A featured contribution from Leadership Perspectives: a curated forum reserved for leaders nominated by our subscribers and vetted by our MedTech Business Review Advisory Board.

CBET Director Cyber Security | HIPAA

Eddie Myers, HCISPP

Ushering in a New Era of Medical Device Security

Eddie Myers

Eddie Myers

Clinical Security Strategist

Eddie Myers serves as the director of cybersecurity for Crothall’s Healthcare Technology Solutions division (HTS) and oversees national cybersecurity programs and initiatives for the HTS service line and its clients. Having worked in the healthcare sector for over 18 years, Myers has gained unique insights into healthcare information technologies, picture archiving and communication systems (PACS), and healthcare technology management. Myers and his team offer a variety of services, including project management, IT consulting, technical support, and security management services for clinical field operations.

Starting his career as a senior field service technician at CHRISTUS Health, Myers handled various responsibilities, including PACS administrator and program manager of clinical technology services, before joining Crothall Healthcare. During his tenure as a program manager at CREST services, he had the opportunity to learn more about HIPAA, which piqued his interest in cybersecurity.

In an interview with Healthcare Tech Outlook magazine, Myers sheds light on some of the challenges prevailing in the medical device security space and how companies can convert those challenges into unique opportunities.

What are some of the  challenges that medical device security  companies face today

One of the major challenges medical device security  organizations face today is educating and getting their clients’  IT departments on board with an understanding that there is  a substantial difference between handling medical devices  and typical IT controls. Patching a medical device is a complex  process as it requires OEMs to find and approve the patches.  Forming strategic partnership with a company named Asimily  helped Crothall Healthcare overcome this prevailing challenge  in the medical device security space. Asimily’s passive asset discovery tools collect real-time insights into hospital traffic and build out unique device profiles for medical devices. Asimily brings Crothall Healthcare clients laser-sharp visibility into their connected medical device profiles. Asimily’s threat detection tools assess risks, prioritize actions, and develop mitigation strategies to reduce security vulnerabilities through state-ofthe- art machine learning and help Crothall Healthcare walk away from conventional methods of relying on computers to control medical devices, figure out the operating system and current patches, and reach out to the OEMs for the MDS.

Can you please walk us through some of the latest projects you have been working on?

Rolling out Asimily to a good chunk of our clients gives us real-time visibility into the client’s data, which helps us build out unique device profiles and match them up with our CMMS. In addition, it enables us to differentiate between identical devices in the same organization. Conducting a thorough gap analysis with Asimily in our CMMS will lead to ultimately integrating these device profiles into our CMMS.

Crothall Healthcare, along with its partners, proactively follows numerous cybersecurity organizations and websites, such as CISA, that monitor device vulnerabilities. Our strategic partner, Asimily, keeps an eye on threat intelligence websites and adds the latest trends to their algorithm

As a medical device security expert, how do you respond to a cyberattack event?

Crothall Healthcare is an independent service organization, and we do not own medical devices or the network. During the event of cyberattacks, we ensure that we are operating under our clients’ incident response plan and a vital part of it. We would fill in where needed during an incident response.

How do you make sure that these medical devices are secure?

 The first step of securing medical devices during cyberattacks is ensuring that you take them off the network and figure out what exactly happened. There were many past incidents where government agencies showed up and took the hard drive for forensic analysis during such events. Knowing how to handle this is the next step toward ensuring medical device security. Having the wherewithal to bring that piece of equipment back up and ensuring that it is clean of any malware can help to put it back on the network and patient care safely.

On top of that, our strategic partners, including Asimily, proactively follow a plethora of threat intelligence agencies such as CISA that are relentlessly on a mission to track device vulnerabilities and put them into their algorithms. We leverage these algorithms to warn our clients beforehand about potential vulnerabilities with their devices.

How do you envision the future of the medical device security industry?

 The medical device security industry will gain more traction in the coming years. Employing “security-by-design” thinking to incorporate cybersecurity features into new products is going to be the next big thing in this era of connected devices, unlike in the past when medical device manufacturers were completely unconcerned about the security part. It is inevitable to initiate productive discussions on the same to bring this into action. Where do you think the medical devices are heading when using technologies such as IoT, AI, or any latest technologies?

Hospitals are leveraging technologies such as AI and IoT to make operations more hassle-free. The increase in the use of wireless connected devices and their growing popularity is a positive trend in this direction. Unfortunately, these wireless devices are not free from system failures and can be manipulated. Therefore, it is critical for hospitals to make sure that the end user knows how to use them during a system failure, as it might be a life-or-death situation. A backup plan should be in place to beat the situation.

What piece of advice would you like to give to your fellow peers in the medical device security space?

 Securing medical devices will become a priority when we connect them with our family’s security. Considering that our families will also be beneficiaries of the same will make us ensure that they are error-free and stay ahead of the game. It is crucial to ensure that medical devices are free from vulnerabilities to protect the lives of people, including our dear ones.

The articles from these contributors are based on their personal expertise and viewpoints, and do not necessarily reflect the opinions of their employers or affiliated organizations.