H-ISAC Hacking Healthcare 8-13-19
TLP White: In this edition of Hacking Healthcare, we take a look at how medical device cybersecurity is increasingly generating interest. We then give you a breakdown of the UK’s massive bet on A.I. in healthcare. Finally, we explore the Department of Defense’s interest in the Zero Trust model of cybersecurity and why you might be interested.
As a reminder, this is the public version of the Hacking Healthcare blog. For additional in-depth analysis and opinion, become a member of H-ISAC and receive the TLP Amber version of this blog (available in the Member Portal.)
Welcome back to Hacking Healthcare.
Hot Links –
1. Medical Devices Take Center Stage.
The increasing scrutiny on the cybersecurity of medical devices got a boost last Thursday with the Medical Device Village at DEF CON[i] in Las Vegas. Whereas the previous year’s installation was relatively sparse, this year’s iteration was completely transformative. Visitors were able to walk through a 2,600sqft “hospital” complete with a mock radiology department, pharmacy, and an intensive care unit that were professionally recreated by students at CalPoly.[ii] All of these “rooms” were filled with various medical devices to be hacked.
The interest in significantly expanding the Medical Device Village comes at an opportune time. With the healthcare sector investing heavily in acquiring and integrating state of the art technologies in IoT and other connected devices, taking stock of the underlying cybersecurity and privacy aspects is increasingly coming to the fore. The organizers of the village were upbeat about the strides the healthcare sector has made with regards to securing devices, but they were quick to stress that much more needed to be done. The organizers were keen to point out that a) many medical devices have never been evaluated by security researchers; b) that many older devices were designed with basic-to-no-security; and c) that too often healthcare providers do not configure their devices properly prior to implementation.[iii]
2. NHS Receives Funding for National Cyber Lab.
The United Kingdom may be going all in on developing AI for the healthcare sector. New Prime Minister Boris Johnson has wasted little time in declaring that the government will set aside £250 million pounds for a National Artificial Intelligence Lab. The lab will reportedly be under the NHSx, which houses public and private sector experts to lead the digitization of the UK’s health service. The UK’s Health Secretary Matt Hancock shared his delight and confidence that AI could help turn the NHS into a “truly predictive, preventive and personalized health and care service”[iv]
While this investment will certainly bring benefits once it gets up and running, there are significant concerns. Some health experts are dubious that other healthcare projects won’t be affected by cuts, as the NHS is already “cash-strapped”.[v] Additionally, the NHS doesn’t have the cleanest bill of health when it comes to cybersecurity and implementing new technologies.[vi] Furthermore, there is speculation that, while well intentioned, NHS may not ensure its investment relies on a robust and inclusive data set that fully represents the breadth of the UK’s population.[vii] Failure to do so will further lend support to criticism that emerging technologies are skewed against minorities.[viii]
3. DoD Launches Zero-Trust Program.
The Pentagon has made its first concrete steps toward initial testing of Zero Trust network architectures and technologies by announcing the creation of a test facility and pilot program.[ix] The Defense Information Systems Agency (DISA) will be tasked with building out the research facility that will be located at Fort Meade. Once completed, the facility will house a joint DISA and Cyber Command pilot program.
Historically, approaches to cybersecurity operated with a significant level of trust given to internal actors on a network, including both hosts and users. In contrast, Zero Trust operates with a “never trust, always verify” mindset. By accepting the limitations of perimeter defense and embracing a data-centric model of cybersecurity the Zero Trust framework is positioned to counter the increase of insider threats and the growth of sophisticated actors able to bypass common cybersecurity systems.
Embracing this philosophical change in cybersecurity strategy may be necessary as current strategies continue to come up short. The Zero Trust model holds promise in this regard by limiting the movement of malicious actors who have gained access to a network by adding additional authentication requirements, making use of encryption, implementing micro-segmentation, and comprehensively applying principles like least privileged access. Additionally, Zero Trust may improve detection and incident response through its prioritization of visibility and analytics.
Congress –
Tuesday, August 13th:
-No relevant hearings
Wednesday, August 14th:
-No relevant hearings
Thursday, August 15th:
-No relevant hearings
International Hearings/Meetings –
EU – No Relevant Hearings
Conferences, Webinars, and Summits –
–H-ISAC Medical Device Security Workshop – Plymouth, MN (9/17/2019)
https://h-isac.org/hisacevents/h-isac-medical-device-security-workshop/
–HEALTH IT Summit (California) – Los Angeles, CA (9/19/2019-9/20/2019)
https://endeavor.swoogo.com/2019-LosAngeles-Health-IT-Summit
— Healthcare Cybersecurity Forum – Los Angeles, CA (9/20/2019)
https://endeavor.swoogo.com/2019-California-Cybersecurity-Forum
Peer Sharing ICS Security Workshop (New Jersey) – Bridgewater, NJ (9/24/2019-9/26/2019)
–Summit on Security and Third-Party Risk – Leesburg, VA (9/30/2019-10/2/2019)
https://grfederation.org/summit/2019/overview
–HEALTH IT Summit (Northeast) – Boston, MA (10/3/2019-10/4/2019)
https://h-isac.org/hisacevents/health-it-summit-northeast/
–Northeast Healthcare Cybersecurity Forum – Boston, MA (10/4/2019)
https://endeavor.swoogo.com/2019-Northeast-Cybersecurity-Forum
–2019 H-ISAC European Summit – Zurich, Switzerland (10/16/2019-10/17/2019)
https://h-isac.org/summits/european_summit/
–Health IT Summit (Midwest) – Minneapolis, MN (10/17/2019-10/18/2019)
https://endeavor.swoogo.com/2019-Minneapolis-Health-IT-Summit
–Healthcare Cybersecurity Forum (Midwest) – Minneapolis, MN (10/18/2019)
https://endeavor.swoogo.com/2019_Midwest_Cybersecurity_Forum
–Health IT Summit (Southwest) – Houston, TX (11/14/2019-11/15/2019)
https://endeavor.swoogo.com/2019-Dallas-Health-IT-Summit
–Southwest Healthcare Cybersecurity Forum – Dallas, TX(11/15/2019)
https://endeavor.swoogo.com/2019_Southwest_Cybersecurity_Forum
–Health IT Summit (Northwest) – Seattle, WA (11/19/2019-11/20/2019)
https://endeavor.swoogo.com/2019-PacificNorthwest-HITSummit
–Pacific Northwest Healthcare Cybersecurity Forum – Seattle, WA (11/20/2019)
https://endeavor.swoogo.com/2019_Pacific_Northwest_Cybersecurity_Forum
–2019 H-ISAC Fall Summit – San Diego, CA (12/2/19-12/6/2019)
<https://www.loewshotels.com/coronado-bay-resort>
Sundries –
–Apple Gives Hackers a Special IPhone—and a Bigger Bug Bounty
https://www.wired.com/story/apple-hacker-iphone-bug-bounty-macos/
–NSA’s reverse-engineering malware tool, Ghidra, to get new features to save time, boost accuracy
https://www.cyberscoop.com/ghidra-nsa-new-version-black-hat-2019/
–Cerner, Duke create Learning Health Network to automate data for research
–Black Hat: GDPR privacy law exploited to reveal personal data
https://www.bbc.com/news/technology-49252501
–Pittsburgh Health Data Alliance teams with AWS for new machine learning use cases
Contact us: follow @HealthISAC, and email at contact@h-isac.org
[i] https://defcon.org/
[ii] https://www.wired.com/story/defcon-medical-device-village-hacking-hospital/
[iii] https://www.wired.com/story/defcon-medical-device-village-hacking-hospital/
[iv] https://www.ft.com/content/c0b3be56-b922-11e9-96bd-8e884d3ea203
[v] https://www.theguardian.com/society/2019/aug/08/boris-johnson-pledges-250m-for-nhs-artificial-intelligence
[vi] https://www.theguardian.com/society/2019/aug/08/boris-johnson-pledges-250m-for-nhs-artificial-intelligence
[vii] https://www.bbc.com/news/health-49270325
[viii] https://www.bbc.com/news/health-49270325
[ix] https://www.nextgov.com/cybersecurity/2019/08/disa-cyber-command-are-launching-zero-trust-pilot-program/159007/