Close Menu
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Facebook X (Twitter) LinkedIn
Facebook X (Twitter) LinkedIn
Information Security BuzzInformation Security Buzz
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Subscribe
Information Security BuzzInformation Security Buzz
Home - Articles - IoT Security In Healthcare: Major Challenges
Articles

IoT Security In Healthcare: Major Challenges

ISBuzz TeamBy ISBuzz TeamFebruary 21, 2017Updated:July 8, 20245 Mins Read
Share LinkedIn Twitter Facebook Copy Link Email
Share
Facebook Twitter LinkedIn Email Copy Link
Quick AI Summary
ChatGPTClaudeGeminiGrokPerplexityDeepSeekCopilot

effective-softThe Internet of thing (IoT) is revolutionizing the world, influencing a broad array of industries in different ways: the global market of connected devices is expected to reach $163.24 billion by 2020.

If we analyze healthcare, the IoT presence in this sphere seems really beneficial: specialists in secured custom application development come up with smart solutions that contribute to physicians’ and patients’ comfort

The bright examples are home monitoring systems equipped with sensors allowing to control the state of health remotely, wearables able to track abnormalities, mobile apps that assist in taking pills on time or controlling medicines’ expiration date, smart beds, mobile EHR (electronic health records) applications, etc. Moreover, hospitals utilize the IoT to keep a close eye on medical devices and pills in stock, personnel, and patients.

However, there’s the other side of the coin, and the IoT expansion entails new risks and vulnerabilities, bringing severe headaches to security experts and harming patients.

To cite an example, Johnson & Johnson’s insulin pump turned out to be highly vulnerable due to the unencrypted wireless connection between the remote and the pump, giving hackers a chance to easily implement their malicious techniques: to trigger unauthorized insulin injections and access the entire hospital system.

Let’s take a look at some of IoT security challenges and analyze the ways to address them.

The BYOD (Bring your own device) technology, so widely used nowadays imposes a problem, as it’s complicated to control all the devices entering hospitals through an extensive range of channels (some of them unknown). With this technology it is not easy to find out the device lifecycle and recognize the operating system.

Beyond that, medical device vendors may introduce additional risks by putting standalone devices to the hospital’s network without the network specialist’s knowledge, thus, creating connectivity and network glitches that, in turn, lead to data migration.

Hackers may use connected medical devices to steal patients’ data for creating a fake ID and buying drugs or medical equipment to resell, filing fraudulent insurance claims, and more.

Besides, even accidental failures (intertwined with medical connected devices) that are regularly highlighted in various media outlets may put an end to these promising technologies.

So, what can be done to address the IoT security challenges?

1) Authentication

To guarantee patients’ safety, hospitals should ensure authentication. The two-factor authentication system (2FA) should be installed to access patient records, when a user is to provide auxiliary information to sign in (e.g. a retinal scan, phone text code, DNA sample, fingerprint, etc.), not just the login and password. Thus, there appears a possibility to limit the access to gadgets and systems and maintain a strict control over device-to-device communication.

If this point is successfully implemented, hackers are granted less chances for hostile activities.

2) Encryption    

Another so-called basic security hygiene practice is encryption. It’s really convenient to get access to EHRs via mobile devices, but this procedure also entails security risks.

To minimize risks of data breaches and avoid negative outcomes like in Johnson & Johnson’s insulin pump case, it’s a must to encrypt data (both while it is in transit and stored).

As far as storage encryption is concerned, healthcare institutions should ask their vendor to use hardware-level encryption. Unlike software-based encryption solutions for mobile devices that decrease performance by exploiting such resources as CPU cycles and memory, hardware-level encryption, as a rule, does not have a tremendous impact on performance.

Data transmission encryption, however, is not less important. To ruin the chances of sensitive data being stolen, hospitals should control the boundaries of data access for gadgets by allowing to use the internal Wi-Fi network (not an external one) and forbidding to transmit data via the cellular network.

And security specialists, in turn, should ensure the encryption of the facility Wi-Fi network. Such encryption affects the connectivity speed, but it’s worth the trouble.

3) A secure boot

This practice is also aimed at avoiding additional trouble and ensuring IoT devices security. With a secure boot you guarantee that none of the configurations have been changed when the device is turned on, and that nobody has tried to tamper the device.

4) Data dictionary

Sometimes maintaining an inventory of all devices and applications is not enough, and it’s a clever idea to start a kind of data dictionary. Thus, you’ll know where particular data is stored, where it appears and moves, considering its transmission capabilities.

5) Education and training

With the emergence and usage of fresh technologies it’s essential to make sure that hospital employees are aware of new challenges, risks and that they know the ways to address them. Moreover, patients represent an indispensable part of the healthcare world (they are active users of IoT devices), so, raising awareness through clear and detailed instructions should not be ignored.

Conclusion:

The IoT has certainly brought considerable advantages to a variety of industries, positively affecting healthcare. Nevertheless, while relishing all possible benefits it’s vital to bear in mind all the arising challenges and timely respond to them.

[su_box title=”About Yana Yelina” style=”noise” box_color=”#336588″][short_info id=’100626′ desc=”true” all=”false”][/su_box]

ISBuzz Team
  • ISBuzz Team
    Air Canada Data Breach: BianLian Extortion Group Claims A Massive Heist Contrary To Airline’s Earlier Statement
  • ISBuzz Team
    Unprecedented DDoS Attack Rocks The Web: Tech Giants Reveal A Digital Tsunami
  • ISBuzz Team
    CISA Flags High-Severity Adobe Acrobat Reader Flaw Amid Active Exploits
  • ISBuzz Team
    Curl Security Alert: Patching A Critical Bug Averting Potential Cyber Catastrophe

The opinions expressed in this post belong to the individual contributors and do not necessarily reflect the views of Information Security Buzz.

Share. Facebook Twitter LinkedIn Email Copy Link

Related Posts

Visual data is the blind spot in enterprise security: that’s about to change

May 4, 20267 Mins Read

Making stolen data worthless: why security must start with the data

March 30, 20265 Mins Read

Meta’s Smart Glasses Privacy Scandal Expands After Sama Credentials Found on the Dark Web

March 10, 20264 Mins Read
ISB-Bora-Side-Bar

No se ha podido establecer conexión. Error 429

 
ISB-Bora-Side-Bar
Black ISB Logo

Information Security Buzz is an independent resource that provides the experts’ comments, analysis, and opinion on the latest Cybersecurity news and topics

X (Twitter) LinkedIn Facebook RSS

Working With Us

  • About Us
  • Advertise With Us
  • Contact Us

Write For Us

  • How To Contribute

The Pages

  • Privacy Policy
  • Cookie Policy
  • AI Policy
  • Terms & Conditions
  • Copyright Notice

Information Security Buzz and all its contents are copyright © 2014-2025. All rights reserved. All third-party trademarks are recognized.

Type above and press Enter to search. Press Esc to cancel.

Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}