NIST Issues New Guidance to Enhance Wireless Infusion Pump Cybersecurity | Healthcare Informatics Magazine | Health IT | Information Technology Skip to content Skip to navigation

NIST Issues New Guidance to Enhance Wireless Infusion Pump Cybersecurity

May 11, 2017
by Rajiv Leventhal
| Reprints

The National Institute of Standards and Technology (NIST), in collaboration with the healthcare community and manufacturers, has released draft guidelines designed to help healthcare delivery organizations improve wireless infusion pump cybersecurity.

As a press release from NIST stated, medical devices, such as infusion pumps, have evolved from standalone instruments that interacted only with the patient and a medical provider into devices that now connect wirelessly to a variety of systems, networks, and other platforms to enhance patient care, as part of the broader Internet of Medical Things (IoMT).

As such, cybersecurity risks have risen. Wireless infusion pump ecosystems, which include the pump, the network, and the data stored in and on a pump, face a range of potential threats, such as unauthorized access to protected health information (PHI), changes to prescribed drug doses, and interference with a pump’s intended function.

The new guidance, NIST Special Publication 1800-8: Securing Wireless Infusion Pumps in Healthcare Delivery Organizations, uses standards-based, commercially available technologies and industry best practices to help healthcare organizations strengthen the security of wireless infusion pumps within healthcare facilities, according to officials from NIST’s National Cybersecurity Center of Excellence. The draft guide is now open for public comment.  

Composed of three parts, the first volume can help hospital administrators better understand the cybersecurity risks of wireless infusion pumps to the hospital enterprise. The second and third volumes detail the approach, risk assessment, standards and security control mappings, and an example implementation of securing the wireless infusion pump ecosystem.

“When we initially launched this project, we received more than 200 comments from interested parties. That’s when we realized the challenges involved in properly securing wireless infusion pumps were complex and significant. We ended up working with 14 technology and manufacturing collaborators and dozens of industry stakeholders to help healthcare delivery organizations reduce their risks,” Gavin O’Brien, senior cybersecurity engineer at the NCCoE, said in a statement.

Biomedical, networking and cybersecurity engineers, along with healthcare IT professionals, can use the second and third volumes to see how the NCCoE used commercially available or open source tools to help configure and deploy wireless infusion pumps. According to O’Brien, “The ultimate goal is to implement a defense-in-depth strategy to reduce the risks.”

O’Brien said that he is confident the guide will provide valuable insights healthcare delivery organizations need to better secure their wireless infusion pump ecosystems. And, he explained, capabilities demonstrated by the NCCoE may also apply to other medical devices on wireless networks as well.

Get the latest information on Cybersecurity and attend other valuable sessions at this two-day Summit providing healthcare leaders with educational content, insightful debate and dialogue on the future of healthcare and technology.

Learn More

Topics

News

Report: Aetna, Apple in Talks about Offering Plan Members Apple Watches

Aetna, which already offers the Apple Watch to its employees as part of a wellness program, is now in talks with Apple about pushing the wearable device to the health insurer’s members, according to a report in CNBC.

HIMSS Accepting Nominations for Most Influential Women in Health IT Awards

The Healthcare Information and Management Systems Society (HIMSS) has announced that nominations are now open for the HIMSS Most Influential Women in Health IT Awards.

E-Visits May Have Unintended Consequences for Docs, New Research Finds

Physicians who adopt e-visits often see increases in office visits and phone consultations, a reduction in new patients being seen by providers, and no noticeable improvements in patient health, according to new research.

CMS Provides More Details on Proposal to Eliminate Mandatory Bundled Payment Programs

The Centers for Medicare and Medicaid (CMS) posted a press release Tuesday that provides more details regarding its proposal to change the Comprehensive Care for Joint Replacement Model and cancel the mandatory Episode Payment Models and Cardiac Rehabilitation Incentive payment model.

HHS Awards $105 Million to Community Health Centers for Quality Improvement

The U.S. Department of Health and Human Services (HHS) has awarded nearly $105 million to 1,333 health centers in all U.S. states, territories and the District of Columbia as an investment in quality improvement.

Survey: Healthcare Pros Challenged to Identify, Mitigate Medical Device Security Risks

More than one-third (36 percent) of surveyed professionals in the Internet of Things (IoT)-connected medical device ecosystem say their organizations have experienced a cybersecurity incident in the past year, according to a recent Deloitte poll.