• 3,000 firms
  • Independent
  • Trusted
Save up to 70% on staff

News » 162 vulnerabilities found in medical devices, patient data at risk: report

162 vulnerabilities found in medical devices, patient data at risk: report

162-vulnerabilities-in-medical-devices
Photo from Depositphotos

CALIFORNIA, UNITED STATES — Global cybersecurity firm Forescout Technologies recently released a report identifying 162 vulnerabilities in Internet of Medical Things (IoMT) devices. 

These vulnerabilities pose significant risks to patient data and healthcare operations, emphasizing the urgent need for enhanced cybersecurity measures.

Critical vulnerabilities threaten patient data

The report analyzed over 2 million devices across 45 healthcare delivery organizations (HDOs), revealing that Digital Imaging and Communications in Medicine (DICOM) workstations, Picture Archiving and Communication Systems (PACS), pump controllers, and medical information systems are among the most vulnerable. 

These devices are crucial to healthcare operations but often remain outdated and difficult to secure.

Cybercriminals exploit healthcare vulnerabilities

Hacking is the leading cause of data breaches in healthcare, with an average of 1.6 incidents reported daily in 2023. Cybercriminals target IoMT devices to steal sensitive patient data or disrupt services. 

“The increasing prevalence of IoMT devices has introduced new cybersecurity risks,” said Barry Mainz, CEO of Forescout. “Once deployed, these devices are difficult to update or patch, making them prime targets for cybercriminals.”

Key findings: High-risk devices

  • DICOM Workstations and PACS: Identified with 32% critical unpatched vulnerabilities.
  • Pump Controllers: Found with 26% critical unpatched vulnerabilities and 20% with extreme exploitability.
  • Medical Information Systems: Reported with 18% critical unpatched vulnerabilities.

These vulnerabilities could lead to remote denial of service, information disclosure, or remote code execution.

Alarming increase in DICOM server attacks

The report also noted a significant rise in attacks against DICOM servers. From August 2022 to May 2024, the number of exposed DICOM servers increased by 27.5%. 

Forescout observed an average of one attack every 20 seconds on these servers. Many attacks aim to steal sensitive patient data through unencrypted communications.

Windows systems at high risk

Windows systems are particularly vulnerable, with half of the top ten vulnerabilities being critical flaws that could allow full device takeover. 

Despite this risk, only 10% of IoMT devices run active anti-malware software, highlighting the need for improved network security measures.

Recommendations for healthcare organizations

Daniel dos Santos, Head of Security Research at Forescout Vedere Labs, emphasized the importance of asset identification and network segmentation. “A single weak point can open the door to sensitive patient data,” he stated

Effective strategies include mapping network communications and continuous monitoring to secure healthcare networks.

Forescout’s report underscores the urgent need for enhanced cybersecurity measures in healthcare to protect patient safety and ensure operational integrity.

Start your
journey today

  • Independent
  • Free
  • Transparent

About OA

Outsource Accelerator is the trusted source of independent information, advisory and expert implementation of Business Process Outsourcing (BPO)

The #1 outsourcing authority

Outsource Accelerator offers the world’s leading aggregator marketplace for outsourcing. It specifically provides the conduit between Philippines outsourcing suppliers and the businesses – clients – across the globe.

The Outsource Accelerator website has over 5,000 articles, 450+ podcast episodes, and a comprehensive directory with 4000+ BPO companies… all designed to make it easier for clients to learn about – and engage with – outsourcing.

About Derek Gallimore

Derek Gallimore has been in business for 20 years, outsourcing for over eight years, and has been living in Manila (the heart of global outsourcing) since 2014. Derek is the founder and CEO of Outsource Accelerator, and is regarded as a leading expert on all things outsourcing.

“Excellent service for outsourcing advice and expertise for my business.”

Learn more
Banner Image
Get 3 Free Quotes Verified Outsourcing Suppliers
3,000 firms.Just 2 minutes to complete.
SAVE UP TO
70% ON STAFF COSTS
Learn more

Connect with over 3,000 outsourcing services providers.

Banner Image

Transform your business with skilled offshore talent.

  • 3,000 firms
  • Simple
  • Transparent
Banner Image