Ransomware attacks targeting hospitals and healthcare systems are becoming increasingly sophisticated, even as healthcare organizations face one of their biggest cybersecurity challenges—how to protect legacy medical devices from new cyber threats.

Legacy medical devices still in use by healthcare organizations were designed and manufactured long before the medical device industry began seriously considering cybersecurity features. Many older devices still in operation run outdated or insecure software, hardware, and protocols that were not designed with cyber defenses in mind, leaving healthcare organizations vulnerable to attacks and putting device manufacturers' reputations and financial stability at risk.

Despite the cybersecurity risks, the number of connected medical devices used in hospital networks is still growing rapidly. According to IBM, the number of internet-connected medical devices is expected to grow from 10 billion to 50 billion over the next decade.

"Those products that are 10 to 15 years old were never designed with the idea of being connected to a network," said David Finn, executive vice president of cybersecurity consulting firm CynergisTek and former CIO of Texas Children's Hospital. "Anything connected to the internet is at risk."

To make matters worse, legacy devices are running operating systems such as Windows XP, for which Microsoft no longer provides security patches and updates.

"That's a 20-year-old system. But some large medical devices can last that long and still function properly from a medical standpoint," said Zach Rothstein, vice president of technology and regulatory affairs at AdvaMed.

IoT cybersecurity company Forescout predicted in a 2020 device security report that healthcare organizations will have to deal with medical devices running legacy operating systems for the foreseeable future.

The report noted: "The proportion of devices running fully unsupported operating system versions has not changed, remaining at 0.4% between 2019 and 2020. This includes now-obsolete Windows operating systems such as Windows XP and Windows Server 2003." The report implied that the legacy operating system problem will persist into the future.

The report noted that while this proportion is small, the most affected systems are often some of the most critical devices supporting clinical care in healthcare organizations, such as insulin pumps and ventilators.

Marc Schlessinger, senior associate at watchdog ECRI, said medical device security is often one of the weakest links in healthcare organizations, calling legacy devices a particularly thorny area because they contain known vulnerabilities that cannot be patched.

"You can't always simply bolt on security measures after the fact, especially for legacy devices—I've personally mailed checks back to clients and told them this can't be fixed," said Chris Gates, director of product security at medical device engineering firm Velentium.

Schlessinger said that just last year, he saw legacy devices in hospitals running Windows 98, even though Microsoft stopped all support for that operating system back in 2006. Such operating system problems are common in aging medical imaging systems.

"But you won't find a hospital rushing to replace a $1.5 million MRI or CT machine just because the operating system is outdated," Schlessinger said. Instead, he recommends that healthcare organizations adopt best practices for managing security risks, including isolating connected medical devices from hospital networks where possible.

At the same time, Schlessinger acknowledged that disconnecting devices from hospital networks is often not practical because doing so could disrupt clinical workflows that are critical to patient care.

Velentium's Gates defines legacy medical devices as those that cannot meet current cybersecurity standards. He believes the United States needs to phase out devices that are "highly insecure" and have been in hospitals for 20 years or more. "Let's clear out the deadwood," he said.

However, in healthcare organizations, competing priorities make limited financial and human resources a major obstacle to fixing vulnerabilities in legacy medical devices, because replacing or repairing these devices is not cost-effective.

Mike Rushanan, healthcare security director at consulting firm Harbor Labs, said the problem is that security analysts and regulators are "too busy chasing down potential vulnerabilities in new devices to pay attention to medical systems that have been in clinical use for years." He argued that hacker groups are different—they have the resources and patience to continually look for new cybersecurity vulnerabilities.

Hospitals and device manufacturers split over liability and regulatory issues

Cybersecurity experts insist that identifying and classifying medical devices running legacy operating systems is critical to reducing risk, and recommend that devices that cannot be retired or patched should be network-segmented, with access limited only to critical information and services.

However, the American Hospital Association has argued that device manufacturers should anticipate the need to upgrade devices from systems like Windows 7 to Windows 10 and treat it as part of planned maintenance at reasonable cost.

The AHA believes that although the FDA has issued premarket and postmarket guidance to device manufacturers on how to ensure system security, "manufacturers have little incentive to address security issues in their installed product base." The hospital organization insists that regulators must make clear that measures to secure legacy devices are mandatory, not optional.

"The FDA plays a leadership role in creating the expectation that manufacturers should proactively reduce risk by building security into products through design, providing security tools to end users, and updating and patching devices as new intelligence and threats emerge," the AHA said.

The FDA outlined in 2016 guidance the steps manufacturers must follow to protect medical devices from cyberattacks. In the document, the agency made clear that cybersecurity risk management is a shared responsibility among stakeholders, including medical device manufacturers and healthcare delivery organizations.

AdvaMed's Rothstein said the FDA's postmarket cybersecurity guidance is binding on manufacturers, but device companies and hospitals share responsibility for ensuring medical device security over the device's useful life.

Complicating matters, the longer useful life of legacy medical devices makes them harder to protect because the cybersecurity landscape is constantly changing as new vulnerabilities and threats emerge.

Under FDA rules, manufacturers of newer devices must disclose vulnerabilities when they are discovered. What worries cybersecurity experts is that many vulnerabilities in legacy devices have not yet been discovered.

Evolving threats

At-risk legacy devices can become easy targets for cybercriminals, who can use these devices as entry points into hospital networks and ultimately gain access to the valuable patient data they covet, either for direct financial gain through ransomware attacks or indirectly by selling stolen information.

"These are actually financially motivated intruders looking for easy targets. And the healthcare industry happens to be a relatively easy target," said Kevin Fu, acting director of medical device cybersecurity at the FDA's Center for Devices and Radiological Health, at last month's Food and Drug Law Institute annual meeting.

"Everything can be hacked," Fu said, noting that medical devices infected with ransomware may be unable to properly perform critical clinical functions, which could lead to patient harm.

Although medical devices such as infusion pumps are used to deliver life-sustaining treatment, ECRI has not yet found hackers harming patients by adjusting device settings.

Nevertheless, IBM last year discovered a cybersecurity vulnerability that could allow hackers to remotely control insulin pumps and change drug dosages delivered to patients.

So far, hackers seem more concerned with financial gain than harming patients.

"They haven't gone after patients yet, but that doesn't mean it won't happen," Schlessinger said. "If hackers wanted to actually harm patients, IV infusion pumps and ventilators would be two devices that would be easy for them to attack."

The FDA's Fu warned that as more medical device companies use the cloud and rely on it for real-time device functionality, the industry may see cybersecurity incidents escalate into patient safety issues.

"Ransomware strikes at the very heart of usability. It just makes the device useless," Fu said.

That possibility has become more real as the problem of ransomware attacks targeting the healthcare industry has become an epidemic.

According to The Wall Street Journal, an Eastern European cybercrime gang called Ryuk has attacked at least 235 U.S. hospitals and inpatient psychiatric facilities since 2018, earning more than $100 million through ransomware attacks. Some ransomware gangs avoid targeting healthcare organizations out of concern for patient safety. However, Ryuk and other gangs have no such hesitation.

"Things out there have gotten bad. The adversaries are much more sophisticated than they were a year ago," Fu said at the FDLI conference, citing the Conti ransomware gang, which has attacked at least 16 U.S. healthcare and emergency networks, prompting the FBI to issue an alert last month.

Fu acknowledged that he does not know the answer to the large-scale problem of legacy devices and their inherent cybersecurity vulnerabilities.

For now, Gates said, the FDA is playing the "long game," essentially allowing legacy devices to reach the end of their useful lives and be replaced by newer, more secure products that comply with the agency's latest cyber regulations—hopefully before hackers can exploit their vulnerabilities and cause harm to hospitals and their patients.

"This is a rather thorny problem," AdvaMed's Rothstein said, noting that given the rapid pace of technological advancement, any medical device that comes to market will quickly be considered legacy. "We will never be completely free of this problem," he said.