Showing posts with label Drug Administration. Show all posts
Showing posts with label Drug Administration. Show all posts

Sunday, July 9, 2017

Hacking of Medical devices increasing as a next huge threat

Medical devices, involving those that are implanted within patients, are increasingly likely to be targeted by hackers and could pose a nightmare scenario if providers do not take measures to improve their defenses.

“The issue with security is that hackers always follow the path of least resistance,” claims Sam Rehman, the chief technology officer at security vendor Arxan, which serves multiple industries and has a large footprint in healthcare.

Like several other security vendors, Rehman says providers require conducting a comprehensive risk assessment and fixing vulnerabilities. In healthcare, medical devices security is a hot topic and for great reason, because providers mostly have hundreds if not thousands of devices in their facilities.

But providers also require increasing security levels for devices that are implanted in patients, and that is because several of those devices have wireless capabilities that enable hackers to interfere with them, Rehman says.

For instance, physicians can utilize hand-held medical devices to wirelessly collect data and even update an implant, for example to change device settings on insulin pumps, pacemakers and other devices. Although, a hacker in a hospital can do the same thing, which represents a potential risk to patient safety, Rehman cautions.

Many hackers might not need to intentionally cause harm, but others will do what someone pays them to do, which could involve causing injury to patients. Rehman says monetary motivation, particularly through blackmail, could rise as a potential risk.

Such hacking could involve efforts to affect the share price of a device manufacturer. Rehman says stock price manipulation could provide another financial motive for hacking. For imstance, if one person can make money by paying another person to cause harm, the instigator can make money when a company’s stock price falls.

A scenario similar to this has already occurred. Previously this year, the Food and Drug Administration confirmed cybersecurity vulnerabilities in St. Jude Medical’s implantable cardiac devices and its Merlin@home transmitter. The vulnerabilities were originally declared by an investment group that threatened to make money by selling its stock short.

St. Jude Medical devices, the FDA stated, could be hacked by outsiders, leading to injury or death, and St. Jude’s share price quickly dropped by 10% as the company scrambled to make fixes. “If someone can make money, this absolutely will happen,” Rehman assumes.

 

Tuesday, May 30, 2017

Manufacturers, Healthcare providers fear attack likely on medical devices

Manufacturers, Healthcare providers fear attack likely on medical devices

The healthcare providers and the medical devices manufacturers that use these devices are primarily unprepared to defend against cyber attacks on their devices, in accordance to the outcomes of a recent survey on security preparedness.

The research by the Ponemon Institute indicates that both makers and users of medical devices are concerned about the likelihood that key medical equipment could be hacked. Two-thirds of device makers and 56% of healthcare providers say an attack on devices is likely during the next year, in accordance to the Ponemon survey.

The Ponemon Institute conducted the research for Synopsys, which sells a platform to handle security and quality problems in software development. The survey covered 242 device makers and 262 healthcare delivery organizations in the North America market.

Some 80% of device firms and healthcare respondents recognized the development of secure devices as a key challenge, asserting that devices remain vulnerable due to coding errors, lack of expertise on secure coding practices and pressure to meet product deadlines.

Despite those complications, fewer than 10% of respondents test devices at least yearly, with 53% of healthcare agencies and 43% of manufacturers report that they do no testing on devices, a finding that surprises Larry Ponemon, chair and founder of Ponemon Institute.

“I was blinded when we discovered that,” he contends. “I would have assumed (providers and manufacturers would have) testing; you would think there would be more due to the cyber threat, but that does not seem to be a driver for change.”

Ponemon puts the onus for change on healthcare organization management, not essentially on chief information officers and chief information security officers, who are attempting to do the right things but do  not have the resources or backing of senior leaders.

He claims that, when an attack happens, the CISO often is the fall guy and is fired, even though he or she may have been forcing for higher security. But the main mission for device makers and healthcare agency is to produce and distribute the product.

The survey discovered that one-third of all respondents reported that no person or function in their agency is primarily responsible for medical device security. Only half of device makers and 44% of healthcare organizations follow Food and Drug Administration guidance on mitigating device security risks.

The challenges that providers face with medical devices, which involve clinician mobile devices like smartphones, are overwhelming. Clinicians, Ponemon says, rely on their devices to efficiently serve sufferers, yet security protocols or architecture built in devices rarely adequately protects data. Security funding increases often occur merely after a serious attack, and encryption is not widely used with Internet of Thing devices.

Too often, Ponemon asserts, providers assume that security of pacemakers, insulin pumps and other devices brought into the hospital is the responsibility of the vendor.

“Healthcare doesn’t prioritize security as much as other industries,” he says. “Healthcare providers are thinking of patient safety, not security risks. We see pressures on healthcare providers to have products available to meet the needs of patients. Are we even capable of knowing if we have been hacked?”

Ponemon was glad to see the Food and Drug Administration recently issue guidance on cybersecurity, which he calls “pretty decent but not prescriptive—it does not tell you step-by-step what to do.” But he fears that following the guidance could be seen by device manufacturers and providers as just adding to existing costs.

“We’re living in a world where everything is a connected device. As we have more connected Internet of Things devices, risks increase. IOT devices are convenient to hack. In healthcare, this could kill people,” he claims.

The full report is available here.

 

Saturday, May 13, 2017

Deep learning computer network excels at verification of breast cancer biopsy slides

Researchers have established a deep learning computer network that is highly precise and accurate in verifying whether invasive forms of breast cancer are present in whole biopsy slides.

A research team supervised by Case Western Reserve University published results of their research in Scientific Reports, detailing their deep learning computer network approach.

The research first involved training the network by downloading 400 biopsy images from several hospitals and then presenting the network with 200 images from The Cancer Genome Atlas and University Hospitals Cleveland Medical Center. Deep learning computer network excels at verification of breast cancer biopsy slides.

In accordance to Anant Madabushi, professor of biomedical engineering at Case Western Reserve and co-author of the study, the network scored 100% precision in determining the presence or absence of cancer on whole slides.

“This is a research with 600 patients, so it is fairly robust,” claims Madabushi, who also directs Case Western Reserve’s Center of Computational Imaging and Personalized Diagnostics. “And there were many human-machine comparisons done.”

In fact, compared with the analyses of 4 pathologists, the machine was more consistent and accurate, Madabushi asserts.

“Pathologists are highly busy, and we are talking about microscopic-level detail in these tissue slides. So, obviously, for them to go in and pick out every cell of cancer wasn’t tenable. There just was not enough time for them to be capable to sit down and manually do that,” adds Madabushi. “The network initiated to get more sophisticated, more granular and more accurate than the pathologists.”

Previous month, the Food and Drug Administration approved the marketing of the Philips IntelliSite Pathology Solution, the first whole slide imaging (WSI) system that enables review and interpretation of digital surgical pathology slides prepared from biopsied tissue. The system enables pathologists to read tissue slides digitally to make diagnoses, instead of looking straightly at a tissue sample mounted on a glass slide under a conventional light microscope.

In accordance to Madabushi, this is the first time the FDA has permitted the marketing of a WSI system for these purposes, which he says is a huge milestone for pathology. “A pathologist can look at an image of a slide on their computer monitor, and that is equivalent to the pathologist looking at a slide under their microscope,” he points out. “That means digital pathology—the digitization of slides—can now be utilized for primary diagnosis by a pathologist. That is a game changer.”

He considers that as pathologists increasingly adopt digital pathology there will be “an even greater need for software and analytics like the one we released in this paper.” Finally, Madabushi emphasizes that the FDA’s clearance of the Philips system “opens the door to an entire market for the analysis of digital pathology slide images.”

 

Wednesday, April 5, 2017

Handheld electroencephalography device quickly evaluate brain bleeding

A clinical trial undertook at eleven emergency departments nationwide has indicated that a handheld electroencephalography device can quickly and with 97% accuracy determine whether someone with a head injury is likely to have brain bleeding and requires further evaluation or treatment.

The Ahead 300 device, established by BrainScope Company, measures electrical activity in the brain and leverages a disposable sensor headset. The Food and Drug Administration cleared the handheld electroencephalography device for clinical use previous September.

Results of the clinical trial, published online in the peer-reviewed journal Academic Emergency Medicine, demonstrated that the device can assist with clinical decision support and triage of patients while potentially decreasing the requirement for CT scans, specifically as an adjunct to acute traumatic brain injury assessment where imaging might be unavailable.

“It is low cost, portable and gives you an objective measure of likelihood to have bleeding in the brain,” claims Daniel Hanley, MD, lead author of the study and Jeffrey and Harriet Legum Professor of Acute Care Neurological Medicine and director of the Brain Injury Outcomes Program at the Johns Hopkins University School of Medicine.

“I consider it is going to objectify head injury in a way that it has not been before,” adds Hanley, who asserts that the Ahead 300 device is “the first of its kind and is likely to change the landscape of traumatic brain injury.”

Hanley considers that the handheld electroencephalography device lends itself to use beyond emergency departments (ED) for use in urgent care and concussion clinics, as well as sports and military environments. The research was funded in part by the U.S. Army. BrainScope’s website states that the Ahead 300 was established in partnership with the Department of Defense through 6 research contracts.

In accordance to the Centers for Disease Control and Prevention, over 2.5 million Americans annually go to emergency departments with suspected head injuries. But, Hanley analyzes that the vast majority of those who present to the ED with mild symptoms following head injury receive a CT scan, however studies show that more than 90% of those scans show that patients do not have an intracranial brain injury.

“Out of an abundance of caution, you can always scan more individuals than you need to, which is what is going on now,” states Hanley, who points out that these CT scans result in needless radiation exposure and cost about $1,200 each scan.

At the similar time, Hanley asserts that the Ahead 300 device is not meant to replace CT scans for sufferers with mild head injuries, but instead gives clinicians with extra information to facilitate routine clinical decision-making. “It may be that we do fewer images” as an outcome of this study, he adds. “That will save money and make care more efficient.”

 

Wednesday, August 3, 2016

Certain number of medical devices intensifies security gaps

Hospitals that need to make better network security should carefully approach the hundreds of medical devices or tools they are utilizing, involving fetal monitors, electrocardiographs, medical imaging devices, lasers and gamma cameras, to name a few.


Few medical devices hold a sizable rate of information that can be hacked; others do not have much information, but can increase network susceptibility. Infusion pumps, for example, do not have a lot of information but are a doorway to the network and “have become the poster kid for medical device security gone incorrect,” claims Stephanie Domas, an ethical hacker and lead medical device security engineer at Battelle, a huge research and development agency.


Infusion pumps aren’t made for security, and their susceptibilities are famous to researchers, who can conveniently purchase a latest device and assess its level of security.


For years, researchers have been attempting to work with medical devices' manufacturers to make better the security of latest devices being manufactured, mostly without much success, Domas states. But that is initiating to change.


The breakthrough came when researchers issued reports on infusion pump susceptibilities, specifically the Hospira Symbiq Infusion System, and then the Food and Drug Administration warned consumers of the Hospira Symbiq to important cybersecurity susceptibilities and suggested discontinuing utilization of the pumps.


Hospira learned to actively react to researchers, Domas claims, and there is increasing cooperation among manufactures and researchers, with certain researchers having approach to devices under development to reverse engineer and seek for mistakes without running afoul of the Digital Millennium Copyright Act.


Manufacturers also growingly are setting up processes to accept data from outsiders who’ve found susceptibilities in medical devices.


Hospitals themselves mostly are to blame for worse device security, Domas contends, with poor patch management. Services utilize a broad range of devices, which mostly require security patches, and the increased complication is an investing factor to increased susceptibility.


Hospitals are not attempting to be lax about security, but the very number of tools makes it complicated. “They first require knowing where all the equipment is,” she states. “It is actually hard to track what is present and where it is, and to track patching.”


The industry also has several third-party medical device resellers, so a hospital might not have a straight contact to a manufacturer, which might not even know that a hospital purchased its products.


When contributors do purchase medical devices from the manufacturer, they should thoroughly specify the security and safety needs that they hope a device to have, Domas counsels. The Mayo Clinic, for example, has a list of hopes for vendors to meet before making a purchase. More of that can actually assist to drive the industry toward safer and better tools, she adds.


“Both sides are actually attempting to get better. The top objectives for contributors are patient care and safety. But there is a deficiency of great security talent for manufacturers to hire.”


 

 

Tuesday, February 23, 2016

FDA reform, privacy law standards required in next healthcare overhaul, group claims

The Healthcare Leadership Council has recognized 6 healthcare reforms that should be executed by the White House, Congress and the healthcare industry to reform healthcare; it was declared previous week at a Capitol Hill briefing and in a report highlighting the changes.


For starters, nationwide health data interoperability in the private sector should be gained by December 31, 2018, the group stated.


The group also aimed the Food and Drug Administration, claiming reforms that focus on decreasing administrative burdens placed on the organization should be enacted so the FDA can better bring innovative treatments and technology to sufferers

Monday, March 15, 2010

FDA Announces New Boxed Warning on Plavix

Alerts patients, health care professionals to potential for reduced effectiveness


The U.S. Food and Drug Administration today added a boxed warning to the anti-blood clotting drug Plavix (clopidogrel), alerting patients and health care professionals that the drug can be less effective in people who cannot metabolize the drug to convert it to its active form.

Plavix reduces the risk of heart attack, unstable angina, stroke, and cardiovascular death in patients with cardiovascular disease by making platelets less likely to form blood clots. Plavix does not have its anti-platelet effects until it is metabolized into its active form by the liver enzyme, CYP2C19.
People who have reduced functioning of their CYP2C19 liver enzyme cannot effectively convert Plavix to its active form. As a result, Plavix may be less effective in altering platelet activity in those people. These "poor metabolizers" may not receive the full benefit of Plavix treatment and may remain at risk for heart attack, stroke, and cardiovascular death.

"We want to highlight this warning to make sure health care professionals use the best information possible to treat their patients," said Mary Ross Southworth, Pharm.D., a clinical analyst in the Division of Cardiovascular and Renal Products in the FDA's Center for Drug Evaluation and Research.

In May 2009, the FDA added this warning to the drug's label. After reviewing more data, the agency felt it was important to highlight this risk in a boxed warning.
It is estimated that 2 percent to 14 percent of the U.S. population are poor metabolizers. The FDA recommends that health care professionalsconsider alternative dosing of Plavix for these patients, or consider using other anti-platelet medications. Tests are available to assess CYP2C19 genotype to determine if a patient is a poor metabolizer.

Patients should not stop taking Plavix unless told to do so by their health care professional. They should talk with their health care professional if they have any concerns about Plavix.

Plavix is made under a Bristol-Myers Squibb - Sanofi Pharmaceuticals partnership.
For information:
FDA Drug Safety Communication: Reduced effectiveness of Plavix (clopidogrel) in patients who are poor metabloizers of the drug
http://www.fda.gov/Drugs/DrugSafety/PostmarketDrugSafetyInformationforPatientsandProviders/ucm203888.htm




Be a part of SNap(R) Family: