Can Your Hospital Be Hacked?

RxQuick answer:  Yes it can!  A recent article in Bloomberg goes deeply into this subject, and reveals the experiences of a white hat hacker named Billy Rios.  Billy and many others in the profession had been hired by the Mayo Clinic in Rochester Minnesota in 2013 to try to hack all the medical devices in the hospital that were connected to the network.  These days, this is just about everything, from infusion pumps, to heart monitors, to MRI and ultrasound equipment.

The outcome was rather bleak, almost all of these machines were taken easily.  The issue of course is that someone could theoretically take control of something like an infusion pump that is delivering pain medication such as morphine, and increase the dosage to kill the patient.  What we know of course is that this years outlandish fantasy is next years successful exploit.

When Billy ran this issue up the flagpole at the Department of Homeland Security and the Food and Drug Administration, of course he was met with disinterest.

But this is just an extension of the problems we are all facing in the Internet of Things world we are creating.  Most of these cute and handy devices have little if any security baked into them, and can be taken over for malicious purposes, or simply hijacked to be used in a worldwide botnet.  We need to insist that these devices are secure out of the box.  At this point in time, this is not likely to be the case.  I suppose someone is going to push for government regulation, but the Bloomberg article revealed just how well that was going to work.  What needs to happen is for manufacturers to step up to the plate and make these devices secure from the get-go.


About the Author:

I am a cybersecurity and IT instructor, cybersecurity analyst, pen-tester, trainer, and speaker. I am an owner of the WyzCo Group Inc. In addition to consulting on security products and services, I also conduct security audits, compliance audits, vulnerability assessments and penetration tests. I also teach Cybersecurity Awareness Training classes. I work as an information technology and cybersecurity instructor for several training and certification organizations. I have worked in corporate, military, government, and workforce development training environments I am a frequent speaker at professional conferences such as the Minnesota Bloggers Conference, Secure360 Security Conference in 2016, 2017, 2018, 2019, the (ISC)2 World Congress 2016, and the ISSA International Conference 2017, and many local community organizations, including Chambers of Commerce, SCORE, and several school districts. I have been blogging on cybersecurity since 2006 at
  Related Posts


Add a Comment

This site uses Akismet to reduce spam. Learn how your comment data is processed.