Security and Privacy Qualities of Medical Devices: An Analysis of FDA Postmarket Surveillance

被引:34
|
作者
Kramer, Daniel B. [1 ]
Baker, Matthew [1 ]
Ransford, Benjamin [2 ]
Molina-Markham, Andres [2 ]
Stewart, Quinn [2 ]
Fu, Kevin [2 ]
Reynolds, Matthew R. [1 ]
机构
[1] Harvard Univ, Beth Israel Deaconess Med Ctr, Dept Med, Sch Med, Boston, MA 02215 USA
[2] Univ Massachusetts, Dept Comp Sci, Amherst, MA 01003 USA
来源
PLOS ONE | 2012年 / 7卷 / 07期
基金
美国国家科学基金会;
关键词
DEFIBRILLATORS; RECALLS;
D O I
10.1371/journal.pone.0040200
中图分类号
O [数理科学和化学]; P [天文学、地球科学]; Q [生物科学]; N [自然科学总论];
学科分类号
07 ; 0710 ; 09 ;
摘要
Background: Medical devices increasingly depend on computing functions such as wireless communication and Internet connectivity for software-based control of therapies and network-based transmission of patients' stored medical information. These computing capabilities introduce security and privacy risks, yet little is known about the prevalence of such risks within the clinical setting. Methods: We used three comprehensive, publicly available databases maintained by the Food and Drug Administration (FDA) to evaluate recalls and adverse events related to security and privacy risks of medical devices. Results: Review of weekly enforcement reports identified 1,845 recalls; 605 (32.8%) of these included computers, 35 (1.9%) stored patient data, and 31 (1.7%) were capable of wireless communication. Searches of databases specific to recalls and adverse events identified only one event with a specific connection to security or privacy. Software-related recalls were relatively common, and most (81.8%) mentioned the possibility of upgrades, though only half of these provided specific instructions for the update mechanism. Conclusions: Our review of recalls and adverse events from federal government databases reveals sharp inconsistencies with databases at individual providers with respect to security and privacy risks. Recalls related to software may increase security risks because of unprotected update and correction mechanisms. To detect signals of security and privacy problems that adversely affect public health, federal postmarket surveillance strategies should rethink how to effectively and efficiently collect data on security and privacy problems in devices that increasingly depend on computing systems susceptible to malware.
引用
收藏
页数:7
相关论文
共 50 条
  • [31] SoK: Security and Privacy in Implantable Medical Devices and Body Area Networks
    Rushanan, Michael
    Rubin, Avid D.
    Kune, Denis Foo
    Swanson, Colleen M.
    [J]. 2014 IEEE SYMPOSIUM ON SECURITY AND PRIVACY (SP 2014), 2014, : 524 - 539
  • [32] Oversight Overhaul: Eliminating the Premarket Review of Medical Devices and Implementing a Provider-Centered Postmarket Surveillance Strategy
    Scott, Bonnie
    [J]. FOOD AND DRUG LAW JOURNAL, 2011, 66 (03) : 377 - 404
  • [33] NFC devices: Security and privacy
    Madlmayr, Gerald
    Langer, Josef
    Kantner, Christian
    Scharinger, Josef
    [J]. ARES 2008: PROCEEDINGS OF THE THIRD INTERNATIONAL CONFERENCE ON AVAILABILITY, SECURITY AND RELIABILITY, 2008, : 642 - +
  • [34] FDA NOT SCRUTINIZING MEDICAL DEVICES
    不详
    [J]. CHEMICAL & ENGINEERING NEWS, 2009, 87 (04) : 24 - 24
  • [35] Ensure Privacy and Security in the Process of Medical Image Analysis
    Gomathisankaran, Mahadevan
    Yuan, Xiaohui
    Kamongi, Patrick
    [J]. 2013 IEEE INTERNATIONAL CONFERENCE ON GRANULAR COMPUTING (GRC), 2013, : 120 - 125
  • [36] Postmarket Surveillance of Point-of-Care Glucose Meters through Analysis of Electronic Medical Records
    Schroeder, Lee F.
    Giacherio, Don
    Gianchandani, Roma
    Engoren, Milo
    Shah, Nigam H.
    [J]. CLINICAL CHEMISTRY, 2016, 62 (05) : 716 - 724
  • [37] Active Surveillance of Postmarket Medical Product Safety in the Federal Partners' Collaboration
    Robb, Melissa A.
    Racoosin, Judith A.
    Worrall, Chris
    Chapman, Summer
    Coster, Trinka
    Cunningham, Francesca E.
    [J]. MEDICAL CARE, 2012, 50 (11) : 948 - 953
  • [38] Communications Surveillance: Privacy and Security at Risk
    Diffie, Whitfield
    Landau, Susan
    [J]. COMMUNICATIONS OF THE ACM, 2009, 52 (11) : 42 - 47
  • [39] Surveillance, Privacy, and Security: Citizens' Perspectives
    Walby, Kevin
    [J]. SECURITY JOURNAL, 2018, 31 (04) : 929 - 930
  • [40] Security and Privacy Analysis of Youth-Oriented Connected Devices
    Solera-Cotanilla, Sonia
    Vega-Barbas, Mario
    Perez, Jaime
    Lopez, Gregorio
    Matanza, Javier
    Alvarez-Campana, Manuel
    [J]. SENSORS, 2022, 22 (11)