196
Internet of Things (IoT)
records appeared for sale on a darknet peer-to-peer marketplace. Frauds that merit a mention are: potential access and theft of over 2.2 million patient data files from the cancer
treatment supplier, 21st Century Oncology; over 600,000 patient ePHI records compromised through stolen laptops; and an estimated 265,000 patient records illegally hacked
via malware at Bizmatics, the electronic medical records management company. Up to 2016,
142 health care breaches were reported at the Department of Health and Human Services.
Similarly, in 2015, 143 health care records were stolen (Anonymous 2016e; Maia et al. 2014).
10.3.1 Various Security Incidents Occurred in the Wireless Medical Devices
Wireless medical device usage in hospitals and other medical application areas have
become common place. In this digital era, medical devices and RFID tags connected with
Internet escalate new security vulnerabilities. In this section, we discuss the various incidents that have occurred with wireless medical devices in recent times. In the United
States of America, there was a recommendation from Food and Drug Administration
(FDA) (Alexandra 2015) that medical device manufacturers and health care facilities
should ensure security against different kinds of attacks. The major reason behind these
recommendations is the security vulnerability presented when using insulin pumps in the
medical field. Insulin pumps are used to control and monitor the insulin level in patients.
In order to operate the insulin pump, the doctor uses wireless devices like smart phone,
smart watches, and personal digital assistant (PDAs). In case, an attacker observed the
serial number of an insulin pump, then it is possible that the attacker can hack the control
of the device from a few feet away. This scenario becomes worse when these kinds of
devices are connected to the Internet. A few years back, Barnaby Jack a security researcher
from McAfee (Dan 2011) hacked Medtronic insulin pumps on 25 October 2011 using a special software and antenna designed by Jack. This permitted him to find and seize overall
control of any device around 300 feet of the antenna without knowing the serial number.
In this context, the FDA has been working closely with other government organizations
and device manufacturers to mitigate vulnerabilities and incidents. These incidents help
create awareness in the secure usage of medical devices. In the next section, recent case
studies are discussed.
Hackers are targeting the health care industry, especially when compared with the
industrial, banking, and retail sectors. In health care, investing for security is negligible,
and as the value of individual protected health information in the black market continues
to increase, even the largest companies in the health care industry have become a victim to
medical data breaches. The following case studies are examples of security data breaches
in the health care industry, as a consequence of which millions of private records have
been compromised (Anonymous 2016e; Rodika 2015).
Table 10.2 shows the recent health care data breaches that occurred in the United States;
these breaches highlight the importance of ensuring the security of medical device usage in
health care IoT. In the next section, different technologies used for security IoT are discussed.
10.4 Technology Used for Securing IoT
Simulation is a cost-sparing technique for creating and overseeing system network. Before
deploying into the real world, users can recognize the basic performance of network protocols,
Précédent

- 221/358

Suivant