Be first to read the latest tech news, Industry Leader's Insights, and CIO interviews of medium and large enterprises exclusively from Medical Tech Outlook
THANK YOU FOR SUBSCRIBING
A featured contribution from Leadership Perspectives: a curated forum reserved for leaders nominated by our subscribers and vetted by our MedTech Outlook Advisory Board.

Novuroze Fazal, Head of Clinical Engineering


Connected medical devices, an integral part of modern healthcare systems, are designed to seamlessly integrate with hospital networks, facilitating the collection and analysis of crucial patient data. This connectivity opens up new avenues for optimising patient care by efficiently amalgamating data, healthcare professionals, workflows, and delivery models. Furthermore, connected devices enable remote and continuous patient monitoring, revolutionising traditional healthcare practices. The connection can be established through various means such as wired networks, Bluetooth, or Wi-Fi, ensuring a versatile and adaptable framework for healthcare providers. In hospitals, connected medical equipment typically transmits data to electronic health record (EHR) or electronic patient record (EPR) systems. Healthcare professionals then analyse this data for patient diagnosis and treatment. Connected devices are also utilised in community healthcare settings for monitoring blood pressure, oxygen saturation, cardiac rhythm, falls prevention, and care management. This is made possible through wearable devices and Wi-Fi or Bluetooth connected equipment.
The introduction of connected devices brings additional devices into proximity with both patients and healthcare staff. For example, computers operating EHR/EPR systems, modems, networking hardware, and various cables are among the devices that healthcare staff are expected to handle and operate in order to access, enter, and retrieve patient data. This poses numerous challenges for hospital IT departments and biomedical (biomed) departments. While connected equipment offers advantages in healthcare, the security of these devices remains a significant concern.
The Medical Device Lifecycle in a Hospital
Traditionally, biomed departments manage the lifecycle of medical devices within hospitals. This includes procurement, maintenance, repairs, and training. However, with the emergence of smarter medical devices, networking and cybersecurity awareness have become essential skills for biomed technicians. Information governance, data security, data integrity, and management are now crucial considerations alongside device maintenance and management.
Information governance and IT security teams are increasingly recognising the challenges faced by healthcare systems and implementing measures to enhance the security of connected devices. Nevertheless, during the installation of medical devices in hospitals, there is still a gap in identifying potential threats to the devices and the network.
The recent introduction of the data security and protection toolkit (DSPT) has prompted biomedical teams across the country to start gathering networking information on devices, such as operating system data, MAC addresses, IP addresses, and other connectivity-related information. Despite these efforts, there remains a clear lack of robust communication between IT departments, information governance teams, and biomedical teams.
Challenges to the Hospital Based Connected Equipment
Visibility of medical equipment is one of the key problems faced by Biomed teams working in hospitals. Although medical engineering departments do have inventory of devices in the form of spreadsheets and computerised maintenance management system (CMMS), this is not always real time information.
Another significant challenge arises from the fact that medical devices running proprietary software lack the capability to run security tools. This limitation prevents the application of security patches and updates on such software and legacy operating systems. As a result, these devices become vulnerable to potential security breaches and exploits, posing a serious risk to patient data privacy and the overall integrity of the healthcare system.
"The field of connected devices is continuously evolving, and with the increasing processing power of devices, the potential for improving patient outcomes and treatment using connected medical devices is promising"
The inability to implement security measures on proprietary software and legacy operating systems not only hampers the device's ability to defend against emerging threats but also hinders the effectiveness of proactive security measures. Without regular security updates, vulnerabilities within the software may go unnoticed and unaddressed, leaving the device and the entire network susceptible to attacks.
Furthermore, the presence of proprietary software introduces additional complexities in the overall security landscape. Interoperability and compatibility issues can arise when integrating these devices with other systems, making it challenging to establish a cohesive security infrastructure. This lack of standardisation makes it difficult to implement comprehensive security protocols, leaving gaps in the defence against potential cyber threats.
To mitigate these challenges, healthcare institutions must prioritise the adoption of more secure and up-to-date medical devices with open-source or regularly updated software. Encouraging manufacturers to provide regular security patches and updates for their proprietary software is crucial. Additionally, healthcare organisations should work closely with device manufacturers, IT departments, and information governance teams to establish effective communication channels and ensure that security concerns are addressed promptly. Healthcare industry has been targeted by cybersecurity attackers to take control of the patient data. Recent ransomware attack is an example of the consequences of not protecting medical devices properly.
In summary the following challenges affect hospital medical devices
• Discovery of existing medical devices in the network
• Lack of review of the current vulnerabilities
• Insufficient protection available for the devices
What Needs to Change?
While the biomed industry is moving in the right direction, constant improvements in the MedTech industry require a proactive rather than a retrospective approach. Challenges such as data breaches, privacy concerns, hacking, and security vulnerabilities continue to impact the connected medical device space. Although some cybersecurity companies have developed products to address industry challenges like ransomware and security threats, protecting devices in hospitals still requires more comprehensive measures.
Many hospitals operate legacy systems with outdated operating systems and firmware. Upgrading operating systems and applying security patches face significant challenges in the medical device industry due to regulatory requirements. Furthermore, medical devices cannot be taken out of action until credible software updates are available, which further amplifies the threat to these devices.
Actions for Protecting Connected Medical Devices
To safeguard connected medical devices within healthcare organisations, the following steps should be taken NHS digital recommends the following measures:
1. Identify connected devices.
2. Create a risk mitigation plan
3. Implement mitigations such as network segmentation to reduce the likelihood and impact of compromises.
4. Regularly review and update the mitigation plan.
By following these steps and maintaining open communication channels with IT service providers and information governance teams, healthcare organisations can establish robust security protocols for protecting connected medical devices. The field of connected devices is continuously evolving, and with the increasing processing power of devices, the potential for improving patient outcomes and treatment using connected medical devices is promising.
I agree We use cookies on this website to enhance your user experience. By clicking any link on this page you are giving your consent for us to set cookies. More info
