Some time ago, we carried out an evaluation of the Digital Health Applications
Ordinance (Digitale-Gesundheitsanwendungen-Verordnung, DiGAV) for the Federal
Chamber of Psychotherapists in Germany (Bundespsychotherapeutenkammer, BPtK)
focusing on the security of digital health applications, often referred to as
apps on prescription.
The audit was intended to determine to which extent security guidelines,
security objectives, and best practices are adhered to by the requirements
formulated by the ordinance, thus enabling the foundations to securely operate
digital health applications. The main subject of the examination is whether
requirements, including procedural requirements defined in the ordinance are
sufficient to ensure security of digital health applications. The examination
has shown that the requirements can be seen as positive. However, in order to be
able to make reliable statements about the IT security of digital healthcare
applications, further details and mechanisms should be clarified within the
ordinance, which I would like to present in the following.
With this blog post I am pleased to announce the publication of a new ERNW White
Paper [1]. The paper
is about severe vulnerabilities in an insulin pump we assessed during project
ManiMed and we are proud to publish this subset of the results today.
Manipulating Medical Devices
The German Federal Office for Information Security (BSI), in its role as the
Federal Cyber Security Authority in Germany, aims to sensitize manufacturers and
the public regarding security risks of networked medical devices. In response to
the often fatal security reports and press releases of networked medical
devices, the BSI initiated the project Manipulation of Medical Devices (ManiMed)
in 2019. In this project, a security analysis of selected products is carried
out through security assessments. In the context of this project, severe
vulnerabilities were identified during the assessment of the DANA Diabecare RS
system.
Digital networking is already widespread in many areas of life. In the
healthcare industry, a clear trend towards networked devices is noticeable, so
that the number of high-tech medical devices in hospitals is steadily
increasing.
In this blog post, we want to elucidate a vulnerability we identified during the
security assessment of a patient monitor. The device sends HL7 v2.x messages,
such as observation results to HL7 v2.x capable electronic medical record (EMR)
systems. A user with malicious intent can tamper these messages. As HL7 v2.x is
a common medical communication standard, we also want to present how this kind
of vulnerability may be mitigated. The assessment was part of the BSI project
ManiMed, which we would like to present in the following section.
Earlier this month I attended the Digital Medical Expertise & Applications
(DMEA) 2019. The DMEA fair in Berlin (formerly conhIT) is the central platform
for digital health care as it brings together companies of health IT, academic
institutions, politics and healthcare delivery organizations in several format
such as innovation hubs and talks during congress sessions as a part of the
industry fair. I participated in a congress session about IT security in
healthcare with a talk about medical device security and common security flaws
in medical devices. Some of the aspects have also been covered in my talk at
#TR19 [1].
Today I am proud to announce that another paper of my former colleagues from
Heilbronn University and me was published in one of the journals with the
highest impact factor for Medical Informatics research called JMIR mHealth and
uHealth. There is a reason why we published in this journal besides its
informatics focus. The journal is an open access journal. That means that
readers are not charged on a pay-per-view basis or other business models to
access the full text of the paper. In return, the authors need to pay
publication fees. In my opinion restricting access to academic research is not a
way to go. I think this isn’t a thing we see in the security community often
anyway. But this is and was the standard in academia for years.
Last week (25^(th) – 27^(th) April), I attended the “Sicherheit 2018” in
Konstanz which is the annual meeting of the security community of the
Gesellschaft für Informatik e.V. (GI) in Germany. The conference is in equal
proportions attended by researchers and people of the industry working in
security-related disciplines which lead to lively and pleasant discussions
conversations.
The topics discussed were contentual wide-reaching, so there were very technical
talks like Sebastian Banescu who was the winner and one of two candidates
nominated for the best PhD thesis award presenting about “Characterizing the
Strength of Software Obfuscation Against Automated Attacks”, as well as
conceptual presentations such as Sabrina Krausz elucidated her bachelor thesis
about an integrated procedure model for planning and implementing an ISMS on the
example of the pharmaceutical production.