.5 EVN 200605290901 200605290900 PID 56782445^^^UAReg^PI KLEINSAMPLE^BARRY^Q^JR 19620910 M 2028-9^^HL70005^RA99113^^XYZ 260 GOODWIN CREST DRIVE^^BIRMINGHAM^AL^35209^^M~NICKELL S PICKLES^10000 W 100TH AVE^BIRMINGHAM^AL^35200^^O 0105I30001^^^99DEF^AN PV1 I W^389^1^UABH^^^^3 12345^MORGAN^REX^J^^^MD^0010^UAMC^L 67890^GRAINGER^LUCY^X^^^MD^0010^UAMC^L MED A0 13579^POTT ER^SHERMAN^T^^^MD^0010^UAMC^L 200605290900 OBX 1 NM ^Body Height 1.80 m^meter^iso+ F OBX 2 NM ^Body Weight 79 kg^kilogram^iso+ F Potential Entry Point AL1 1 ^ASPIRIN DG1 1 786.50^CHEST PAIN, UNSPECIFIED^I9 A

MSH ^~\& MegaReg XYZHospC SuperOE XYZImgCtr 20060529090131-0500 ADT^A01^ADT_A01 01052901 P 2.5 EVN 200605290901 200605290900 PID 56782445^^^UAReg^PI KLEINSAMPLE^BARRY^Q^JR 19620910 M 2028-9^^HL70005^RA99113^^XYZ 260 GOODWIN CREST DRIVE^^BIRMINGHAM^AL^35209^^M~NICKELL S PICKLES^10000 W 100TH AVE^BIRMINGHAM^AL^35200^^O 0105I30001^^^99DEF^AN PV1 I W^389^1^UABH^^^^3 12345^MORGAN^REX^J^^^MD^0010^UAMC^L or my evil script MED A0 13579^POTTER^SHERMAN^T^^^MD^0010^UAMC^L 200605290900 OBX 1 NM ^Body Height 1.80 m^meter^iso+ F OBX 2 NM ^Body Weight 79999999999999999999999999999999999999999999 kg^kilogram^iso+ F AL1 1 ^ASPIRIN DG1 1 786.50^CHEST PAIN, UNSPECIFIED^I9 A

Time for a demo

Questions

Thank you! Minatee Mishra Ben Kokx Christopher Melo Sanjog Panda Ajay Pratap Singh Geethu Aravind Michael Mc Neil Shashank Shekhar Madhu Jiggyasu Sharma Pardhiv Reddy My uptown friends ;)