CISA warned that software versions 2.7 and prior releases of Philips’ e-Alert contain a security vulnerability that could potentially allow unauthorized users to remotely shutdown systems.
According to the warning, the software does not perform any authentication for critical system functionality, meaning that in the event of a cybersecurity incident, an unauthorized party, who has access to a healthcare facility’s network, would be able to get into the system.
Phillips released its own warning March 29 stating that it has received no reports of exploitation due to this vulnerability and that its software does not pose a risk to patient safety as it is “not a medical device.”
Philips plans a new release to remediate the vulnerability before July 2022, according to CISA.
At the Becker's 11th Annual IT + Revenue Cycle Conference: The Future of AI & Digital Health, taking place September 14–17 in Chicago, healthcare executives and digital leaders from across the country will come together to explore how AI, interoperability, cybersecurity, and revenue cycle innovation are transforming care delivery, strengthening financial performance, and driving the next era of digital health. Apply for complimentary registration now.