SlideShare a Scribd company logo
IoT for healthcare industry
Alessandro Sappia
Ordine degli Ingegneri della Provincia di Torino
Via Giolitti, 1
10123 Torino
TEL: 011 562.24.68
PEC: ordine.torino@ingpec.eu
ordine.ingegneri@ording.torino.it
Visit us on the web:
www.ording.torino.it/professione
IoT
• IoT is a combination of hardware and software
technology that produces date through connecting
multiple devices and sensors with the cloud and making
sense of data with intelligent tools.
What is Iot?
• IoT involves extending Internet connectivity beyond
standard devices, such as laptops, smartphones and
tablets, to any range of traditionally dumb or non-internet
enabled physical devices and everyday objects.
• These devices can communicate and interact over the
internet and they can be remotely monitored and
controlled.
How does it work?
Benefits of IoT in healthcare
• Improve diagnosis and treatment.
• The ability to carry out remote monitoring .
• Reducing operating costs to counteract the rising cost of care.
IoT for Health Landscape
Glucose meter
App Tracking Food
Calories
Telemedicine
Infusion Pump in
Hospital
Digital Health
Smart Weight Scale
Connected Defibrillator
implant
Connected Blood
Pressure Monitor
Connecter MRI
Connected Hospital
Monitors
Connected Hearing Aid
Wearable tracker
IoT Healthcare
The IoT for health sits within the
broader field of digital health.
Digital health is the merging of
digital technologies with health and
care. The US FDA includes mobile
health (mHealth), health
information technology (IT),
wearable devices, telehealth,
telemedicine, and personal
medicine in this broad category.
For instance, mHealth may include
health services ‘supported by
mobile devices, such as mobile
phones, patient monitoring devices,
personal digital assistants (PDAs),
and other wireless devices’.
Security principles
A modest approach to security focuses on the following three key principles:
• Confidentiality
• Integrity
• Availability
ensuring information and systems are protected from unauthorised access
ensuring that information and systems are unaltered and accurate
throughout the lifecycle. For instance, information integrity applies to data
collection, transfer, use and storage
ensuring that information is and services are accessible by users or systems
as and when needed
What about the risks?
Date
Disclosed
Device Type
(Manufacturer)
Vulnerability Potential Impact On
Security
19 May 2008 Implantable Defibrillator
(Medtronic)
Remote access Direct impact on the safety
of the device for the user
• Hackers remotely
accessed a heart
defibrillator and
pacemaker
• Hackers shut down the
device
• Hackers made device
deliver electric jolts
What about the risks?
Date
Disclosed
Device Type
(Manufacturer)
Vulnerability Potential Impact On
Security
13 June 2013 Medical Devices (multiple) Hard-Coded Passwords Increased vulnerability to
attacks such as command
and control or malware
• Inability of
users/owners to change
passwords manually
• Potential for “mass
hack” of devices with
same or similar
passwords
• Use of connected
environments for
downstream attacks
What about the risks?
Date
Disclosed
Device Type
(Manufacturer)
Vulnerability Potential Impact On
Security
10 June 2015 Patient-Controlled Infusion
System
(Hospira LifeCare)
Connected Devices and
Systems
Direct impact on
downstream security and
safety of the device for the
user
• Vulnerability allowed
hackers to remotely
command and control
• Exploitation could
impact delivery of
medication via the
bloodstream
What about the risks?
Date
Disclosed
Device Type
(Manufacturer)
Vulnerability Potential Impact On
Security
08 July 2018 Fitness Tracker Data API
(Polar)
Personal Data Collection Direct impact on user
privacy and data
protection as a result of
non-medical uses
• Access user location
data
• Identify names and
addresses of users
• Identify military
personnel and
locations
Architecture Use Cases
• Fixed Use Case: Connected MRI scanner
• Portable Local Use Case: Hospital Vital Signs Monitor
• Portable Loaned Use Case: Blood Pressure Monitor
• Personal Device Use Case: Wireless Connected Hearing Aid
Connected MRI Scanner
Image
Storage
(Archive)
External
Doctor
System
Request for
scan
Hospital
Information
system
Radiology
Information System
MRI
Scanner
External
cloud backup
System
Patients ID orders
for examination
Diagnosis
Reports &
Images
Legend :
Internal Data Flows External recipient of Data
External Data Flows Device
Systems and / or Data Process of Management
Repository points Interface
The fixed use case example centres on a connected
MRI scanner, a type of connected diagnostic
equipment, to demonstrate the risks and security
considerations for connected health devices.
There are several reasons for wanting to add
network connectivity to devices like MRI scanners,
such as image transfer and storage, remote control
and management, consumable monitoring, and
capacity planning.
For this use case the MRI scanner is considered a permanent fixed
installation that is part of a larger healthcare facility, such as a general
hospital. Such a facility is likely to have its own intranet, but physical
protection of the local area network (LAN) might be poor as many visitors
would have access to the building. Additionally, networks such as intranets
should be configured in a way to protect devices with a variety of security
capabilities, such as legacy devices, from incoming threats such as
malware.
Vital Signal monitor
Legend :
Internal Data Flows External recipient of Data
External Data Flows Device
Systems and / or Data Process of Management
Repository points Interface
Nurse Alert
System
Portable
Monitor
Hospital
Information
System
Patient
Information
System
External
Doctor
System
External
Cloud Backup
Archive
Doctor
Information
System
Patient
Information
Request
Device
Configuration
Wired or
Wireless
Connection Periodic
Patient
Information
This use case focuses on monitors that may be
ported with the patient within the health service
environment.
With modern technology, there are several
reasons for wanting to use a portable vital signs
monitor, such as automatic data upload, settings
configuration, time synchronisation and firmware
update.
It is assumed that portable monitors will be owned by the healthcare provider
and generally remain within the vicinity of the healthcare facility. No
assumptions related to connectivity technologies are made. This is because
devices may connect using a variety of network technologies, or via a local IP-
based LAN. As such, no detailed assumptions are made about the
environment in which the portable monitor functions other than the
healthcare environment adopts network and information security best
practices.
Blood Pressure Monitor
Legend :
Internal Data Flows External recipient of Data
External Data Flows Device
Systems and / or Data Process of Management
Repository points Interface
Remote
configuration
Patient
informtion &
device
management
Portable
Pressure
Monitor
Hospital
Information
System
Patient
Information
System
External
Doctor
System
External
Cloud Backup
Archive
Doctor
Information
System
Remote
Information
request
Initial device
configuration
Wired or
Wireless
Connection Periodic
Patient
Information
In-home
Nurse user
interface
Patient/
User interface
Controlled
user interface
Loaned portable devices can be conceptualised
as owned by the healthcare provider but used
by the patient. Devices are not constrained to
one dedicated environment and may be ported
with the patient to a single remote location or
be as mobile as the patient. Given the nature of
the device and its integration into the patient’s
daily life, the patient is likely to have more
control over and engagement with this type of
IoT device.
No assumptions are made about the environment in which the loaned device
functions.
Wireless connected Hearing Aid
Hospital
Information
System
Patient
Information
System
External
Doctor
System
External
CloudBackup
Archive
Doctor
Information
System
Hearing
Aid
Pushed
Patient
Information
Legend :
Internal Data Flows External recipient of Data
External Data Flows Device
Systems and / or Data
Repository points
Hearing aids are a common personal medical device, and there
has been a continuing trend of miniaturisation to improve
comfort and aesthetics. Modern in-canal hearing aids can be
effectively invisible in normal use. Their very small size means
that it is impractical to have volume controls on the hearing aid
itself. As a connected digital device that is always worn, there is
an inclination to converge functionality with other portable
electronic devices, such as syncing with smartphones or music
and games consoles.
Due to the small size of some connected health devices they exist in an
extremely constrained environment and therefore may require different
security considerations than larger connected health devices with more
computing capacity. From the constrained environment and drive to make
IoT solutions tailored and user-friendly, it is assumed the hearing aid or
similar devices will connect to another mobile device or a personal and/or
health-professional’s computer.
Reference Architecture
• Has a defined boundary between
network zones.
Bounded
• Has no defined organizational
intranet or security mechanisms.
Boundaryless
• Include a variety of network
technologies and topologies
including bounded and
boundaryless networks.
Hybrid
Bounded Network architecture
Legend :
Internal Data Flows External recipient of Data
External Data Flows Device
Systems and / or Data Process of Management
Repository points Interface
internet Network Name Network Boundary
Security Management Point
Sensitive
data
Workstations
High Integrity
zone
Standard
Intranet
Internet
Critical
Equipment
Trusted
Server
Internal
Gateway
External
Gateway
Boundaryless Environment Mapping
Nurse
Mobile Device
Configuration
App
Health
Information
System
Time
Server
Sensors
Laptop or
USB Stick
Barcode
Scanner
Vital Sign
Monitor
Blood Pressure
Temperature
Sp O2 Pulse
Patient ID
Configuration
Firmware Update
Public
Internet
Local Hospital
Network
Local
Wired
Connections
Legend :
Internal Data Flows External recipient of Data
External Data Flows Device
Systems and / or Data Process of Management
Repository points Interface
internet Network Name Network Boundary
Security Management Point
Hybrid IoT Environment Mapping
Hearing
Aid
Audio
Streamer
Hearing
Aid App
Audio
Source
Body Area
Network
(NFMI)
Audio
playback
Personal Area
Network
(Bluetooth)
Smart
Phone
Public
Internet
(WI-FI)
Hospital
Information
System
Visitor
Information
System
Local
Hospital
network
Legend :
Internal Data Flows External recipient of Data
External Data Flows Device
Systems and / or Data Process of Management
Repository points Interface
internet Network Name Network Boundary
Security Management Point
Time for Questions
THANK
YOU…
Alessandro Sappia
Copyright, Trade Marks and Licensing
All product names are trademarks, registered trademarks, or service
marks of their respective owners.
Copyright © 2019, IoTSF. All rights reserved.
Copyright © 2021, Alessandro Sappia. All rights reserved.
This work is licensed under the Creative Commons Attribution 4.0
International License.
Presentation based on «IoT Security Reference Architecture for the
Healthcare Industry»
https://www.iotsecurityfoundation.org/best-practice-guidelines/
Ordine degli Ingegneri della Provincia di Torino
Via Giolitti, 1
10123 Torino
TEL: 011 562.24.68
PEC: ordine.torino@ingpec.eu
ordine.ingegneri@ording.torino.it
Visit us on the web:
www.ording.torino.it/professione

More Related Content

What's hot

IoT in Healthcare
IoT in HealthcareIoT in Healthcare
IoT in Healthcare
Vish Anantraman
 
Medical Device Security: State of the Art -- NoConName, Barcelona, 2011
Medical Device Security:  State of the Art -- NoConName, Barcelona, 2011 Medical Device Security:  State of the Art -- NoConName, Barcelona, 2011
Medical Device Security: State of the Art -- NoConName, Barcelona, 2011
shawn_merdinger
 
IoT potential in Asia Healthcare System_i4
IoT potential in Asia Healthcare System_i4IoT potential in Asia Healthcare System_i4
IoT potential in Asia Healthcare System_i4Guna Sekaran
 
اینترنت اشیاء در حوزه سلامت
اینترنت  اشیاء در حوزه سلامت اینترنت  اشیاء در حوزه سلامت
اینترنت اشیاء در حوزه سلامت
Mahmood Khosravi
 
IoT as enabler(future) of Smart Hospital Technology
IoT as enabler(future) of Smart Hospital TechnologyIoT as enabler(future) of Smart Hospital Technology
IoT as enabler(future) of Smart Hospital TechnologyVolodymyr Nazarenko
 
PreScouter Internet of Medical Things: Industry Roundtable Webinar
PreScouter Internet of Medical Things: Industry Roundtable WebinarPreScouter Internet of Medical Things: Industry Roundtable Webinar
PreScouter Internet of Medical Things: Industry Roundtable Webinar
PreScouter
 
Connected Medical Devices in the Internet of Things
Connected Medical Devices in the Internet of ThingsConnected Medical Devices in the Internet of Things
Connected Medical Devices in the Internet of Things
Real-Time Innovations (RTI)
 
Iot healthcare
Iot healthcareIot healthcare
Iot healthcare
Satyajit Roy
 
OnDemand Webinar: Key Considerations to Securing the Internet of Things (IoT)...
OnDemand Webinar: Key Considerations to Securing the Internet of Things (IoT)...OnDemand Webinar: Key Considerations to Securing the Internet of Things (IoT)...
OnDemand Webinar: Key Considerations to Securing the Internet of Things (IoT)...
Great Bay Software
 
Digital transformation and application of iot to healthcare
Digital transformation and application of iot to healthcareDigital transformation and application of iot to healthcare
Digital transformation and application of iot to healthcare
sandhibhide
 
The internet of things for health care a comprehensive survey
The internet of things for health care a comprehensive surveyThe internet of things for health care a comprehensive survey
The internet of things for health care a comprehensive survey
redpel dot com
 
Big Data, CEP and IoT : Redefining Healthcare Information Systems and Analytics
Big Data, CEP and IoT : Redefining Healthcare Information Systems and AnalyticsBig Data, CEP and IoT : Redefining Healthcare Information Systems and Analytics
Big Data, CEP and IoT : Redefining Healthcare Information Systems and Analytics
Tauseef Naquishbandi
 
MongoDB IoT City Tour EINDHOVEN: IoT in Healthcare: by, Microsoft & Barco
MongoDB IoT City Tour EINDHOVEN: IoT in Healthcare: by, Microsoft & BarcoMongoDB IoT City Tour EINDHOVEN: IoT in Healthcare: by, Microsoft & Barco
MongoDB IoT City Tour EINDHOVEN: IoT in Healthcare: by, Microsoft & Barco
MongoDB
 
Acus intel medical_devices
Acus intel medical_devicesAcus intel medical_devices
Acus intel medical_devicesatlanticcouncil
 
The Service Revolution and the Transformation of Marketing Science
The Service Revolution and the Transformation of Marketing ScienceThe Service Revolution and the Transformation of Marketing Science
The Service Revolution and the Transformation of Marketing Science
Mohamadreza Mashouf
 
IoT Healthcare/Medical Devices Insights from Patents
IoT Healthcare/Medical Devices Insights from PatentsIoT Healthcare/Medical Devices Insights from Patents
IoT Healthcare/Medical Devices Insights from Patents
Alex G. Lee, Ph.D. Esq. CLP
 
THE FDA and Medical Device Cybersecurity Guidance
THE FDA and Medical Device Cybersecurity GuidanceTHE FDA and Medical Device Cybersecurity Guidance
THE FDA and Medical Device Cybersecurity GuidancePam Gilmore
 
A MODERN HEALTH CARE SYSTEM USING IOT AND ANDROID
A MODERN HEALTH CARE SYSTEM USING IOT AND ANDROIDA MODERN HEALTH CARE SYSTEM USING IOT AND ANDROID
A MODERN HEALTH CARE SYSTEM USING IOT AND ANDROID
Journal For Research
 
IOT in healthcare
IOT in healthcareIOT in healthcare
IOT in healthcare
Midhun Abraham
 
Understanding Cybersecurity in Medical Devices and Applications
Understanding Cybersecurity in Medical Devices and ApplicationsUnderstanding Cybersecurity in Medical Devices and Applications
Understanding Cybersecurity in Medical Devices and Applications
EMMAIntl
 

What's hot (20)

IoT in Healthcare
IoT in HealthcareIoT in Healthcare
IoT in Healthcare
 
Medical Device Security: State of the Art -- NoConName, Barcelona, 2011
Medical Device Security:  State of the Art -- NoConName, Barcelona, 2011 Medical Device Security:  State of the Art -- NoConName, Barcelona, 2011
Medical Device Security: State of the Art -- NoConName, Barcelona, 2011
 
IoT potential in Asia Healthcare System_i4
IoT potential in Asia Healthcare System_i4IoT potential in Asia Healthcare System_i4
IoT potential in Asia Healthcare System_i4
 
اینترنت اشیاء در حوزه سلامت
اینترنت  اشیاء در حوزه سلامت اینترنت  اشیاء در حوزه سلامت
اینترنت اشیاء در حوزه سلامت
 
IoT as enabler(future) of Smart Hospital Technology
IoT as enabler(future) of Smart Hospital TechnologyIoT as enabler(future) of Smart Hospital Technology
IoT as enabler(future) of Smart Hospital Technology
 
PreScouter Internet of Medical Things: Industry Roundtable Webinar
PreScouter Internet of Medical Things: Industry Roundtable WebinarPreScouter Internet of Medical Things: Industry Roundtable Webinar
PreScouter Internet of Medical Things: Industry Roundtable Webinar
 
Connected Medical Devices in the Internet of Things
Connected Medical Devices in the Internet of ThingsConnected Medical Devices in the Internet of Things
Connected Medical Devices in the Internet of Things
 
Iot healthcare
Iot healthcareIot healthcare
Iot healthcare
 
OnDemand Webinar: Key Considerations to Securing the Internet of Things (IoT)...
OnDemand Webinar: Key Considerations to Securing the Internet of Things (IoT)...OnDemand Webinar: Key Considerations to Securing the Internet of Things (IoT)...
OnDemand Webinar: Key Considerations to Securing the Internet of Things (IoT)...
 
Digital transformation and application of iot to healthcare
Digital transformation and application of iot to healthcareDigital transformation and application of iot to healthcare
Digital transformation and application of iot to healthcare
 
The internet of things for health care a comprehensive survey
The internet of things for health care a comprehensive surveyThe internet of things for health care a comprehensive survey
The internet of things for health care a comprehensive survey
 
Big Data, CEP and IoT : Redefining Healthcare Information Systems and Analytics
Big Data, CEP and IoT : Redefining Healthcare Information Systems and AnalyticsBig Data, CEP and IoT : Redefining Healthcare Information Systems and Analytics
Big Data, CEP and IoT : Redefining Healthcare Information Systems and Analytics
 
MongoDB IoT City Tour EINDHOVEN: IoT in Healthcare: by, Microsoft & Barco
MongoDB IoT City Tour EINDHOVEN: IoT in Healthcare: by, Microsoft & BarcoMongoDB IoT City Tour EINDHOVEN: IoT in Healthcare: by, Microsoft & Barco
MongoDB IoT City Tour EINDHOVEN: IoT in Healthcare: by, Microsoft & Barco
 
Acus intel medical_devices
Acus intel medical_devicesAcus intel medical_devices
Acus intel medical_devices
 
The Service Revolution and the Transformation of Marketing Science
The Service Revolution and the Transformation of Marketing ScienceThe Service Revolution and the Transformation of Marketing Science
The Service Revolution and the Transformation of Marketing Science
 
IoT Healthcare/Medical Devices Insights from Patents
IoT Healthcare/Medical Devices Insights from PatentsIoT Healthcare/Medical Devices Insights from Patents
IoT Healthcare/Medical Devices Insights from Patents
 
THE FDA and Medical Device Cybersecurity Guidance
THE FDA and Medical Device Cybersecurity GuidanceTHE FDA and Medical Device Cybersecurity Guidance
THE FDA and Medical Device Cybersecurity Guidance
 
A MODERN HEALTH CARE SYSTEM USING IOT AND ANDROID
A MODERN HEALTH CARE SYSTEM USING IOT AND ANDROIDA MODERN HEALTH CARE SYSTEM USING IOT AND ANDROID
A MODERN HEALTH CARE SYSTEM USING IOT AND ANDROID
 
IOT in healthcare
IOT in healthcareIOT in healthcare
IOT in healthcare
 
Understanding Cybersecurity in Medical Devices and Applications
Understanding Cybersecurity in Medical Devices and ApplicationsUnderstanding Cybersecurity in Medical Devices and Applications
Understanding Cybersecurity in Medical Devices and Applications
 

Similar to connected Medical devices IoT Cybersecurity reference architecture Telemedicine

REMOTE MONITORING- A RECENT ADVANCE.pptx
REMOTE MONITORING- A RECENT ADVANCE.pptxREMOTE MONITORING- A RECENT ADVANCE.pptx
REMOTE MONITORING- A RECENT ADVANCE.pptx
Dr. Ravikiran H M Gowda
 
Fast and fire-walled IOT healthcare-Baseer
Fast and fire-walled  IOT healthcare-BaseerFast and fire-walled  IOT healthcare-Baseer
Fast and fire-walled IOT healthcare-Baseer
AbdulBaseer (Baseer) Mohammed
 
Presentation about IoT in media and communication.pdf
Presentation about IoT in media and communication.pdfPresentation about IoT in media and communication.pdf
Presentation about IoT in media and communication.pdf
ezzAyman1
 
IRJET - IoT based Health Monitoring System and Telemedicine
IRJET - IoT based Health Monitoring System and TelemedicineIRJET - IoT based Health Monitoring System and Telemedicine
IRJET - IoT based Health Monitoring System and Telemedicine
IRJET Journal
 
icu patient smart monitoring system using iot
icu patient smart monitoring system using ioticu patient smart monitoring system using iot
icu patient smart monitoring system using iot
renjithnatraj96
 
IRJET- Virtual Assistant for Medical Emergency
IRJET-  	  Virtual Assistant for Medical EmergencyIRJET-  	  Virtual Assistant for Medical Emergency
IRJET- Virtual Assistant for Medical Emergency
IRJET Journal
 
Medical Security [EN] .pdf
Medical       Security      [EN]    .pdfMedical       Security      [EN]    .pdf
Medical Security [EN] .pdf
Snarky Security
 
Medical & Healthcare IoT M2M Solutions
Medical & Healthcare IoT M2M SolutionsMedical & Healthcare IoT M2M Solutions
Medical & Healthcare IoT M2M Solutions
Eurotech
 
EXTEMPORIZING HEALTHCARE USING SMART FABRIC
EXTEMPORIZING HEALTHCARE USING SMART FABRICEXTEMPORIZING HEALTHCARE USING SMART FABRIC
EXTEMPORIZING HEALTHCARE USING SMART FABRIC
AM Publications,India
 
The Internet Of Things UOP
The Internet Of Things UOPThe Internet Of Things UOP
The Internet Of Things UOP
Ahmad Atef Al-Shoubaki
 
IRJET- Remote HRV Monitoring System for Hypertensive Patients using IoT
IRJET- Remote HRV Monitoring System for Hypertensive Patients using IoTIRJET- Remote HRV Monitoring System for Hypertensive Patients using IoT
IRJET- Remote HRV Monitoring System for Hypertensive Patients using IoT
IRJET Journal
 
Embedded systems in biomedical applications
Embedded systems in biomedical applicationsEmbedded systems in biomedical applications
Embedded systems in biomedical applications
Seminar Links
 
IRJET - IoT based Asset Tracking System
IRJET - IoT based Asset Tracking SystemIRJET - IoT based Asset Tracking System
IRJET - IoT based Asset Tracking System
IRJET Journal
 
IRJET- Hiding Sensitive Medical Data using Encryption
IRJET- Hiding Sensitive Medical Data using EncryptionIRJET- Hiding Sensitive Medical Data using Encryption
IRJET- Hiding Sensitive Medical Data using Encryption
IRJET Journal
 
Future Internet of IoT- A Survey of Healthcare Internet of Things (HIoT) : A ...
Future Internet of IoT- A Survey of Healthcare Internet of Things (HIoT) : A ...Future Internet of IoT- A Survey of Healthcare Internet of Things (HIoT) : A ...
Future Internet of IoT- A Survey of Healthcare Internet of Things (HIoT) : A ...
M Shamim Iqbal
 
Security Requirements, Counterattacks and Projects in Healthcare Applications...
Security Requirements, Counterattacks and Projects in Healthcare Applications...Security Requirements, Counterattacks and Projects in Healthcare Applications...
Security Requirements, Counterattacks and Projects in Healthcare Applications...
arpublication
 
Android Based Patient Health Monitoring System
Android Based Patient Health Monitoring SystemAndroid Based Patient Health Monitoring System
Android Based Patient Health Monitoring System
IRJET Journal
 
IEC 80001 and Planning for Wi-Fi Capable Medical Devices
IEC 80001 and Planning for Wi-Fi Capable Medical DevicesIEC 80001 and Planning for Wi-Fi Capable Medical Devices
IEC 80001 and Planning for Wi-Fi Capable Medical DevicesAli Youssef
 
ealth Monitoring System in Emergency Using IoT: A Review
ealth Monitoring System in Emergency Using IoT: A Reviewealth Monitoring System in Emergency Using IoT: A Review
ealth Monitoring System in Emergency Using IoT: A Review
IRJET Journal
 
A review of security protocols in m health wireless body area networks (wban)...
A review of security protocols in m health wireless body area networks (wban)...A review of security protocols in m health wireless body area networks (wban)...
A review of security protocols in m health wireless body area networks (wban)...
James Kang
 

Similar to connected Medical devices IoT Cybersecurity reference architecture Telemedicine (20)

REMOTE MONITORING- A RECENT ADVANCE.pptx
REMOTE MONITORING- A RECENT ADVANCE.pptxREMOTE MONITORING- A RECENT ADVANCE.pptx
REMOTE MONITORING- A RECENT ADVANCE.pptx
 
Fast and fire-walled IOT healthcare-Baseer
Fast and fire-walled  IOT healthcare-BaseerFast and fire-walled  IOT healthcare-Baseer
Fast and fire-walled IOT healthcare-Baseer
 
Presentation about IoT in media and communication.pdf
Presentation about IoT in media and communication.pdfPresentation about IoT in media and communication.pdf
Presentation about IoT in media and communication.pdf
 
IRJET - IoT based Health Monitoring System and Telemedicine
IRJET - IoT based Health Monitoring System and TelemedicineIRJET - IoT based Health Monitoring System and Telemedicine
IRJET - IoT based Health Monitoring System and Telemedicine
 
icu patient smart monitoring system using iot
icu patient smart monitoring system using ioticu patient smart monitoring system using iot
icu patient smart monitoring system using iot
 
IRJET- Virtual Assistant for Medical Emergency
IRJET-  	  Virtual Assistant for Medical EmergencyIRJET-  	  Virtual Assistant for Medical Emergency
IRJET- Virtual Assistant for Medical Emergency
 
Medical Security [EN] .pdf
Medical       Security      [EN]    .pdfMedical       Security      [EN]    .pdf
Medical Security [EN] .pdf
 
Medical & Healthcare IoT M2M Solutions
Medical & Healthcare IoT M2M SolutionsMedical & Healthcare IoT M2M Solutions
Medical & Healthcare IoT M2M Solutions
 
EXTEMPORIZING HEALTHCARE USING SMART FABRIC
EXTEMPORIZING HEALTHCARE USING SMART FABRICEXTEMPORIZING HEALTHCARE USING SMART FABRIC
EXTEMPORIZING HEALTHCARE USING SMART FABRIC
 
The Internet Of Things UOP
The Internet Of Things UOPThe Internet Of Things UOP
The Internet Of Things UOP
 
IRJET- Remote HRV Monitoring System for Hypertensive Patients using IoT
IRJET- Remote HRV Monitoring System for Hypertensive Patients using IoTIRJET- Remote HRV Monitoring System for Hypertensive Patients using IoT
IRJET- Remote HRV Monitoring System for Hypertensive Patients using IoT
 
Embedded systems in biomedical applications
Embedded systems in biomedical applicationsEmbedded systems in biomedical applications
Embedded systems in biomedical applications
 
IRJET - IoT based Asset Tracking System
IRJET - IoT based Asset Tracking SystemIRJET - IoT based Asset Tracking System
IRJET - IoT based Asset Tracking System
 
IRJET- Hiding Sensitive Medical Data using Encryption
IRJET- Hiding Sensitive Medical Data using EncryptionIRJET- Hiding Sensitive Medical Data using Encryption
IRJET- Hiding Sensitive Medical Data using Encryption
 
Future Internet of IoT- A Survey of Healthcare Internet of Things (HIoT) : A ...
Future Internet of IoT- A Survey of Healthcare Internet of Things (HIoT) : A ...Future Internet of IoT- A Survey of Healthcare Internet of Things (HIoT) : A ...
Future Internet of IoT- A Survey of Healthcare Internet of Things (HIoT) : A ...
 
Security Requirements, Counterattacks and Projects in Healthcare Applications...
Security Requirements, Counterattacks and Projects in Healthcare Applications...Security Requirements, Counterattacks and Projects in Healthcare Applications...
Security Requirements, Counterattacks and Projects in Healthcare Applications...
 
Android Based Patient Health Monitoring System
Android Based Patient Health Monitoring SystemAndroid Based Patient Health Monitoring System
Android Based Patient Health Monitoring System
 
IEC 80001 and Planning for Wi-Fi Capable Medical Devices
IEC 80001 and Planning for Wi-Fi Capable Medical DevicesIEC 80001 and Planning for Wi-Fi Capable Medical Devices
IEC 80001 and Planning for Wi-Fi Capable Medical Devices
 
ealth Monitoring System in Emergency Using IoT: A Review
ealth Monitoring System in Emergency Using IoT: A Reviewealth Monitoring System in Emergency Using IoT: A Review
ealth Monitoring System in Emergency Using IoT: A Review
 
A review of security protocols in m health wireless body area networks (wban)...
A review of security protocols in m health wireless body area networks (wban)...A review of security protocols in m health wireless body area networks (wban)...
A review of security protocols in m health wireless body area networks (wban)...
 

Recently uploaded

ventilator, child on ventilator, newborn
ventilator, child on ventilator, newbornventilator, child on ventilator, newborn
ventilator, child on ventilator, newborn
Pooja Rani
 
Empowering ACOs: Leveraging Quality Management Tools for MIPS and Beyond
Empowering ACOs: Leveraging Quality Management Tools for MIPS and BeyondEmpowering ACOs: Leveraging Quality Management Tools for MIPS and Beyond
Empowering ACOs: Leveraging Quality Management Tools for MIPS and Beyond
Health Catalyst
 
ABDOMINAL COMPARTMENT SYSNDROME
ABDOMINAL COMPARTMENT SYSNDROMEABDOMINAL COMPARTMENT SYSNDROME
ABDOMINAL COMPARTMENT SYSNDROME
Rommel Luis III Israel
 
Yemen National Tuberculosis Program .ppt
Yemen National Tuberculosis Program .pptYemen National Tuberculosis Program .ppt
Yemen National Tuberculosis Program .ppt
Esam43
 
Navigating Challenges: Mental Health, Legislation, and the Prison System in B...
Navigating Challenges: Mental Health, Legislation, and the Prison System in B...Navigating Challenges: Mental Health, Legislation, and the Prison System in B...
Navigating Challenges: Mental Health, Legislation, and the Prison System in B...
Guillermo Rivera
 
Leading the Way in Nephrology: Dr. David Greene's Work with Stem Cells for Ki...
Leading the Way in Nephrology: Dr. David Greene's Work with Stem Cells for Ki...Leading the Way in Nephrology: Dr. David Greene's Work with Stem Cells for Ki...
Leading the Way in Nephrology: Dr. David Greene's Work with Stem Cells for Ki...
Dr. David Greene Arizona
 
Health Education on prevention of hypertension
Health Education on prevention of hypertensionHealth Education on prevention of hypertension
Health Education on prevention of hypertension
Radhika kulvi
 
Surgery-Mini-OSCE-All-Past-Years-Questions-Modified.
Surgery-Mini-OSCE-All-Past-Years-Questions-Modified.Surgery-Mini-OSCE-All-Past-Years-Questions-Modified.
Surgery-Mini-OSCE-All-Past-Years-Questions-Modified.
preciousstephanie75
 
Roti bank chennai PPT [Autosaved].pptx1
Roti bank  chennai PPT [Autosaved].pptx1Roti bank  chennai PPT [Autosaved].pptx1
Roti bank chennai PPT [Autosaved].pptx1
roti bank
 
How many patients does case series should have In comparison to case reports.pdf
How many patients does case series should have In comparison to case reports.pdfHow many patients does case series should have In comparison to case reports.pdf
How many patients does case series should have In comparison to case reports.pdf
pubrica101
 
GLOBAL WARMING BY PRIYA BHOJWANI @..pptx
GLOBAL WARMING BY PRIYA BHOJWANI @..pptxGLOBAL WARMING BY PRIYA BHOJWANI @..pptx
GLOBAL WARMING BY PRIYA BHOJWANI @..pptx
priyabhojwani1200
 
Navigating Women's Health: Understanding Prenatal Care and Beyond
Navigating Women's Health: Understanding Prenatal Care and BeyondNavigating Women's Health: Understanding Prenatal Care and Beyond
Navigating Women's Health: Understanding Prenatal Care and Beyond
Aboud Health Group
 
💘Ludhiana ℂall Girls 📞]][89011★83002][[ 📱 ❤ESCORTS service in Ludhiana💃💦Ludhi...
💘Ludhiana ℂall Girls 📞]][89011★83002][[ 📱 ❤ESCORTS service in Ludhiana💃💦Ludhi...💘Ludhiana ℂall Girls 📞]][89011★83002][[ 📱 ❤ESCORTS service in Ludhiana💃💦Ludhi...
💘Ludhiana ℂall Girls 📞]][89011★83002][[ 📱 ❤ESCORTS service in Ludhiana💃💦Ludhi...
ranishasharma67
 
Demystifying-Gene-Editing-The-Promise-and-Peril-of-CRISPR.pdf
Demystifying-Gene-Editing-The-Promise-and-Peril-of-CRISPR.pdfDemystifying-Gene-Editing-The-Promise-and-Peril-of-CRISPR.pdf
Demystifying-Gene-Editing-The-Promise-and-Peril-of-CRISPR.pdf
SasikiranMarri
 
R3 Stem Cells and Kidney Repair A New Horizon in Nephrology.pptx
R3 Stem Cells and Kidney Repair A New Horizon in Nephrology.pptxR3 Stem Cells and Kidney Repair A New Horizon in Nephrology.pptx
R3 Stem Cells and Kidney Repair A New Horizon in Nephrology.pptx
R3 Stem Cell
 
.Metabolic.disordersYYSSSFFSSSSSSSSSSDDD
.Metabolic.disordersYYSSSFFSSSSSSSSSSDDD.Metabolic.disordersYYSSSFFSSSSSSSSSSDDD
.Metabolic.disordersYYSSSFFSSSSSSSSSSDDD
samahesh1
 
A Community health , health for prisoners
A Community health  , health for prisonersA Community health  , health for prisoners
A Community health , health for prisoners
Ahmed Elmi
 
Neuro Saphirex Cranial Brochure
Neuro Saphirex Cranial BrochureNeuro Saphirex Cranial Brochure
Neuro Saphirex Cranial Brochure
RXOOM Healthcare Pvt. Ltd. ​
 
Dimensions of Healthcare Quality
Dimensions of Healthcare QualityDimensions of Healthcare Quality
Dimensions of Healthcare Quality
Naeemshahzad51
 
Antibiotic Stewardship by Anushri Srivastava.pptx
Antibiotic Stewardship by Anushri Srivastava.pptxAntibiotic Stewardship by Anushri Srivastava.pptx
Antibiotic Stewardship by Anushri Srivastava.pptx
AnushriSrivastav
 

Recently uploaded (20)

ventilator, child on ventilator, newborn
ventilator, child on ventilator, newbornventilator, child on ventilator, newborn
ventilator, child on ventilator, newborn
 
Empowering ACOs: Leveraging Quality Management Tools for MIPS and Beyond
Empowering ACOs: Leveraging Quality Management Tools for MIPS and BeyondEmpowering ACOs: Leveraging Quality Management Tools for MIPS and Beyond
Empowering ACOs: Leveraging Quality Management Tools for MIPS and Beyond
 
ABDOMINAL COMPARTMENT SYSNDROME
ABDOMINAL COMPARTMENT SYSNDROMEABDOMINAL COMPARTMENT SYSNDROME
ABDOMINAL COMPARTMENT SYSNDROME
 
Yemen National Tuberculosis Program .ppt
Yemen National Tuberculosis Program .pptYemen National Tuberculosis Program .ppt
Yemen National Tuberculosis Program .ppt
 
Navigating Challenges: Mental Health, Legislation, and the Prison System in B...
Navigating Challenges: Mental Health, Legislation, and the Prison System in B...Navigating Challenges: Mental Health, Legislation, and the Prison System in B...
Navigating Challenges: Mental Health, Legislation, and the Prison System in B...
 
Leading the Way in Nephrology: Dr. David Greene's Work with Stem Cells for Ki...
Leading the Way in Nephrology: Dr. David Greene's Work with Stem Cells for Ki...Leading the Way in Nephrology: Dr. David Greene's Work with Stem Cells for Ki...
Leading the Way in Nephrology: Dr. David Greene's Work with Stem Cells for Ki...
 
Health Education on prevention of hypertension
Health Education on prevention of hypertensionHealth Education on prevention of hypertension
Health Education on prevention of hypertension
 
Surgery-Mini-OSCE-All-Past-Years-Questions-Modified.
Surgery-Mini-OSCE-All-Past-Years-Questions-Modified.Surgery-Mini-OSCE-All-Past-Years-Questions-Modified.
Surgery-Mini-OSCE-All-Past-Years-Questions-Modified.
 
Roti bank chennai PPT [Autosaved].pptx1
Roti bank  chennai PPT [Autosaved].pptx1Roti bank  chennai PPT [Autosaved].pptx1
Roti bank chennai PPT [Autosaved].pptx1
 
How many patients does case series should have In comparison to case reports.pdf
How many patients does case series should have In comparison to case reports.pdfHow many patients does case series should have In comparison to case reports.pdf
How many patients does case series should have In comparison to case reports.pdf
 
GLOBAL WARMING BY PRIYA BHOJWANI @..pptx
GLOBAL WARMING BY PRIYA BHOJWANI @..pptxGLOBAL WARMING BY PRIYA BHOJWANI @..pptx
GLOBAL WARMING BY PRIYA BHOJWANI @..pptx
 
Navigating Women's Health: Understanding Prenatal Care and Beyond
Navigating Women's Health: Understanding Prenatal Care and BeyondNavigating Women's Health: Understanding Prenatal Care and Beyond
Navigating Women's Health: Understanding Prenatal Care and Beyond
 
💘Ludhiana ℂall Girls 📞]][89011★83002][[ 📱 ❤ESCORTS service in Ludhiana💃💦Ludhi...
💘Ludhiana ℂall Girls 📞]][89011★83002][[ 📱 ❤ESCORTS service in Ludhiana💃💦Ludhi...💘Ludhiana ℂall Girls 📞]][89011★83002][[ 📱 ❤ESCORTS service in Ludhiana💃💦Ludhi...
💘Ludhiana ℂall Girls 📞]][89011★83002][[ 📱 ❤ESCORTS service in Ludhiana💃💦Ludhi...
 
Demystifying-Gene-Editing-The-Promise-and-Peril-of-CRISPR.pdf
Demystifying-Gene-Editing-The-Promise-and-Peril-of-CRISPR.pdfDemystifying-Gene-Editing-The-Promise-and-Peril-of-CRISPR.pdf
Demystifying-Gene-Editing-The-Promise-and-Peril-of-CRISPR.pdf
 
R3 Stem Cells and Kidney Repair A New Horizon in Nephrology.pptx
R3 Stem Cells and Kidney Repair A New Horizon in Nephrology.pptxR3 Stem Cells and Kidney Repair A New Horizon in Nephrology.pptx
R3 Stem Cells and Kidney Repair A New Horizon in Nephrology.pptx
 
.Metabolic.disordersYYSSSFFSSSSSSSSSSDDD
.Metabolic.disordersYYSSSFFSSSSSSSSSSDDD.Metabolic.disordersYYSSSFFSSSSSSSSSSDDD
.Metabolic.disordersYYSSSFFSSSSSSSSSSDDD
 
A Community health , health for prisoners
A Community health  , health for prisonersA Community health  , health for prisoners
A Community health , health for prisoners
 
Neuro Saphirex Cranial Brochure
Neuro Saphirex Cranial BrochureNeuro Saphirex Cranial Brochure
Neuro Saphirex Cranial Brochure
 
Dimensions of Healthcare Quality
Dimensions of Healthcare QualityDimensions of Healthcare Quality
Dimensions of Healthcare Quality
 
Antibiotic Stewardship by Anushri Srivastava.pptx
Antibiotic Stewardship by Anushri Srivastava.pptxAntibiotic Stewardship by Anushri Srivastava.pptx
Antibiotic Stewardship by Anushri Srivastava.pptx
 

connected Medical devices IoT Cybersecurity reference architecture Telemedicine

  • 1. IoT for healthcare industry Alessandro Sappia Ordine degli Ingegneri della Provincia di Torino Via Giolitti, 1 10123 Torino TEL: 011 562.24.68 PEC: ordine.torino@ingpec.eu ordine.ingegneri@ording.torino.it Visit us on the web: www.ording.torino.it/professione
  • 2. IoT • IoT is a combination of hardware and software technology that produces date through connecting multiple devices and sensors with the cloud and making sense of data with intelligent tools. What is Iot? • IoT involves extending Internet connectivity beyond standard devices, such as laptops, smartphones and tablets, to any range of traditionally dumb or non-internet enabled physical devices and everyday objects. • These devices can communicate and interact over the internet and they can be remotely monitored and controlled. How does it work? Benefits of IoT in healthcare • Improve diagnosis and treatment. • The ability to carry out remote monitoring . • Reducing operating costs to counteract the rising cost of care.
  • 3. IoT for Health Landscape Glucose meter App Tracking Food Calories Telemedicine Infusion Pump in Hospital Digital Health Smart Weight Scale Connected Defibrillator implant Connected Blood Pressure Monitor Connecter MRI Connected Hospital Monitors Connected Hearing Aid Wearable tracker IoT Healthcare The IoT for health sits within the broader field of digital health. Digital health is the merging of digital technologies with health and care. The US FDA includes mobile health (mHealth), health information technology (IT), wearable devices, telehealth, telemedicine, and personal medicine in this broad category. For instance, mHealth may include health services ‘supported by mobile devices, such as mobile phones, patient monitoring devices, personal digital assistants (PDAs), and other wireless devices’.
  • 4. Security principles A modest approach to security focuses on the following three key principles: • Confidentiality • Integrity • Availability ensuring information and systems are protected from unauthorised access ensuring that information and systems are unaltered and accurate throughout the lifecycle. For instance, information integrity applies to data collection, transfer, use and storage ensuring that information is and services are accessible by users or systems as and when needed
  • 5. What about the risks? Date Disclosed Device Type (Manufacturer) Vulnerability Potential Impact On Security 19 May 2008 Implantable Defibrillator (Medtronic) Remote access Direct impact on the safety of the device for the user • Hackers remotely accessed a heart defibrillator and pacemaker • Hackers shut down the device • Hackers made device deliver electric jolts
  • 6. What about the risks? Date Disclosed Device Type (Manufacturer) Vulnerability Potential Impact On Security 13 June 2013 Medical Devices (multiple) Hard-Coded Passwords Increased vulnerability to attacks such as command and control or malware • Inability of users/owners to change passwords manually • Potential for “mass hack” of devices with same or similar passwords • Use of connected environments for downstream attacks
  • 7. What about the risks? Date Disclosed Device Type (Manufacturer) Vulnerability Potential Impact On Security 10 June 2015 Patient-Controlled Infusion System (Hospira LifeCare) Connected Devices and Systems Direct impact on downstream security and safety of the device for the user • Vulnerability allowed hackers to remotely command and control • Exploitation could impact delivery of medication via the bloodstream
  • 8. What about the risks? Date Disclosed Device Type (Manufacturer) Vulnerability Potential Impact On Security 08 July 2018 Fitness Tracker Data API (Polar) Personal Data Collection Direct impact on user privacy and data protection as a result of non-medical uses • Access user location data • Identify names and addresses of users • Identify military personnel and locations
  • 9. Architecture Use Cases • Fixed Use Case: Connected MRI scanner • Portable Local Use Case: Hospital Vital Signs Monitor • Portable Loaned Use Case: Blood Pressure Monitor • Personal Device Use Case: Wireless Connected Hearing Aid
  • 10. Connected MRI Scanner Image Storage (Archive) External Doctor System Request for scan Hospital Information system Radiology Information System MRI Scanner External cloud backup System Patients ID orders for examination Diagnosis Reports & Images Legend : Internal Data Flows External recipient of Data External Data Flows Device Systems and / or Data Process of Management Repository points Interface The fixed use case example centres on a connected MRI scanner, a type of connected diagnostic equipment, to demonstrate the risks and security considerations for connected health devices. There are several reasons for wanting to add network connectivity to devices like MRI scanners, such as image transfer and storage, remote control and management, consumable monitoring, and capacity planning. For this use case the MRI scanner is considered a permanent fixed installation that is part of a larger healthcare facility, such as a general hospital. Such a facility is likely to have its own intranet, but physical protection of the local area network (LAN) might be poor as many visitors would have access to the building. Additionally, networks such as intranets should be configured in a way to protect devices with a variety of security capabilities, such as legacy devices, from incoming threats such as malware.
  • 11. Vital Signal monitor Legend : Internal Data Flows External recipient of Data External Data Flows Device Systems and / or Data Process of Management Repository points Interface Nurse Alert System Portable Monitor Hospital Information System Patient Information System External Doctor System External Cloud Backup Archive Doctor Information System Patient Information Request Device Configuration Wired or Wireless Connection Periodic Patient Information This use case focuses on monitors that may be ported with the patient within the health service environment. With modern technology, there are several reasons for wanting to use a portable vital signs monitor, such as automatic data upload, settings configuration, time synchronisation and firmware update. It is assumed that portable monitors will be owned by the healthcare provider and generally remain within the vicinity of the healthcare facility. No assumptions related to connectivity technologies are made. This is because devices may connect using a variety of network technologies, or via a local IP- based LAN. As such, no detailed assumptions are made about the environment in which the portable monitor functions other than the healthcare environment adopts network and information security best practices.
  • 12. Blood Pressure Monitor Legend : Internal Data Flows External recipient of Data External Data Flows Device Systems and / or Data Process of Management Repository points Interface Remote configuration Patient informtion & device management Portable Pressure Monitor Hospital Information System Patient Information System External Doctor System External Cloud Backup Archive Doctor Information System Remote Information request Initial device configuration Wired or Wireless Connection Periodic Patient Information In-home Nurse user interface Patient/ User interface Controlled user interface Loaned portable devices can be conceptualised as owned by the healthcare provider but used by the patient. Devices are not constrained to one dedicated environment and may be ported with the patient to a single remote location or be as mobile as the patient. Given the nature of the device and its integration into the patient’s daily life, the patient is likely to have more control over and engagement with this type of IoT device. No assumptions are made about the environment in which the loaned device functions.
  • 13. Wireless connected Hearing Aid Hospital Information System Patient Information System External Doctor System External CloudBackup Archive Doctor Information System Hearing Aid Pushed Patient Information Legend : Internal Data Flows External recipient of Data External Data Flows Device Systems and / or Data Repository points Hearing aids are a common personal medical device, and there has been a continuing trend of miniaturisation to improve comfort and aesthetics. Modern in-canal hearing aids can be effectively invisible in normal use. Their very small size means that it is impractical to have volume controls on the hearing aid itself. As a connected digital device that is always worn, there is an inclination to converge functionality with other portable electronic devices, such as syncing with smartphones or music and games consoles. Due to the small size of some connected health devices they exist in an extremely constrained environment and therefore may require different security considerations than larger connected health devices with more computing capacity. From the constrained environment and drive to make IoT solutions tailored and user-friendly, it is assumed the hearing aid or similar devices will connect to another mobile device or a personal and/or health-professional’s computer.
  • 14. Reference Architecture • Has a defined boundary between network zones. Bounded • Has no defined organizational intranet or security mechanisms. Boundaryless • Include a variety of network technologies and topologies including bounded and boundaryless networks. Hybrid
  • 15. Bounded Network architecture Legend : Internal Data Flows External recipient of Data External Data Flows Device Systems and / or Data Process of Management Repository points Interface internet Network Name Network Boundary Security Management Point Sensitive data Workstations High Integrity zone Standard Intranet Internet Critical Equipment Trusted Server Internal Gateway External Gateway
  • 16. Boundaryless Environment Mapping Nurse Mobile Device Configuration App Health Information System Time Server Sensors Laptop or USB Stick Barcode Scanner Vital Sign Monitor Blood Pressure Temperature Sp O2 Pulse Patient ID Configuration Firmware Update Public Internet Local Hospital Network Local Wired Connections Legend : Internal Data Flows External recipient of Data External Data Flows Device Systems and / or Data Process of Management Repository points Interface internet Network Name Network Boundary Security Management Point
  • 17. Hybrid IoT Environment Mapping Hearing Aid Audio Streamer Hearing Aid App Audio Source Body Area Network (NFMI) Audio playback Personal Area Network (Bluetooth) Smart Phone Public Internet (WI-FI) Hospital Information System Visitor Information System Local Hospital network Legend : Internal Data Flows External recipient of Data External Data Flows Device Systems and / or Data Process of Management Repository points Interface internet Network Name Network Boundary Security Management Point
  • 19. THANK YOU… Alessandro Sappia Copyright, Trade Marks and Licensing All product names are trademarks, registered trademarks, or service marks of their respective owners. Copyright © 2019, IoTSF. All rights reserved. Copyright © 2021, Alessandro Sappia. All rights reserved. This work is licensed under the Creative Commons Attribution 4.0 International License. Presentation based on «IoT Security Reference Architecture for the Healthcare Industry» https://www.iotsecurityfoundation.org/best-practice-guidelines/ Ordine degli Ingegneri della Provincia di Torino Via Giolitti, 1 10123 Torino TEL: 011 562.24.68 PEC: ordine.torino@ingpec.eu ordine.ingegneri@ording.torino.it Visit us on the web: www.ording.torino.it/professione