Medical devices improve and save lives, but security risks around them are increasing, putting patients and providers at risk
Medical devices help improve patient outcomes and can save lives, and dozens of new technologies are approved by the U.S. Food and Drug Administration (FDA) each year.
However, the increasing availability and use of medical devices is also leading to increased security risks. Additionally, not only are more medical devices becoming available, increasingly hackers and others intent on doing damage are developing more ways to access them, often through technology—and they are becoming more determined and sophisticated in their efforts.
What’s the incentive? Accessing a medical device gives thieves an array of information and options:
Here are examples of some of the most vulnerable devices, and how thieves and others can access them and other related equipment in order to put patients and providers at serious risk:
Plus, if a security breach occurs and PHI is stolen or a patient is harmed, the healthcare organization can suffer near catastrophic damage, as HIPPA or other federal and state regulators step in to impose fines and lawyers appear to file lawsuits.
Fortunately, there are steps a hospital or healthcare organization can begin taking today to strengthen their security around medical devices, as well as overall security related to PHI. They include:
One of the best ways for a hospital or other healthcare organization to begin to reduce medical device-related security risk is to adopt a virtual desktop infrastructure (VDI). VDI allows clinicians to securely access files, data and applications related to medical devices that are hosted on remote servers. VDI is a proven way to quickly and securely deliver applications and provide access to healthcare systems, enhancing a user’s experience and cutting costs. Cloud-based VDI has emerged as an attractive alternative to hosted on-premise VDI implementations as VDI removes the security risk resulting from lost or stolen devices.
Until recently, most healthcare organizations hosted their own IT infrastructure, including client/desktops. While giving organizations control over their infrastructure, applications and information, this approach is expensive to install, manage and upgrade.
On-premise VDI removes some level of that work by eliminating the need to manage patches, upgrades and security for endpoint devices. In some cases it also extends the life of those assets since users don’t need the latest and greatest computing devices to work in a VDI environment. Yet IT is still responsible for managing the infrastructure itself – including security, which is critical in healthcare.
To save time and cost, many organizations have migrated to a cloud-based VDI – specifically Desktop-as-a-Service (DaaS) – as an attractive alternative to hosted on-premise VDI implementations. By placing VDI in the cloud, a service provider takes on the responsibility for all operational requirements, including management and maintenance of the VDI infrastructure. Thin clients are used to connect end-users to all cloud-based services.
A cloud-based VDI approach typically is sufficient to mitigate security risks inherent in medical devices. Moving the client/desktop infrastructure to the cloud places all patient information behind an encrypted and highly available firewall. Healthcare data, however, must have additional security in order to meet the requirements of the Health Insurance Portability and Accountability Act (HIPAA). Healthcare organizations considering a move to a cloud-based VDI should ensure that the security measures provided by the partner meet HIPAA requirements.
With proper security measures in place, VDI can without question improve security on the user end without IT having to secure each individual device. With cloud-based VDI, when clinicians use medical devices – they click on a desktop icon and instantaneously receive a virtual desktop running in the cloud. PHI is kept safe behind the data center firewall, and organizations are able to more easily meet compliance requirements.
The enablement of telehealth through medical devices is a major force in managing costs and improving patient outcomes. The use of cloud-based VDI can play a key role in increasing provider productivity while mitigating growing risks of HIPAA violations and other regulatory compliance concerns.
Matt Ferrari is a skilled technology veteran with more than a decade of success delivering managed hosting and secure cloud-based computing to companies around the world. As Co-Founder & Former CTO, he was responsible for the strategy and execution of ClearDATA’s healthcare technology platform and services. In this role he oversaw Engineering, Product Management and back office systems.
Matt’s HIPAA and HITECH expertise, combined with his extensive understanding of Cloud Storage and Disaster Recovery, make him uniquely qualified to build healthcare storage environments for organizations that require a high degree of scalability, data security, and regulatory compliance.