homehome Home chatchat Notifications


Hackers are increasingly targeting hospitals -- IVs and other devices are at risk

A lot of hospitals still use default passwords and settings.

Fermin Koop
January 21, 2022 @ 3:05 pm

share Share

More than half of the internet-connected medical devices in hospitals have known vulnerabilities that can put patients’ data and health at risk, a new report shows. The researchers said security threats within healthcare environments remain under-addressed, despite large investments, and much more is needed to ensure that hospitals systems are safe from hacking attacks. 

Image credit: Flickr / Diyan Nenov.

Health organizations are an attractive target for hackers because of their medical and billing information from patients, which can then be sold for insurance fraud or even be used to extort money from the hospital. Hackers can get a big profit, with medical records sold at the black market valued at 50 times more than stolen credit cards.

A hospital’s database can be breached in several ways. The easiest option is social hacking — obtaining credentials from one of the individuals with legitimate access to the network. The second option, much more challenging, involves using brute force to gain access to the network of a health center in an unauthorized way.

A study from 2019 identified over 1,400 hospital-related breaches between 2009 and 2019, affecting 170 million people. The researchers classified the leaked data into three categories: medical information, including diagnoses and treatment, demographic, such as names and addresses, and financial, such as payment info. 

“Healthcare is a top target for cyber-attacks, and even with continued investments in cybersecurity, critical vulnerabilities remain in many of the medical devices hospitals rely on for patient care,” Daniel Brodie, co-founder of Cynerio, said in a statement. “Hospitals and health systems don’t need more data – they need advanced solutions.”

Vulnerable devices

The healthcare cybersecurity company Cynerio went through data from 10 million devices at 300 healthcare facilities and hospitals. The report showed that 53% of all connected medical devices have at least one vulnerability. Additionally, a third of the bedside devices, which patients rely on for their health, have a known critical risk.

Infusion pumps are the most common type of device connected to the internet in hospitals, accounting for 12% of all devices, researchers found. Pumps are also the device most likely to have vulnerabilities that can be exploited by hackers. This creates a big risk, as someone could hack the system and change the dosage of a medication, for instance.

Most hospital devices are used at least once a month. While this is great for hospitals in terms of getting a good return on the investment, it has consequences for the security of the devices, the report found. If they are frequently used, it means that it can be difficult for hospitals to find the time to update the security of the devices. 

“Without robust healthcare security in place, hospitals are sitting on a ticking time bomb,” the report reads. “A ransomware attack may be able to take down the majority of their IoT (internet of things) infrastructure and the hospital won’t have any visibility into how to proactively prevent the attack or shut it down once it’s launched.” 

Where do hospitals go from here, then? Cynerio’s report said most of the vulnerabilities in devices can be fixed with relative ease, especially because many vulnerabilities are linked to default passwords and settings that hackers can get easily from manuals posted online. It’s a good place to start, but there’s still a long way to go.

The full report can be accessed here. 

share Share

The world’s largest wildlife crossing is under construction in LA, and it’s no less than a miracle

But we need more of these massive wildlife crossings.

Your gold could come from some of the most violent stars in the universe

That gold in your phone could have originated from a magnetar.

Ronan the Sea Lion Can Keep a Beat Better Than You Can — and She Might Just Change What We Know About Music and the Brain

A rescued sea lion is shaking up what scientists thought they knew about rhythm and the brain

Did the Ancient Egyptians Paint the Milky Way on Their Coffins?

Tomb art suggests the sky goddess Nut from ancient Egypt might reveal the oldest depiction of our galaxy.

Dinosaurs Were Doing Just Fine Before the Asteroid Hit

New research overturns the idea that dinosaurs were already dying out before the asteroid hit.

Denmark could become the first country to ban deepfakes

Denmark hopes to pass a law prohibiting publishing deepfakes without the subject's consent.

Archaeologists find 2,000-year-old Roman military sandals in Germany with nails for traction

To march legionaries across the vast Roman Empire, solid footwear was required.

Mexico Will Give U.S. More Water to Avert More Tariffs

Droughts due to climate change are making Mexico increasingly water indebted to the USA.

Chinese Student Got Rescued from Mount Fuji—Then Went Back for His Phone and Needed Saving Again

A student was saved two times in four days after ignoring warnings to stay off Mount Fuji.

The perfect pub crawl: mathematicians solve most efficient way to visit all 81,998 bars in South Korea

This is the longest pub crawl ever solved by scientists.