The FDA won’t approve medical devices vulnerable to cyberattack

The majority of digital medical devices (53{bf0515afdcaddba073662ceb89fbb62b6b1bf123143c0e06b788e1946e8c353f}) in the US, as well as internet-connected tools in hospitals, are at risk of cyberattack, according to a 2022 FBI report.

The US Food and Drug Administration (FDA) wants to change that, and has published new approval guidance that addresses the issue. Starting March 29, following directives contained in the federal omnibus spending bill, the FDA will reject applications for any cyber medical device that does not include a cyberattack protection plan.

The agency defines a cyber medical device as any medical device that has software capability or can be connected to the internet.

Most digital medical devices are vulnerable to attack

According to the 2022 FBI report, each of the medical devices currently on the market has on average 6.2 vulnerabilities to cyberattacks, and there have been recalls for insulin pumps and pacemakers that were found to have particularly serious security issues. For end-of-life devices, as many as 40{bf0515afdcaddba073662ceb89fbb62b6b1bf123143c0e06b788e1946e8c353f} of devices have no protection at all against attacks, the report found.

This means that a large number of health devices, many of which are lifesaving, are susceptible to attack. The list provided by the FBI included insulin pumps, intracardiac defibrillators, and pacemakers. “Malign actors who compromise these devices can direct them to give inaccurate readings, administer drug overdoses, or otherwise endanger patient health,” said the report.

While such direct attacks have not yet occurred, about half of all hospitals have been targeted with ransomware, and nearly as many believe the attacks ended up affecting their patients’ care, too.

What comes next for digital medical device security?

Going forward, FDA approval of digital medical devices will depend on their sponsors providing evidence that their products are reasonably safe against cyber attacks, and submitting a plan to “monitor, identify, and address” any vulnerabilities and threats.

Until Oct. 1, 2023 , devices that have already been submitted for premarket approval before will not receive a refusal to accept from the FDA, which will instead work with the manufacturers and sponsors to obtain relevant information to assess their safety.

The guidance is only valid until 2025 at the latest, as the omnibus bill requires the FDA to update its cybersecurity guidance every two years at the most, to keep up with updates in threats and technology.

It’s ‘Telehealth vs. No Care’: Doctors Say Congress Risks Leaving Patients Vulnerable

When the covid-19 pandemic hit, Dr. Corey Siegel was additional organized than most of his peers.

50 percent of Siegel’s sufferers — several with non-public insurance and Medicaid — were previously employing telehealth, logging on to appointments via phones or pcs. “You get to meet up with their spouse and children associates you get to satisfy their pets,” Siegel reported. “You see far more into their lives than you do when they come to you.”

Siegel’s Medicare patients weren’t coated for telehealth visits till the pandemic drove Congress and regulators to temporarily shell out for distant health care remedy just as they would in-person care.

Siegel, segment main for gastroenterology and hepatology at Dartmouth-Hitchcock Health care Middle, is certified in a few states and many of his Medicare people had been regularly driving two to 3 several hours round journey for appointments, “which isn’t a modest feat,” he said.

The $1.7 trillion paying package deal Congress passed in December bundled a two-year extension of key telehealth provisions, this kind of as protection for Medicare beneficiaries to have telephone or movie health care appointments at house. But it also signaled political reluctance to make the payment modifications long-lasting, requiring federal regulators to examine how Medicare enrollees use telehealth.

The federal extension “basically just kicked the can down the road for two many years,” stated Julia Harris, associate director for the wellness program at the D.C.-based Bipartisan Policy Middle assume tank. At problem are inquiries about the price and cost of telehealth, who will gain from its use, and whether or not audio and video appointments should continue on to be reimbursed at the identical charge as confront-to-encounter treatment.

Right before the pandemic, Medicare paid out for only slim employs of remote drugs, these as emergency stroke treatment supplied at hospitals. Medicare also included telehealth for people in rural spots but not in their households — individuals ended up expected to journey to a selected site these as a medical center or doctor’s workplace.

But the pandemic brought a “seismic modify in perception” and telehealth “became a home time period,” reported Kyle Zebley, senior vice president of community coverage at the American Telemedicine Association.

The omnibus bill’s provisions include things like: paying out for audio-only and home care permitting for a assortment of medical doctors and many others, this kind of as occupational therapists, to use telehealth delaying in-particular person specifications for mental overall health sufferers and continuing current telehealth providers for federally experienced well being clinics and rural wellbeing clinics.

Telehealth use amid Medicare beneficiaries grew from less than 1{bf0515afdcaddba073662ceb89fbb62b6b1bf123143c0e06b788e1946e8c353f} before the pandemic to a lot more than 32{bf0515afdcaddba073662ceb89fbb62b6b1bf123143c0e06b788e1946e8c353f} in April 2020. By July 2021, the use of remote appointments retreated relatively, settling at 13{bf0515afdcaddba073662ceb89fbb62b6b1bf123143c0e06b788e1946e8c353f} to 17{bf0515afdcaddba073662ceb89fbb62b6b1bf123143c0e06b788e1946e8c353f} of promises submitted, in accordance to a charge-for-provider statements examination by McKinsey & Co.

Fears around possible fraud and the charge of expanding telehealth have made politicians hesitant, reported Josh LaRosa, vice president at the Wynne Wellbeing Team, which focuses on payment and care shipping reform. The report expected in the omnibus bundle “is genuinely going to enable to give extra clarity,” LaRosa said.

In a 2021 report, the Authorities Accountability Office environment warned that employing telehealth could maximize paying out in Medicare and Medicaid, and historically the Congressional Spending plan Business office has explained telehealth could make it less complicated for persons to use far more well being treatment, which would guide to additional paying.

Advocates like Zebley counter that distant treatment doesn’t automatically price tag extra. “If the priority is preventative care and expanding obtain, that must be taken into account when looking at prices,” Zebley reported, conveying that elevated use of preventative treatment could push down a lot more high priced expending.

Siegel and his colleagues at Dartmouth see distant treatment as a resource for serving to chronically ill patients get ongoing treatment and preventing pricey unexpected emergency episodes. It “allows clients to not be burdened by their health problems,” he stated. “It’s significant that we maintain this going.”

Some of Seigel’s operate is funded by The Leona M. and Harry B. Helmsley Charitable Have faith in. (The Helmsley Charitable Believe in also contributes to KHN.)

For the earlier 9 months, Dartmouth Health’s telehealth visits plateaued at additional than 500 for every working day. That’s 10{bf0515afdcaddba073662ceb89fbb62b6b1bf123143c0e06b788e1946e8c353f} to 15{bf0515afdcaddba073662ceb89fbb62b6b1bf123143c0e06b788e1946e8c353f} of all outpatient visits, reported Katelyn Darling, director of operations for Dartmouth’s virtual care centre.

“Patients like it and they want to continue accomplishing it,” Darling claimed, including that doctors — specially psychologists — like telehealth also. If Congress decides not to carry on funding for distant at-property visits immediately after 2024, Darling explained, she fears patients will have to drive yet again for appointments that could have been managed remotely.

The similar fears are worrying leaders at Sanford Health, which offers providers across the Higher Midwest.

“We definitely have to have those provisions to become long-lasting,” said Brad Schipper, president of virtual care at Sanford, which has health system associates, hospitals, clinics, and other amenities in the Dakotas, Iowa, and Minnesota. In addition to the provisions, Sanford is carefully looking at irrespective of whether medical professionals will go on to get paid out for supplying care throughout condition traces.

For the duration of the pandemic, licensing demands in states had been frequently relaxed to help health professionals to follow in other states and many of all those necessities are established to expire at the conclude of the community wellness emergency.

Licensing prerequisites were being not tackled in the omnibus, and to ensure telehealth accessibility, states need to have to allow for medical professionals to address people across condition lines, said Dr. Jeremy Cauwels, Sanford Health’s chief medical professional. This has been notably critical in delivering mental health care, he reported digital visits now account for about 20{bf0515afdcaddba073662ceb89fbb62b6b1bf123143c0e06b788e1946e8c353f} of Sanford’s appointments.

Sanford is based mostly in Sioux Falls, South Dakota, and Cauwels recalled a person circumstance in which a affected individual lived four hrs from the closest youngster-adolescent psychiatrist and was “on the erroneous facet of the border.” Simply because of the latest licensing waivers, Cauwels stated, the patient’s wait for an appointment was minimize from several months to six times.

“We were in a position to get that child viewed with no Mom having a working day off to generate again and forth, with out a six-week hold off, and we had been able to do all the matters just about for that relatives,” Cauwels mentioned.

Psychiatrist Dr. Sara Gibson has utilised telehealth for many years in rural Apache County, Arizona. “There are some people today who have no accessibility to treatment without the need of telehealth,” she said. “That has to be additional into the equation.”

Gibson, who is also clinical director for Tiny Colorado Behavioral Health and fitness Centers in Arizona, said one critical query for policymakers as they search forward is not no matter if telehealth is superior than experience-to-encounter. It is “telehealth vs. no care,” she stated.

KHN (Kaiser Health News) is a national newsroom that creates in-depth journalism about health issues. Alongside one another with Policy Evaluation and Polling, KHN is a person of the 3 important functioning applications at KFF (Kaiser Spouse and children Basis). KFF is an endowed nonprofit organization supplying details on health difficulties to the country.

USE OUR Information

This tale can be republished for absolutely free (facts).

The latest cyberattack on health care shows how vulnerable the sector is

Comment

Welcome to The Cybersecurity 202! Aubrey Plaza is a national treasure.

Reading this online? Sign up for The Cybersecurity 202 to get scoops and sharp analysis in your inbox each morning. 

Below: Cybercriminals stole more than $500,000 from a senator’s campaign committee, and T-Mobile is again hacked. First:

Apparent BlackCat ransomware attack demonstrates risks to health-care sector, vendors

An apparent ransomware attack on a major electronic health records company demonstrates the vulnerability of the health-care sector to potentially disastrous cyberattacks.

The cyber incident impacted NextGen Healthcare last week. It apparently took place at the hands of a ransomware group that the Department of Health and Human Services warned about earlier this month.

The company says it doesn’t look like the hackers obtained any client data, although it didn’t say anything about patient or employee data. The suspected Russian ransomware group that claimed responsibility, BlackCat, put an alleged sample of NextGen information on its extortion site — typically used to compel victims to pay or risk further exposure — but later took down the NextGen listing.

However the NextGen incident plays out in the end, it highlights trends of attacks on major vendors and the health-care system.

What happened (according to those involved)

Founded in 1974, the Atlanta-based NextGen Healthcare claims 2,800 employees and reported revenue of nearly $600 million in 2022. It says it provides software and technology services in “ambulatory” settings, a term that ranges from physician offices to outpatient clinics, and has helped more than 2,500 health-care organizations across the world. 

Here’s what NextGen told media outlets happened in response to inquiries about the BlackCat extortion site listing:

  • “NextGen Healthcare is aware of this claim and we have been working with leading cybersecurity experts to investigate and remediate. We immediately contained the threat, secured our network, and have returned to normal operations. Our forensic review is ongoing and, to date, we have not uncovered any evidence of access to or exfiltration of client data. The privacy and security of our client information is of the utmost importance to us.”

The statement is silent on whether any patient or employee data was affected, Databreaches.net pointed out. Spokespeople for the company didn’t answer questions about those elements of the incident on Sunday. And a purported spokesperson for BlackCat (also known as ALPHV) refused to provide further proof of obtaining client data.

It’s not uncommon for companies to learn later that a breach was more extensive than originally believed. It’s also not uncommon for cybercriminals to lie about what kind of data they’ve stolen, or boast that they’ve stolen something they never did.

BlackCat is “a relatively new but highly-capable ransomware threat to the health sector,” according to an HHS threat briefing dated Jan. 12. It’s not the first time U.S. authorities have issued warnings about the group.

  • HHS dubbed it a “triple-extortion” group, marked by ransomware attacks that accompany threats to leak data and conducted distributed denial-of-service attacks intended to knock websites offline.
  • It has ties to older, infamous Russian ransomware gangs, such as Darkside/Black Matter and REvil.
  • The group has said it doesn’t “attack state medical institutions, ambulances, hospitals,” but that the “rule does not apply to pharmaceutical companies, private clinics.” HHS notes that ransomware gangs have frequently broken these promises.
  • BlackCat favors U.S. targets, according to HHS, which is not uncommon for ransomware gangs, many of which are believed to be based in Eastern Europe.

The ransomware risks for health-care organizations are severe, including potentially causing patient death. North Korean and Iranian hackers have demonstrated particular interest in pursuing attacks on the sector.

Companies that are vendors for other firms are a prominent way for ransomware gangs and other cybercriminals to expand their reach. Notable incidents include:

  • In 2021, REvil got into a software system developed by Kaseya, which in turn affected what Kaseya estimated to be 800 to 1,500 businesses.
  • Suspected Russian hackers accessed SolarWinds software as a means of obtaining access to U.S. government agencies, government organizations around the world and major tech companies.
  • Specifically in the health-care sector, a ransomware incident in the United Kingdom last summer affecting a service provider caused issues for the country’s National Health Service.

Regardless of how the NextGen incident turns out, it’s one episode in an eventful start to 2023 for ransomware. This year has seen the usual array of attacks and disclosures mixed in with some unusual reversals.

  • Restaurants in the U.K., including KFC, Pizza Hut and Taco Bell, had to shut down after a ransomware attack on parent company Yum!, the company said Wednesday.
  • The Los Angeles Unified School District earlier this month acknowledged that ransomware hackers last year stole employee Social Security numbers.
  • On New Year’s Eve, the LockBit gang apologized for what it said was an affiliate hacking a children’s hospital in Canada, and offered the hospital a decryptor to unlock its systems.
  • A study by blockchain analytics company Chainalysis released over the weekend suggested that ransomware payments were down in 2022, as more victims appeared to refuse forking over ransoms to crooks holding their networks hostage. But ransomware criminals continue to use cryptocurrency, contributing to illicit crypto activity reaching an all-time high last year, the firm concluded in another report this year.

Cybercriminals steal more than $500,000 from GOP senator’s campaign committee

They stole the money after sending phony invoices to Moran for Congress, the campaign committee for Sen. Jerry Moran (R-Kan.), Raw Story’s Dave Levinthal reports. The committee has recovered around a quarter of the stolen funds, which amounted to $690,000, it said in a Federal Election Commission filing.

“Cybercriminals targeted the accounting firm employed by Moran For Kansas and money was wired to fraudulent bank accounts,” Moran for Kansas spokesman Tom Brandt told Raw Story in an email. “As soon as a discrepancy was realized, it was reported to law enforcement. We are currently pursuing all avenues available to recover the money and there is an ongoing investigation with the FBI. The campaign also consulted with the FEC on how to transparently report the unauthorized expenditures.”

Cybercriminals have targeted other political campaigns as well. “Joining Moran among the federal-level politicians to experience thefts from their campaign accounts in recent years is President Joe Biden, whose 2020 Democratic presidential campaign committee lost at least $71,000,” Levinthal writes. “The Republican National Committee, Rep. Diana Harshbarger (R-TN), former Democratic presidential candidate and congresswoman Tulsi Gabbard and rapper-turned-2020 presidential candidate Ye, formerly Kanye West, are among others who reported money stolen from their political accounts.”

T-Mobile got hacked — again

T-Mobile said the hacker stole information like names, addresses, emails, phone numbers, birth dates and account numbers on as many as 37 million customers, TechCrunch’s Lorenzo Franceschi-Bicchierai reports. It’s the eighth time the phone carrier — which has 110 million customers — has been hacked since 2018.

“Our investigation is still ongoing, but the malicious activity appears to be fully contained at this time, and there is currently no evidence that the bad actor was able to breach or compromise our systems or our network,” the company said in a Securities and Exchange Commission filing.

A spokesperson for the company didn’t respond to TechCrunch’s request for comment.

A hacker found the sensitive U.S. no-fly list on an open server

Swiss hacker maia arson crimew found the list — which includes people not allowed to fly in or to the United States — on a server run by a regional U.S. airline, the Daily Dot’s Mikael Thalen and David Covucci report.

“The server contained data from a 2019 version of the federal no-fly list that included first and last names and dates of birth,” CommuteAir spokesman Erik Kane told the Daily Dot. “In addition, certain CommuteAir employee and flight information was accessible. We have submitted notification to the Cybersecurity and Infrastructure Security Agency and we are continuing with a full investigation.”

The Transportation Security Administration told the Daily Dot that it’s “aware of a potential cybersecurity incident with CommuteAir, and we are investigating in coordination with our federal partners.” 

U.S. law enforcement has noticed the hacker, crimew, before. In 2021, a grand jury indicted crimew, accusing the hacker of breaching “dozens of companies and government agencies.” Crimew was also a member of a group of hackers who breached security camera firm Verkada.

Hackers penetrated LAUSD computers much earlier than previously known, district probe finds (Los Angeles Times)

Riot Games hacked, delays game patches after security breach (Bleeping Computer)

A hack at ODIN Intelligence exposes a huge trove of police raid files (TechCrunch)

Majority of GAO’s cyber recommendations since 2010 have gone unresolved (NextGov)

  • Jack Cable and Lauren Zabierek have joined the Cybersecurity and Infrastructure Security Agency as senior technical adviser and senior policy adviser.
  • CIA deputy director for analysis Linda Weissgold speaks at an event hosted by the Intelligence and National Security Alliance on Tuesday at 9 a.m.

Thanks for reading. See you tomorrow.