News
The cybersecurity implications of medical devices have come under scrutiny, as the digitisation of healthcare reaches a wider net of professional, personal and public environments.
In the bid to consider and plan for an evolving cybersecurity landscape to maintain patient safety, the Therapeutic Goods Administration (TGA) has released a draft regulation guidance on cybersecurity for medical devices, in line with the existing regulatory requirements.
The Medical Device Cybersecurity Draft Guidance and Information for Consultation report calls for a clear regulatory environment for connected medical devices and identifies strategies to influence the approaches of those who use medical devices.
“Connectivity and digitisation of medical device technologies may help improve or increase device functionality. However, the connection of devices to networks or the internet exposes devices to increased cyber vulnerabilities that can potentially lead to unacceptable risk of harm to patients,” the report identified.
“These include denial of service or intended therapy, alteration of personal health data or alteration of device function so that it can cause actual patient harm.
“In 2016, the Australian Government released Australia’s Cyber Security Strategy, detailing priority actions to improve Australia’s general cyber security posture, alongside supporting the growth of the local cyber security industry… In line with this, the continued safety, quality and performance of medical devices impacted by cyber-related issues is the responsibility of the TGA.”
According to the TGA, operating environments are highly variable and cybersecurity risks are dependent on the knowledge, expertise and approach of the users of medical devices.
“A compliant medical device will only be as secure as the most vulnerable aspect of the system it is expected to operate in. Users of medical devices also have share responsibility for providing a cyber secure environment for these devices to operate in,” the report stated.
WHAT IS NECESSARY?
Key to the implementation of medical devices, according to the report, is the development of a “clear and well documented” risk assessment and business continuity strategy, where the goal is to develop an environment where risk to patients is minimised.
It includes an injunction for device manufacturers and users to develop a cybersecurity strategic plan, which includes a cyber specific risk assessment and response strategies.
“The plan should have clearly defined event response procedures that define the responsibilities of each department in the event of an incident, and emphasise the importance of each area being familiar with these procedures,” it said.
“The strategy will need to be revised as new types and classes of connected medical devices are added to the healthcare environment.”
[Read more: Is your healthcare ecosystem cyber resilient enough? | "Humans are not the weakest link": Shifting the cybersecurity narrative to fend off healthcare hacks]
Cross-functional collaboration is a tool that the report claimed is essential for effective cybersecurity control of medical devices.
The TGA said healthcare service providers should aim to facilitate an environment which drives cross functional collaboration between the biomedical, clinical support and IT teams, helping all areas develop a better understanding of the work completed within each team.
“The biomedical team should… engage with medical professionals within the healthcare organisation to help broaden their understanding of the operating profile of their devices, the technology under their management, implementation of cyber security controls and the associated risk,” it said.
Collaborative procurement is another area for improvement as updating procurement practices to ensure the purchase of appropriately secure devices will create greater demand for improved cybersecurity within medical devices, the report identified.
“[One way is to] incentivise procurement teams to work with IT and biomedical teams on the procurement of new medical devices to help ensure that cybersecurity is a measurable factor in procurement.”
The report also suggested that organisations develop an inventory and risk profile of the current state of connected medical devices, providing insight to vulnerabilities in the operating environment.
This inventory could include information such as the operation and purpose of a medical device, its secondary uses, who the primary users are, expected life-span of the device, support agreements in place and support for critical components.
The report also called for more general training for all staff within organisations to raise baseline security awareness and skills.
“Many professionals in the health and medical sector have received little training on cybersecurity. [Organisations need to] actively work to create a culture of cyber security awareness, vigilance and reporting, and regularly communicate potential cyber security issues,” it said.
Segmenting the corporate network from the biomedical network could also help improve cybersecurity attacks.
“Ideally, this should be done with an internal firewall. This will significantly reduce the risk of malware spreading from one network to another. Medical devices should be segmented into logical groups (manufacturer or modality) to reduce the attack surface. When possible, medical devices should be isolated,” the report said.
[Read more: World-first cybersecurity trial safeguarding medical devices from hackers to take place in Victoria | Tyde set to become the first digital health company to earn the government’s top cybersecurity accreditation]
In addition, it recommended that healthcare organisations consider implementing multi-factor authentication for staff access to networks, especially in areas of high traffic, and reduce privileges to only those required.
“Access to the network is critical for most medical devices, especially with an Electronic Medical Record (EMR) system. Ensuring that only authenticated access is provided is key but when credentials are compromised, it can be challenging to define authenticated but unauthorised access.
“So, regular reviews of network access should be completed. These must be managed to ensure usability of systems is not adversely impacted.”
The report also said that more focus should be given to securing medical devices themselves, instead of just to ICT equipments.
“Monitoring the internal and external environment for medical device abnormalities and cyber security threats is important to building a stronger cyber security posture. One advantage of monitoring medical devices is that their range of normal operation is narrow. This means that anomalies can be easier to spot in medical devices than ICT equipment,” it identified.
The TGA has invited industry, peak bodies, professional and consumer groups, and individuals to provide comment on the draft guidance. Submissions for comment close on 14 February and will be used to help inform the final guidance document.
Dr. John Halamka, CIO of Beth Israel Deaconess Medical Center, traveled 400,000 miles in 2018 – jetting all over the world, from China to India to Scotland to Scandinavia.
On those journeys, he has seen how care is delivered in very different ways. In China, for instance (he has been there 35 times), there is no primary care. As a result, patients can self-select any provider, leading to a scattered lifetime record across diverse provider sites.
In India, where active tuberculosis is widespread, access to care is much more difficult, and treatments are often mismatched to illness.
"This is not precision medicine," Halamka said, speaking at the HIMSS19 Precision Medicine Summit.
What is precision medicine? It's not just genomics. It's more than just social determinants of health (although those do play a much bigger role than many realise). At its core, he said, precision med is "the right care in the right setting from the right provider at the right time."
That's a easier said than done, of course. There are big differences between diagnosis and treatment, and so much depends on demographics, genetics and other biomarkers, geography, climate and more.
Data – structured, complete, well-governed and easy to see – will be key to precision medicine becoming more widespread, Halamka said: "On the precision medicine journey, having the data accessible is going to be hugely important."
That's why Scotland, for instance, which has set up a single database for most of its five million-plus people, may be in a better position than, say, Australia, whose health record modernisation was at first planned to be centered around PDFs and fax machines, Halamka said -- until he raised the alarm about the need for discrete and well-groomed data that can be mined by AI-powered analytics.
The good news? "In 2019 tools are finally good enough to help us realise the promise of precision medicine," Halamka said. The challenge? There's also a lot of "interesting politics and policy issues that are part of our precision medicine journey. It's not just technology."
But there are some urgent imperatives that will force those issues to sort themselves out soon, such as aging societies all over the world, falling birth rates, clinician shortages and, of course, wildly unsustainable healthcare costs, he said. In the US, we spend more than 18 per cent of our GDP on "very imprecise care," Halamka added.
That's got to change, of course, and has been slowly. The pace will quicken in the years ahead, with a profusion of emerging tech, he said.
"The internet of things and connected health devices are exploding; AI and machine learning are going mainstream; apps and cloud hosted services are ubiquitous; application programming interfaces are "increasing in number and sophistication," he explained.
But more needs to happen to help harness those new technologies for this larger purpose on a wider scale: "Precision medicine means that we need to deliver in the context of workflow decision support to the clinician to do the right thing at the right time," Halamka said. "None of this happens without a policy driver."
He listed some of the policy changes that could help achieve that – notably, ONC's long-awaited information blocking rule, which was being released at HIMSS19 as he spoke. Other policies, such as CMS' rules meant to reduce clinician burden and various other governmental nudges to encourage third-party innovation, will only help move the needle.
But in the meantime, the challenges persist, said Halamka, whether related to data provenance and quality or security and privacy concerns.
A subsequent panel discussion at the Precision Medicine Summit drove that point home.
The promise and potential are all there, but "it's still in this very squishy phase right now," Professor and Chair of Radiation Oncology at Jefferson Institute For Digital Health Dr. Adam Dicker said.
"We're not ready for prime time," agreed Jean Wright, Chief Innovation Officer at Atrium Health.
Part of that has a lot to do with technology – at least as the infrastructure exists today.
"Epic and Cerner are not at the leading edge of this," Wright said. There's plenty of valuable, envelope-pushing tools developed by some very creative smaller vendors, but "much of the technology is out there, but not in a plug-and-play format."
That too is fast-evolving, however, as APIs proliferate – many of them mandated by ONC – and patients get more comfortable using apps and devices that can then easily integrate with electronic health records.
That's creating a wellspring of genomic and social determinant information. And while interoperability and decision support still need to catch up, the data is there, more every day, and ready to be integrated into clinical workflows for personalised care.
This article first appeared in the global edition of Healthcare IT News.
With worries that China and other countries are outpacing the U.S. in artificial intelligence maturity, the initiative seeks to boost R&D and education. But it's spare on specifics and has no new funding attached.
It’s not for cost-savings on storage and compute. Instead, NewYork-Presbyterian, Mercy and Humana are harnessing the cloud to improve patient and clinician experience.
Salesforce is working with social determinants of health, Information Builders is aiming to ensure accurate provider information across multiple data systems and Nyansa is working on Citrix and GE Healthcare data.
At the HIMSS19 Precision Medicine Summit, John Halamka and other healthcare leaders described how policy, technology, clinical processes and patient engagement need to evolve to make it a reality for primary care.
NC HealthConnex now combines InterSystems’ health information exchange platform, HealthShare, with SAS’s health analytics, the companies announced at HIMSS19.
The vendor’s new system leverages its machine learning engine to offer an interactive retrospective analysis of order utilization, matched up against the evidence-based interventions proven to affect quality outcomes.
Cerner debuts Chart Assist, a new AI-enabled workflow, to join a suite of systems designed to reduce physician burnout, enhance the clinician’s experience and increase productivity.
Healthcare providers and plans need to implement open data sharing technologies to support transitions of care as patients move between plan types.