Security Research Institute Post Market Surveillance for Cyber Security of Healthcare Internet of Things (HIoT) devices in Australian Healthcare and Public Health Sector
Cyber Security in Healthcare Sector Security Research Institute Cyber Security in Healthcare Sector DHS PPD-21 identified Health care and public health sector among Critical Infrastructure Sector. “The Federal Government shall work with critical infrastructure owners and operators and state, local, tribal, and territorial (SLTT) entities to take proactive steps to manage risk and strengthen the security and resilience of the Nation's critical infrastructure, considering all hazards that could have a debilitating impact on national security, economic stability, public health and safety, or any combination thereof. These efforts shall seek to reduce vulnerabilities, minimize consequences, identify and disrupt threats, and hasten response and recovery efforts related to critical infrastructure.”
Cyber Security in Healthcare Sector Security Research Institute Cyber Security in Healthcare Sector Food and Drug Administration Authority (FDA) in Jan 2017 issued non-binding recommendations for “Post Market Management of Cybersecurity in Medical Devices”.
Cyber Security in Healthcare Sector Security Research Institute Cyber Security in Healthcare Sector Therapeutic Goods Administration (TGA) acknowledges that Cyber Security is a key element. (May 2017) Efforts are underway to define pathways to regulate the compliance. Key Issue: Post market surveillance of medical device.
Cyber Security in Healthcare Sector Security Research Institute Cyber Security in Healthcare Sector Why post market surveillance of medical devices? Direct monitoring of the functional Orientation of the Medical Devices. Quick Anomaly Response Downstream Application in Coronial Investigations Shared Risks among the stakeholders
Example Continuous Glucose Monitoring Unit Subsidized by the Government in 2017 Approved unit by the TGA Connected to the Insulin pump via Bluetooth. Irregular dosage can cause serious harm to the patients. The list goes on.
Cyber Security in Healthcare Sector Who are we? Security Research Institute at Edith Cowan University. Academic Centre of Cyber Security Excellence (ACCSE) Research Themes critical infrastructure security human security cyber security digital forensics.
Cyber Security in Healthcare Sector So what are the Cyber security Issues in Health care and Public Health Sector Key Assets Patient Data Security Healthcare Information Systems Medical Control Systems Medical Information Systems Medical Devices Security Monitoring and Governance Unskilled (Absent) workforce
Cyber Security in Healthcare Sector What is post market surveillance? “Postmarketing surveillance (PMS) (also post market surveillance) is the practice of monitoring the safety of a pharmaceutical drug or medical device after it has been released on the market and is an important part of the science of pharmacovigilance.”
Cyber Security in Healthcare Sector Can we test a device for foreseen and unforeseen anomalies before releasing it into the market? Yes, you can.
Cyber Security in Healthcare Sector Post-market Surveillance of Medical Devices for Cyber Security in Medical and Healthcare Sector in Australia OR POStCODE for short.
POStCODE Medical Devices have three main technological portals. Medical Data: Generated after interacting with the patient/environment. Control Data: Contains instructions sent to or received from the medical device. Management Data: Use to update the firmware of Medical Devices.
POStCODE Medical Devices have three main technological portals. Medical Data Property of the patient or caregiver institute. Control Data Sent directly to the device locally/remotely. Management Data Sent directly to the device locally/remotely.
POStCODE Medical Devices have three main technological portals. Medical Data Property of the patient or caregiver institute. Control Data Sent directly to the device locally/remotely. Management Data Sent directly to the device locally/remotely.
POStCODE
POStCODE
POStCODE POStCODE Repository Clients Regulatory Bodies i.e. FDA, TGA, EMA etc. Device Manufacturers HIS administrators Research and Development
POStCODE Future work POStCODE Real time Implementation Collaboration and joint projects Workforce training Assistance in policy development.
POStCODE Conclusion Duty of care towards improving the caregiving facilities for the vulnerable and needy Australians. Open issues that need immediate action.
Who am I?