Vulnerability found in GE anesthesia and respiratory machines

A team of security researchers found a vulnerability in two versions of GE anesthesia and respiratory machines, according to TechCrunch.

Advertisement

When the machines are connected to a hospital network, the vulnerability allows hackers to silence alarms, alter records and change the composition of aspirated gases.

CyberMDX disclosed the vulnerability to GE in late October 2018. GE said versions of its 7100 and 7900 Aestiva and Aespire models were affected. The company did not say how many devices were affected; however, GE does not allow gas composition modification in systems that were sold after 2009.

On July 9, Homeland Security issued an advisory that said the flaws required “low skill level” to exploit.

GE remains confident that there is not risk to patients.

“After a formal risk investigation, we have determined that this potential implementation scenario does not introduce clinical hazard or direct patient risk, and there is not vulnerability with the anesthesia device itself,” a spokesperson for the company told TechCrunch. “Our assessment does not lead us to believe there are patient safety issues.”

More articles on cybersecurity:
Hospital CFOs are stepping into cybersecurity roles
US warns against Microsoft Outlook vulnerability
Smaller health systems struggle to follow cybersecurity best practices

At the Becker's 11th Annual IT + Revenue Cycle Conference: The Future of AI & Digital Health, taking place September 14–17 in Chicago, healthcare executives and digital leaders from across the country will come together to explore how AI, interoperability, cybersecurity, and revenue cycle innovation are transforming care delivery, strengthening financial performance, and driving the next era of digital health. Apply for complimentary registration now.

Register to Attend Webinar

The hidden cost of lost clinical time and how leading health systems are responding

Friday, August 7
12:00 PM - 1:00 PM CDT

Presenters: Kassaundra McKnight-Young, Zebra TechnologiesGregory Carras, Zebra TechnologiesJennifer Gene, Levata

Advertisement

Next Up in Cybersecurity

Advertisement

Comments are closed.