• Follow us

Internet

Secure lifeline - Security needs to be designed into healthcare IoT

Connected devices are transforming our home lives, and are now starting to have a real impact on our healthcare. Thanks to advances in health tech, medical professionals now have reliable remote patient monitoring, automated drug dose delivery, live updated patient records, patient and equipment tracking, and a plethora of other functionalities that not only optimise the care pathway but also improve the level of care provided by medical professionals.

But while health tech manufactures have been forging ahead developing a multitude of Internet of Things (IoT) devices to support medical professionals, one key area has been neglected during development: the security of those devices.

Time to disconnect?

The WannaCry ransomware attack brought UK hospitals’ administration processes to their knees, but the future security issues our healthcare services face due to connected devices could have a significantly more direct and sinister patient impact.

This insecurity in health tech isn’t a new problem. Back in 2013, former US Vice President, Dick Cheney made a decision, along with his cardiologist, to have the wireless access feature disabled in his connected pacemaker for fear that it could be remotely accessed and triggered by an adversarial individual. More recently, manufactures have also issued recalls for both insulin pumps and pacemakers due to security issues, flaws that could potentially have life threatening implications.

While simply disconnecting these products might provide a quick fix, it’s not going to solve the bigger underlying problem. Currently, many IoT products are receiving software patches to enhance security, for example enabling encryption for communications, and organisations are developing dedicated IoT antivirus solutions. But despite this being a step in the right direction for the broader connected device market, delivering security for health tech comes with slightly more complications.

Take implantables like pacemakers as an example, similar to the one Dick Cheney had. Even though delivering a software patch to the device over its wireless connection is possible, the potential result of that patch not working, or causing a problem with how the device operates, is far more dangerous than it is in a connected TV. And by relying solely on patching software insecurities, it leaves people vulnerable to a ‘zero day’ or targeted malicious attack, in the same way those who don’t regularly update their phone are vulnerable to malware. In fact, simply having a device that is capable of being triggered to accept a downloaded firmware update is open to abuse, unless the update process itself is fully secured.

Rebuilding trust

People need to be able to trust their healthcare providers. By the same token, healthcare providers need to be able to trust the medical devices they use. The only real way to ensure trust all around is by health tech manufacturers taking a secure by design approach to their product development.

Secure by design means making security the number one priority during the design phase, and keeping it there throughout the whole lifecycle of the device. Without security, none of the other safeguards that are designed to prevent harm can be assured. It’s something which has become so crucial for IoT products that the UK government introduced a Code of Practice, to help drive manufacturers, retailers and other industry stakeholders to boost the security of connected devices. It is comprehensive, yet easy to follow and provides 13 clear guidelines for manufacturers to adhere to.

The Code of Practice is part of the five-year £1.9 billion security initiative – the Secure by Design review – that was created in collaboration with consumer device manufacturers, retailers and the National Cyber Security Centre to address the number of glaring vulnerabilities in smart devices. Whilst it was developed with a focus on consumer products, the advice provided is valid for those developing connected devices for healthcare.

One of the biggest things which can help those trying to take a secure by design approach is implementing a hardware root of trust.

In general, there are good reasons why hardware-based security is considered to be more secure than a purely software-based approach. Delivered at chip level through a secure core, the hardware root of trust separates general processing from secure processing – allowing a separate processor element dedicated to security tasks. Having a hardware root of trust, which uniquely and immutably identifies a device and can be used as a cryptographic seed, permits a manufacturer to manage the access rights for the devices it produces, and assign those access rights to legitimate parties. Using cryptographic functions, this then enables a secure line of communication to be had between the device and those who need access to it, removing the ability for remote access by a non-approved individual. By eliminating the risk of unauthorised communication and access, along with enabling devices to only accept digitally signed updates that are specific to the device, trust can be assured both in the functions of the device and the data it reports.

Connected healthcare devices: are they as safe as they could be?

As our world get smarter around us, the potential benefits connected technology can provide are huge. But if we really want to see the connected age deliver on its healthcare promise, then we need to make sure that security is front and centre of the conversation. If we don’t do this, then the trust needed for the healthcare sector to benefit from connectivity, big data and automation will be lacking and patients won’t see the benefits they should.

Scott Best, Technical Director of Anti-counterfeiting Technology, RambusImage Credit: Lightpoet / Shutterstock

Read More



Leave A Comment

More News

Latest ITProPortal news

Government and telecoms meeting up over Google's new 2019-04-22 08:30:17An encrypted version could spell trouble for some internet users.

5G will fuel server shipments next year 2019-04-22 07:35:40The new technology will force organisations to refresh their gear.

Multi-cloud and distributed computing – managing your data 2019-04-22 07:00:58Even as companies commit more to cloud, they aren’t addressing the real problems that exist around data and the cloud.

Using RPA for software testing: A “tech hack”? 2019-04-22 06:30:23RPA is not a sustainable solution for software test automation…and the modifications required to make the RPA tool sustainable for the task of

US intelligence claims Huawei funded by China state 2019-04-22 06:00:43Huawei denies the allegations, yet again.

Why SaaS companies should consider outsourcing 2019-04-22 06:00:00As SaaS increases in popularity, outsourcing can indeed be an essential component for long term success. Here are three reasons why SaaS companies sho

Possibilities beyond payments: the far-reaching potential of biometric 2019-04-22 05:30:53Whilst the payment sector is already pioneering change with fingerprint biometric innovation, there is a range of key learnings and successes that man

Pros & cons of integrating artificial intelligence in 2019-04-22 05:00:41AI has started playing a role in mobile app development, with many ride sharing, food delivery etc apps using the app to run operations.

Six skills needed to successfully roll-out Industry 4.0 2019-04-22 04:30:06The transition from initial pilot stage to the large-scale roll-out of an Industry 4.0 and digital transformation project is no easy task. Here are si

Complex transformations need analytics and intelligence 2019-04-22 04:00:48What works for simpler projects won't work for complex transformations - what needs to change?

Digitisation is only the beginning - true transformation 2019-04-19 07:00:17Too many projects begin with the right intentions but the wrong direction.

Fight your space: Multi-tenant big data clusters 2019-04-19 06:30:15Multi-tenant big data clusters are commonplace and essential to businesses, here is how to manage them.

TechRadar: Internet news

Libreoffice vs Apache OpenOffice: how to choose the 2019-04-20 13:00:00These open source office suites have a lot in common, but there are some key differences between the two.

UFC live stream: how to watch Overeem vs 2019-04-20 10:51:48Watch the MMA action from Russia on ESPN+ and beyond with our guide to getting a UFC live stream for Fight NIght 149.

Apple reportedly planning big upgrades to the cameras 2019-04-20 09:30:25One of the top Apple analysts in the business has dropped hints about what Apple is planning for the iPhone cameras in 2019.

Disney’s biggest competitor isn’t Netflix - it’s Fortnite 2019-04-20 09:00:02Disregard the idea that Disney has to beat Netflix, it's Fornite who poses a bigger threat.

Man City vs Spurs live stream: how to 2019-04-20 07:07:11Can Man City get revenge in the Premier League? See how to watch a Man City vs Tottenham live stream wherever you are.

BlackBerry Messenger is closing down for consumers at 2019-04-20 05:30:34BBM is closing its doors for good in the face of fierce competition, though the enterprise version lives on.

Galaxy S10e deals: reduced prices on Samsung's cheapest 2019-04-20 04:59:55Tariffs from £26 per month on the two-month old handset - these Samsung Galaxy S10e deals are well worth a look.

Leak claims Moto Z4 will pack a Snapdragon 2019-04-19 17:13:54A leak claims the Moto Z4 will have a mid-range Snapdragon 675, which may be less powerful than the Moto Z3's main chip.

Amazon Music playlists are now playable on Echo 2019-04-19 15:26:40Amazon is unlocking a free tier of Amazon Music for all Alexa owners that allows you to access playlists and stations.

Best Mac 2019: the best Macs to buy 2019-04-19 15:22:27We weigh the pros and cons of Apple's best Mac desktops and laptops, from Mac mini to the MacBook Pro.

Best Mac apps: the best macOS apps for 2019-04-19 15:20:16From Atom to Amphetamine, these are the best Mac apps out there today.

Best laptops for kids 2019: the top laptops 2019-04-19 15:19:21Find the best laptops for children of all ages, from their first to their last day of school and everything in between.

TechCrunch » Enterprise

Google expands its container service with GKE Advanced 2019-04-16 13:06:12With its Kuberntes Engine (GKE), Google Cloud Google has long offered a managed service for running containers on its platform. Kubernetes users tend

Why it just might make sense that Salesforce.com 2019-04-16 12:18:52Yesterday, Salesforce .com announced its intent to buy its own educational/non-profit arm, Salesforce.org for $300 million. On its face, this feels li

Salesforce ‘acquires’ Salesforce.org for $300M in a wider 2019-04-16 10:38:05Salesforce yesterday announced a move to reposition how it provides software to and works with nonprofits like educational institutions and charities:

Adobe launches an Adobe XD accelerator to woo 2019-04-16 09:03:34The design world is in a state of full-fledged competition. Never in history have designers and their respective teams had so many options from which

Logistics startup Zencargo raises $20M to take on 2019-04-16 08:12:52Move over, Flexport. There is another player looking to make waves in the huge and messy business of freight logistics. Zencargo — a London star

Leapwork raises $10M for its easy process automation 2019-04-16 06:16:15Most work involving computers is highly repetitive, which is why companies regularly have developers write code to automate repetitive tasks. But that

Diving into Google Cloud Next and the future 2019-04-14 13:00:09Extra Crunch offers members the opportunity to tune into conference calls led and moderated by the TechCrunch writers you read every day. This week, T

OpenStack Stein launches with improved Kubernetes support 2019-04-12 16:41:12The OpenStack project, which powers more than 75 public and thousands of private clouds, launched the 19th version of its software this week. You&rsqu

Homeland Security warns of security flaws in enterprise 2019-04-12 11:26:32Several enterprise virtual private networking apps are vulnerable to a security bug that can allow an attacker to remotely break into a company’

Google Cloud makes some strong moves to differentiate 2019-04-11 12:23:24Google Cloud held its annual customer conference, Google Cloud Next, this week in San Francisco. It had a couple of purposes. For starters, it could i

Much to Oracle’s chagrin, Pentagon names Microsoft and 2019-04-11 10:27:09Yesterday, the Pentagon announced two finalists in the $10 billion, decade-long JEDI cloud contract process — and Oracle was not one of them. In

Rasa raises $13M led by Accel for its 2019-04-11 10:12:30Conversational AI and the use of chatbots have been through multiple cycles of hype and disillusionment in the tech world. You know the story: first y

ShoutMeLoud

Ahrefs Review 2019: (Overview, Features & Free Trial) 2019-04-10 03:02:09Are you wondering what Ahrefs can do for you? I have for everything covered for you in this extensive Ahrefs review. Ahrefs has been making news with

10 Best Email marketing Services & Software for 2019-04-06 05:51:25Email marketing isn’t going away this year. Despite what others say (that it’s dead), it will continue to be a powerful tool for any serio

100+ Blogging Tools For 2019, Categorized (+ Expert 2019-04-05 09:30:56Blogging is an art, and using the right blogging tools will make your art rise and shine! This is an epic list of blogging tools to which you can refe

[Deal Alert] BlueHost Hosting Coupon: Save 66% + 2019-03-31 15:23:03Bluehost Webhosting is officially recommended by WordPress hosting page, and it’s the best choice for your WordPress site. Before I share this s

How To Start A Blog & Make $4734 2019-03-29 14:31:28Want to start a blog and get paid by blogging? From last 10 years,  ShoutMeLoud has been teaching about blogging to millions of users around the

YouTube SEO 101: How To Rank Videos on 2019-03-27 21:16:11Want to know how to rank videos on YouTube? Read on to learn everything about YouTube SEO? We all know YouTube is the second largest search engine on

QuadMenu Review: Add a Mega Menu to Any 2019-03-24 03:54:03Running a blog or website isn’t just about creating great content, it’s also about making it easy for your visitors to find and navigate t

13 Easy Online Business Ideas With Minimal Or 2019-03-23 15:24:13Maybe you’re a young boy/girl who wants to start getting dirty in the entrepreneurial side of the business world. Maybe you’re a college g

How To Generate A Disavow File Using Ahrefs 2019-03-23 02:09:51Negative SEO is a real thing. Many marketers are trying to manipulate the system by sending spam backlinks to their competitor’s website. To han

The 5 Best eCommerce Platforms (Compared with Pros 2019-03-23 01:30:46Before the rise of the internet, being a business person was a costly endeavor for most people. It involved, among other things, having a large sum of

Top 14 Reasons Why People Blog 2019-03-21 15:30:22Blogs today have become an essential part and needed for most of the generation worldwide. It’s raining blogs. Life was never so tech savvy befo

How To Write SEO Friendly Content (Beginner To 2019-03-20 20:11:00Do you want to write SEO friendly content? Well, this is an art which could take your blog or your writing career to the next level. Anyone can write

Digital Trends

Geoengineering is risky and unproven, but soon it 2019-04-22 04:00:59Geoengineering is a field dedicated to purposely changing the world's climate using technology. Call it 'playing god' if you must; here's why its

How 3D printing has changed the world of 2019-04-22 04:00:52When he was 13 years old, Christophe Debard had his leg amputated. Here in 2019, Debard's Print My Leg startup helps others to create 3D-printed pros

Climeworks wants to clean the atmosphere with a 2019-04-22 04:00:51Using machines that resemble jet engines, Climeworks wants to fight climate change by extracting CO2 from thin air. The gas can then be sold to carbon

Inside the Ocean Cleanup’s ambitious plan to rid 2019-04-22 04:00:50In 2013, Boyan Slat crowdfunded $2.2 million to fund the Ocean Cleanup, a non-profit organization that builds big, floating trash collectors and sets

Burgers are just the beginning: Embracing the future 2019-04-22 04:00:22You’ve almost certainly heard of the 'farm to fork' movement, but what about 'lab to table'? Welcome to the fast-evolving world of lab-grown

The grid of the future will be powered 2019-04-22 04:00:07In order to transition to a more renewable-focused energy system, we need to scale up our grid storage capacity --- and our existing methods aren't g

Online passwords: Research confirms millions of people are 2019-04-21 22:15:43According to recent analysis of data caught up in cyber attacks, millions of people are continuing to use super-simple passwords, with 123456 topping

Weekend box office: Curse of La Llorona tops 2019-04-21 21:44:04Warner Bros. Pictures' horror film The Curse of La Llorona beat pundits' predictions and middling reviews to end the two-week reign of superhero adv

Joker in Super Smash Bros. Ultimate is freezing 2019-04-21 19:05:51There have been reports that Joker in Super Smash Bros. Ultimate is causing Nintendo Switch units to freeze. Even with the glitch, players may still t

Best new shows and movies to stream: Mid90s, 2019-04-21 19:00:35Need something to watch this weekend? Check out our list of the best new shows and movies to stream right now. On the list this week: Jonah Hill's Mi

LG reportedly files patent for triple selfie camera 2019-04-21 16:58:18LG has reportedly filed a patent for a smartphone with three front-facing cameras. However, if the patent turns out to be true, it may come down as ju

Get cooking with a Masterbuilt meat smoker, now 2019-04-21 16:46:55Warm weather means it’s time to enjoy the great outdoors, but meat lovers know that spring and summer are prime cookout time. The Masterbuilt me


Disclaimer and Notice:WorldProNews.com is not responsible of these news or any information published on this website.