Science Current Events | Science News | Brightsurf.com
 
Email a Friend Send to a friend
Printer Friendly Print Implantable medical devices may expose patients to security, privacy risks; solutions suggested

Implantable medical devices may expose patients to security, privacy risks; solutions suggested

March 13, 2008

Study conducted by team from UMass Amherst, University of Washington

Some medical devices such as implantable cardiac defibrillators and pacemakers are now equipped with wireless technology, allowing for remote device checks and freeing patients from repeated doctor visits. But this convenience may come with unanticipated risks. A team of researchers from three leading universities has demonstrated that patients' private medical information could be extracted and their devices reprogrammed without the patients' authorization or knowledge.




There has never been a reported case of a patient with an implantable cardiac defibrillator or pacemaker being targeted by hackers, and the researchers emphasized that the study was designed to identify and prevent future problems. Undertaking the study required a high level of technical expertise, and the published paper omits certain details in methodology that prevents the findings from being used for anything other than improving patient security and privacy.

The study was led by two computer scientists, Tadayoshi Kohno of the University of Washington and Kevin E. Fu of the University of Massachusetts Amherst, and cardiologist Dr. William H. Maisel of the Beth Israel Deaconess Medical Center and Harvard Medical School. Their scholarly peer-reviewed report will be presented and published at the Institute of Electrical and Electronic Engineers Symposium on Security and Privacy in Oakland, Calif., May 19, 2008.

Dr. Maisel, director of the Medical Device Safety Institute at Beth Israel Deaconess Medical Center in Boston, notes, "One of the purposes of this research is to encourage the medical device industry to think more carefully about the security and privacy of patient information, particularly as wireless communication becomes more common. Fortunately, there are some safeguards already in place, but device manufacturers can do better."

The team expects this issue to take on greater importance as implantable cardiac defibrillators operate wirelessly at greater distances. These devices typically receive short-range wireless signals over several feet, but new technologies are expanding that reach even farther, creating the potential for information to be intercepted en route.

"We hope our research is a wake-up call for the industry," said Kohno, an assistant professor of computer science and engineering at the University of Washington. "In the 1970s, the Bionic Woman was a dream, but modern technology is making it a reality. People will have sophisticated computers with wireless capabilities in their bodies. Our goal is to make sure those devices are secure, private, safe and effective."

Fu, an assistant professor of computer science at UMass Amherst, noted that the study developed several prototype defenses. "One of our primary contributions is the invention of three defense mechanisms that require no battery power, making them potentially easy to incorporate in the devices without extensive redesigning. While there has been much research that explores the biological safety of implantable medical devices, there is limited understanding about the related issues of wireless security and privacy. Understanding the security and privacy of implantable devices is essential for protecting the nation's health and cyber infrastructure."

The researchers' experiments used an implantable cardiac defibrillator, a sophisticated device that automatically regulates the heart beat by sending small electrical signals to the heart to stimulate the heart rate or by delivering a large shock to restore a potentially fatal heart rhythm back to normal. Implantable defibrillators have improved survival in selected patients at risk for sudden cardiac death, and millions of the devices have been implanted worldwide. The model used in the researchers' experiment contained computers and radios that allow health-care practitioners to diagnose patients, read and write private medical information, and adjust the device's therapy settings wirelessly.

In computer laboratory bench tests, the research team used an inexpensive software radio to intercept and capture signals sent from the implantable device. They were able to obtain detailed information about a hypothetical patient, including name, diagnosis, date of birth and medical ID number. Researchers could determine the make and model of the device and access real-time electrocardiogram results as well as data on the hypothetical patient's heart rate and cardiac activity.

The team then mounted several attacks. Researchers were able to turn off the therapy settings stored in the implantable device, rendering it incapable of responding to dangerous cardiac events. Additional commands were delivered, resulting in the delivery of a shock that could induce ventricular fibrillation, a potentially lethal arrhythmia.

Three deterrence and prevention mechanisms were developed as part of the study, including a notification device that audibly alerts patients of security sensitive events, a device that authenticates requests for access from outside devices and a vibrating device that patients can sense. All three mechanisms require no power from the battery, and one of them was evaluated for effectiveness in a substance similar to human tissue.

Because the team studied one common model of implantable cardiac defibrillator, the susceptibility of similar devices to privacy and security risks is uncertain. The researchers believe future studies are needed to assess potential risks associated with other implantable devices equipped with wireless technology. The researchers feel strongly that nothing in their report should deter patients from receiving these devices if recommended by their physician. The implantable cardiac defibrillator is a proven, life-saving technology.

University of Washington




More Implantable Medical Device Current Events and Implantable Medical Device News Articles
ISO 14708-1:2000, Implants for surgery -- Active implantable medical devices -- Part 1: General requirements for safety, marking and for information to be provided by the manufacturer

ISO 14708-1:2000, Implants for surgery -- Active implantable medical devices -- Part 1: General requirements for safety, marking and for information to be provided by the manufacturer
by ISO TC 150/SC 6 (Author)

This part of ISO 14708 specifies requirements that are generally applicable to active implantable medical devices.The tests that are specified in this part of ISO 14708 are type tests intended to be carried out on samples of a device to show compliance, and are not intended to be used for the routine testing of manufactured products.This part of ISO 14708 is applicable not only to active implantable medical devices that are electrically powered, but also to those powered by other energy sources (for example gas pressure or springs).This part of ISO 14708 is also applicable to some non-implantable parts and accessories of the devices (see 3.3).

  Testing implantable medical devices: minimal analog access ports make testing today's complex digital implantable medical devices a unique challenge.(Medical ... An article from: EE-Evaluation Engineering
by J. Max Cortner (Author)

This digital document is an article from EE-Evaluation Engineering, published by Nelson Publishing on June 1, 2004. The length of the article is 2469 words. The page length shown above is based on a typical 300-word page. The article is delivered in HTML format and is available in your Amazon.com Digital Locker immediately after purchase. You can view it with any web browser.

Citation Details
Title: Testing implantable medical devices: minimal analog access ports make testing today's complex digital implantable medical devices a unique challenge.(Medical Electronics Test)
Author: J. Max Cortner
Publication: EE-Evaluation Engineering (Refereed)
Date: June 1, 2004
Publisher: Nelson Publishing
Volume: 43 Issue: 6 Page: 38(4)

Distributed by Thomson...

ISO 14708-2:2005, Implants for surgery - Active implantable medical devices - Part 2: Cardiac pacemakers

ISO 14708-2:2005, Implants for surgery - Active implantable medical devices - Part 2: Cardiac pacemakers
by ISO/TC 150/SC 6 (Author)

ISO 14708-2:2005 specifies requirements that are applicable to those active implantable medical devices intended to treat bradyarrhythmias (cardiac pacemakers). The tests that are specified in ISO 14708-2:2005 are type tests, and are to be carried out on samples of a device to show compliance. ISO 14708-2:2005 is also applicable to some non-implantable parts and accessories of the devices. The device that is commonly referred to as an active implantable medical device may in fact be a single device, a combination of devices, or a combination of a device or devices and one or more accessories. Not all of these parts are required to be either partially or totally implantable, but there is a need to specify some requirements of non-implantable parts and accessories if they could affect the...

Implantable Medical Devices in Japan: A Strategic Entry Report, 1996 (Strategic Planning Series)

Implantable Medical Devices in Japan: A Strategic Entry Report, 1996 (Strategic Planning Series)
by The Healthcare Research Group (Author), Inc Icon Group International (Other Contributor)

This report puts executives and strategic planners on the fast track. The first chapter describes the study's methodology. The second chapter gives an overview of how to strategically access the market, mid-term forecasts of latent demand and accessibility benchmarks. The remaining nine chapters are not industry specific, but instead discuss economic fundamentals, marketing & distribution options, export and direct investment options, and full risk assessments (political, cultural, legal, human resources). Combined, the information provided in this market study is a "one-stop" shop for the strategic planner. Ample statistical benchmarks and comparative graphs are given.

ISO 16429:2004, Implants for surgery - Measurements of open-circuit potential to assess corrosion behaviour of metallic implantable materials and medical devices over extended time periods

ISO 16429:2004, Implants for surgery - Measurements of open-circuit potential to assess corrosion behaviour of metallic implantable materials and medical devices over extended time periods
by ISO/TC 150/SC 1 (Author)

ISO 16429:2004 specifies a test method for measurements over extended time periods of the open-circuit potential of implant materials and surgically implantable devices immersed in a test environment related to body fluid, using a standard corrosion test cell to study the electrochemical corrosion properties of the devices.This method of monitoring the open-circuit potential can also be combined with mechanical static or dynamic loading tests.ISO 16429:2004 is applicable in particular to metallic materials which form passive layers with protective properties against corrosion, as typical for surgical implant materials.This test method is intended for the investigation of single metallic materials or alloys. It is not applicable to dissimilar material combinations, which require particular...

ISO 16428:2005, Implants for surgery - Test solutions and environmental conditions for static and dynamic corrosion tests on implantable materials and medical devices

ISO 16428:2005, Implants for surgery - Test solutions and environmental conditions for static and dynamic corrosion tests on implantable materials and medical devices
by ISO/TC 150/SC 1 (Author)

ISO 16428:2005 specifies standard environmental conditions for the testing of metallic materials intended for implantation, surgical implants, and medical devices. The testing conditions described simulate physiological conditions in a simplified manner controlling the test solution, the temperature, the gaseous atmosphere and the proportions of sample size and volume of solution. These environmental testing conditions can be employed where necessary in combination with various static or dynamic tests where the effect of the physiological environment is to be considered. Typical applications are corrosion fatigue tests and selected fretting and wear tests, as well as general electrochemical tests. Typical articulating joint simulator tests and aspects particular to the dental field are...

Implantable Neural Prostheses 1: Devices and Applications (Biological and Medical Physics, Biomedical Engineering)

Implantable Neural Prostheses 1: Devices and Applications (Biological and Medical Physics, Biomedical Engineering)
by David Zhou (Editor), Elias Greenbaum (Editor)

This book and its companion volume describe state-of-the-art advances in techniques associated with implantable neural prosthetic devices and their applications. Researchers, engineers, clinicians, students and any specialist in this field will gain a deeper understanding of the neural prosthetic techniques currently available for a wide range of biomedical applications.

In part one of this two-volume sequence, Implantable Neural Prostheses 1: Devices and Applications, the focus is on implant designs and applications. Devices covered include sensory prosthetic devices such as cochlear implants, auditory midbrain implants, visual implants, spinal cord stimulators, and motor prosthetic devices including deep brain stimulators, Bions, and cardiac electro-stimulators. Readers will...

  Ce Marking for Medical Devices: A Handbook to the Medical Devices Directives : Medical Devices Directive 93/42/Eec : The Active Implantable Medical Devices Directive 90/396/Eec
by C. C. W. Schoenmakers (Author)



  The Active Implantable Medical Devices (Amendment and Transitional Provisions) Regulations 1995 (Statutory Instruments: 1995: 1671)
by Stationery Office Books (Publisher)



  Active implantable medical devices (The single market)
by Great Britain (Author)



© 2009 BrightSurf.com