The advisory relates to a detected vulnerability that “may allow an attacker with physical access to impact confidentiality and integrity of the product.” The vulnerability is that the software uses simple encryption that is not strong enough for the level of protection required.
A security researcher reported this vulnerability to Philips, and the company has also issued a product security advisory stating, “this vulnerability will be addressed by a new software release scheduled for [the first quarter of] 2019.”
Additionally, Philips noted it has not received reports of exploitation of this vulnerability or of clinical use incidents associated with the vulnerability.
More articles on health IT:
Colorado hospital to pay $111K HIPAA settlement
HIMSS taps new chief Americas officer: 4 things to know
4 questions to assess whether blockchain ‘makes sense’ at your hospital
At the Becker's 11th Annual IT + Revenue Cycle Conference: The Future of AI & Digital Health, taking place September 14–17 in Chicago, healthcare executives and digital leaders from across the country will come together to explore how AI, interoperability, cybersecurity, and revenue cycle innovation are transforming care delivery, strengthening financial performance, and driving the next era of digital health. Apply for complimentary registration now.