FBI Warns Healthcare Providers About Unpatched and Outdated Medical Device Risks
The Federal Bureau of Investigation (FBI) has issued a private industry notification warning about the rising number of vulnerabilities in medical devices. If medical devices are not promptly patched and are running out of date software, malicious actors could exploit vulnerabilities and gain access to sensitive patient data or the networks to which the devices connect. With a foothold in the network, threat actors could conduct attacks that adversely impact the operational functions of healthcare facilities. Medical devices are often used to sustain patients with mild to severe medical conditions and attacks on those devices have the potential to cause serious harm to patients and even result in the loss of life. The FBI says vulnerabilities in medical devices predominantly stem from device hardware design and device software management. When medical devices are operated in the default configuration, that often provides threat actors with an opportunity to exploit vulnerabilities. Devices with customized software can be difficult to patch, often requiring specialized procedures,...
HC3 Highlights Privacy and Security Risks Associated with Emerging Technologies
Emerging technologies have the potential to revolutionize the healthcare industry. While there are many potential benefits, these technologies can introduce risks that could threaten patient privacy and safety. If vulnerabilities are not properly addressed, they could be exploited by malicious actors to gain access to sensitive patient data or internal networks, which could threaten patient safety. The Health Sector Cybersecurity Coordination Center (HC3) has drawn attention to some of the most beneficial emerging technologies that have the potential to revolutionize clinical research, the monitoring and delivery of care, communication, data analysis, and data protection, and has highlighted some of the risks associated with these technologies. Artificial intelligence systems can rapidly analyze big data, provide deeper patient insights, and accurately diagnose medical conditions from medical images and data far more quickly than humans, accelerating clinical decisions. While the uses of AI in healthcare are numerous, these systems can introduce risks. AI systems need access to...
4 Vulnerabilities Identified in Baxter & Sigma Spectrum Infusion Pumps
Researchers at Rapid 7 have identified four vulnerabilities in Baxter and Sigma Spectrum infusion pumps, which are used to deliver medications and nutrition to patients. The devices are TCP/IP enabled and are usually connected to healthcare networks. Successful exploitation of the vulnerabilities could allow malicious actors to make system configuration changes and access sensitive patient data. The vulnerabilities were discovered around 5 months ago and were reported to Baxter. Rapid 7 has been working with Baxter to resolve the medium- and low-severity vulnerabilities and recently published a report on the flaws. The flaws affected the following Baxter and Sigma Spectrum infusion pumps. Sigma Spectrum v6.x model 35700BAX Sigma Spectrum v8.x model 35700BAX2 Baxter Spectrum IQ (v9.x) model 35700BAX3 Sigma Spectrum LVP v6.x Wireless Battery Modules v16, v16D38, v17, v17D19, v20D29 to v20D32, and v22D24 to v22D28 Sigma Spectrum LVP v8.x Wireless Battery Modules v17, v17D19, v20D29 to v20D32, and v22D24 to v22D28 Baxter Spectrum IQ LVP (v9.x) with Wireless Battery Modules v22D19 to...
Michigan Law Firm and Medical Imaging Companies Confirm Breaches of Patient Information
The Michigan law firm, Warner Norcross and Judd LLP, has issued notification letters to 255,160 individuals advising them about an October 2021 security breach in which files containing their personal and protected health information were potentially accessed and exfiltrated from its systems. The breach was detected on October 22, 2021. The substitute breach notification does not state when, and for how long, unauthorized individuals had access to its systems. A digital forensics firm was engaged to investigate the nature and scope of the data breach and a programmatic and manual review was conducted on files on the affected parts of its network. The review confirmed that the files contained information such as names, dates of birth, Social Security numbers, driver’s license numbers, government-issued IDs, annual compensation amounts, benefit contribution information, credit card or debit card numbers, credit card or debit card PINs, financial account or routing numbers, passport numbers, patient account numbers, health information, and life insurance policy information....
The Urology Center of Colorado Agrees to Settle Class Action Data Breach Lawsuit
The Urology Center of Colorado has agreed to settle a class action lawsuit that was filed in response to a 137,820-record data breach in September 2021. On November 5, 2021, the urology practice sent notification letters to its patients advising them that some of their protected health information was potentially compromised two months previously, between September 7 and September 8, 2022. Unauthorized individuals accessed its network and potentially removed files containing patient information such as names, addresses, dates of birth, Social Security numbers, medical record numbers, diagnoses, physician names, insurance provider names, guarantor names, and treatment cost information. Affected individuals were offered complimentary credit monitoring and identity theft protection services for 12 months. A lawsuit was filed in response to the data breach on behalf of plaintiffs Kristen Snyder and Diona Lopez and other individuals similarly affected by the data breach. The plaintiffs alleged the Urology Center of Colorado was negligent for failing to implement necessary safeguards to...



