We use cookies, including third-party cookies from Google to serve personalized ads through AdSense, to operate this site and understand how it is used. By continuing to browse, you accept this use. See our Privacy Policy and Terms of Use for details, including how to opt out of personalized advertising.
Accept
Health Works CollectiveHealth Works CollectiveHealth Works Collective
  • Health
    • Mental Health
  • Policy and Law
    • Global Healthcare
    • Medical Ethics
  • Medical Innovations
  • News
  • Wellness
  • Tech
Search
© 2023 HealthWorks Collective. All Rights Reserved.
Reading: Medical Device Security and the FDA
Share
Notification Show More
Font ResizerAa
Health Works CollectiveHealth Works Collective
Font ResizerAa
Search
Follow US
  • About
  • Contact
  • Privacy
© 2023 HealthWorks Collective. All Rights Reserved.
Health Works Collective > eHealth > Medical Records > Medical Device Security and the FDA
Medical RecordsMobile HealthTechnology

Medical Device Security and the FDA

Rick Delgado
Rick Delgado
Share
6 Min Read
medical device security
SHARE

medical device securityOver the past few years there have been a number of high profile data breaches, from companies like The Home Depot to Target. But it isn’t just large retailers who are vulnerable to cyber attacks.

medical device securityOver the past few years there have been a number of high profile data breaches, from companies like The Home Depot to Target. But it isn’t just large retailers who are vulnerable to cyber attacks. An increasing number of industries are facing network security issues, and some of these industries would be in a much tougher spot if their information was lost or their systems were compromised.  

One such industry is health care. Unfortunately, healthcare organizations haven’t been as diligent about cybersecurity issues. Healthcare IT spending is only about one-fifth the size of comparable industries, showing a significant lack of effort and a clear need for network security improvements.

In an effort to address this issue, the U.S. Food and Drug Administration (FDA) recently issued a number of new guidelines aimed at medical device manufacturers. The hope is to help improve the security measures of these devices, in order to better protect patient information and improve treatment. Some of these new recommendations include:

More Read

How Healthcare Data Analytics Can Influence Patient Care
Cybersecurity in Healthcare: What’s Working?
High Quality, Low Cost HealthCare: Thoughts for Our Upcoming Webinar
Person-Centered HealthCare: Improving Patient Experience By Improving Care
Pfizer and Hospira: It’s Not About Generics
  • Limiting device access to trusted users through the use of authentication, such as IDs, passwords, smart cards and biometrics

  • Using data encryption to ensure information is secure when transferred between devices

  • Implementing features that allow for security compromises to be detected, recognized, logged, timed and acted upon

  • Providing information to end users about the appropriate actions to take upon detection of a cybersecurity event

It should go without saying that protecting health information and securing medical devices is a big deal. Unlike other industries, tampering with healthcare equipment and personal health records could lead to serious risks, even death. With those dangers in mind, you’d think manufacturers would be a lot more conscious of potential threats facing their devices. However, this isn’t the case. Many medical devices aren’t designed to allow for software patches. As a result, when major threats like the recent Heartbleed or Shellshock come along, there is no way to patch up the system and prevent attacks. Not to mention, with so many devices interconnected on a single network, once one machine is compromised, others can fall victim as well. Hopefully the new FDA guidelines will encourage manufacturers to improve their devices so they can be updated in order to fight new security threats.

When these devices are compromised, it doesn’t simply mean a loss of private patient information. Yes, sensitive information falling into the wrong hands is scary, but there are even scarier outcomes. So much medical equipment is controlled by computers, meaning hackers who break into the network could alter drug infusion pumps and administer lethal doses, or control defibrillators and deliver random shocks. In addition, medical records could be altered, leading doctors to prescribe the wrong medicine or unable to access important documents during life-threatening situations.  

Another area contributing to medical network security issues is the many insecure, IP-enabled devices brought into hospitals and clinics. Bring Your Own Device (BYOD) trends aren’t specific to just one industry. Almost everyone is looking to use their phones, tablets or whatever for work. Studies show that 69 percent of hospital nurses and 80 percent of physicians are using their personal smartphones at work. That doesn’t even count all the other devices entering hospitals with patients and visitors. BYOD has many positive aspects. When healthcare professionals use devices with which they are familiar, it can help improve access to information and increase productivity. Those are incredibly important features when lives are on the line. However, these devices aren’t always secure, meaning they could be the means of data leaks and network infections. Doctors could use their tablets to store patient information, but if those devices aren’t properly protected, that information could easily fall into the wrong hands. When working to improve network security, IT professionals working in the healthcare industry will need to consider solutions capable of handling BYOD.

For the moment, the FDA recommendations are only guidelines, not regulations. Opting to follow them is only voluntary, but that shouldn’t encourage manufacturers or hospitals to take their cybersecurity lightly. With new devices come new threats, and healthcare organizations could face severe penalties if they don’t take the right steps to protect their patients and their information.

security / shutterstock

TAGGED:security
Share This Article
Facebook Copy Link Print
Share

Stay Connected

1.5KFollowersLike
4.5KFollowersFollow
2.8KFollowersPin
136KSubscribersSubscribe

Latest News

Mental Health Reimbursements Fail Emergency Departments -- AI-generated illustration
Mental Health Reimbursements Fail Emergency Departments
Hospital Administration Mental Health
August 6, 2026
Advances in Diagnostic Tools for Early Detection of Dementia -- AI-generated illustration
Advances in Diagnostic Tools for Early Detection of Dementia
Diagnostics
August 1, 2026
How Virtual Schools Deliver Therapy and Special-Education Support for Children With Disabilities -- AI-generated illustration
How Virtual Schools Deliver Therapy and Special-Education Support for Children With Disabilities
Health News Therapy
July 31, 2026
mri technology
Why Preventive MRI Maintenance Is Essential for Hospitals
Business Hospital Administration
July 24, 2026

You Might also Like

Management Software in Healthcare
Technology

The Critical Role of Maintenance Management Software in Healthcare

August 12, 2024

Young Google Science Fair Champ Discovers New Leads for Anti-Flu Drugs

October 1, 2013

HealthEdge COO Desrochers on ICD-10 (transcript)

February 23, 2011

5 Best Practices for Switching to an EMR System

September 6, 2016
Subscribe
Subscribe to our newsletter to get our newest articles instantly!
Follow US
© 2008-2026 HealthWorks Collective. All Rights Reserved.
  • About
  • Contact
  • Privacy
Welcome Back!

Sign in to your account

Username or Email Address
Password

Lost your password?