NIST Issues New Guidance to Enhance Wireless Infusion Pump Cybersecurity | Healthcare Informatics Magazine | Health IT | Information Technology Skip to content Skip to navigation

NIST Issues New Guidance to Enhance Wireless Infusion Pump Cybersecurity

May 11, 2017
by Rajiv Leventhal
| Reprints

The National Institute of Standards and Technology (NIST), in collaboration with the healthcare community and manufacturers, has released draft guidelines designed to help healthcare delivery organizations improve wireless infusion pump cybersecurity.

As a press release from NIST stated, medical devices, such as infusion pumps, have evolved from standalone instruments that interacted only with the patient and a medical provider into devices that now connect wirelessly to a variety of systems, networks, and other platforms to enhance patient care, as part of the broader Internet of Medical Things (IoMT).

As such, cybersecurity risks have risen. Wireless infusion pump ecosystems, which include the pump, the network, and the data stored in and on a pump, face a range of potential threats, such as unauthorized access to protected health information (PHI), changes to prescribed drug doses, and interference with a pump’s intended function.

The new guidance, NIST Special Publication 1800-8: Securing Wireless Infusion Pumps in Healthcare Delivery Organizations, uses standards-based, commercially available technologies and industry best practices to help healthcare organizations strengthen the security of wireless infusion pumps within healthcare facilities, according to officials from NIST’s National Cybersecurity Center of Excellence. The draft guide is now open for public comment.  

Composed of three parts, the first volume can help hospital administrators better understand the cybersecurity risks of wireless infusion pumps to the hospital enterprise. The second and third volumes detail the approach, risk assessment, standards and security control mappings, and an example implementation of securing the wireless infusion pump ecosystem.

“When we initially launched this project, we received more than 200 comments from interested parties. That’s when we realized the challenges involved in properly securing wireless infusion pumps were complex and significant. We ended up working with 14 technology and manufacturing collaborators and dozens of industry stakeholders to help healthcare delivery organizations reduce their risks,” Gavin O’Brien, senior cybersecurity engineer at the NCCoE, said in a statement.

Biomedical, networking and cybersecurity engineers, along with healthcare IT professionals, can use the second and third volumes to see how the NCCoE used commercially available or open source tools to help configure and deploy wireless infusion pumps. According to O’Brien, “The ultimate goal is to implement a defense-in-depth strategy to reduce the risks.”

O’Brien said that he is confident the guide will provide valuable insights healthcare delivery organizations need to better secure their wireless infusion pump ecosystems. And, he explained, capabilities demonstrated by the NCCoE may also apply to other medical devices on wireless networks as well.

Get the latest information on Cybersecurity and attend other valuable sessions at this two-day Summit providing healthcare leaders with educational content, insightful debate and dialogue on the future of healthcare and technology.

Learn More

Topics

News

Survey: By 2019, 60% of Medicare Revenues will be Tied to Risk

Medical groups and health systems that are members of AMGA (the American Medical Group Association) expect that nearly 60 percent of their revenues from Medicare will be from risk-based products by 2019, according to the results from a recent survey.

83% of Physicians Have Experienced a Cyber Attack, Survey Finds

Eighty-three percent of physicians in a recent survey said that they have experienced some sort of cyber attack, such as phishing and viruses.

Community Data Sharing: Eight Recommendations From San Diego

A learning guide focuses on San Diego’s experience in building a community health information exchange and the realities of embarking on a broad community collaboration to achieve better data sharing.

HealthlinkNY’s Galanis to Step Down as CEO

Christina Galanis, who has served as president and CEO of HealthlinkNY for the past 13 years, will leave her position at the end of the year.

Email-Related Cyber Attacks a Top Concern for Providers

U.S. healthcare providers overwhelmingly rank email as the top source of a potential data breach, according to new research from email and data security company Mimecast and conducted by HIMSS Analytics.

Former Health IT Head in San Diego County Charged with Defrauding Provider out of $800K

The ex-health IT director at North County Health Services, a San Diego County-based healthcare service provider, has been charged with spearheading fraudulent operations that cost the organization $800,000.