spk-logo-tm-2023
0%
1-888-310-4540 (main) / 1-888-707-6150 (support) info@spkaa.com
Select Page

Cyber Security in Medical Device Design

windchill features best plm software
Written by Mike Solinap
Published on June 2, 2014

With the push by big technology players (Cisco, Google, Intel, etc.) towards connectivity in everyday devices, cyber security is becoming more and more crucial. This push is even seen in medical device design as the industry begins to move toward cloud-integrated and network-connected devices so that they may be monitored or customized to surgeons needs on the fly.

The issue is that medical devices that used to be standalone machines are now being connected to wider networks. While this is useful, most manufacturers are not adding any increased security to their systems where a single machine attack used to be isolated and required physical access.

An infection and attack on an entire network of devices around the world can now occur completely remotely. A single change to an insecure cloud database or device that sets and gets settings from the cloud could lead to an entire device line being compromised. A few years ago, security expert Barnaby Jack showed that it is possible to compromise devices such as pacemakers and insulin pumps to attack patients as well. Any device with network connectivity will be insecure — and with strict FDA regulations on system updates, many manufacturers will not be patching issues as quickly as may be needed.

Thankfully, the FDA has been working on a draft guidance to try to set guidelines medical device engineers should use while designing their systems. The guidance also mentions possibly allowing validated operating system updates to be patched into systems in-between fully validated releases. Hopefully, the new guidance will help keep systems and patient data safe.

Next Steps:

Latest White Papers

Introducing Atlassian’s Service Collection

Introducing Atlassian’s Service Collection

Are you looking for new tools that empower your teams to deliver exceptional service experiences? Atlassian’s Service Collection ensures great service for both employees and customers. What You Will Learn In the following eBook, you will discover: The tools and...

Related Resources

GitLab and Gemini: Agentic Software Development on Google Cloud

GitLab and Gemini: Agentic Software Development on Google Cloud

Key takeaways Agentic software development goes beyond AI coding assistants: GitLab Duo Agent Platform gives AI agents context across issues, source code, merge requests, CI/CD pipelines, security findings, and development history. GitLab and Gemini combine lifecycle...

AI-driven DevSecOps in Air Gapped Environments

AI-driven DevSecOps in Air Gapped Environments

Federal system integrators (FSIs) must deliver advanced solutions while managing the complexities of day-to-day work. Explore how GitLab Duo Self-Hosted enables FSIs to deploy AI capabilities securely across any federal environment.What You Will Learn In this eBook,...