• Support
  • Login
  • Contact
  • Blog
  • Support
  • Login
  • Contact
  • Blog
SecurityScorecard SecurityScorecard
  • Products
    PRODUCTS
    • Security Ratings
      Identify security strengths across ten risk factors.
    • Security Data
      Get actionable, data-based insights.
    • Security Assessments
      Automate security questionnaire exchange.
    • Attack Surface Intelligence
      NEW
      On-demand contextualized global threat intelligence.
    • Automatic Vendor Detection
      Uncover your third and fourth party vendors.
    • Cyber Risk Quantification
      Translate cyber risk into financial impact.
    • Reporting Center
      Streamline cyber risk reporting.
    • SecurityScorecard Marketplace
      Discover and deploy pre-built integrations.
    SERVICES
    • Active Security Services
      Test your security controls.
    • Cyber Risk Intelligence
      Partner to obtain meaningful threat intelligence.
    • Digital Forensics & Incident Response
      Prepare to respond to any threat.
    • Third-Party Risk Management
      Reduce risk across your vendor ecosystem.
    BUY NOW
    • Compare All Plans
      Choose a plan that's right for your business.
    • Try Free Account
      Make informed decisions with confidence.
    • Buy Pro Now
      Add automated event responses.
    • Buy Business Now
      Expand on Pro with vendor management and integrations.
    • Request Enterprise Demo
      See the capabilities of an enterprise plan in action.
    icon__SSClogoMark icon__SSClogoMark

    Understand and reduce risk with SecurityScorecard.

    Free account sign up
  • Solutions
    BY USE CASE
    • Compliance
    • Cyber Insurance
    • Digital Forensics
    • Due Diligence
    • Enterprise Cyber Risk
    • Executive-Level Reporting
    • Incident Response
    • Regulatory Oversight
    • Third-Party Risk
    BY INDUSTRY
    • Critical Infrastructure
    • Enterprise
    • Financial Services
    • Government
    • Healthcare
    • Insurance
    • Retail & Consumer
    • Technology
    Help your organization calculate its risk
    View All Solutions
  • Customers
    OUR CUSTOMERS
    • Customer Overview
      Trusted by companies of all industries and sizes.
    • Peer Reviews
      Find out what our customers are saying.
    SUCCESS AND SUPPORT
    • Customer Success
      Receive award-winning customer service.
    • Support
      Get your questions answered by our experts.
    COMMUNITY
    • SecurityScorecard Connect
      Engage in fun, educational, and rewarding activities.
    • Connect Login
      Join our exclusive online customer community.
    icon__SSClogoMark icon__SSClogoMark
    Understand and reduce risk with SecurityScorecard.
    Free account sign up
  • Partners

    Partner Program Overview

    Partner with SecurityScorecard and leverage our global cybersecurity ratings leadership to expand your solution, deliver more value, and win new business.

    Learn more
    • Locate a Partner
      Access our industry-leading partner network.
    • Value-Added Resellers
      Enter new markets, deliver more value, and get rewarded.
    • Managed Service Providers
      Meet customer needs with cybersecurity ratings.
    • ISAC Partner Program
      Learn more about the industries we support and ISAC member benefits.
    • Technology Alliances
      Access innovative solutions from leading providers.
    • SCORE Portal Login
      Use the SCORE Partner Program to grow your business.
    • SecurityScorecard Marketplace
      Find a trusted solution that extends your SecurityScorecard experience.

    Understand and reduce risk with SecurityScorecard.

    Free account sign up
  • Resources
    RESOURCES
    • Resource Center
      Explore our cybersecurity ebooks, data sheets, webinars, and more.
    • SecurityScorecard Blog
      Read the latest blog posts published weekly.
    • Research & Insights Center
      Access our research on the latest industry trends and sector developments.
    • SecurityScorecard Academy
      NEW
      Complete certification courses and earn industry-recognized badges.
    TOOLS AND DOCUMENTATION
    • Free Security Rating
      Get your free ratings report with customized security score.
    • Product Release Notes
      Visit our support portal for the latest release notes.
    • Free Account Signup
      Start monitoring your cybersecurity posture today.
    • Chrome Extension
      NEW
      Show the security rating of websites you visit.
    • Assessments ROI Calculator
      Calculate the ROI of automating questionnaires.
    Trust begins with transparency. Take a look at the data that drives our ratings.
    Learn more
  • Company

    Working at SecurityScorecard

    Committed to promoting diversity, inclusion, and collaboration–and having fun while doing it.

    Join our team
    • About Us
      SecurityScorecard is the global leader in cybersecurity ratings.
    • Leadership
      Meet the team that is making the world a safer place.
    • Press
      Explore our most recent press releases and coverage.
    • Events
      Join us at any of these upcoming industry events.
    • Policy Insights
      Raising the bar on cybersecurity with security ratings.
    • Careers
      APPLY TODAY
      Come join the SecurityScorecard team!
    • Contact Us
      Contact us with any questions, concerns, or thoughts.
    • Trust Portal
      Take an inside look at the data that drives our technology.
    • Help Center
      We are here to help with any questions or difficulties.
Request a demo
SecurityScorecard SecurityScorecard
  • Support
  • Login
  • Contact
  • Blog
  • Support
  • Login
  • Contact
  • Blog
SecurityScorecard SecurityScorecard
  • Products
    PRODUCTS
    • Security Ratings
      Identify security strengths across ten risk factors.
    • Security Data
      Get actionable, data-based insights.
    • Security Assessments
      Automate security questionnaire exchange.
    • Attack Surface Intelligence
      NEW
      On-demand contextualized global threat intelligence.
    • Automatic Vendor Detection
      Uncover your third and fourth party vendors.
    • Cyber Risk Quantification
      Translate cyber risk into financial impact.
    • Reporting Center
      Streamline cyber risk reporting.
    • SecurityScorecard Marketplace
      Discover and deploy pre-built integrations.
    SERVICES
    • Active Security Services
      Test your security controls.
    • Cyber Risk Intelligence
      Partner to obtain meaningful threat intelligence.
    • Digital Forensics & Incident Response
      Prepare to respond to any threat.
    • Third-Party Risk Management
      Reduce risk across your vendor ecosystem.
    BUY NOW
    • Compare All Plans
      Choose a plan that's right for your business.
    • Try Free Account
      Make informed decisions with confidence.
    • Buy Pro Now
      Add automated event responses.
    • Buy Business Now
      Expand on Pro with vendor management and integrations.
    • Request Enterprise Demo
      See the capabilities of an enterprise plan in action.
    icon__SSClogoMark icon__SSClogoMark

    Understand and reduce risk with SecurityScorecard.

    Free account sign up
  • Solutions
    BY USE CASE
    • Compliance
    • Cyber Insurance
    • Digital Forensics
    • Due Diligence
    • Enterprise Cyber Risk
    • Executive-Level Reporting
    • Incident Response
    • Regulatory Oversight
    • Third-Party Risk
    BY INDUSTRY
    • Critical Infrastructure
    • Enterprise
    • Financial Services
    • Government
    • Healthcare
    • Insurance
    • Retail & Consumer
    • Technology
    Help your organization calculate its risk
    View All Solutions
  • Customers
    OUR CUSTOMERS
    • Customer Overview
      Trusted by companies of all industries and sizes.
    • Peer Reviews
      Find out what our customers are saying.
    SUCCESS AND SUPPORT
    • Customer Success
      Receive award-winning customer service.
    • Support
      Get your questions answered by our experts.
    COMMUNITY
    • SecurityScorecard Connect
      Engage in fun, educational, and rewarding activities.
    • Connect Login
      Join our exclusive online customer community.
    icon__SSClogoMark icon__SSClogoMark
    Understand and reduce risk with SecurityScorecard.
    Free account sign up
  • Partners

    Partner Program Overview

    Partner with SecurityScorecard and leverage our global cybersecurity ratings leadership to expand your solution, deliver more value, and win new business.

    Learn more
    • Locate a Partner
      Access our industry-leading partner network.
    • Value-Added Resellers
      Enter new markets, deliver more value, and get rewarded.
    • Managed Service Providers
      Meet customer needs with cybersecurity ratings.
    • ISAC Partner Program
      Learn more about the industries we support and ISAC member benefits.
    • Technology Alliances
      Access innovative solutions from leading providers.
    • SCORE Portal Login
      Use the SCORE Partner Program to grow your business.
    • SecurityScorecard Marketplace
      Find a trusted solution that extends your SecurityScorecard experience.

    Understand and reduce risk with SecurityScorecard.

    Free account sign up
  • Resources
    RESOURCES
    • Resource Center
      Explore our cybersecurity ebooks, data sheets, webinars, and more.
    • SecurityScorecard Blog
      Read the latest blog posts published weekly.
    • Research & Insights Center
      Access our research on the latest industry trends and sector developments.
    • SecurityScorecard Academy
      NEW
      Complete certification courses and earn industry-recognized badges.
    TOOLS AND DOCUMENTATION
    • Free Security Rating
      Get your free ratings report with customized security score.
    • Product Release Notes
      Visit our support portal for the latest release notes.
    • Free Account Signup
      Start monitoring your cybersecurity posture today.
    • Chrome Extension
      NEW
      Show the security rating of websites you visit.
    • Assessments ROI Calculator
      Calculate the ROI of automating questionnaires.
    Trust begins with transparency. Take a look at the data that drives our ratings.
    Learn more
  • Company

    Working at SecurityScorecard

    Committed to promoting diversity, inclusion, and collaboration–and having fun while doing it.

    Join our team
    • About Us
      SecurityScorecard is the global leader in cybersecurity ratings.
    • Leadership
      Meet the team that is making the world a safer place.
    • Press
      Explore our most recent press releases and coverage.
    • Events
      Join us at any of these upcoming industry events.
    • Policy Insights
      Raising the bar on cybersecurity with security ratings.
    • Careers
      APPLY TODAY
      Come join the SecurityScorecard team!
    • Contact Us
      Contact us with any questions, concerns, or thoughts.
    • Trust Portal
      Take an inside look at the data that drives our technology.
    • Help Center
      We are here to help with any questions or difficulties.
Request a demo
SecurityScorecard SecurityScorecard
BLOG

How New Technology is Bringing Risk to the Healthcare Industry

11/11/2016


The Internet of Things (IoT) is increasingly becoming a popular topic of choice in the cybersecurity industry and for unfortunate reasons. In short, the Internet of Things is the name applied to a wide variety of devices that connect to the internet. These can be routers, cameras, smart light bulbs, and medical devices. Unfortunately, the security of these devices is less than stellar and they pose a real risk to multiple industries.

For health facilities such as hospitals, their security vulnerability is exacerbated by the large infrastructure that is increasing with the adoption of wirelessly connected medical devices. This array of new IoT devices has paved the way for technological and medical advances like never before, benefiting hospitals and patients alike. However, with a speedy delivery and implementation, the security of such devices has been less than an afterthought, and now present a real security risk to the networks they’re connecting to.

We recently covered how many Internet of Things devices have become exploited en masse by the Mirai Botnet, where it’s being used to engage in targeted DDoS that look to bring down websites. Because these IoT devices are using legacy protocols such as Telnet and FTP for ease of use, they also make exploitation an easier task for hackers. Hackers often exploit these devices by first finding them through automated scanning processes that look for internet-connected devices and brute-force password combinations, taking advantage of the default passwords that are often intact in the devices.

The risk for IoT medical devices isn’t limited to a botnet or malware infection, rather if the IoT device is accessed via its default password or any other means, it can provide an access point into the organization’s network, which can lead to a data breach.

Because a medical organization’s personal health information (PHI) is such a valuable asset, malicious actors can limit their search and specifically target devices connected to a healthcare organization in order to access their network and exfiltrate sensitive information. Other consequences may be even more dire. If a hacker is specifically targeting an individual or a group, they can access vulnerable medical devices that connect to the internet and execute arbitrary code, either forcing the device to malfunction or not function at all, putting the person who’s reliant on the device at risk.

IoT Security is Attracting Attention From Regulators and Other Agencies

In mid-Summer 2015, the US-CERT released a warning on a Hospira PCA LifePump medical device that had a number of vulnerabilities, including a hardcoded password, that left it open to a remote exploit vulnerability, potentially putting anyone using the device or the network it was connected to at risk. It was one of the first times a warning referring to a medical device was posted. Since then, other regulatory bodies, security researchers, and organizations have increased their attention on IoT security. Earlier this year, MedSec Holdings, a research firm announced that a number of St. Jude cardiac implants were susceptible to hacking, a claim disputed by St. Jude. The day of the announcement, St. Jude’s stock dropped 5% and the FDA is currently investigating the claim. The consequences of weak IoT security don’t stop at malicious actors, the business impact is real as the issue becomes more of a mainstream topic.

Back in June of 2016, a report was released noting that the NSA was looking to exploit medical devices in order to improve intelligence by exploiting the device to facilitate monitoring and spying for information gathering purposes. On the other side of the government spectrum, the National Institute of Standards and Technology (NIST) issued a draft report on standardizing lightweight cryptography aimed to improve the security of IoT devices used in manufacturing, industrial, and healthcare industries among others. NIST released the draft back in August and was taking comments on the report until the end of October.

In the private sector, the Industrial Internet Consortium, a cross-industry group made up of healthcare, energy, manufacturing, and transportation companies such as General Electric, IBM, Intel, Toyota and others took a role in promoting IoT safety. They released the Industrial Internet Security Framework IISF in September 2016, a security framework aimed at IoT devices manufacturing that hopes to tackle the security issue from a manufacturing perspective while also providing guidelines and best practices.

While it’s too early to tell whether or not the additional attention and released framework will bolster IoT security, the conversations stemming from both private and government organizations do provide a form of optimism for the industry as a whole.

Simple Steps Healthcare Organizations Can Take To Protect Their Patients

There’s more that an organization as a whole can do to avoid exposing their network to potential hackers. When it comes to common IoT devices such as routers, cameras, and even smart-products such as bulbs and TV’s, it’s important to perform due diligence to purchase the most secure options. However, multiple options may not be available for specialized medical devices. In those cases, the first thing to do, as we noted in our coverage of the Mirai botnet problem, is to change any default administrative passwords found on the device. Because there are a number of automatically scanning processes set up by hackers made to infect IoT devices, changing the passwords of devices prior to connecting to the internet is a good way to safeguard from automated attacks.

CISOs and other heads of information security should segregate sensitive network assets and employ network segmentation in order to reduce the risk of exposure all internet-facing devices pose to a network. Medical IoT devices should be segregated from portions of the local intranet that are used for administrative tasks and the same should be done with all internet-facing devices, including printers, routers, and cameras.

The Healthcare Industry’s Internal Risk Factor

Unfortunately, the healthcare industry is also facing an internal risk that may lead to even worse consequences: their own employees.

Social Engineering is one of the most common ways hackers are accessing a company’s sensitive information. By taking advantage of employees who aren’t as versed in security, hackers can eschew complicated technologies to simply obtain sensitive information or credentials to enter into a network utilizing psychological methods. In our next blog post we’ll discuss how the Healthcare Industry is especially susceptible to Social Engineering attacks and what they can do to improve their employee security awareness.

For a complete look into the security performance of the entire healthcare industry, download our 2016 Annual Healthcare Industry Cybersecurity Report Below.


Download our 2016 Annual Healthcare Industry Cybersecurity Report


Return to Blog
Join us in making the world a safer place.
FREE ACCOUNT SIGN UP
Products
Solutions
Customers
Marketplace
Partners
Resources
Company
Trust Portal
Security Ratings
Login
Blog
Contact
Careers

SecurityScorecard
Tower 49
12 E 49th St
Suite 15-100
New York, NY 10017

[email protected]

United States: (800) 682-1701
International: +1(646) 809-2166
Social-linkedin Social-facebook Twitter Instagram Youtube