john_dix
Editor in Chief

A matter of life and death

Opinion
Aug 16, 20043 mins

In a two-year span beginning in 1985, a type of computer-controlled radiation therapy machine called the Therac-25 maimed or killed six patients by wrongly delivering massive doses of radiation.

While an extreme example, computer problems in healthcare can have dire consequences, which we have pointed out in our string of stories about problems applying software patches to medical systems (herehere and here).

These stories have touched off a firestorm online, both in our own forums  and on Slashdot.

The issue is a classic Catch-22 that has resulted in industry paralysis. Suppliers say they can’t issue timely software patches because extensive evaluation is needed to ensure the patches don’t cause more problems than they fix, and healthcare organizations have to patch to stay in compliance with HIPAA and other regulations.

The answer isn’t as simple as isolating systems from open networks or abandoning Windows. Going back to the era where equipment didn’t talk to anything else is out of the question, as one expert posted: “The more advanced features you want a clinical system to provide, the more that system needs to integrate with other systems. It’s nice to be standing by the patient’s bed and see monitoring data. It’s even better to be able to export that data to another system so it’s more useful or display it on a Web site so MDs can see it. All of this requires networking capability, and Microsoft (like it or not) is considered a leader in the field for server software.”

Making matters worse, however, is all the finger-pointing. Vendors decry hospital security practices, and hospitals say vendors don’t get it. For example: “As a senior [field service engineer] with a large healthcare equipment vendor, it never stops amazing me how the hospital is pushing their lack of IT security off on the vendors.”

And this from a hospital worker: “Vendors don’t know the communication requirements of their own system or state them so broadly as to be useless.”

What is needed is an ongoing forum on the subject. But it is heartening to see the FDA championing the cause at conferences like the Department of Veterans Affairs event last week (see story).

As one poster from a vendor said: “Is there an easy solution? Yes, allow IT to patch patient equipment. Is it a good solution? No, I think it’s dangerous to the patients.”

We need vendors to step up, the FDA to apply more pressure to get this resolved, and the finger-pointing to be replaced by collaborative effort.