Trump power order exposes a hospital IT blind spot

Advertisement

A new executive order targeting security risks in foreign-made power equipment is prompting at least one health system CIO to scrutinize the technology embedded in hospital facilities infrastructure, an area that historically has fallen outside IT’s view.

President Donald Trump signed the order Aug. 26, declaring a national emergency over what the administration described as growing national security and supply chain risks associated with foreign-produced equipment used in the U.S. bulk-power system.

The order points to the growing electricity demands of data centers, artificial intelligence, advanced manufacturing and defense production as factors increasing the consequences of an attack or supply disruption.

For Muhammad Siddiqui, CIO of Richmond, Ind.-based Reid Health, the order immediately raised questions about equipment that may be connected to a hospital network but was never purchased or evaluated like traditional IT.

“We discussed this exact topic in our executive meeting earlier today, specifically building control systems and other facilities hardware where IT does not have full visibility,” Mr. Siddiqui told Becker’s.

The executive order gives the Energy Department authority to prohibit certain acquisitions, imports, transfers or installations of foreign-produced bulk-power equipment when the equipment or associated technology is tied to a covered foreign entity and presents unacceptable security, sabotage or supply chain risks. The order also allows the department to impose conditions on some equipment already in use, including requirements to identify, isolate, monitor, secure, disconnect, replace or remove it.

Exactly how far those powers will extend into hospitals remains uncertain.

The order defines the bulk-power system around the interconnected electric transmission network and excludes facilities used for local electricity distribution. At the same time, its definition of bulk-power system electric equipment includes backup generators, battery energy storage systems, uninterruptible power supply systems supporting critical infrastructure and industrial control systems, along with associated software, firmware and remote-access capabilities that could create security risks.

“The main detail to watch is the final definition of covered equipment,” Mr. Siddiqui said. “If the rule stays focused on utility-scale power transmission, most hospitals will sit downstream of it. If it covers backup power and industrial controls inside critical buildings, many health systems own hardware in scope that they have not tracked yet.”

The energy secretary has 120 days from the order to publish implementing rules or regulations as needed, including rules identifying countries, companies or equipment that warrant additional scrutiny.

Regardless of the eventual scope, Mr. Siddiqui said the order raises a broader question for healthcare cybersecurity teams: whether connected facilities equipment receives the same scrutiny as medical devices and traditional IT.

“Any equipment with a network port or an internal radio needs the same review we run for clinical software and medical devices,” he said. “We need clear answers on component origin, firmware ownership, vendor remote support paths and our ability to segment the device from core hospital networks.”

That visibility may be difficult to achieve because much of the infrastructure was not originally purchased through IT.

“Procurement explains the gap,” Mr. Siddiqui said.

UPS units, backup generators, automatic transfer switches and chillers may have been purchased years ago using facilities’ capital budgets and installed through general contractors, he said. As a result, those purchases may never have crossed an IT or cybersecurity desk.

“The nameplate on the cabinet identifies the integrator,” he said. “It will not tell you who built the controller board, whose code is on the firmware, or whether an active cellular modem is sitting inside for vendor maintenance.”

Mr. Siddiqui said that distinction separates facilities infrastructure from the traditional assets health system cybersecurity teams have spent years cataloging.

“Most health systems do not have that level of visibility right now,” he said. “The organizations that believe they do are usually thinking of traditional IT and clinical gear. Power and facilities infrastructure sit outside that inventory.”

Any federal requirement to replace equipment could present another challenge.

Large hospital power and cooling systems often remain in service for 15 to 25 years, Mr. Siddiqui said, making rapid replacement impractical for infrastructure essential to patient care.

“Physical replacement will be the real hurdle,” he said. “A hospital cannot take critical electrical infrastructure offline to meet an arbitrary policy timeline.”

The executive order directs federal officials to consider reliability, safety, the availability of secure replacements and continuity of essential services before requiring equipment to be isolated, disconnected, replaced or removed, and allows for phased compliance.

In the meantime, Mr. Siddiqui said hospitals do not need to wait for the federal rules to begin assessing their exposure.

Segmenting facilities systems from core hospital networks and eliminating unnecessary persistent vendor remote access are two steps organizations can take now, he said.

His first recommendation is even more basic.

“Building that inventory is where I would start.”

At the Becker's 11th Annual IT + Revenue Cycle Conference: The Future of AI & Digital Health, taking place September 14–17 in Chicago, healthcare executives and digital leaders from across the country will come together to explore how AI, interoperability, cybersecurity, and revenue cycle innovation are transforming care delivery, strengthening financial performance, and driving the next era of digital health. Apply for complimentary registration now.

Advertisement

Next Up in Health IT

Advertisement