<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Hacker Archives - InnoHEALTH magazine</title>
	<atom:link href="https://innohealthmagazine.com/tag/hacker/feed/" rel="self" type="application/rss+xml" />
	<link>https://ztt.nrm.mybluehostin.me/innohealthmagazinetag/hacker/</link>
	<description>India&#039;s first magazine on healthcare innovations</description>
	<lastBuildDate>Thu, 23 May 2019 09:45:17 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=6.9.1</generator>

<image>
	<url>https://innohealthmagazine.com/wp-content/uploads/2017/11/innohealthmagazine-favicon.png</url>
	<title>Hacker Archives - InnoHEALTH magazine</title>
	<link>https://ztt.nrm.mybluehostin.me/innohealthmagazinetag/hacker/</link>
	<width>32</width>
	<height>32</height>
</image> 
<site xmlns="com-wordpress:feed-additions:1">139068796</site>	<item>
		<title>Cybercrime and Threats in 2019</title>
		<link>https://innohealthmagazine.com/2019/persona/exclusive-interview/cybercrime-and-threats-in-2019/</link>
					<comments>https://innohealthmagazine.com/2019/persona/exclusive-interview/cybercrime-and-threats-in-2019/#respond</comments>
		
		<dc:creator><![CDATA[InnoHEALTH Magazine]]></dc:creator>
		<pubDate>Thu, 23 May 2019 09:45:17 +0000</pubDate>
				<category><![CDATA[Exclusive Interview]]></category>
		<category><![CDATA[Persona]]></category>
		<category><![CDATA[access point]]></category>
		<category><![CDATA[AI]]></category>
		<category><![CDATA[Artificial Intelligence]]></category>
		<category><![CDATA[biometric hacking]]></category>
		<category><![CDATA[Bitcoin]]></category>
		<category><![CDATA[black hat hacker]]></category>
		<category><![CDATA[blockchain]]></category>
		<category><![CDATA[Bot]]></category>
		<category><![CDATA[botnet]]></category>
		<category><![CDATA[Chatbot]]></category>
		<category><![CDATA[clinical data]]></category>
		<category><![CDATA[crypto]]></category>
		<category><![CDATA[cryptocurrency]]></category>
		<category><![CDATA[cyber criminal]]></category>
		<category><![CDATA[cyber threat]]></category>
		<category><![CDATA[Cybercrime]]></category>
		<category><![CDATA[cybersecurity]]></category>
		<category><![CDATA[Evil twin]]></category>
		<category><![CDATA[firewall]]></category>
		<category><![CDATA[Hacker]]></category>
		<category><![CDATA[healthcare]]></category>
		<category><![CDATA[injection attack]]></category>
		<category><![CDATA[innovation]]></category>
		<category><![CDATA[Internet of Things]]></category>
		<category><![CDATA[IoT]]></category>
		<category><![CDATA[IP address]]></category>
		<category><![CDATA[IP camera]]></category>
		<category><![CDATA[IT]]></category>
		<category><![CDATA[IT Act 2000]]></category>
		<category><![CDATA[Ransomware]]></category>
		<category><![CDATA[refrigerator]]></category>
		<category><![CDATA[smart gadgets]]></category>
		<category><![CDATA[Smartphone]]></category>
		<category><![CDATA[Social media]]></category>
		<category><![CDATA[tabletheater]]></category>
		<category><![CDATA[white hat hacker]]></category>
		<guid isPermaLink="false">https://ztt.nrm.mybluehostin.me/innohealthmagazine?p=5917</guid>

					<description><![CDATA[<p>Exclusive Interview: Karnal Singh, the Former Director of Enforcement Directorate opens up his opinion on trends of cybercrime and threats in 2019.</p>
<p>The post <a href="https://innohealthmagazine.com/2019/persona/exclusive-interview/cybercrime-and-threats-in-2019/">Cybercrime and Threats in 2019</a> appeared first on <a href="https://innohealthmagazine.com">InnoHEALTH magazine</a>.</p>
]]></description>
										<content:encoded><![CDATA[
		<div id="fws_69aa58e6d8966"  data-column-margin="default" data-midnight="dark"  class="wpb_row vc_row-fluid vc_row top-level"  style="padding-top: 0px; padding-bottom: 0px; "><div class="row-bg-wrap" data-bg-animation="none" data-bg-animation-delay="" data-bg-overlay="false"><div class="inner-wrap row-bg-layer" ><div class="row-bg viewport-desktop"  style=""></div></div></div><div class="row_col_wrap_12 col span_12 dark left">
	<div  class="vc_col-sm-12 wpb_column column_container vc_column_container col no-extra-padding"  data-padding-pos="all" data-has-bg-color="false" data-bg-color="" data-bg-opacity="1" data-animation="" data-delay="0" >
		<div class="vc_column-inner" >
			<div class="wpb_wrapper">
				
<div class="wpb_text_column wpb_content_element " >
	<p style="text-align: justify !important;"><strong>Karnal Singh</strong>, <em>the Former Director of Enforcement Directorate</em> opens up with the <strong>Sachin Gaur</strong>, <em>Executive Editor, InnoHEALTH Magazine</em> about his opinion on trends of cybercrime and threats in 2019.</p>
<p style="text-align: justify !important;"><em>He is a 1984 batch IPS officer and Engineer from Delhi College of Engineering (DCE) and Indian Institute of Technology (IIT), has over 34 years of experience in the investigation of corruption, terrorism, money laundering, and cyber-crime cases. He is a recipient of President’s medal for distinguished service and Police medal for meritorious service.</em></p>
</div>




			</div> 
		</div>
	</div> 
</div></div>
		<div id="fws_69aa58e6d92c1"  data-column-margin="default" data-midnight="dark"  class="wpb_row vc_row-fluid vc_row"  style="padding-top: 0px; padding-bottom: 0px; "><div class="row-bg-wrap" data-bg-animation="none" data-bg-animation-delay="" data-bg-overlay="false"><div class="inner-wrap row-bg-layer" ><div class="row-bg viewport-desktop"  style=""></div></div></div><div class="row_col_wrap_12 col span_12 dark left">
	<div  class="vc_col-sm-12 wpb_column column_container vc_column_container col no-extra-padding"  data-padding-pos="all" data-has-bg-color="false" data-bg-color="" data-bg-opacity="1" data-animation="" data-delay="0" >
		<div class="vc_column-inner" >
			<div class="wpb_wrapper">
				
<div class="wpb_text_column wpb_content_element " >
	<p style="text-align: justify !important;"><strong>Q. Given your important assignments for the Government of India in the past, share with us the big picture. What are the trends you see in terms of cybercrime and threats for 2019?</strong></p>
<p style="text-align: justify !important;">The world is getting more connected and technology has seeped into every aspect of our lives. On one hand, these advancements make our lives easier and on the other bring a lot of vulnerabilities with them if security isn’t strong enough to tackle cyber criminals. Hackers today are well-educated and have the capabilities to develop new methods and tools to exploit the vulnerabilities on the computer systems and networks. Few do it for their academic interest and thrill and inform the person concerned about the vulnerabilities so that the same can be plugged. They are known as white hat hackers. While the others do it with malice and self-gain and are known as Black hat hackers.</p>
<p style="text-align: justify !important;">To gain access to the computer systems, the cybercriminals and hackers will continue to deploy already existing tools (called as exploits) with enhanced capabilities. More advanced tools will be also be developed in the coming years. Some of the important ones are enumerated below:</p>
</div>



<div class="img-with-aniamtion-wrap center" data-max-width="100%" data-max-width-mobile="100%" data-shadow="none" data-animation="fade-in" >
      <div class="inner">
        <div class="hover-wrap"> 
          <div class="hover-wrap-inner">
            <a href="http://bit.ly/2IY3u54" target="_blank" class="center">
              <img decoding="async" class="img-with-animation skip-lazy" data-delay="0" height="60" width="728" data-animation="fade-in" src="https://innohealthmagazine.com/wp-content/uploads/2019/04/cyber4healthcare-online-course-bottom-ad-2.png" alt="cyber4healthcare-online-course-bottom-ad (2)" srcset="https://innohealthmagazine.com/wp-content/uploads/2019/04/cyber4healthcare-online-course-bottom-ad-2.png 728w, https://innohealthmagazine.com/wp-content/uploads/2019/04/cyber4healthcare-online-course-bottom-ad-2-300x25.png 300w" sizes="(max-width: 728px) 100vw, 728px" />
            </a>
          </div>
        </div>
        
      </div>
      </div>
			</div> 
		</div>
	</div> 
</div></div>
		<div id="fws_69aa58e6da6d3"  data-column-margin="default" data-midnight="dark"  class="wpb_row vc_row-fluid vc_row"  style="padding-top: 0px; padding-bottom: 0px; "><div class="row-bg-wrap" data-bg-animation="none" data-bg-animation-delay="" data-bg-overlay="false"><div class="inner-wrap row-bg-layer" ><div class="row-bg viewport-desktop"  style=""></div></div></div><div class="row_col_wrap_12 col span_12 dark left">
	<div  class="vc_col-sm-12 wpb_column column_container vc_column_container col no-extra-padding"  data-padding-pos="all" data-has-bg-color="false" data-bg-color="" data-bg-opacity="1" data-animation="" data-delay="0" >
		<div class="vc_column-inner" >
			<div class="wpb_wrapper">
				
<div class="wpb_text_column wpb_content_element " >
	<p style="text-align: justify !important;"><strong>1. Chatbots:</strong> There will be extensive use of machine learning techniques (Artificial intelligence) in the near future. A Chatbot can be injected into the important website (for example, a banking site). Chatbot in the form of a man or woman would pop up on the screen and will start interacting with the user (like what we see the google assistant doing). Then it may misdirect the customer to a nefarious link similar to an actual banking site, thereby fetching important information from the customer and compromising his banking information.</p>
</div>




			</div> 
		</div>
	</div> 
</div></div>
		<div id="fws_69aa58e6dab04"  data-column-margin="default" data-midnight="dark"  class="wpb_row vc_row-fluid vc_row"  style="padding-top: 0px; padding-bottom: 0px; "><div class="row-bg-wrap" data-bg-animation="none" data-bg-animation-delay="" data-bg-overlay="false"><div class="inner-wrap row-bg-layer" ><div class="row-bg viewport-desktop"  style=""></div></div></div><div class="row_col_wrap_12 col span_12 dark left">
	<div  class="vc_col-sm-12 wpb_column column_container vc_column_container col no-extra-padding"  data-padding-pos="all" data-has-bg-color="false" data-bg-color="" data-bg-opacity="1" data-animation="" data-delay="0" >
		<div class="vc_column-inner" >
			<div class="wpb_wrapper">
				
<div class="wpb_text_column wpb_content_element " >
	<p style="text-align: justify !important;"><strong>2. Bot and botnet:</strong> The hackers have been successful in remotely taking control of the hacked computer systems. Such a system is known as a bot. The hacker can remotely misuse a machine (using computing time or other resources) without the actual user being aware of it. If there is more than one compromised device, then it is called a botnet. Botnets can be put to perform some distributed function viz, crypto jacking (mining bitcoins) or distributed denial of service attack.</p>
</div>




			</div> 
		</div>
	</div> 
</div></div>
		<div id="fws_69aa58e6daea4"  data-column-margin="default" data-midnight="dark"  class="wpb_row vc_row-fluid vc_row"  style="padding-top: 0px; padding-bottom: 0px; "><div class="row-bg-wrap" data-bg-animation="none" data-bg-animation-delay="" data-bg-overlay="false"><div class="inner-wrap row-bg-layer" ><div class="row-bg viewport-desktop"  style=""></div></div></div><div class="row_col_wrap_12 col span_12 dark left">
	<div  class="vc_col-sm-12 wpb_column column_container vc_column_container col no-extra-padding"  data-padding-pos="all" data-has-bg-color="false" data-bg-color="" data-bg-opacity="1" data-animation="" data-delay="0" >
		<div class="vc_column-inner" >
			<div class="wpb_wrapper">
				
<div class="wpb_text_column wpb_content_element " >
	<p style="text-align: justify !important;"><strong>3. Discover and target organizations outside the firewall:</strong> Most of the commercial organizations deploy firewalls, intrusion detection systems, and intrusion protection systems; thereby making hacking difficult. But they use the third-party software, which may be having vulnerabilities. Hackers can attack the third-party systems used by commercial websites.</p>
</div>




			</div> 
		</div>
	</div> 
</div></div>
		<div id="fws_69aa58e6db2b1"  data-column-margin="default" data-midnight="dark"  class="wpb_row vc_row-fluid vc_row"  style="padding-top: 0px; padding-bottom: 0px; "><div class="row-bg-wrap" data-bg-animation="none" data-bg-animation-delay="" data-bg-overlay="false"><div class="inner-wrap row-bg-layer" ><div class="row-bg viewport-desktop"  style=""></div></div></div><div class="row_col_wrap_12 col span_12 dark left">
	<div  class="vc_col-sm-12 wpb_column column_container vc_column_container col no-extra-padding"  data-padding-pos="all" data-has-bg-color="false" data-bg-color="" data-bg-opacity="1" data-animation="" data-delay="0" >
		<div class="vc_column-inner" >
			<div class="wpb_wrapper">
				
<div class="wpb_text_column wpb_content_element " >
	<p style="text-align: justify !important;"><strong>4. Injection Attack:</strong> Protective systems installed on computers look for malicious files to detect cyber-attack. The injection attack is filed less; the hacker directly inserts the malicious code in the memory, thereby compromising the machine, without ever dropping a file onto the infected system. One such example is British Airways site hack in 2018, resulting in identity theft of around 3,80,000 users.</p>
</div>




			</div> 
		</div>
	</div> 
</div></div>
		<div id="fws_69aa58e6db7a6"  data-column-margin="default" data-midnight="dark"  class="wpb_row vc_row-fluid vc_row"  style="padding-top: 0px; padding-bottom: 0px; "><div class="row-bg-wrap" data-bg-animation="none" data-bg-animation-delay="" data-bg-overlay="false"><div class="inner-wrap row-bg-layer" ><div class="row-bg viewport-desktop"  style=""></div></div></div><div class="row_col_wrap_12 col span_12 dark left">
	<div  class="vc_col-sm-12 wpb_column column_container vc_column_container col no-extra-padding"  data-padding-pos="all" data-has-bg-color="false" data-bg-color="" data-bg-opacity="1" data-animation="" data-delay="0" >
		<div class="vc_column-inner" >
			<div class="wpb_wrapper">
				
<div class="wpb_text_column wpb_content_element " >
	<p style="text-align: justify !important;"><strong>5. Biometric Hacking:</strong> Cybercriminals use brute force attack, dictionary attack or social engineering, etc., to crack the passwords. Many people have shifted to biometrics. The academic research suggests that a number of officers print authentication systems could be spoofed, even highly sophisticated facial recognition system has been proven vulnerable to more advanced hacking efforts.</p>
</div>




			</div> 
		</div>
	</div> 
</div></div>
		<div id="fws_69aa58e6dbaec"  data-column-margin="default" data-midnight="dark"  class="wpb_row vc_row-fluid vc_row"  style="padding-top: 0px; padding-bottom: 0px; "><div class="row-bg-wrap" data-bg-animation="none" data-bg-animation-delay="" data-bg-overlay="false"><div class="inner-wrap row-bg-layer" ><div class="row-bg viewport-desktop"  style=""></div></div></div><div class="row_col_wrap_12 col span_12 dark left">
	<div  class="vc_col-sm-12 wpb_column column_container vc_column_container col no-extra-padding"  data-padding-pos="all" data-has-bg-color="false" data-bg-color="" data-bg-opacity="1" data-animation="" data-delay="0" >
		<div class="vc_column-inner" >
			<div class="wpb_wrapper">
				
<div class="wpb_text_column wpb_content_element " >
	<p style="text-align: justify !important;"><strong>6. Application of artificial intelligence:</strong> Artificial intelligence techniques will be used more and more to avoid detection by intrusion detection tools. For example, Waterminer, a cryptocurrency mining tool injected as malware, stops mining when task manager or antimalware scan is run.</p>
</div>




<div class="wpb_text_column wpb_content_element " >
	<p>Also Read:<br />
<a href="https://innohealthmagazine.comissues/social-isolation-in-a-digitally-connected-world/">Social Isolation in a Digitally Connected World</a><br />
<a href="https://innohealthmagazine.compersona/sweden-india-collaboration-health-sector/">Sweden-India Collaboration in Health Sector</a></p>
</div>




			</div> 
		</div>
	</div> 
</div></div>
		<div id="fws_69aa58e6dbe9f"  data-column-margin="default" data-midnight="dark"  class="wpb_row vc_row-fluid vc_row"  style="padding-top: 0px; padding-bottom: 0px; "><div class="row-bg-wrap" data-bg-animation="none" data-bg-animation-delay="" data-bg-overlay="false"><div class="inner-wrap row-bg-layer" ><div class="row-bg viewport-desktop"  style=""></div></div></div><div class="row_col_wrap_12 col span_12 dark left">
	<div  class="vc_col-sm-12 wpb_column column_container vc_column_container col no-extra-padding"  data-padding-pos="all" data-has-bg-color="false" data-bg-color="" data-bg-opacity="1" data-animation="" data-delay="0" >
		<div class="vc_column-inner" >
			<div class="wpb_wrapper">
				
<div class="wpb_text_column wpb_content_element " >
	<p style="text-align: justify !important;"><strong>7. Rouge AP(access point) and Evil Twin:</strong> Rouge AP is an access point installed on the network without the knowledge of the administrator, while the evil twin is identical network.</p>
<p style="text-align: justify !important;">The above-mentioned techniques will be sharpened to attack numerous utility services (some of which are listed below) by the black hat hackers for malicious purposes:</p>
<p style="text-align: justify !important;"><strong>A. Internet of things(IoT):</strong> the Considerable number of smart gadgets (such as TV, plugs, IP cameras, smartphones, tablets, network video recorders, heaters, refrigerators) are used at homes and industries. When these gadgets are connected to the Internet, they are termed as the Internet of Things. The hackers will increase their attacks on IoT using a vulnerability in cloud infrastructure and hardware to threaten the users physically or mentally.</p>
<p style="text-align: justify !important;"><strong>B. Attack on identity platforms:</strong> Identity platforms offer centralized secure authentication of users, devices, and services across the IT environment. It could be a database of banks, hospitals, social media sites, etc. Identities of a large number of persons would be attempted to be stolen for extortion, impersonation or proving the inadequacy of the commercial organization in securing the important data (so as to blackmail).</p>
<p style="text-align: justify !important;"><strong>C. Real world damages:</strong> There will be more and more attacks on services providing community services viz, municipality, health sector, electricity supply, water supply, and sewer systems. Besides the cybercriminals, who would use such hacking for ransom, terrorists and even nations can use it against public or adversaries.</p>
<p style="text-align: justify !important;"><strong>D. Social media content compromise:</strong> There will be increased use of Botnets to compromise social media to influence public opinion.</p>
</div>




			</div> 
		</div>
	</div> 
</div></div>
		<div id="fws_69aa58e6dc581"  data-column-margin="default" data-midnight="dark"  class="wpb_row vc_row-fluid vc_row"  style="padding-top: 0px; padding-bottom: 0px; "><div class="row-bg-wrap" data-bg-animation="none" data-bg-animation-delay="" data-bg-overlay="false"><div class="inner-wrap row-bg-layer" ><div class="row-bg viewport-desktop"  style=""></div></div></div><div class="row_col_wrap_12 col span_12 dark left">
	<div  class="vc_col-sm-12 wpb_column column_container vc_column_container col no-extra-padding"  data-padding-pos="all" data-has-bg-color="false" data-bg-color="" data-bg-opacity="1" data-animation="" data-delay="0" >
		<div class="vc_column-inner" >
			<div class="wpb_wrapper">
				
<div class="wpb_text_column wpb_content_element " >
	<p><strong>Q. Being a healthcare publication, our readers would be interested in healthcare-specific cyber threats. What is your opinion on the health sector threats? </strong><br />
The health sector offers life critical services. It maintains the identity and clinical records of a large number of patients. The following factors make the health sector more vulnerable as compared to the other sectors.</p>
<ul>
<li>IoT (Internet of Things) devices are used extensively for the treatment of the patients viz. smart continuous glucose monitoring, connected inhalers for asthma, apple watch Identity platforms offer centralized secure authentication of users, devices and services across IT environment. It could be a database of banks, hospitals, social media sites, etc. PERSONA THEME TRENDS WELL-BEING ISSUES RESEARCH NEWSCOPE app that monitors depression, etc.</li>
<li>The doctors and patients can connect external storage devices and even mobile phones to the hospital database system.</li>
<li>Third-party software and hardware are deployed which makes it vulnerable to supply chain poisoning.</li>
<li>Most of the services provided by the hospital are connected through the Internet or the cloud services.</li>
</ul>
<p>Clinical data is of immense use for cybercriminals and cyber terrorists. They can use vulnerabilities in cybersecurity in the following ways:</p>
<ol>
<li>Identity theft: Medical identity record is very useful for the cybercriminals as it can be used to impersonate people in the digital world and gain access to financial systems as well as to commit fraud by claiming treatment or insurance at the cost of insurance agencies and the patients. Therefore, this data is sold at a higher rate in the darknet as compared to identity records of other sectors.</li>
<li>The clinical records of the patients may sometimes contain their psychological disorders or conditions, or a person may be suffering from concealed diseases (sexually transmitted disease, etc). The hacker may make use of such information by blackmailing or harassing the patients. It would cause hardship to the patients and would put the reputation of the healthcare service provider/hospital at stake which failed to protect the patients’ identity and clinical records.</li>
<li>Ransomware attacks on hospitals will be on rising. The information of the patients is mostly time critical. If the cybercriminal denies the access of data to the hospital even for a short span of time, it may lead to lack of timely treatment to critical patients and therefore, hospital administration is not in a position to delay the ransom payment.</li>
<li>Prescription change: In India, the majority of renowned hospitals in metro cities are computerized. Doctors give online prescriptions which immediately become available to the concerned medical staff, such as a nurse who administers the drug to the patient. Cybercriminal scan tampers the prescription which may harm or even cause the death of the patient. They can cause an obstruction in the oxygen supply line or failure of electricity. They would be able to change the medical records of the patients, which will lead to wrong diagnosis and treatment. Not only cybercriminals but the terrorists can adopt the above techniques and threaten the nations or can even cause large scale fatalities.</li>
</ol>
<p>Therefore, it becomes extremely important to adequately secure the health sector databases.</p>
</div>




			</div> 
		</div>
	</div> 
</div></div>
		<div id="fws_69aa58e6dc87a"  data-column-margin="default" data-midnight="dark"  class="wpb_row vc_row-fluid vc_row"  style="padding-top: 0px; padding-bottom: 0px; "><div class="row-bg-wrap" data-bg-animation="none" data-bg-animation-delay="" data-bg-overlay="false"><div class="inner-wrap row-bg-layer" ><div class="row-bg viewport-desktop"  style=""></div></div></div><div class="row_col_wrap_12 col span_12 dark left">
	<div  class="vc_col-sm-12 wpb_column column_container vc_column_container col no-extra-padding"  data-padding-pos="all" data-has-bg-color="false" data-bg-color="" data-bg-opacity="1" data-animation="" data-delay="0" >
		<div class="vc_column-inner" >
			<div class="wpb_wrapper">
				
<div class="wpb_text_column wpb_content_element " >
	<p style="text-align: justify !important;"><strong>Q. The health sector has seen major attacks of ransomware; part of the equation is &#8216;money aka cryptocurrency&#8217; in organized crime. How do we handle this? </strong></p>
<p style="text-align: justify !important;">Being proactive about cybersecurity is perhaps the best approach to tackle cyber-attacks. The health sector should form cybersecurity forum for cybersecurity policy formulations and mutually evaluate hospitals’ preparedness against the cyberattacks ensuring adherence to the cybersecurity policies. Additionally, each hospital network should have a dedicated team of IT security professionals to guide the management and proactively check for any cyber invasion. The IT team should ensure that the latest patches for all the devices and software are installed and there is protection from supply chain poisoning. The system should be equipped with features firewalls, Intrusion Detection System, Intrusion Protection system and processes analytical tools among others.</p>
<p style="text-align: justify !important;">The blockchain techniques can also be explored for data management and the patient databases should be encrypted so that they are of no use to the hacker. Further, the hospitals must take data backup with a fast recovery plan. Regular penetration testing of the system should be done to eliminate potential vulnerabilities.</p>
<p style="text-align: justify !important;">Hospitals should invest in training IT staff in cybersecurity policies and cybersecurity technologies. Regular analysis should be done of employees’ computer usage pattern so that any compromised user is effectively detected and timely removed from using the system. There should also be a secure access control preferably using biometric features.</p>
</div>




			</div> 
		</div>
	</div> 
</div></div>
		<div id="fws_69aa58e6dcb23"  data-column-margin="default" data-midnight="dark"  class="wpb_row vc_row-fluid vc_row"  style="padding-top: 0px; padding-bottom: 0px; "><div class="row-bg-wrap" data-bg-animation="none" data-bg-animation-delay="" data-bg-overlay="false"><div class="inner-wrap row-bg-layer" ><div class="row-bg viewport-desktop"  style=""></div></div></div><div class="row_col_wrap_12 col span_12 dark left">
	<div  class="vc_col-sm-12 wpb_column column_container vc_column_container col no-extra-padding"  data-padding-pos="all" data-has-bg-color="false" data-bg-color="" data-bg-opacity="1" data-animation="" data-delay="0" >
		<div class="vc_column-inner" >
			<div class="wpb_wrapper">
				
<div class="wpb_text_column wpb_content_element " >
	<p style="text-align: justify !important;"><strong>Q. Today security has become a hot topic and world over we see that regulation is leading change and innovation! What is your vision for India in regard? What regulations will make the health sector more secure? Or we don&#8217;t need regulation? </strong></p>
<p style="text-align: justify !important;">The cybercriminals attempt to hack the computer resources of the hospitals by exploiting the vulnerabilities in the computer systems. They manipulate the stored information, steal the same or hold it for ransom. The hospital databases work on the trust reposed by patients in the hospital administration that their data will be guarded with privacy.</p>
<p style="text-align: justify !important;">Cybercriminals can be prosecuted under various provisions of the Indian Information Technology Act, 2000(ITA). The IT Act creates civil liabilities for the offenses under the Act vide Sections 43 to 45, wherein an amount of compensation can be given to victims; it also creates criminal liabilities vide Sections 65 to 74 of the Act. Cybercriminals are liable to both civil and criminal liabilities.</p>
<p style="text-align: justify !important;">Hospital administration is responsible for protecting the data and failure to protect can result in civil liability under Section 43A of the IT Act. However, this section can be invoked if the breached data results into wrongful loss to the victim or wrongful gain to a cybercriminal. The victim has to prove that there was a wrongful loss to him/her. The offenses by the intermediaries are criminalized under Section 67C of the IT Act. However, the same gets diluted by the provisions contained in Section 79 of the IT Act. Hence, the IT act doesn’t provide absolute data security laws.</p>
<p style="text-align: justify !important;">The Government of India appointed Justice BN Srikrishna Committee for effective data protection laws in India. The committee submitted the Draft Data Protection Bill, 2018 to the government in July 2018. It will be introduced in parliament after the forthcoming elections in India. The Government of India is also planning to introduce “The Digital Information Security in Healthcare Bill” in the parliament to secure the healthcare data of patients in India.</p>
</div>




			</div> 
		</div>
	</div> 
</div></div>
		<div id="fws_69aa58e6dcdb0"  data-column-margin="default" data-midnight="dark"  class="wpb_row vc_row-fluid vc_row"  style="padding-top: 0px; padding-bottom: 0px; "><div class="row-bg-wrap" data-bg-animation="none" data-bg-animation-delay="" data-bg-overlay="false"><div class="inner-wrap row-bg-layer" ><div class="row-bg viewport-desktop"  style=""></div></div></div><div class="row_col_wrap_12 col span_12 dark left">
	<div  class="vc_col-sm-12 wpb_column column_container vc_column_container col no-extra-padding"  data-padding-pos="all" data-has-bg-color="false" data-bg-color="" data-bg-opacity="1" data-animation="" data-delay="0" >
		<div class="vc_column-inner" >
			<div class="wpb_wrapper">
				
<div class="wpb_text_column wpb_content_element " >
	<p style="text-align: justify !important;"><strong>Q. As the cyber incidents keep rising and legal regime catches up, what is your opinion on our abilities in investigating cybercrime? As you know attribution and audit trail are not the easiest in the cyber world, any advice for stakeholders so that they are not wrongly prosecuted or get justice on time? </strong></p>
<p style="text-align: justify !important;">According to Section 78 of the IT Act, 2000, a police officer of the rank of Inspector and above is authorized to investigate the offenses under the IT Act. This is to ensure the quality of the investigation. However, all Inspectors in police are not trained in cybercrime investigation. Further, complexities of computer technology, tools, and methodology used by cybercriminals make it difficult even for a trained person to keep pace with the development in this field. Police organizations don’t employ external cyber experts to aid in the investigation. Each police officer investigating the case seeks help from other expert police officers or cyber experts of his/her choice. Therefore, institutional help is lagging.</p>
<p style="text-align: justify !important;">There is also the dearth of cyber experts in forensic science laboratories, resulting in delays of months and years in getting reports from them which can compromise the further evidence leading from forensic analysis of seized electronic material. During my tenure in the Enforcement Directorate, I found this delay to be of 1 to 3 years, therefore, I initiated six in-house cyber forensic labs. This led to the cyber forensic analysis done at a quicker pace also improving the quality of investigation.</p>
<p style="text-align: justify !important;">The next hurdle is the global spread of evidence into other jurisdictions. A letter rogatory (letter of request) is sent to each foreign jurisdiction for getting the evidence located in that jurisdiction. The process is slow and it may take 3 to 4 years in getting a reply. If that reply further requires evidence from another foreign jurisdiction then another 3-4 years are gone. Therefore, the entire investigation is time-consuming.</p>
<p style="text-align: justify !important;">The investigation becomes further complicated if Tor or onion routing is employed by cybercriminals. Finding the cybercriminal in this scenario becomes more difficult.</p>
<p style="text-align: justify !important;">The IP address (internet protocol) and the time of its use, identify uniquely the source of the attack. However, the cybercriminal may commit cyberattack through Bot or botnet. In that case, the IP address will lead the investigation officer to the slave machine, even though the user of this machine would have no knowledge of the misuse of his computer resources. If the investigating officer doesn’t go into the depth of log analysis of such a system, then the innocent people might have to face false prosecution. The stakeholders should ensure all logs are maintained and stored by his computer system so that the audit trail can lead to actual perpetrator of cyber-attack.</p>
</div>



<div class="img-with-aniamtion-wrap center" data-max-width="100%" data-max-width-mobile="100%" data-shadow="none" data-animation="fade-in" >
      <div class="inner">
        <div class="hover-wrap"> 
          <div class="hover-wrap-inner">
            <a href="http://bit.ly/2IY3u54" target="_blank" class="center">
              <img decoding="async" class="img-with-animation skip-lazy" data-delay="0" height="60" width="728" data-animation="fade-in" src="https://innohealthmagazine.com/wp-content/uploads/2019/04/cyber4healthcare-online-course-bottom-ad-2.png" alt="cyber4healthcare-online-course-bottom-ad (2)" srcset="https://innohealthmagazine.com/wp-content/uploads/2019/04/cyber4healthcare-online-course-bottom-ad-2.png 728w, https://innohealthmagazine.com/wp-content/uploads/2019/04/cyber4healthcare-online-course-bottom-ad-2-300x25.png 300w" sizes="(max-width: 728px) 100vw, 728px" />
            </a>
          </div>
        </div>
        
      </div>
      </div>
			</div> 
		</div>
	</div> 
</div></div>
<p>The post <a href="https://innohealthmagazine.com/2019/persona/exclusive-interview/cybercrime-and-threats-in-2019/">Cybercrime and Threats in 2019</a> appeared first on <a href="https://innohealthmagazine.com">InnoHEALTH magazine</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://innohealthmagazine.com/2019/persona/exclusive-interview/cybercrime-and-threats-in-2019/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">5917</post-id>	</item>
		<item>
		<title>RANSOMWARE EPIDEMIC &#8211; WHO IS NEXT?</title>
		<link>https://innohealthmagazine.com/2017/issues/ransomware-epidemic/</link>
					<comments>https://innohealthmagazine.com/2017/issues/ransomware-epidemic/#respond</comments>
		
		<dc:creator><![CDATA[InnoHEALTH Magazine]]></dc:creator>
		<pubDate>Fri, 17 Nov 2017 09:59:44 +0000</pubDate>
				<category><![CDATA[Issues]]></category>
		<category><![CDATA[Barnaby Jack]]></category>
		<category><![CDATA[Cardiovascular]]></category>
		<category><![CDATA[Catastrophic]]></category>
		<category><![CDATA[Centre for Cyber Safety and Education]]></category>
		<category><![CDATA[Clinic]]></category>
		<category><![CDATA[Cognetyx]]></category>
		<category><![CDATA[Cost effective]]></category>
		<category><![CDATA[Credit Card Data]]></category>
		<category><![CDATA[Cyber Attack]]></category>
		<category><![CDATA[Cyber Defence Strategy]]></category>
		<category><![CDATA[Cyber Security]]></category>
		<category><![CDATA[Defibrillators]]></category>
		<category><![CDATA[Dick Cheney]]></category>
		<category><![CDATA[Digitalization]]></category>
		<category><![CDATA[Electronic Health Record]]></category>
		<category><![CDATA[FDA]]></category>
		<category><![CDATA[Financial Services]]></category>
		<category><![CDATA[Fluoroscopy]]></category>
		<category><![CDATA[Hacker]]></category>
		<category><![CDATA[healthcare]]></category>
		<category><![CDATA[healthcare management]]></category>
		<category><![CDATA[Hospitals]]></category>
		<category><![CDATA[IBM]]></category>
		<category><![CDATA[Implants]]></category>
		<category><![CDATA[Indovation in innovation]]></category>
		<category><![CDATA[Insulin Pumps]]></category>
		<category><![CDATA[Insurance]]></category>
		<category><![CDATA[Internal Security Breach]]></category>
		<category><![CDATA[Internet Black Market]]></category>
		<category><![CDATA[IoT]]></category>
		<category><![CDATA[iStan]]></category>
		<category><![CDATA[IT]]></category>
		<category><![CDATA[Johnson & Johnson]]></category>
		<category><![CDATA[Las Vegas]]></category>
		<category><![CDATA[Linac]]></category>
		<category><![CDATA[Medical devices]]></category>
		<category><![CDATA[Merlin@Home Transmitter]]></category>
		<category><![CDATA[Neurological]]></category>
		<category><![CDATA[NHS]]></category>
		<category><![CDATA[Nimisha Singh Verma]]></category>
		<category><![CDATA[Optum]]></category>
		<category><![CDATA[Pacemakers]]></category>
		<category><![CDATA[PACS]]></category>
		<category><![CDATA[Patient]]></category>
		<category><![CDATA[Public Service Network]]></category>
		<category><![CDATA[Radiation]]></category>
		<category><![CDATA[Radio Frequency]]></category>
		<category><![CDATA[Ransomware]]></category>
		<category><![CDATA[Religare Technologies]]></category>
		<category><![CDATA[Respiratory]]></category>
		<category><![CDATA[RF]]></category>
		<category><![CDATA[Security Infrastructure]]></category>
		<category><![CDATA[Skill Development]]></category>
		<category><![CDATA[Smart Bed]]></category>
		<category><![CDATA[Smart Emergency System]]></category>
		<category><![CDATA[St Jude Medical]]></category>
		<category><![CDATA[Stakeholder]]></category>
		<category><![CDATA[Start-up]]></category>
		<category><![CDATA[Surgical]]></category>
		<category><![CDATA[Sustainable Solutions]]></category>
		<category><![CDATA[Tertiary Care Hospital]]></category>
		<category><![CDATA[Threat]]></category>
		<category><![CDATA[TrapX Security]]></category>
		<category><![CDATA[UK]]></category>
		<category><![CDATA[University of South Alabama]]></category>
		<category><![CDATA[US]]></category>
		<category><![CDATA[WannaCry]]></category>
		<category><![CDATA[Washington]]></category>
		<category><![CDATA[Wearable]]></category>
		<category><![CDATA[Xray]]></category>
		<guid isPermaLink="false">http://innovatiocuris.com/?p=2366</guid>

					<description><![CDATA[<p>By Nimisha Singh Verma</p>
<p>The post <a href="https://innohealthmagazine.com/2017/issues/ransomware-epidemic/">RANSOMWARE EPIDEMIC &#8211; WHO IS NEXT?</a> appeared first on <a href="https://innohealthmagazine.com">InnoHEALTH magazine</a>.</p>
]]></description>
										<content:encoded><![CDATA[
		<div id="fws_69aa58e6df4c3"  data-column-margin="default" data-midnight="dark"  class="wpb_row vc_row-fluid vc_row"  style="padding-top: 0px; padding-bottom: 0px; "><div class="row-bg-wrap" data-bg-animation="none" data-bg-animation-delay="" data-bg-overlay="false"><div class="inner-wrap row-bg-layer" ><div class="row-bg viewport-desktop"  style=""></div></div></div><div class="row_col_wrap_12 col span_12 dark left">
	<div  class="vc_col-sm-2 wpb_column column_container vc_column_container col no-extra-padding"  data-padding-pos="all" data-has-bg-color="false" data-bg-color="" data-bg-opacity="1" data-animation="" data-delay="0" >
		<div class="vc_column-inner" >
			<div class="wpb_wrapper">
				[vc_single_image image=&#8221;939&#8243; alignment=&#8221;center&#8221; onclick=&#8221;link_image&#8221; qode_css_animation=&#8221;&#8221;]
			</div> 
		</div>
	</div> 

	<div  class="vc_col-sm-10 wpb_column column_container vc_column_container col no-extra-padding"  data-padding-pos="all" data-has-bg-color="false" data-bg-color="" data-bg-opacity="1" data-animation="" data-delay="0" >
		<div class="vc_column-inner" >
			<div class="wpb_wrapper">
				
<div class="wpb_text_column wpb_content_element " >
	<p style="text-align: justify !important;"><span style="color: #0071b2;"><strong>Nimisha Singh Verma</strong></span> is Healthcare IT consultant. She brings with her experience of various esteemed healthcare organizations Optum, Religare Technologies and tertiary care hospitals. Authored chapter on Indovation in Innovations in Healthcare Management: Cost Effective and Sustainable Solutions book published in US.</p>
</div>




			</div> 
		</div>
	</div> 
</div></div>
		<div id="fws_69aa58e6dfd4e"  data-column-margin="default" data-midnight="dark"  class="wpb_row vc_row-fluid vc_row"  style="padding-top: 0px; padding-bottom: 0px; "><div class="row-bg-wrap" data-bg-animation="none" data-bg-animation-delay="" data-bg-overlay="false"><div class="inner-wrap row-bg-layer" ><div class="row-bg viewport-desktop"  style=""></div></div></div><div class="row_col_wrap_12 col span_12 dark left">
	<div  class="vc_col-sm-12 wpb_column column_container vc_column_container col no-extra-padding"  data-padding-pos="all" data-has-bg-color="false" data-bg-color="" data-bg-opacity="1" data-animation="" data-delay="0" >
		<div class="vc_column-inner" >
			<div class="wpb_wrapper">
				[vc_empty_space]
			</div> 
		</div>
	</div> 
</div></div>
		<div id="fws_69aa58e6e0137"  data-column-margin="default" data-midnight="dark"  class="wpb_row vc_row-fluid vc_row"  style="padding-top: 0px; padding-bottom: 0px; "><div class="row-bg-wrap" data-bg-animation="none" data-bg-animation-delay="" data-bg-overlay="false"><div class="inner-wrap row-bg-layer" ><div class="row-bg viewport-desktop"  style=""></div></div></div><div class="row_col_wrap_12 col span_12 dark left">
	<div  class="vc_col-sm-12 wpb_column column_container vc_column_container col no-extra-padding"  data-padding-pos="all" data-has-bg-color="false" data-bg-color="" data-bg-opacity="1" data-animation="" data-delay="0" >
		<div class="vc_column-inner" >
			<div class="wpb_wrapper">
				
<div class="wpb_text_column wpb_content_element " >
	<h5 style="text-align: justify !important;">Ransomware epidemic is spreading in healthcare like wildfire due to its increasing digitalization which is and will attract more attention of hackers.</h5>
</div>




			</div> 
		</div>
	</div> 
</div></div>
		<div id="fws_69aa58e6e05b6"  data-column-margin="default" data-midnight="dark"  class="wpb_row vc_row-fluid vc_row"  style="padding-top: 0px; padding-bottom: 0px; "><div class="row-bg-wrap" data-bg-animation="none" data-bg-animation-delay="" data-bg-overlay="false"><div class="inner-wrap row-bg-layer" ><div class="row-bg viewport-desktop"  style=""></div></div></div><div class="row_col_wrap_12 col span_12 dark left">
	<div  class="vc_col-sm-12 wpb_column column_container vc_column_container col no-extra-padding"  data-padding-pos="all" data-has-bg-color="false" data-bg-color="" data-bg-opacity="1" data-animation="" data-delay="0" >
		<div class="vc_column-inner" >
			<div class="wpb_wrapper">
				[vc_empty_space]
			</div> 
		</div>
	</div> 
</div></div>
		<div id="fws_69aa58e6e0a7d"  data-column-margin="default" data-midnight="dark"  class="wpb_row vc_row-fluid vc_row"  style="padding-top: 0px; padding-bottom: 0px; "><div class="row-bg-wrap" data-bg-animation="none" data-bg-animation-delay="" data-bg-overlay="false"><div class="inner-wrap row-bg-layer" ><div class="row-bg viewport-desktop"  style=""></div></div></div><div class="row_col_wrap_12 col span_12 dark left">
	<div  class="vc_col-sm-12 wpb_column column_container vc_column_container col no-extra-padding"  data-padding-pos="all" data-has-bg-color="false" data-bg-color="" data-bg-opacity="1" data-animation="" data-delay="0" >
		<div class="vc_column-inner" >
			<div class="wpb_wrapper">
				
<div class="wpb_text_column wpb_content_element " >
	<p style="text-align: justify !important;">The healthcare industry has been a victim of various cyber attacks in the last few years. According to recent studies, healthcare has outnumbered financial services and become the most cyber attacked industry. The latest in cyber-attack is ransomware wherein the hacker encrypts the data and threatens to publish it until the ransom is paid in form of bitcoins. In US alone, healthcare industry was the victim of 88 per cent of all ransomware attacks across industries last year.</p>
<p style="text-align: justify !important;">The recent case of WannaCry ransomware crippled the IT systems of NHS, UK. And after hitting NHS, it spread globally targeting more than 99 nations. The hackers demanded payment of £300 &#8211; £600 to unlock systems and have earned about £55,000 in ransom.</p>
<p style="text-align: justify !important;">Ransomware has indeed become a lucrative revenue source for hackers due to which the number of attacks is predicted to quadruple by 2020. Medical records have 10-20 times more value than the credit card data in the internet black market. Ransomware epidemic is spreading in healthcare like wildfire due to its increasing digitalization which is and will attract more attention of hackers. Also, the vulnerability of the health data tends the organizations to pay the ransom to get the data back to maintain privacy and confidentiality of patient data.</p>
<p style="text-align: justify !important;">Even after so many cases of cyber attacks compromising millions of electronic health records each year, the healthcare industry is inadequately prepared to prevent and resolve these attacks. Whether it is India or US, cyber security is always discussed in forums and budget is allocated for the same but is not put to proper use. Cyber attacks happen due to outdated security infrastructure or employee negligence.</p>
<p style="text-align: justify !important;">Hospitals and insurance companies have been the main targets of hackers. But, a new vulnerability is catching everyone’s attention i.e. medical devices. The next nightmare in ransomware attacks could be hacking of medical devices such as insulin pumps, pacemakers, defibrillators, implants etc.</p>
<p style="text-align: justify !important;">Disfunctioning of medical devices can be catastrophic. Just imagine, hackers take control of one’s pacemaker and ask for ransom or else they would manipulate the device which could be fatal. This kind of attack has been showcased in the very famous TV show Homeland wherein the Vice President dies due to hackers remotely disable his pacemaker.</p>
</div>




			</div> 
		</div>
	</div> 
</div></div>
		<div id="fws_69aa58e6e0e98"  data-column-margin="default" data-midnight="dark"  class="wpb_row vc_row-fluid vc_row"  style="padding-top: 0px; padding-bottom: 0px; "><div class="row-bg-wrap" data-bg-animation="none" data-bg-animation-delay="" data-bg-overlay="false"><div class="inner-wrap row-bg-layer" ><div class="row-bg viewport-desktop"  style=""></div></div></div><div class="row_col_wrap_12 col span_12 dark left">
	<div  class="vc_col-sm-8 wpb_column column_container vc_column_container col no-extra-padding"  data-padding-pos="all" data-has-bg-color="false" data-bg-color="" data-bg-opacity="1" data-animation="" data-delay="0" >
		<div class="vc_column-inner" >
			<div class="wpb_wrapper">
				
<div class="wpb_text_column wpb_content_element " >
	<p style="text-align: justify !important;">Just like the serial, the former US Vice President Dick Cheney’s doctors disabled his pacemaker’s wireless functionality due to fear of possible assassination attempts as revealed by him during an interview in 2013. This clearly showcases that medical devices can be the next target for hackers.</p>
<p style="text-align: justify !important;">Regulators such as FDA are increasingly getting concerned about medical device security and have issued warning. In 2015, for the first time FDA issued safety notice to hospitals which strongly discouraged hospitals to use an infusion pump which was found to be vulnerable to cyber attacks. But it has been observed that FDA did not force the company to fix the devices being used in the hospitals and didn’t investigate other insulin pump models. This shows that FDA needs to be more stringent towards medical device security. The vulnerability of infusion pump was pointed out by a white hat hacker Billy Rios during his hospital stay.</p>
</div>




			</div> 
		</div>
	</div> 

	<div  class="vc_col-sm-4 wpb_column column_container vc_column_container col no-extra-padding"  data-padding-pos="all" data-has-bg-color="false" data-bg-color="" data-bg-opacity="1" data-animation="" data-delay="0" >
		<div class="vc_column-inner" >
			<div class="wpb_wrapper">
				[vc_single_image image=&#8221;2367&#8243; img_size=&#8221;medium&#8221; alignment=&#8221;center&#8221; onclick=&#8221;link_image&#8221; qode_css_animation=&#8221;&#8221;]
			</div> 
		</div>
	</div> 
</div></div>
		<div id="fws_69aa58e6e196d"  data-column-margin="default" data-midnight="dark"  class="wpb_row vc_row-fluid vc_row"  style="padding-top: 0px; padding-bottom: 0px; "><div class="row-bg-wrap" data-bg-animation="none" data-bg-animation-delay="" data-bg-overlay="false"><div class="inner-wrap row-bg-layer" ><div class="row-bg viewport-desktop"  style=""></div></div></div><div class="row_col_wrap_12 col span_12 dark left">
	<div  class="vc_col-sm-12 wpb_column column_container vc_column_container col no-extra-padding"  data-padding-pos="all" data-has-bg-color="false" data-bg-color="" data-bg-opacity="1" data-animation="" data-delay="0" >
		<div class="vc_column-inner" >
			<div class="wpb_wrapper">
				[vc_empty_space]
			</div> 
		</div>
	</div> 
</div></div>
		<div id="fws_69aa58e6e1c94"  data-column-margin="default" data-midnight="dark"  class="wpb_row vc_row-fluid vc_row"  style="padding-top: 0px; padding-bottom: 0px; "><div class="row-bg-wrap" data-bg-animation="none" data-bg-animation-delay="" data-bg-overlay="false"><div class="inner-wrap row-bg-layer" ><div class="row-bg viewport-desktop"  style=""></div></div></div><div class="row_col_wrap_12 col span_12 dark left">
	<div  class="vc_col-sm-12 wpb_column column_container vc_column_container col no-extra-padding"  data-padding-pos="all" data-has-bg-color="false" data-bg-color="" data-bg-opacity="1" data-animation="" data-delay="0" >
		<div class="vc_column-inner" >
			<div class="wpb_wrapper">
				
<div class="wpb_text_column wpb_content_element " >
	<p style="text-align: justify !important;">Few of the medical device companies/providers have been proactive in strengthening their device security such as Johnson &amp; Johnson in Oct 2016 warned 114,000 diabetic patients about a security lax that a hacker could exploit in one of its insulin pumps (J&amp;J Animas OneTouch Ping). The hackers can disable or alter the dosage which could be fatal. J&amp;J suggested ways to the patients for mitigating risk.</p>
<p style="text-align: justify !important;">There have been no documented cases of medical device hacking till date but demonstrations have been conducted in research environment. One such example is of Barnaby Jack who succeeded in hacking an insulin pump and demonstrated giving off lethal dose of insulin without the pump alerting the user. Another example is that of St Jude Medical’s implantable devices such as pacemakers, defibrillators, and resynchronization devices. The radio frequency (RF) enabled St. Jude medical implantable cardiac device and corresponding Merlin@home Transmitter enables transmitting and receiving patient data stored on the device to the physician to monitor his health. But FDA reviewed the device and confirmed about cybersecurity vulnerabilities, if exploited, could be fatal.</p>
<p style="text-align: justify !important;">Also, researchers at TrapX Security analysed three hospitals for medical device hacking. The deception technology was installed which utilized emulated medical devices in the hospitals. These emulated devices attract and trap hackers so that TrapX could trace the hackers activity. These fake medical devices such as Radiation Oncology system, LINAC , Fluoroscopy, PACS and Xray system appeared real to the hackers and TrapX could monitor hacker’s activity.</p>
<p style="text-align: justify !important;">According to TrapX, these hospitals utilized older version of Windows that made it vulnerable and most medical devices did not have additional endpoint security software which made the attack undetectable. It was also noticed that the main goal of hackers was to steal medical records not to manipulate the device.</p>
<p style="text-align: justify !important;">Another research at University of South Alabama showcased how they hacked pacemaker and killed a medical simulator called iStan. The $100,000 medical dummy comes equipped with robotics that mimic the human cardiovascular, respiratory, and neurological systems. The researchers could speed the heart rate up or could slow it down. Not only pacemaker, researchers could manipulate an insulin pump or a number of things that would cause life-threatening injuries or death. This clearly illustrates why medical device security is important.</p>
<p style="text-align: justify !important;">With the advent of IoT, where devices are connected via internet should focus on cyber security. Industrial experts are realizing that cyber security is prime priority for all the devices connected to the internet.</p>
<p style="text-align: justify !important;">Devices such as wearables, smart bed, smart emergency system, etc. are all lagging behind in cyber security. Apart from medical devices, surgical robots are not being scrutinized for cyber security. Just imagine, surgical robots been hacked which could lead to life threatening situation of the patient. One such demonstration has been showcased by researchers at University of Washington in 2015. They hacked a tele-operated surgical robot, Raven II. The experiment demonstrated three types of attacks that made telesurgery vulnerable with this robot. The researchers demonstrated how they took complete control over the robot and disrupted the operation.</p>
</div>




			</div> 
		</div>
	</div> 
</div></div>
		<div id="fws_69aa58e6e2105"  data-column-margin="default" data-midnight="dark"  class="wpb_row vc_row-fluid vc_row"  style="padding-top: 0px; padding-bottom: 0px; "><div class="row-bg-wrap" data-bg-animation="none" data-bg-animation-delay="" data-bg-overlay="false"><div class="inner-wrap row-bg-layer" ><div class="row-bg viewport-desktop"  style=""></div></div></div><div class="row_col_wrap_12 col span_12 dark left">
	<div  class="vc_col-sm-12 wpb_column column_container vc_column_container col no-extra-padding"  data-padding-pos="all" data-has-bg-color="false" data-bg-color="" data-bg-opacity="1" data-animation="" data-delay="0" >
		<div class="vc_column-inner" >
			<div class="wpb_wrapper">
				[vc_empty_space]
			</div> 
		</div>
	</div> 
</div></div>
		<div id="fws_69aa58e6e23e7"  data-column-margin="default" data-midnight="dark"  class="wpb_row vc_row-fluid vc_row"  style="padding-top: 0px; padding-bottom: 0px; "><div class="row-bg-wrap" data-bg-animation="none" data-bg-animation-delay="" data-bg-overlay="false"><div class="inner-wrap row-bg-layer" ><div class="row-bg viewport-desktop"  style=""></div></div></div><div class="row_col_wrap_12 col span_12 dark left">
	<div  class="vc_col-sm-8 wpb_column column_container vc_column_container col no-extra-padding"  data-padding-pos="all" data-has-bg-color="false" data-bg-color="" data-bg-opacity="1" data-animation="" data-delay="0" >
		<div class="vc_column-inner" >
			<div class="wpb_wrapper">
				
<div class="wpb_text_column wpb_content_element " >
	<p style="text-align: justify !important;">All of this sounds scary but it can be prevented if we are well prepared. It is important to understand that not only regulators like FDA need not address the challenge of cyber security but also the medical device vendors and providers should take shared responsibility. It has been observed that providers point the device manufacturers to be accountable for cyber security for responding to vulnerabilities and providing fixes for the same.</p>
<p style="text-align: justify !important;">On the other hand, the device vendors hold providers responsible for their negligence and having outdated network  protection. To be safe from such attacks, organisations should review their cyber defence strategies and budget. Also, employee training and awareness needs to be tackled to avoid falling for opening phishing mails and change passwords regularly.</p>
</div>




			</div> 
		</div>
	</div> 

	<div  class="vc_col-sm-4 wpb_column column_container vc_column_container col no-extra-padding"  data-padding-pos="all" data-has-bg-color="false" data-bg-color="" data-bg-opacity="1" data-animation="" data-delay="0" >
		<div class="vc_column-inner" >
			<div class="wpb_wrapper">
				[vc_single_image image=&#8221;2369&#8243; img_size=&#8221;medium&#8221; alignment=&#8221;center&#8221; onclick=&#8221;link_image&#8221; qode_css_animation=&#8221;&#8221;]
			</div> 
		</div>
	</div> 
</div></div>
		<div id="fws_69aa58e6e2b24"  data-column-margin="default" data-midnight="dark"  class="wpb_row vc_row-fluid vc_row"  style="padding-top: 0px; padding-bottom: 0px; "><div class="row-bg-wrap" data-bg-animation="none" data-bg-animation-delay="" data-bg-overlay="false"><div class="inner-wrap row-bg-layer" ><div class="row-bg viewport-desktop"  style=""></div></div></div><div class="row_col_wrap_12 col span_12 dark left">
	<div  class="vc_col-sm-12 wpb_column column_container vc_column_container col no-extra-padding"  data-padding-pos="all" data-has-bg-color="false" data-bg-color="" data-bg-opacity="1" data-animation="" data-delay="0" >
		<div class="vc_column-inner" >
			<div class="wpb_wrapper">
				[vc_empty_space]
			</div> 
		</div>
	</div> 
</div></div>
		<div id="fws_69aa58e6e2df0"  data-column-margin="default" data-midnight="dark"  class="wpb_row vc_row-fluid vc_row"  style="padding-top: 0px; padding-bottom: 0px; "><div class="row-bg-wrap" data-bg-animation="none" data-bg-animation-delay="" data-bg-overlay="false"><div class="inner-wrap row-bg-layer" ><div class="row-bg viewport-desktop"  style=""></div></div></div><div class="row_col_wrap_12 col span_12 dark left">
	<div  class="vc_col-sm-12 wpb_column column_container vc_column_container col no-extra-padding"  data-padding-pos="all" data-has-bg-color="false" data-bg-color="" data-bg-opacity="1" data-animation="" data-delay="0" >
		<div class="vc_column-inner" >
			<div class="wpb_wrapper">
				
<div class="wpb_text_column wpb_content_element " >
	<p style="text-align: justify !important;">It has also been observed that providers such as middle scale hospitals, clinics or laboratories have often overlooked cyber security as priority as they believe not much data is present with them and only the big organisations are in trouble. Which is not true, as hackers are aware of the precious financial and patient data these clinics hold and are aiming at clinics or small hospitals also to get the data. So, they should also focus on medical device security.</p>
<p style="text-align: justify !important;">The next big thing in helping fight against cybersecurity is artificial intelligence (AI). According to some analysts, the advantage of using AI is it can help predict cyber attack before it happens with the use of behaviour analysis. It alerts security team on any behaviour deviation or authentication failures while accessing records. AI not only helps in detecting threats quickly but it is also cost efficient compared to the money paid by companies in ransom. It does not replace security tools but acts as an additional layer of security. AI can also help in analysing employee behaviour for avoiding any internal security breach. AI can help in bridging the shortage of skilled cyber security professionals also. According to Centre for Cyber Safety and Education, there is a shortfall of 1.8 million cyber security professionals by 2022 worldwide. Companies such as IBM are already investing in AI system Watson for cyber security.</p>
<p style="text-align: justify !important;">Also start-ups such as Cognetyx are providing cognitive cyber surveillance solution to healthcare organizations. Use of AI for cyber security in other areas has been showcased, for example, the Las Vegas city officials and UK government to monitor their Public Services Network and protect their records from security threats. Whereas, the successful implementation of AI in healthcare cyber security is yet to happen.</p>
<p style="text-align: justify !important;">The next wave of medical device cyber attacks can be prevented by collaborative approach and commitment from all the stakeholders. Not only the healthcare organizations should make sure their security practices and strategies are updated but the government should also help in skill development of cyber security professionals and encourage more research on medical device security by providing medical device at low cost. Since medical devices are expensive and require license, it makes it difficult for researchers to explore this area. At the end, we should not forget that we have to stay a step ahead of hackers to be a hard target for them.</p>
</div>




			</div> 
		</div>
	</div> 
</div></div>
		<div id="fws_69aa58e6e3200"  data-column-margin="default" data-midnight="dark"  class="wpb_row vc_row-fluid vc_row"  style="padding-top: 0px; padding-bottom: 0px; "><div class="row-bg-wrap" data-bg-animation="none" data-bg-animation-delay="" data-bg-overlay="false"><div class="inner-wrap row-bg-layer" ><div class="row-bg viewport-desktop"  style=""></div></div></div><div class="row_col_wrap_12 col span_12 dark left">
	<div  class="vc_col-sm-12 wpb_column column_container vc_column_container col no-extra-padding"  data-padding-pos="all" data-has-bg-color="false" data-bg-color="" data-bg-opacity="1" data-animation="" data-delay="0" >
		<div class="vc_column-inner" >
			<div class="wpb_wrapper">
				[vc_empty_space]
			</div> 
		</div>
	</div> 
</div></div>
		<div id="fws_69aa58e6e34ad"  data-column-margin="default" data-midnight="dark"  class="wpb_row vc_row-fluid vc_row"  style="padding-top: 0px; padding-bottom: 0px; "><div class="row-bg-wrap" data-bg-animation="none" data-bg-animation-delay="" data-bg-overlay="false"><div class="inner-wrap row-bg-layer" ><div class="row-bg viewport-desktop"  style=""></div></div></div><div class="row_col_wrap_12 col span_12 dark left">
	<div  class="vc_col-sm-12 wpb_column column_container vc_column_container col no-extra-padding"  data-padding-pos="all" data-has-bg-color="false" data-bg-color="" data-bg-opacity="1" data-animation="" data-delay="0" >
		<div class="vc_column-inner" >
			<div class="wpb_wrapper">
				
<div class="wpb_text_column wpb_content_element " >
	<p>Want to write for InnoHEALTH? send us your article at  <a href="mailto:magazine@innovatiocuris.com">magazine@innovatiocuris.com</a></p>
</div>




			</div> 
		</div>
	</div> 
</div></div>
		<div id="fws_69aa58e6e3950"  data-column-margin="default" data-midnight="dark"  class="wpb_row vc_row-fluid vc_row"  style="padding-top: 0px; padding-bottom: 0px; "><div class="row-bg-wrap" data-bg-animation="none" data-bg-animation-delay="" data-bg-overlay="false"><div class="inner-wrap row-bg-layer" ><div class="row-bg viewport-desktop"  style=""></div></div></div><div class="row_col_wrap_12 col span_12 dark left">
	<div  class="vc_col-sm-6 wpb_column column_container vc_column_container col no-extra-padding"  data-padding-pos="all" data-has-bg-color="false" data-bg-color="" data-bg-opacity="1" data-animation="" data-delay="0" >
		<div class="vc_column-inner" >
			<div class="wpb_wrapper">
				
<div class="wpb_text_column wpb_content_element " >
	<p><strong>Read all the issues of InnoHEALTH magazine:</strong><br />
InnoHEALTH Volume 1 Issue 1 (July to September 2016) – <a href="https://goo.gl/iWAwN2">https://goo.gl/iWAwN2 </a><br />
InnoHEALTH Volume 1 Issue 2 (October to December 2016) – <a href="https://goo.gl/4GGMJz">https://goo.gl/4GGMJz </a><br />
InnoHEALTH Volume 2 Issue 1 (January to March 2017) – <a href="https://goo.gl/DEyKnw">https://goo.gl/DEyKnw </a><br />
InnoHEALTH Volume 2 Issue 2 (April to June 2017) – <a href="https://goo.gl/Nv3eev">https://goo.gl/Nv3eev</a><br />
InnoHEALTH Volume 2 Issue 3 (July to September 2017) – <a href="https://goo.gl/MCVjd6">https://goo.gl/MCVjd6</a></p>
</div>




			</div> 
		</div>
	</div> 

	<div  class="vc_col-sm-6 wpb_column column_container vc_column_container col no-extra-padding"  data-padding-pos="all" data-has-bg-color="false" data-bg-color="" data-bg-opacity="1" data-animation="" data-delay="0" >
		<div class="vc_column-inner" >
			<div class="wpb_wrapper">
				
<div class="wpb_text_column wpb_content_element " >
	<p><strong>Connect with InnovatioCuris on:</strong><br />
<em><strong>Facebook: </strong></em><a href="https://www.facebook.com/InnovatioCuris">https://www.facebook.com/innovatiocuris</a><br />
<em><strong>Twitter: </strong></em><a href="https://twitter.com/innovatiocuris">https://twitter.com/innovatiocuris</a><br />
<em><strong>Linkedin: </strong></em><a href="https://www.linkedin.com/groups/7043791">https://www.linkedin.com/groups/7043791</a><br />
Stay update about IC by visiting: <a href="http://innovatiocuris.com/">www.innovatiocuris.com</a></p>
</div>




			</div> 
		</div>
	</div> 
</div></div>
<p>The post <a href="https://innohealthmagazine.com/2017/issues/ransomware-epidemic/">RANSOMWARE EPIDEMIC &#8211; WHO IS NEXT?</a> appeared first on <a href="https://innohealthmagazine.com">InnoHEALTH magazine</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://innohealthmagazine.com/2017/issues/ransomware-epidemic/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">2366</post-id>	</item>
		<item>
		<title>Upcoming Cyber Security Threats in Health Sector</title>
		<link>https://innohealthmagazine.com/2017/issues/cyber-security-threats/</link>
					<comments>https://innohealthmagazine.com/2017/issues/cyber-security-threats/#respond</comments>
		
		<dc:creator><![CDATA[InnoHEALTH Magazine]]></dc:creator>
		<pubDate>Thu, 16 Nov 2017 06:25:35 +0000</pubDate>
				<category><![CDATA[Issues]]></category>
		<category><![CDATA[Authentication mechanism]]></category>
		<category><![CDATA[Bitcoin]]></category>
		<category><![CDATA[Bot]]></category>
		<category><![CDATA[Bot Traffic]]></category>
		<category><![CDATA[Breaches]]></category>
		<category><![CDATA[Breeding]]></category>
		<category><![CDATA[Communication Interfaces]]></category>
		<category><![CDATA[Crime]]></category>
		<category><![CDATA[Criminal Businesses]]></category>
		<category><![CDATA[Currency]]></category>
		<category><![CDATA[Cyber Security]]></category>
		<category><![CDATA[Cyber Weapon]]></category>
		<category><![CDATA[Data leak]]></category>
		<category><![CDATA[Denial attack]]></category>
		<category><![CDATA[Diagnosis]]></category>
		<category><![CDATA[Dick Cheney]]></category>
		<category><![CDATA[Digital System]]></category>
		<category><![CDATA[Dollar]]></category>
		<category><![CDATA[Electronic Device]]></category>
		<category><![CDATA[Encrypts]]></category>
		<category><![CDATA[Estonia]]></category>
		<category><![CDATA[Gadgets]]></category>
		<category><![CDATA[Google]]></category>
		<category><![CDATA[Hacker]]></category>
		<category><![CDATA[hacking]]></category>
		<category><![CDATA[Health Sector]]></category>
		<category><![CDATA[Health Systems]]></category>
		<category><![CDATA[Healthcare Delivery]]></category>
		<category><![CDATA[Hospital Information System]]></category>
		<category><![CDATA[Infection]]></category>
		<category><![CDATA[innovatiocuris]]></category>
		<category><![CDATA[Interent]]></category>
		<category><![CDATA[Internet of Things]]></category>
		<category><![CDATA[IoT]]></category>
		<category><![CDATA[KLoC]]></category>
		<category><![CDATA[Lawmaker]]></category>
		<category><![CDATA[Lethal Attack]]></category>
		<category><![CDATA[Lung Diseases]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[Marc Andreessen]]></category>
		<category><![CDATA[Medical devices]]></category>
		<category><![CDATA[mHealth]]></category>
		<category><![CDATA[Microsoft]]></category>
		<category><![CDATA[Mitigation Strategy]]></category>
		<category><![CDATA[Nuclear program]]></category>
		<category><![CDATA[Programming code Snippet]]></category>
		<category><![CDATA[Ransom ware]]></category>
		<category><![CDATA[Russia]]></category>
		<category><![CDATA[Sachin Gaur]]></category>
		<category><![CDATA[SCADA]]></category>
		<category><![CDATA[Silicon Walley]]></category>
		<category><![CDATA[Smartphone]]></category>
		<category><![CDATA[Software]]></category>
		<category><![CDATA[software Code]]></category>
		<category><![CDATA[software programmer]]></category>
		<category><![CDATA[Stealing Identity information]]></category>
		<category><![CDATA[Stethoscope]]></category>
		<category><![CDATA[Stuxnet]]></category>
		<category><![CDATA[Tallinn Square]]></category>
		<category><![CDATA[Technology]]></category>
		<category><![CDATA[Thermometer]]></category>
		<category><![CDATA[Threats]]></category>
		<category><![CDATA[Treatment]]></category>
		<category><![CDATA[Vice president]]></category>
		<guid isPermaLink="false">http://innovatiocuris.com/?p=2359</guid>

					<description><![CDATA[<p>By Sachin Gaur</p>
<p>The post <a href="https://innohealthmagazine.com/2017/issues/cyber-security-threats/">Upcoming Cyber Security Threats in Health Sector</a> appeared first on <a href="https://innohealthmagazine.com">InnoHEALTH magazine</a>.</p>
]]></description>
										<content:encoded><![CDATA[
		<div id="fws_69aa58e6e7213"  data-column-margin="default" data-midnight="dark"  class="wpb_row vc_row-fluid vc_row"  style="padding-top: 0px; padding-bottom: 0px; "><div class="row-bg-wrap" data-bg-animation="none" data-bg-animation-delay="" data-bg-overlay="false"><div class="inner-wrap row-bg-layer" ><div class="row-bg viewport-desktop"  style=""></div></div></div><div class="row_col_wrap_12 col span_12 dark left">
	<div  class="vc_col-sm-2 wpb_column column_container vc_column_container col no-extra-padding"  data-padding-pos="all" data-has-bg-color="false" data-bg-color="" data-bg-opacity="1" data-animation="" data-delay="0" >
		<div class="vc_column-inner" >
			<div class="wpb_wrapper">
				<div class="img-with-aniamtion-wrap center" data-max-width="100%" data-max-width-mobile="100%" data-shadow="none" data-animation="fade-in" >
      <div class="inner">
        <div class="hover-wrap"> 
          <div class="hover-wrap-inner">
            <img decoding="async" class="img-with-animation skip-lazy" data-delay="0" height="150" width="150" data-animation="fade-in" src="https://innohealthmagazine.com/wp-content/uploads/2015/07/Sachin-Gaur-Team-InnovatioCuris.jpg" alt="Sachin Gaur - Team InnovatioCuris"  />
          </div>
        </div>
        
      </div>
    </div>
			</div> 
		</div>
	</div> 

	<div  class="vc_col-sm-10 wpb_column column_container vc_column_container col no-extra-padding"  data-padding-pos="all" data-has-bg-color="false" data-bg-color="" data-bg-opacity="1" data-animation="" data-delay="0" >
		<div class="vc_column-inner" >
			<div class="wpb_wrapper">
				
<div class="wpb_text_column wpb_content_element " >
	<p style="text-align: justify !important;">Sachin Gaur is director operations at <a href="http://www.innovatiocuris.com">InnovatioCuris</a>. He is interested in topics of mHealth and Cyber Security.</p>
<p style="text-align: justify !important;"><strong>Abstract:</strong> We are seeing phenomenal technology shifts and human life is greatly impacted by them. Health sector is not untouched as the health systems now have deep IT integration and care givers increasingly rely on the information shown by digital systems. Hence, any compromise to the integrity of such systems would lead to wrong diagnosis or treatment. This paper investigates some of the early signals about the kind of threats out there relevant to the health systems.</p>
</div>




			</div> 
		</div>
	</div> 
</div></div>
		<div id="fws_69aa58e6e85c0"  data-column-margin="default" data-midnight="dark"  class="wpb_row vc_row-fluid vc_row"  style="padding-top: 0px; padding-bottom: 0px; "><div class="row-bg-wrap" data-bg-animation="none" data-bg-animation-delay="" data-bg-overlay="false"><div class="inner-wrap row-bg-layer" ><div class="row-bg viewport-desktop"  style=""></div></div></div><div class="row_col_wrap_12 col span_12 dark left">
	<div  class="vc_col-sm-12 wpb_column column_container vc_column_container col no-extra-padding"  data-padding-pos="all" data-has-bg-color="false" data-bg-color="" data-bg-opacity="1" data-animation="" data-delay="0" >
		<div class="vc_column-inner" >
			<div class="wpb_wrapper">
				
<div class="wpb_text_column wpb_content_element " >
	<p><span style="color: #0071b2;"><strong>Introduction</strong></span></p>
<p style="text-align: justify !important;">The famous Silicon Valley investor Marc Andreessen says, “software is eating the world”. By, which he means that increasingly we are bringing software into systems to increase efficiency, lower down the cost or time involved in the process. Interestingly, humans also do software writing and humans are prone to make mistakes. It is estimated by various experts that 1000 lines of code (KLoC) has approximately 15-50 bugs present. Bugs here mean mistakes made by the software programmer while writing the software code. Bugs often result in some kind of malfunction or wrong output. Some of these bugs can lead to exploit by a third party making the larger system vulnerable or as we call hackable. As long as humans will write software, bugs will be there.</p>
<p style="text-align: justify !important;">In a typical software company as bugs are discovered, new code is written to fix these bugs. The new code might further result into new bugs hence the cycle continues. At the consumer end, we keep receiving software updates over the air, as we use our phone / laptops or other devices, which are many times an attempt of the software company to overcome the past mistakes.</p>
<p style="text-align: justify !important;">A lone computer hacker or an organized crime group looks at these software updates (sometimes called patches) very curiously as for them this could be a chance of hitting the jackpot! They reverse engineer it and try to understand the bug, that the patch is trying to cover. Very often systems are not updated with latest updates. Leading to most system having a known vulnerability, which the hacker can take advantage after understanding it well. Hackers further can create a simple script (programming code snippet) to some sophisticated software, which can then take advantage of the vulnerable system. We often call such a program as malware, as it is built with bad intention.</p>
<p style="text-align: justify !important;">Today, as we talk it has become from a hobby crime to organized crime! Software companies regularly receive communication from bounty hunters about exposing their critical software bugs and in exchange not to do so, hackers want to charge them bounty money. Some software companies have gone further and engaged these bounty hunters to reduce security risks in their software.</p>
<p style="text-align: justify !important;">In some cases the hacker is not interested in the bounty money (hence they do not inform the software maker) but rather interested in exploiting the bug. Sometimes, the bug is not known to the software maker or anyone else in the world and can be converted into a lethal attack. Such attacks are known as a zero day attack! As prior knowledge of such a vulnerability does not exist. Hence, most software security solutions, like anti virus software do not work on them. Further selling the knowledge of exploit as lethal software is now called as a cyber weapon. Nation states are now engaged in buying or building such software to infect systems of enemy states. Hence, we have come very far in the business of software bugs, where the enemy could be a lone developer, an organized crime group or a Nation state.</p>
</div>




			</div> 
		</div>
	</div> 
</div></div>
		<div id="fws_69aa58e6e8b1d"  data-column-margin="default" data-midnight="dark"  class="wpb_row vc_row-fluid vc_row"  style="padding-top: 0px; padding-bottom: 0px; "><div class="row-bg-wrap" data-bg-animation="none" data-bg-animation-delay="" data-bg-overlay="false"><div class="inner-wrap row-bg-layer" ><div class="row-bg viewport-desktop"  style=""></div></div></div><div class="row_col_wrap_12 col span_12 dark left">
	<div  class="vc_col-sm-12 wpb_column column_container vc_column_container col no-extra-padding"  data-padding-pos="all" data-has-bg-color="false" data-bg-color="" data-bg-opacity="1" data-animation="" data-delay="0" >
		<div class="vc_column-inner" >
			<div class="wpb_wrapper">
				
<div class="wpb_text_column wpb_content_element " >
	<p><span style="color: #0071b2;"><strong>How is software eating the health sector and the threats linked to it?</strong></span></p>
<p style="text-align: justify !important;">In the above section we discussed in general, how the exploitation of software is increasingly becoming a serious business. While, we have seen many examples in last 30 years from a hobby software programmer to Nation states taking advantage of the software driven vulnerabilities. We would like to share some examples closer to the health sector.</p>
<p><strong>1. Malware affecting data systems</strong></p>
<p style="text-align: justify !important;">Hospital information systems and similar information systems as part of the healthcare delivery have become very commonplace and one of the core component of the system. As pointed out in the introductory section, organized crime groups are now looking to exploit software bugs for commercial purposes. One of the ingenious way that they have developed is a malware known as ransomware . Ransomware is a malicious computer program which when executed on a system encrypts the data with very strong encryption making it unusable for hospitals or any other care provider to access patient records or other vital information. It then demands a ransom inform of bitcoins (a crypto currency) in order for the victim to have the key to decrypt the vital information. In recent incidents of ransomware infection, some hospitals in USA have even demanded millions of dollars as ransom and some have even paid.</p>
<p style="text-align: justify !important;">The mitigation strategy for countering ransomware for any organization would be a strong backup of data. Also, creating awareness among the employees on sources of malware and reducing the chances of accidental infection of the workplace systems.</p>
<p style="text-align: justify !important;">The long-term solution of tackling such organized crime is a better international legal framework, which allows international prosecution and cooperation among law enforcement agencies.</p>
<p><strong>2. Denial of service attacks on ehealth services</strong></p>
<p style="text-align: justify !important;">In 2007 there was a distributed denial of service attack that took place in Estonia. A statue of the Russian soldier was removed from the Tallinn Square, capital of the country. Which sparked a response from sympathizers from Russia and it brought down the Estonian economy for three days. Estonia being one of the most advance countries when it comes to take up of e governance services, ehealth being one of them. The entire attack costed less than 50,000 US dollars. That was the first Denial of service attack the world saw at the level of a nation state.</p>
<p style="text-align: justify !important;">The basic premise behind such an attack is that you have a service (e-service) to be provided to citizens over Internet like their own health records for example. The provider would have some finite amount of bandwidth and computing power at the backend of the service correlating to the average load on the service. In a distributed denial of service attack, the attacker uses compromised computing devices (commonly known as a bot) to access the Internet service. The botnet, which is a collection of such bots could be having thousands or millions of such devices that simultaneously access the service. The service provider is not able to distinguish the normal traffic from the bot traffic and often the server crashes under the heavy load. For a normal user trying to access the service, the service is unavailable because of the finite resources of the server being exhausted by the bot traffic. Hence, it is called a denial of service attack.</p>
<p style="text-align: justify !important;">Hence, when a city, state or a nation is considering providing an eservice to citizens it could witness such attacks. One strategy to mitigate such attacks is to have tracking of the server traffic for any anomalies and having redundancy available in the system. This is achieved many times by putting the service on a cloud, which can tolerate such traffic fluctuations.</p>
<p><strong>3. Data leak and breaches</strong></p>
<p style="text-align: justify !important;">Many health systems or systems require some kind of authentication mechanism to log in to the system in order to access the service. Many a times these are text password based systems behind which, important patient profile or health records information is stored. The largest of the companies like that of Google, Microsoft etc have seen attacks where the attacker is able to leak the passwords of millions of their customers. Such scenarios result in massive breach of data privacy and compromise for customers.</p>
<p style="text-align: justify !important;">Good security practices, proper encryption of data and regular updates of the system are some of the key considerations for avoiding such instances. Nowadays, two-factor authentication has become a standard practice for making the authentication systems more robust. However, still some user awareness is needed to opt for better security practices whenever possible.</p>
<p><strong>4. Hacking medical devices and health system</strong></p>
<p style="text-align: justify !important;">If we look at the building blocks of the health systems, where information technology is deeply integrated. We have already covered the health information systems, eservices and patient interface of authentication into the services. However, increasingly we hear about Internet of Things (IoT) devices in the health sector domain. Which means the integration of Internet services into traditional medical devices or new age devices, which have also connectivity. For example, a thermometer which can send the temperature data to your phone or a stethoscope which can record the patient breathing sound and upload in a server for finding patterns of lung diseases. These are powerful use cases and provide great opportunity to clinicians and care providers, where they have greater computation power available to them and they are able to do more with less. However, these IoT devices are prone to the same kind of attacks as any other communication device or a software program. They can be compromised to show wrong values and totally messing up the diagnosis. There are already such instances. One such instance not related to health sector but important is of the Stuxnet. Stuxnet was designed for the SCADA systems of Iranian nuclear program by USA and Israel in order to delay their nuclear program.</p>
<p><strong>5. Stealing identity information</strong></p>
<p style="text-align: justify !important;">As mentioned in the point 3, about data leaks and breaches at the system level. One problem, which can arise from such an attack, is a further more damaging attack that is stealing of identity information. In India, mobile phones to receive an sms message containing one time password is increasingly becoming a standard practise because of being cost effective, simple and secure. Any such application, which you may install on your phone, can also get access to the sms and other features of your phone. Meaning the incoming sms or calls can also be stolen by this application to complete the transaction on your behalf. As increasingly we have to prove ourselves using biometrics or passwords to online systems. It is possible for the attackers to steal these credentials and access our records without our knowledge. Hence, any third party applications that we install on our devices (especially phone) , we need to be very careful about the type of access control they have on our devices.</p>
<p><strong>6. Implantable medical devices with communication interfaces:</strong></p>
<p style="text-align: justify !important;">In 2007, the former US Vice President, Dick Cheney’s implanted pacemaker’s wireless communication was disabled fearing a terrorist attack. This sounds like science fiction to many but incident has already happened ten years back! Many of the medical devices are built with a communication interface and it is quite normal for a typical pacemaker or other such devices to have a Bluetooth or a similar communication technology based interface for remote diagnosis and other purposes. While, the communication ability of such a device was planned for looking at the state of the pacemaker it was not designed with keeping security in mind. Hence, it is possible that someone can connect to a critical device like pacemaker and shuts it down remotely.</p>
<p style="text-align: justify !important;">One more reason that such exploits are possible increasingly as computing is becoming cheaper. What seems strong security today might not be strong tomorrow. However, an implantable device might stay in the patient’s body for tens of years. Hence, we need to have a long-term view on the communication interfaces and their capabilities on such devices. We need to make considerations on control and information capabilities of these interfaces. Misuse of control capabilities can lead to even death and misuse of information capabilities can lead to breach of patient privacy.</p>
</div>




			</div> 
		</div>
	</div> 
</div></div>
		<div id="fws_69aa58e6e94b6"  data-column-margin="default" data-midnight="dark"  class="wpb_row vc_row-fluid vc_row"  style="padding-top: 0px; padding-bottom: 0px; "><div class="row-bg-wrap" data-bg-animation="none" data-bg-animation-delay="" data-bg-overlay="false"><div class="inner-wrap row-bg-layer" ><div class="row-bg viewport-desktop"  style=""></div></div></div><div class="row_col_wrap_12 col span_12 dark left">
	<div  class="vc_col-sm-12 wpb_column column_container vc_column_container col no-extra-padding"  data-padding-pos="all" data-has-bg-color="false" data-bg-color="" data-bg-opacity="1" data-animation="" data-delay="0" >
		<div class="vc_column-inner" >
			<div class="wpb_wrapper">
				
<div class="wpb_text_column wpb_content_element " >
	<p><span style="color: #0071b2;"><strong>Way forward: why Internet is the new breeding ground for crime?</strong></span></p>
<p style="text-align: justify !important;">The law of the land governs the Internet in every country and hence the legal regime globally is very fragmented. However, a user of Internet does not see any borders or walls and so is the criminal. They build their criminal businesses where they do not fear strict government action and often for paltry sums the user or the national law enforcement agencies do not pursue the criminal cases cross border.</p>
<p style="text-align: justify !important;">On top of it newer crypto currencies like Bitcoins, makes it easy to make such transaction in an anonymous manner. Dark net marketplaces provide a breeding ground for criminals to conduct illegal transactions of billions of dollars without getting caught. So, the three important components, weak legal enforcement, anonymous currency and secret marketplaces are enabling the cyber crime to flourish. If we want to slow it down, we will need greater international collaboration among lawmakers and user awareness at all levels.</p>
</div>




			</div> 
		</div>
	</div> 
</div></div>
		<div id="fws_69aa58e6e9b2e"  data-column-margin="default" data-midnight="dark"  class="wpb_row vc_row-fluid vc_row"  style="padding-top: 0px; padding-bottom: 0px; "><div class="row-bg-wrap" data-bg-animation="none" data-bg-animation-delay="" data-bg-overlay="false"><div class="inner-wrap row-bg-layer" ><div class="row-bg viewport-desktop"  style=""></div></div></div><div class="row_col_wrap_12 col span_12 dark left">
	<div  class="vc_col-sm-12 wpb_column column_container vc_column_container col no-extra-padding"  data-padding-pos="all" data-has-bg-color="false" data-bg-color="" data-bg-opacity="1" data-animation="" data-delay="0" >
		<div class="vc_column-inner" >
			<div class="wpb_wrapper">
				
<div class="wpb_text_column wpb_content_element " >
	<p><span style="color: #0071b2;"><strong>Reference:</strong></span><br />
<strong>(i)</strong> <a href="https://www.wsj.com/articles/SB10001424053111903480904576512250915629460">https://www.wsj.com/articles/SB10001424053111903480904576512250915629460</a><br />
<strong>(ii)</strong> <a href="http://labs.sogeti.com/how-many-defects-are-too-many/">http://labs.sogeti.com/how-many-defects-are-too-many/</a><br />
<strong>(iii)</strong> <a href="https://www.ted.com/talks/mikko_hypponen_fighting_viruses_defending_the_net/transcript?language=en">https://www.ted.com/talks/mikko_hypponen_fighting_viruses_defending_the_net/transcript?language=en</a><br />
<strong>(iv)</strong> <a href="https://hackerone.com">https://hackerone.com</a><br />
<strong>(v)</strong> <a href="https://en.wikipedia.org/wiki/Zero-day_(computing)">https://en.wikipedia.org/wiki/Zero-day_(computing)</a><br />
<strong>(vi)</strong> <a href="https://en.wikipedia.org/wiki/Cyberweapon">https://en.wikipedia.org/wiki/Cyberweapon</a><br />
<strong>(vii)</strong> <a href="https://en.wikipedia.org/wiki/Ransomware">https://en.wikipedia.org/wiki/Ransomware</a><br />
<strong>(viii)</strong> <a href="https://en.wikipedia.org/wiki/Bitcoin">https://en.wikipedia.org/wiki/Bitcoin</a><br />
<strong>(ix)</strong> <a href="http://www.csoonline.com/article/3033160/security/ransomware-takes-hollywood-hospital-offline-36m-demanded-by-attackers.html">http://www.csoonline.com/article/3033160/security/ransomware-takes-hollywood-hospital-offline-36m-demanded-by-attackers.html</a><br />
<strong>(x)</strong> <a href="https://www.theguardian.com/technology/2016/feb/17/los-angeles-hospital-hacked-ransom-bitcoin-hollywood-presbyterian-medical-center">https://www.theguardian.com/technology/2016/feb/17/los-angeles-hospital-hacked-ransom-bitcoin-hollywood-presbyterian-medical-center</a><br />
<strong>(xi)</strong> <a href="http://innovatiocuris.com/looming-danger-of-ransomware/">http://innovatiocuris.com/looming-danger-of-ransomware/</a><br />
<strong>(xii)</strong> <a href="http://www.bbc.com/news/technology-24608435">http://www.bbc.com/news/technology-24608435</a></p>
</div>




			</div> 
		</div>
	</div> 
</div></div>
		<div id="fws_69aa58e6eaa9b"  data-column-margin="default" data-midnight="dark"  class="wpb_row vc_row-fluid vc_row"  style="padding-top: 0px; padding-bottom: 0px; "><div class="row-bg-wrap" data-bg-animation="none" data-bg-animation-delay="" data-bg-overlay="false"><div class="inner-wrap row-bg-layer" ><div class="row-bg viewport-desktop"  style=""></div></div></div><div class="row_col_wrap_12 col span_12 dark left">
	<div  class="vc_col-sm-12 wpb_column column_container vc_column_container col no-extra-padding"  data-padding-pos="all" data-has-bg-color="false" data-bg-color="" data-bg-opacity="1" data-animation="" data-delay="0" >
		<div class="vc_column-inner" >
			<div class="wpb_wrapper">
				
<div class="wpb_text_column wpb_content_element " >
	<p>Want to write for InnoHEALTH? send us your article at  <a href="mailto:magazine@innovatiocuris.com">magazine@innovatiocuris.com</a></p>
</div>




			</div> 
		</div>
	</div> 
</div></div>
<p>The post <a href="https://innohealthmagazine.com/2017/issues/cyber-security-threats/">Upcoming Cyber Security Threats in Health Sector</a> appeared first on <a href="https://innohealthmagazine.com">InnoHEALTH magazine</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://innohealthmagazine.com/2017/issues/cyber-security-threats/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">2359</post-id>	</item>
	</channel>
</rss>
