<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>Medical on Insinuator.net - Bold Statements</title>
    <link>https://insinuator.net/tags/medical/</link>
    <description>Recent content in Medical on Insinuator.net - Bold Statements</description>
    <generator>Hugo</generator>
    <language>en-us</language>
    <lastBuildDate>Thu, 29 Jul 2021 00:00:00 +0000</lastBuildDate>
    <atom:link href="https://insinuator.net/tags/medical/index.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>ManiMed: Ypsomed AG – mylife YpsoPump System Vulnerabilities</title>
      <link>https://insinuator.net/2021/07/manimed-ypsomed-ag-mylife-ypsopump-system-vulnerabilities/</link>
      <pubDate>Thu, 29 Jul 2021 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2021/07/manimed-ypsomed-ag-mylife-ypsopump-system-vulnerabilities/</guid>
      <description>&lt;p&gt;The Federal Office for Information Security (BSI) aims to sensitize&#xA;manufacturers and the public regarding security risks of networked medical&#xA;devices in Germany. In response to the often fatal security reports and press&#xA;releases of networked medical devices, the BSI initiated the project&#xA;Manipulation of Medical Devices (ManiMed) in 2019. In this project, a security&#xA;analysis of selected products is carried out through security assessments&#xA;followed by Coordinated Vulnerability Diclosure (CVD) processes. The project&#xA;report was published on December 31, 2020, and can be accessed on the BSI&#xA;website&#xA;[&lt;a href=&#34;https://www.bsi.bund.de/SharedDocs/Downloads/DE/BSI/DigitaleGesellschaft/ManiMed_Abschlussbericht_EN.html&#34;&gt;1&lt;/a&gt;].&lt;/p&gt;</description>
    </item>
    <item>
      <title>ManiMed: Hamilton Medical AG – HAMILTON-T1 Ventilator Vulnerabilities</title>
      <link>https://insinuator.net/2021/02/manimed-hamilton-medical-ag-hamilton-t1-ventilator-vulnerabilities/</link>
      <pubDate>Mon, 22 Feb 2021 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2021/02/manimed-hamilton-medical-ag-hamilton-t1-ventilator-vulnerabilities/</guid>
      <description>&lt;p&gt;The Federal Office for Information Security (BSI) aims to sensitize&#xA;manufacturers and the public regarding security risks of networked medical&#xA;devices in Germany. In response to the often fatal security reports and press&#xA;releases of networked medical devices, the BSI initiated the project&#xA;Manipulation of Medical Devices (ManiMed) in 2019. In this project, a security&#xA;analysis of selected products is carried out through security assessments&#xA;followed by Coordinated Vulnerability Diclosure (CVD) processes. The project&#xA;report was published on December 31, 2020, and can be accessed on the BSI&#xA;website &lt;sup id=&#34;fnref:1&#34;&gt;&lt;a href=&#34;#fn:1&#34; class=&#34;footnote-ref&#34; role=&#34;doc-noteref&#34;&gt;1&lt;/a&gt;&lt;/sup&gt;.&lt;/p&gt;</description>
    </item>
    <item>
      <title>ManiMed: B. Braun Melsungen AG – Space System Vulnerabilities</title>
      <link>https://insinuator.net/2021/02/manimed-b.-braun-melsungen-ag-space-system-vulnerabilities/</link>
      <pubDate>Mon, 15 Feb 2021 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2021/02/manimed-b.-braun-melsungen-ag-space-system-vulnerabilities/</guid>
      <description>&lt;p&gt;The Federal Office for Information Security (BSI) aims to sensitize&#xA;manufacturers and the public regarding security risks of networked medical&#xA;devices in Germany. In response to the often fatal security reports and press&#xA;releases of networked medical devices, the BSI initiated the project&#xA;Manipulation of Medical Devices (ManiMed) in 2019. In this project, a security&#xA;analysis of selected products is carried out through security assessments&#xA;followed by Coordinated Vulnerability Diclosure (CVD) processes. The project&#xA;report was published on December 31, 2020, and can be accessed on the BSI&#xA;website&lt;sup id=&#34;fnref:1&#34;&gt;&lt;a href=&#34;#fn:1&#34; class=&#34;footnote-ref&#34; role=&#34;doc-noteref&#34;&gt;1&lt;/a&gt;&lt;/sup&gt;.&lt;/p&gt;</description>
    </item>
    <item>
      <title>ManiMed: Innokas Yhtymä Oy - VC150 Patient Monitor Vulnerabilities</title>
      <link>https://insinuator.net/2021/02/manimed-innokas-yhtym%C3%A4-oy-vc150-patient-monitor-vulnerabilities/</link>
      <pubDate>Mon, 01 Feb 2021 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2021/02/manimed-innokas-yhtym%C3%A4-oy-vc150-patient-monitor-vulnerabilities/</guid>
      <description>&lt;p&gt;The Federal Office for Information Security (BSI) aims to sensitize&#xA;manufacturers and the public regarding security risks of networked medical&#xA;devices in Germany. In response to the often fatal security reports and press&#xA;releases of networked medical devices, the BSI initiated the project&#xA;Manipulation of Medical Devices (ManiMed) in 2019. In this project, a security&#xA;analysis of selected products is carried out through security assessments&#xA;followed by Coordinated Vulnerability Diclosure (CVD) processes. The project&#xA;report was published on December 31, 2020, and can be accessed on the BSI&#xA;website&lt;sup id=&#34;fnref:1&#34;&gt;&lt;a href=&#34;#fn:1&#34; class=&#34;footnote-ref&#34; role=&#34;doc-noteref&#34;&gt;1&lt;/a&gt;&lt;/sup&gt;.&lt;/p&gt;</description>
    </item>
    <item>
      <title>ManiMed: Philips Medizin Systeme Böblingen GmbH – IntelliVue System Vulnerabilities</title>
      <link>https://insinuator.net/2021/01/manimed-philips-medizin-systeme-b%C3%B6blingen-gmbh-intellivue-system-vulnerabilities/</link>
      <pubDate>Mon, 25 Jan 2021 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2021/01/manimed-philips-medizin-systeme-b%C3%B6blingen-gmbh-intellivue-system-vulnerabilities/</guid>
      <description>&lt;p&gt;The Federal Office for Information Security (BSI) aims to sensitize&#xA;manufacturers and the public regarding security risks of networked medical&#xA;devices in Germany. In response to the often fatal security reports and press&#xA;releases of networked medical devices, the BSI initiated the project&#xA;Manipulation of Medical Devices (ManiMed) in 2019. In this project, a security&#xA;analysis of selected products is carried out through security assessments&#xA;followed by Coordinated Vulnerability Diclosure (CVD) processes. The project&#xA;report was published on December 31, 2020, and can be accessed on the BSI&#xA;website&lt;sup id=&#34;fnref:1&#34;&gt;&lt;a href=&#34;#fn:1&#34; class=&#34;footnote-ref&#34; role=&#34;doc-noteref&#34;&gt;1&lt;/a&gt;&lt;/sup&gt;/&lt;/p&gt;</description>
    </item>
    <item>
      <title>ManiMed: Market Analysis</title>
      <link>https://insinuator.net/2021/01/manimed-market-analysis/</link>
      <pubDate>Mon, 18 Jan 2021 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2021/01/manimed-market-analysis/</guid>
      <description>&lt;p&gt;The Federal Office for Information Security (BSI) aims to sensitize&#xA;manufacturers and the public regarding security risks of networked medical&#xA;devices in Germany. In response to the often fatal security reports and press&#xA;releases of networked medical devices, the BSI initiated the project&#xA;Manipulation of Medical Devices (ManiMed) in 2019. In this project, a security&#xA;analysis of selected products is carried out through security assessments&#xA;followed by Coordinated Vulnerability Diclosure (CVD) processes. The project&#xA;report was published on December 31, 2020, and can be accessed on the BSI&#xA;website&lt;sup id=&#34;fnref:1&#34;&gt;&lt;a href=&#34;#fn:1&#34; class=&#34;footnote-ref&#34; role=&#34;doc-noteref&#34;&gt;1&lt;/a&gt;&lt;/sup&gt;.&lt;/p&gt;</description>
    </item>
    <item>
      <title>ERNW White Paper 70 – HL7 FHIR: Preserving Distributed Resource Integrity</title>
      <link>https://insinuator.net/2020/12/ernw-white-paper-70-hl7-fhir-preserving-distributed-resource-integrity/</link>
      <pubDate>Fri, 18 Dec 2020 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2020/12/ernw-white-paper-70-hl7-fhir-preserving-distributed-resource-integrity/</guid>
      <description>&lt;p&gt;With this blog post I am pleased to announce the publication of a new ERNW White Paper about the HL7 FHIR communication standard.&lt;/p&gt;&#xA;&lt;h2 id=&#34;introduction&#34;&gt;Introduction&lt;/h2&gt;&#xA;&lt;p&gt;Digital networking is already widespread in many areas of life. More and more medical devices are also being networked in the healthcare industry. This growth makes the development and use of new medical communication standards necessary since existing solutions can only meet the changing requirements with great effort. The HL7 FHIR standard is an example of such a medical communication standard. FHIR is said to have increased the interoperability between different medical contexts,e.g., administration, billing, and clinical care, to enable data exchange of various systems. The FHIR standard addresses the security risks associated with strongly networked communication from a large number of systems across the trust and organizational boundaries only indirectly because FHIR does not define mandatory security controls or requirements.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Apps on Prescription?! – Perspectives on Digital Health Applications (DiGA)</title>
      <link>https://insinuator.net/2020/11/apps-on-prescription-perspectives-on-digital-health-applications-diga/</link>
      <pubDate>Thu, 05 Nov 2020 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2020/11/apps-on-prescription-perspectives-on-digital-health-applications-diga/</guid>
      <description>&lt;p&gt;Some time ago, we carried out an evaluation of the &lt;em&gt;Digital Health Applications Ordinance&lt;/em&gt; (Digitale-Gesundheitsanwendungen-Verordnung, DiGAV) for the &lt;em&gt;Federal Chamber of Psychotherapists in Germany&lt;/em&gt; (Bundespsychotherapeutenkammer, BPtK) focusing on the security of digital health applications, often referred to as &lt;em&gt;apps on prescription&lt;/em&gt;.&lt;/p&gt;&#xA;&lt;p&gt;The audit was intended to determine to which extent security guidelines, security objectives, and best practices are adhered to by the requirements formulated by the ordinance, thus enabling the foundations to securely operate digital health applications. The main subject of the examination is whether requirements, including procedural requirements defined in the ordinance are sufficient to ensure security of digital health applications. The examination has shown that the requirements can be seen as positive. However, in order to be able to make reliable statements about the IT security of digital healthcare applications, further details and mechanisms should be clarified within the ordinance, which I would like to present in the following.&lt;/p&gt;</description>
    </item>
    <item>
      <title>ERNW White Paper 69 – Safety Impact of Vulnerabilities in Insulin Pumps</title>
      <link>https://insinuator.net/2020/09/ernw-white-paper-69-safety-impact-of-vulnerabilities-in-insulin-pumps/</link>
      <pubDate>Fri, 11 Sep 2020 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2020/09/ernw-white-paper-69-safety-impact-of-vulnerabilities-in-insulin-pumps/</guid>
      <description>&lt;p&gt;With this blog post I am pleased to announce the publication of a new ERNW White Paper &lt;a href=&#34;https://ernw-research.de/en/whitepapers/issue-69.html&#34;&gt;[1]&lt;/a&gt;. The paper is about severe vulnerabilities in an insulin pump we assessed during project ManiMed and we are proud to publish this subset of the results today.&lt;/p&gt;&#xA;&lt;h2 id=&#34;manipulating-medical-devices&#34;&gt;Manipulating Medical Devices&lt;/h2&gt;&#xA;&lt;p&gt;The German Federal Office for Information Security (BSI), in its role as the Federal Cyber Security Authority in Germany, aims to sensitize manufacturers and the public regarding security risks of networked medical devices. In response to the often fatal security reports and press releases of networked medical devices, the BSI initiated the project Manipulation of Medical Devices (ManiMed) in 2019. In this project, a security analysis of selected products is carried out through security assessments. In the context of this project, severe vulnerabilities were identified during the assessment of the DANA Diabecare RS system.&lt;/p&gt;</description>
    </item>
    <item>
      <title>How can data from fitness trackers be obtained and analyzed with a forensic approach?</title>
      <link>https://insinuator.net/2020/09/how-can-data-from-fitness-trackers-be-obtained-and-analyzed-with-a-forensic-approach/</link>
      <pubDate>Thu, 10 Sep 2020 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2020/09/how-can-data-from-fitness-trackers-be-obtained-and-analyzed-with-a-forensic-approach/</guid>
      <description>&lt;p&gt;The use of Internet of Things devices is continuously increasing: People buy devices, such as smart assistants, to make their lives more comfortable or fitness trackers to assess sports activities. According to the Pew Research Center [1], every fifth American wears a device to track their fitness. In Germany, the number increases likewise. The increasing number of fitness trackers in use can also be seen in criminal proceedings, as there exist more and more cases where these devices provide evidence.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Medical Device Security: HL7v2 Injections in Patient Monitors</title>
      <link>https://insinuator.net/2020/04/medical-device-security-hl7v2-injections-in-patient-monitors/</link>
      <pubDate>Thu, 23 Apr 2020 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2020/04/medical-device-security-hl7v2-injections-in-patient-monitors/</guid>
      <description>&lt;p&gt;Digital networking is already widespread in many areas of life. In the healthcare industry, a clear trend towards networked devices is noticeable, so that the number of high-tech medical devices in hospitals is steadily increasing.&lt;/p&gt;&#xA;&lt;p&gt;In this blog post, we want to elucidate a vulnerability we identified during the security assessment of a patient monitor. The device sends HL7 v2.x messages, such as observation results to HL7 v2.x capable electronic medical record (EMR) systems. A user with malicious intent can tamper these messages. As HL7 v2.x is a common medical communication standard, we also want to present how this kind of vulnerability may be mitigated. The assessment was part of the BSI project ManiMed, which we would like to present in the following section.&lt;/p&gt;</description>
    </item>
    <item>
      <title>MRMCD16 – diagnosis:critical</title>
      <link>https://insinuator.net/2016/09/mrmcd16-diagnosiscritical/</link>
      <pubDate>Sat, 03 Sep 2016 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2016/09/mrmcd16-diagnosiscritical/</guid>
      <description>&lt;p&gt;This year’s &lt;a href=&#34;https://2016.mrmcd.net/en/&#34;&gt;MRMCD16&lt;/a&gt; had a topic that immediately let me submit a talk about medical device security: “diagnosis:critical”. Or to quote the official website:&lt;/p&gt;&#xA;&lt;p&gt;Security issues in soft- and hardware have a low chance of healing, especially in medical IT.&lt;/p&gt;&#xA;&lt;p&gt;Despite years of therapy using code reviews and programming guidelines, we still face huge amounts of vulnerable software that probably is in need of palliative treatment.&lt;/p&gt;&#xA;&lt;p&gt;Security vulnerabilities caused by the invasion of IT in the medical sector are becoming real threats. From insulin pumps over analgesic pumps through to pace makers, more and more medical devices have been hacked already. This year&amp;rsquo;s motto &amp;ldquo;mrmcd2016 - diagnosis:critical&amp;rdquo; stands summarizing for the current state of the whole IT sector.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Unpatchable – Living with a vulnerable implanted device</title>
      <link>https://insinuator.net/2016/04/unpatchable-living-with-a-vulnerable-implanted-device/</link>
      <pubDate>Thu, 07 Apr 2016 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2016/04/unpatchable-living-with-a-vulnerable-implanted-device/</guid>
      <description>&lt;p&gt;TL;DR: Marie Moe talked about security issues of medical devices, especially implantable devices like pacemakers, but not in overwhelming technological depth. She wanted to point out the necessity of intensified security research in the field of medical devices as vendors and medical personnel seem to be lacking necessary awareness of security of devices, interfaces, services, and even data privacy.”Get involved, &lt;a href=&#34;https://www.iamthecavalry.org/&#34;&gt;join the cavalry&lt;/a&gt;” was her core message.&lt;/p&gt;&#xA;&lt;p&gt;&lt;strong&gt;Lub-Dub-Lub-Dub-Lub-Dub&lt;/strong&gt;&lt;br&gt;&#xA;Marie started her talk with the sound of a repeating heartbeat. First she introduced how she came up with the topic of her talk: Marie relies on a pacemaker herself andsince she got it implanted she was curious how secure this little device might be. A minimum education of the auditorium followed including an explanation how a human heart works and what a pacemaker does.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Medical Device Security: Hack or Hype</title>
      <link>https://insinuator.net/2016/03/medical-device-security-hack-or-hype/</link>
      <pubDate>Wed, 30 Mar 2016 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2016/03/medical-device-security-hack-or-hype/</guid>
      <description>&lt;p&gt;Kevin Fu is an Associate Professor at the University of Michigan where he directs the Archimedes Center for Medical Device Security and cofounded Virta Labs. At Troopers 16 he held a talk in the field of his research: &lt;a href=&#34;https://www.troopers.de/events/troopers16/697_medical_device_security_hack_or_hype/&#34;&gt;medical device security&lt;/a&gt;.&lt;/p&gt;&#xA;&lt;p&gt;He started his talk with a brief introduction how he got started with medical device security and how it has changed since he started. Round about ten years ago he started dumpster diving for medical devices to investigate how they are protected and maintained. In 2006 he held his first talk about medical device security at the FDA. In 2008 he presented a wireless replay attack against a pacemaker. In 2013 concerns about medical device security became more and more mainstream when the television series homeland featured an episode where the pacemaker of the American vice president was attacked resulting in his death. Now, instead of dumpster diving for medical devices, he works together with clinicians and has a lab for testing devices. The communication with clinicians is very important for his work, so he visits hospitals with his student so that they can learn how the process works on the inside.&lt;/p&gt;</description>
    </item>
    <item>
      <title>“We have a Code Blue right here!”</title>
      <link>https://insinuator.net/2015/11/we-have-a-code-blue-right-here/</link>
      <pubDate>Wed, 04 Nov 2015 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2015/11/we-have-a-code-blue-right-here/</guid>
      <description>&lt;p&gt;That was the opener for my presentation on the Security in Medical Devices at &lt;a href=&#34;http://codeblue.jp/2015/en/&#34;&gt;CodeBlue 2015&lt;/a&gt; last week in Tokyo, Japan. A &lt;a href=&#34;https://en.wikipedia.org/wiki/Hospital_emergency_codes#Code_Blue&#34;&gt;Code Blue&lt;/a&gt; often describes a patient in a critical condition, mostly needing resuscitation. That just seemed to be a perfect match, also in the sense that the condition of some medical devices out there are still pretty critical concerning security. If you follow our current research on this you know what I am talking about. I hope that we are not talking about this topic anymore three years from now. That would mean that we have made the world a safer place, although it took some time … 😉&lt;/p&gt;</description>
    </item>
    <item>
      <title>ERNW speaking @ hardwear.io</title>
      <link>https://insinuator.net/2015/10/ernw-speaking-@-hardwear.io/</link>
      <pubDate>Mon, 05 Oct 2015 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2015/10/ernw-speaking-@-hardwear.io/</guid>
      <description>&lt;p&gt;&lt;img src=&#34;http://www.insinuator.net/wp-content/uploads/2015/10/hardwarebug-266x300.png&#34; alt=&#34;Hardwarebug&#34;&gt;&lt;/p&gt;&#xA;&lt;p&gt;On October 1st and 2nd Flo and I were presenting at&lt;br&gt;&#xA;hardwear.io in The Hague, NL. My topic was “&lt;a href=&#34;https://www.ernw.de/download/ERNW_hardwear.io_2015_living_in_a_fools_wireless-secured_paradise_skiese.pdf&#34;&gt;Living in a fool’s&lt;/a&gt;&lt;br&gt;&#xA;&lt;a href=&#34;https://www.ernw.de/download/ERNW_hardwear.io_2015_living_in_a_fools_wireless-secured_paradise_skiese.pdf&#34;&gt;wireless-secured paradise&lt;/a&gt;” and Flo was presenting his current research&lt;br&gt;&#xA;on medical device security. It was the first talk at an international&lt;br&gt;&#xA;security conference for me and I am still quite excited!&lt;/p&gt;&#xA;&lt;p&gt;I was speaking about the (in)security of wireless consumer alarm&lt;br&gt;&#xA;systems, which you can buy just in every consumer electronics store&lt;br&gt;&#xA;around the corner for about $10 – $250. I analyzed the systems on&lt;br&gt;&#xA;different levels, e.g. looking at UART and JTAG and the wireless domain&lt;br&gt;&#xA;with Software Defined Radio (SDR). I gave an overview of my current&lt;br&gt;&#xA;research and the tools I usually use for hardware hacking, especially my&lt;br&gt;&#xA;favorite thing to play with: SDR.&lt;/p&gt;</description>
    </item>
    <item>
      <title>The patient’s last words: I am not a target!</title>
      <link>https://insinuator.net/2015/07/the-patients-last-words-i-am-not-a-target/</link>
      <pubDate>Wed, 01 Jul 2015 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2015/07/the-patients-last-words-i-am-not-a-target/</guid>
      <description>&lt;p&gt;Last week I gave a short interview for Süddeutsche Zeitung on the security of medical devices. You can find it &lt;a href=&#34;http://www.sueddeutsche.de/wirtschaft/medizintechnik-naechtliches-desaster-1.2534424&#34;&gt;here&lt;/a&gt;. Unfortunately it is in German so I decided to sum up some of my key points that made it into the article and some that didn’t in this blog post.&lt;/p&gt;&#xA;&lt;p&gt;The medical devices that we have been looking into include patient monitors, syringe pumps, EEGs, home monitoring devices and an MRI. All of these devices had major flaws that look like they came straight out of the 90s. Sometimes, we were able to crash the machines by simply doing a port scan, sometimes we could get around access controls protecting PIN codes of devices, and in most cases we were able to render the machine unusable. All these attacks were performed over the network and no physical access to the device was needed.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Power of Community 2014</title>
      <link>https://insinuator.net/2014/11/power-of-community-2014/</link>
      <pubDate>Thu, 13 Nov 2014 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2014/11/power-of-community-2014/</guid>
      <description>&lt;p&gt;I had the pleasure to participate in this year’s &lt;a href=&#34;http://www.powerofcommunity.net/index.html&#34; title=&#34;Power of Community 2014&#34;&gt;Power of Community&lt;/a&gt; and was invited to talk about the insecurity of medical devices. The conference is based in Seoul, Korea and started in 2006. It has a strong technical focus and it is a community driven event. For me it was great to participate as mostly hackers from Asia were there and I got the chance to talk to a lot of nice folks that I wouldn’t be able to meet otherwise. This is especially true for the host, vangelis.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Medical Device Security</title>
      <link>https://insinuator.net/2013/11/medical-device-security/</link>
      <pubDate>Thu, 21 Nov 2013 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2013/11/medical-device-security/</guid>
      <description>&lt;p&gt;One of our guiding principles at ERNW is “Make the World a Safer Place”. There could not be a topic that matches this principle more than the security or insecurity of medical devices. This is why we started a research project that is looking at how vulnerable those devices are that might be deployed in hospitals around the world. Recently the U.S. Food and Drug Administration (FDA) has put out a &lt;a href=&#34;http://www.fda.gov/medicaldevices/safety/alertsandnotices/ucm356423.htm&#34; title=&#34;FDA recommendation&#34;&gt;recommendation&lt;/a&gt; concerning the security of medical devices. It recommends that “manufacturers and health care facilities take steps to assure that appropriate safeguards are in place to reduce the risk of failure due to cyberattack, which could be initiated by the introduction of malware into the medical equipment or unauthorized access to configuration settings in medical devices and hospital networks”. We thought that we should take a look at how manufacturers deal with security for these devices.&lt;/p&gt;</description>
    </item>
  </channel>
</rss>
