Business Wire

Armis Identifies the Riskiest Medical and IoT Devices in Clinical Environments

Share

HIMSS Armis, the leading asset visibility and security company, today released new research identifying the top connected medical and IoT devices that are exposed to malicious activity in clinical environments. Data analyzed from the Armis Asset Intelligence and Security Platform, which tracks over three billion assets, found nurse call systems to be the riskiest* IoMT device, followed by infusion pumps and medication dispensing systems. When looking at IoT devices, IP cameras, printers and Voice Over Internet Protocol (VoIP) devices are topping the list.

By 2026, smart hospitals are expected to deploy over 7 million IoMT devices, doubling the amount from 2021. Medical and non-medical devices are increasingly connected, automatically feeding patient data from monitoring devices into electronic records. These connections and communications within a medical environment help improve patient care but also make it increasingly vulnerable to cyberattacks, which could result in the interruption of patient care.

Upon a comprehensive analysis of the data from all connected medical and IoT devices on the Armis Asset Intelligence and Security Platform, several noteworthy conclusions can be drawn:

  • Nurse call systems are the riskiest connected medical device, with 39% of them having critical severity unpatched Common Vulnerabilities and Exposures (CVEs) and almost half (48%) having unpatched CVEs.
  • Infusion pumps are second, with 27% having critical severity unpatched CVEs and 30% having unpatched CVEs.
  • Medication dispensing systems are in third place, with 4% having critical severity unpatched CVEs, but 86% having unpatched CVEs. Moreover, 32% run on unsupported Windows versions.
  • Almost 1 in 5 (19%) connected medical devices are running unsupported OS versions.
  • More than half of IP cameras we monitored in clinical environments have critical severity unpatched CVEs (56%) and unpatched CVEs (59%), making it the riskiest IoT device.
  • Printers are the second riskiest IoT device in clinical environments, with 37% having unpatched CVEs, and 30% having critical severity unpatched CVEs.
  • VoIP devices are in third place. Although 53% of them have unpatched CVEs, only 2% have critical severityunpatched CVEs.

“These numbers are a strong indicator of the challenges faced by healthcare organizations globally. Advances in technology are essential to improve the speed and quality of care delivery as the industry is challenged with a shortage of care providers, but with increasingly connected care comes a bigger attack surface,” said Mohammad Waqas, Principal Solutions Architect for Healthcare at Armis. “Protecting every type of connected device, medical, IoT, even the building management systems, with full visibility and continuous contextualized monitoring is a key element to ensuring patient safety.”

Armis secures all medical assets and patient care environments in some of the largest healthcare delivery organizations around the world:

“Armis appeared to be a good alternative for us because it immediately provided us with visibility into what devices were plugging into the network. It shows us how they are interacting with each other, creates alerts based on observed behavior and enforces firewall rules based on those alerts,” said Brian Schultz, Director of Network Operations and Security, Burke Rehabilitation Hospital.

“Metrics and accountability are key to understanding how to protect the hospital’s network, and Armis has a major role in making the relevant data available to us in an easy-to-access manner. It has definitely filled in the gaps in our security arsenal by uncovering risks we never knew about previously. At first, I thought Armis was a nice-to-have, but now it’s become an integral part of our cyber defense,” said Dr. Michael Connolly, Chief Information Officer (CIO), Mater Misericordiae University Hospital.

KLAS Research recently named Armis a top performer at the 2023 Best in KLAS Software & Services Report for Healthcare IoT Security. To learn more about how Armis enables healthcare organizations to identify and secure IoMT, IoT, OT and IT assets please visit: https://www.armis.com/cybersecurity/healthcare/

Armis is attending HIMSS April 17-21, 2023 in Chicago, IL with a speaking session taking place on Wednesday, April 19, 2023 from 3:45pm - 4:05pm CT titled: Hackers Rush in Where Agents Fear to Tread . To meet with Armis at HIMSS, please visit booth 2276 or Kiosk 4309-48 in the Cyber Command Center.

To understand what role you can play in strengthening cybersecurity for your healthcare organization, book a demo.

*Armis defined the riskiest device types by looking at all connected medical and IoT devices on the Armis Asset Intelligence and Security Platform and identifying which types have the highest percentage of devices with unpatched critical severity Common Vulnerabilities and Exposures ( CVEs).

About Armis

Armis, the leading asset visibility and security company, provides the industry’s first unified asset intelligence platform designed to address the new extended attack surface that connected assets create. Fortune 100 companies trust our real-time and continuous protection to see with full context all managed, unmanaged assets across IT, cloud, IoT devices, medical devices (IoMT), operational technology (OT), industrial control systems (ICS), and 5G. Armis provides passive cyber asset management, risk management, and automated enforcement. Armis is a privately held company and headquartered in California.

To view this piece of content from cts.businesswire.com, please give your consent at the top of this page.

Contact information

Media Contacts:
Rebecca Cradick
Senior Director, Global Communications
Armis
pr@armis.com

About Business Wire

For more than 50 years, Business Wire has been the global leader in press release distribution and regulatory disclosure.

Subscribe to releases from Business Wire

Subscribe to all the latest releases from Business Wire by registering your e-mail address below. You can unsubscribe at any time.

Latest releases from Business Wire

Interactive Brokers Launches Daily Options on the CAC 40® Index2.5.2024 17:00:00 EEST | Press release

Interactive Brokers (Nasdaq: IBKR), an automated global electronic broker, today announced the availability of Daily Options on the CAC 40® index, further expanding Interactive Brokers’ robust product suite. Daily Options on the CAC 40® index provide experienced investors with another means to execute short-term trading strategies and manage exposure to the French stock market. Milan Galik, Chief Executive Officer of Interactive Brokers, commented on the launch, "We are pleased to offer Daily Options on the CAC 40® index, which will allow our clients to balance risk and swiftly adjust their portfolios in response to market movements. At Interactive Brokers, we strive to equip our clients with an array of products to find global opportunities, and this new offering underscores our commitment to providing traders with comprehensive product solutions.” Daily Options on the CAC 40® index cater to growing demand from institutional and retail investors for options with daily expirations. The

AMRA Medical’s Muscle Composition Analysis Used to Evaluate the Effect of Liraglutide Treatment in Obesity2.5.2024 16:35:00 EEST | Press release

AMRA Medical - a health informatics and precision medicine company that is pioneering body composition research through gold-standard MRI-based analysis platforms - collaborated on a study driven by University of Texas Southwestern and University Hospital Cleveland to publish new data revealing the effect of liraglutide treatment on muscle composition in adults with obesity. This press release features multimedia. View the full release here: https://www.businesswire.com/news/home/20240502719692/en/ Credit: Collaboration with Dr. Ian J Neeland, University Hospitals Cleveland. Data from NCT03038620 (ClinicalTrials.gov identifier) analysed with AMRA® Researcher The analysis included 128 diabetes-free adults with obesity who received a lifestyle intervention in addition to being randomized to either a liraglutide (n = 73) or a placebo (n = 55) treatment group. Using the proprietary MRI-based AMRAⓇ Researcher, baseline and follow-up muscle composition analyses were performed, with the prima

Brightcove Integrates New AWS-Powered Generative AI Solution to Enhance Its Award-Winning Customer Service2.5.2024 16:00:00 EEST | Press release

Brightcove (NASDAQ: BCOV), the world’s most trusted streaming technology company, today shared it has implemented Amazon Q Business, a new generative AI assistant on Amazon Web Services (AWS). Using its own public documentation, product, and release notes, Brightcove is leveraging the new assistant internally for real-world use cases applicable to the media and entertainment technology sector. Brightcove is tapping into the technology to build a program to equip its global services and customer success team to further bolster its award-winning customer service. As an early adopter of Amazon Q, Brightcove has launched the “Brightcove Expert Bot,” an AI-powered chatbot embedded into the internal tools, as a new resource for the customer and product support teams. Streamlining its customer support processes enables employees to quickly and effectively find relevant information, solve technical cases, analyze support requests, summarize support tickets, and use those results to help recomm

Power2Drive Europe: Contributing to the Energy Transition With Bidirectional Charging2.5.2024 15:39:00 EEST | Press release

E-mobility is about much more than driving on climate-neutral electricity from renewable sources. The batteries of electric vehicles can be used as temporary storage. And it’s not just vehicle owners who benefit from this: In the medium-term, bidirectional charging can take the burden off distribution grids while making them more flexible. Power2Drive Europe, the international exhibition for charging infrastructure and e-mobility, showcases the latest state of the art. As part of The smarter E Europe, the continent’s largest alliance of exhibitions for the energy industry, it will take place from June 19–21, 2024, at Messe München. The Power2Drive Europe Conference, the industry's meeting point and forum for exchange and discourse among experts, stakeholders, and thought leaders in the new mobility sector, kicks off one day earlier. This press release features multimedia. View the full release here: https://www.businesswire.com/news/home/20240502196803/en/ Power2Drive Europe 2024 highl

Owlet Announces European Medical Certification of Dream SockⓇ2.5.2024 15:37:00 EEST | Press release

Owlet, Inc. (“Owlet” or the “Company”) (NYSE:OWLT), the pioneer of smart infant monitoring, announces the EU medical device certification of Dream Sock. This EU-CE-Mark certification, issued by Owlet’s EU notified body, signifies that Owlet’s Dream Sock has been assessed and certified to meet safety and health requirements set out under EU medical device legislation. With this certification, Owlet plans to expand its medical-device product portfolio to even more caregivers around the world. This EU medical device certification follows two marketing authorizations from the U.S. Food and Drug Administration (the “FDA”), for Dream Sock, with new medical technology for healthy infants over-the-counter without a prescription, and for BabySat Ⓡ, a prescription-only pulse oximeter designed for use with babies that have a pre-existing medical condition. “Our mission to be there for every parent and every baby becomes even more realized with the European medical certification for Dream Sock,” s

In our pressroom you can read all our latest releases, find our press contacts, images, documents and other relevant information about us.

Visit our pressroom
HiddenA line styled icon from Orion Icon Library.Eye