Connected Hospital & Cybersecurity – Scott Trevino, TRIMEDX
Scott Trevino, senior vice president of cybersecurity for TRIMEDX, explains why the connected hospital has become such a tempting threat for cybercriminals.
Transcript
This is Textron TV. Hey guys. Thanks for the throw.
We're here with Scott Trevino. We're talking about connected hospitals and cybersecurity issues. Scott is a senior vice president for cybersecurity at trimetics area that they specialize in so I'm sure we're all about to learn something.
We probably didn't know or suspect Scott welcome to the show. Thank you very much. Glad to be here.
So the more things are connected the more challenging security becomes it's always been kind of one of the paradoxes of our happy little IT industry Integrations of the enemy of security and hospitals are rich Target. So if we have all these connected hospitals, what are the challenges with securing them and and what the folks need to be thinking about? Great question.
And as you I love what you said as Things become more connected the number of connection points increases and it's a complexity increase that's not just linear but exponential it's almost a factorial and when you look at medical device connectivity, that's sort of the dual-edge sword. We've got great Innovation on the devices side more connectivity just estimated to get to almost 70% in the next couple years medical device connectivity, but on the other end, you've got increased risk when it comes to cyber security and managing that for healthcare. So that's kind of at the heart of the risk discussion around cybersecurity and connected medical devices.
And then when you look at Healthcare as a whole as one of our critical infrastructures, it is one of the most highly if not the highly most highly exploited portions of our critical infrastructure and has significant opportunity to evolve and improve when you Look at it, you know for 11 years straight Health Care has the highest cost of a breach at between 9 and 10 million dollars a year with no slowdown in sight and you know recent data shows that at the end of last year in Q4. Globally, the number of attacks per week has increased almost 70% to 830 per week. So there's a massive opportunity here to address and to put it in perspective in terms of connectivity.
And you know, I said 70% of medical devices will be connected over the next couple of years that's estimated, you know through 2028 at a 22 percent caggered. So to put it in dollar perspective. We're looking at going from a market of connected devices around 30 million dollars to over a hundred and twenty billion in the next couple years.
So there's a big opportunity for my perspective. Hospitals of course are dealing with ransomware left right center. But are they prepared for this security challenge around connected devices or they thinking that through or is it just kind of something that you know will deal with when we get there.
So what I would say is that there's a wide spectrum just like any industry or any group. I would say as a Whole Health Care has really pivoted over the last few years to realize the significant need for cybersecurity and I would say yes that the majority of Health Care Providers and systems are looking at cybersecurity the maturity level for you know overalls an industry. I would say is behind the other critical infrastructure areas.
I mentioned that before and it's probably one of the reasons why healthcare's highly targeted in addition to the the value of the information and the sensitivity and and what can happen through attacks and ransomware and you know, denial of service. Physically to patients or delay of service for them. And so what I would say is that there's a spectrum but as a whole there's big opportunity to improve I would say the industry in General's behind other critical infrastructure.
And what's really critical here is is to put in place a comprehensive cyber security program and in particular have an understanding of what it means for medical devices because the cybersecurity issues for medical devices are unique when it comes to other iot due to the regulatory regulated nature of those devices really driving whether there are off the shelf patches that are quickly available other compensating controls and what you can and cannot do from a cybersecurity standpoint for those devices. And of course not every Healthcare organization is the size of mass gen or Columbia Presbyterian are the a lot of these hospitals are in small towns. They're in small cities, you know, do they have the resources to do this or do they need some additional help from outside or is there Cavalry coming over the hill for these folks?
That's that's another great point and it's, you know a general though, you know Rural Community Hospitals in general have challenges with delivery healthcare service and economic challenges those sorts of things and cyber security is no different. What I would say is that the approach the general approach for cyber security, maybe the same but the way it's delivered might be slightly different for instance. There's Technologies and services that can be acquired to put in place a cyber security program that may not have dedicated on site resources for instance.
It may not require those but the simple answer is yes things can be done and in fact Cybersecurity what I would say is that they can be done more easily than some of the other challenges where you might require folks on site to do work. You can do remote monitoring you can put in a security operations center. You can help assist teams in implementing and training on how to apply patches and the availability of those things and some of the other challenges around cybersecurity for healthcare.
What I would also point out is that there's a Confluence of challenges that occurring in healthcare related to cybersecurity on one hand. There is a shortage of cybersecurity talent in general estimated over 300,000 person shortage in terms of General call General it cyber security on the other side of the fence the biomed engineering or clinical engineering world or Healthcare technology management has more people retiring than are being replaced on an annual basis with a significant short. There and when you combine the two expertise which is really required to apply cybersecurity medical devices, you know, you might be looking, you know, you're looking at scarcity for in the market for those resources individually, but when you bring them together, it's you know, not the overuse the term but it's almost a unicorn in some cases.
So there's a lot of challenges with that and so to your question and in the way I answered by doing things remotely. I think that's an efficient way for healthcare to address cybersecurity is you may not have the luxury of onsite, but you can probably scale and do virtual for a lot of things. To help deploy and improve the maturity posture risk posture for Healthcare through those sorts of approaches.
Do you think governments around the world are going to start paying more attention to this connected Hospital cybersecurity issue? Because you know, it does tend to impact their constituents and it is a public safety issue at the end of the day. Absolutely I can say with first-hand knowledge.
It's something I'm actively involved with in the US in particular with FDA with legislators on Capitol Hill. I've seen just in the last few years. I should say been in the health care world my entire career over 25 years now and I would say cyber security has gotten the attention more.
So in the last couple of years and I've seen throughout my my tenure and I think that's a good thing. I think there's a lot of opportunity to educate around what it means for medical devices versus General cyber security, but I would say there's interest in all aspects whether it's FDA from a regulatory standpoint legislators, you know looking at what can they do through the mechanisms they have Other new legislation putting components into you know medical device user fee act to drive behaviors and and requirements across the board and health care to ensure cybersecurity and safety. So I would say yes, but what I would also say is not quick enough as you know, I mentioned some of the data before the threats are growing significantly the level of Technology evolution is fantastic, and that's a good thing.
But with that comes increased risk and the need to respond, so give an example You know, I really applaud what fdas doing. They're working update their pre-market guidance on the development of medical devices. Right which is fantastic requiring secure by Design practices for software and other risk considerations as you look at implementing new product and that's that's terrific.
I think the last update was around 2014. I help comment and was you know participated in and I think that's another message I'd give is folks should get involved the help educate and make sure what's coming out is good. But the wheels turn slow at that level and the pace of what's happening in the cyber world, whether it's on the you know, the attacker response side is evolving at a quicker Pace then regulation and and legislation so we can't rest on that but I would apply what's happening and encouraged more of it and to encourage all participants in health care to get involved because Education into the legislator is involved and The Regulators is really important because there's multiple factors to consider not just the design of the product but one of the things I'm most concerned about is the life cycle management the clinical asset management and lifecycle.
So what happens in the post Market, what are the requirements for response on safety issues a unique thing in medical device world is you know in my experience you see, you know, roughly half only of the devices are patched that have known vulnerabilities, even if there's an you know, let's say a patch for an operating system that's off the shelf that's readily available for that operating system. It may not be validated. And applied or it may not be required to be provided.
And so that presents a very unique challenge in the medical device ecosystem for cybersecurity. And I think there's opportunity to improve from a regulatory and legislative standpoint. I mentioned earlier the delay of treatment and you mentioned safety for patients, which is you know, where we start from and kind of work from to look at how how to assess risk posture and go after our highest risks.
Delay in treatment I think is a very significant risk, and I think that's the awareness of that is increasing. However My opinion is that the the delay of treatment risk is not at the level that requires appropriate action. Meaning there's not a recall a mandatory fix that's in place.
And that's why you see the lack of patches being available for devices that are still susceptible to want to cry which is many years old now. To that point who is responsible for securing these devices because is the manufacturer of the device who may or may not be providing some sort of service agreement around that or is it the responsibility of the IT team in the hospital or is this one of these classic kind of co-managed things that we got to figure out? Yeah, I think you know, it's the it's a ladder that you ended on there.
I would say it's a it's a complexity so ecosystem. So I'll start at you know. The easy one which is if they're where I just ended in my last response.
So it's very easy to see when there's an issue with a drug or a device that let's say has a mechanical failure and breaks and is found to be deficient in its design for safety. There's a recall and we've all been a part of these whether it's Automotive, but on the medical side, it's very much the same which is manufacturer will have to fix something they assess to have an intrinsic safety issue with it. And so that is the responsibility of the design owner who owns the five 10K.
So they you know, there's well established processes for reporting on those safety issues and responding and so that is a manufacturer responsibility. And so when you look at how I you know talked about the cybersecurity issue a risk assessments done for those security and safety issues essentially as a reported and an oem response to those and takes appropriate action based on the requirements of that risk assessment. That's one aspect.
So there's the OEM piece there oems. Also May service device under contract. At the you know at the behest of the owner of the device, so who the purchaser the clinical provider typically and the clinical provider also has their own it Network ecosystem for cybersecurity.
So there's that responsibility that applies there in collaboration with whatever the relationship is or is not with the OEM if there's a service contract there if there's not a service contract regardless, it's a device has an issue there. There is a responsibility from the design owner for that product just like there is with your automobile and maybe 10 years old that there's a safety recall the OEM will fix it. Now if the owner of the device Services the device themself through in-house service with a biomed team that's part of the hospital system.
For instance or they hire an independent service organization that again would be a collaboration where the responsibilities are determined based on, you know the contract with an independent service. Provider who may or may not provide a comprehensive medical device security program, which would then maybe change the boundaries of what would be their under other contracts. Now if the owner of the equipment manages the service themselves or some hybrid form of it, you you see where the complexity May lie, which is the network policies for the overall ecosystem might be specific to the hospital overall.
Generally. Let's say but you might have a subnetwork within an individual department for a particular device that's managed as part of a single OEM service contract for those device types within a system that has you know, it's own biomedical, you know service department that may service other devices on its own without an oem contract so it can get fairly complicated and hence the reason for a comprehensive medical device security program that takes into account. Clinical Asset Management across the board so it can handle or who is responsible where how to best respond given an event how to detect and that's what I would say is another component of this.
So your questions about who's responsible. What I would say is if we step back for a moment one thing to consider is that within the ecosystem for medical devices without and this will sound very simple without good information. Is very difficult to even know what to do for which device and with whom is responsible.
So having a comprehensive security approach for medical devices is critical because what we find and what I find in industry is there is overall a lack of inventory accuracy, so Almost every you know, the vast majority of facilities. Are you that I have seen when you go in and look at inventory. There's the there's a difference between what's traditionally done as a physical inventory and managed in a traditional service world.
And then there's what's really on the network when you think about cyber, you know, hygiene and risk posture and if you compare the two by employing some very straightforward technology just to see what traffic's on the networks and you compare what medical what medical what medical devices are seen on a network versus what you think you have in your cmms. There's a significant difference it ranges widely, but I would say an average, you know, we find you know, 20 to 40 percent devices that may we're not known so to get good, you know cyber hygiene. You need to know what you have now, that's just knowing at a high level what devices you have, but further required is understanding specific details and attributes related to those devices.
So Order to know. What is susceptible or vulnerable to a cybersecurity known vulnerability for instance? You need to understand, you know?
That operating system its revision number specifically the specific details of the make and model of a medical device because they can very widely. What options are on the device Mac address those sorts of things and traditionally and in healthcare so many of those attributes have not been collected because you know, you know working years back the the number of connective medical devices the amount of cyber threats was much lower. So that's the foundation you need good inventory and then from that You can really understand.
Okay, let's get that. Let's get that good then what is it that we need to do from a risk perspective and that's how you can assess what's truly vulnerable you can weigh the devices context. So there's a difference in the risk profile the device based on where and how it's used.
So for instance, you might have redundant CT scanners and a level one Trauma Center because that's a regulatory requirement, you know for that sort of certification and availability so that those devices might be at a different risk level than the same CT scanner type. That's in a you know, nine to five off site Radiology Clinic that's not urgent care. So putting that into perspective along with what the Cyber profile is for the device what vulnerabilities are there help you understand risk prioritization and then finally How do you act and so I mentioned before how do you act depends on what's available for those vulnerabilities?
And as I mentioned in some cases only about half maybe a little bit more there's no patches that can be applied that have are provided by the OEM and what I want to want to really emphasize here the uniqueness of medical device cybersecurity patching for instance or any change requires the OEM to assess the change and there, you know validate that that change doesn't change the form fitter function or safety performance of the device. So that's why there's a delay in getting patches that are available for you know off the chef Os Os is for instance. So that's part of what needs to be done and working and the medical device world is collaborating with those oems to get that out.
And in the case where there's not known fixes. It's really important to apply compensating controls or other risk mitigations, not remediations because there's no remediation available in that case. As Network segmentation take devices off the network and employing other strategies within your hospital system or your ecosystem in general to reduce the risk profile.
So I wanted to make sure I kind of laid that context be you know, as you talked about who's responsible that might help understand not only who's responsible and how you how you can determine that but what's required to put in place a comprehensive system for cybersecurity and and Healthcare. Is it your sense that these are issues present now and things that we're addressing or is this more like a time bomb that we know is going to go off but it's just a question away. Well, what I would say is this is there's good awareness a great awareness and folks I talked to are aware and working on addressing these known challenges and I think what it comes down to is, you know, it's it's the Pareto risk prioritization approach.
How do we go after the right risks first? I would say as as in any industry right now and and I'll use critical infrastructure because that really, you know, people can relate to that Power Systems water treatment, you know, those sorts of our their critical for a reason they're high value targets if you will high profile targets and so what I would say is healthcare's right at the top of the list as those financial systems government bodies, you know power power grid in terms of It's it's a profile for you know, nefarious characters and so behooves the industry to continue to push the ball forward and do it from a risk-based approach and I would say this susceptibility is probably no different than any of the others or at least the profile for the targets, but the data is showing that Healthcare is leading the pack in terms of attacks. I mentioned the reasons before and I don't see any slowdown in that in the data sources.
I'm you know, looking at and consuming tend to indicate the same for the reasons I mentioned there's there's a lot of value in it both monetarily as well as from an impact societal and cultural impact. I would say as well as maybe where where the maturity is across the industry in terms of its Association. All right, folks.
Let's hope we don't wind up on cybersecurity life support. Hey, Scott. Thanks for being on the show.
Thank you very much. Mike. Appreciate the opportunity.
All right back to you guys in the studio.