Imagine millions of aging babyboomers, stuffed with all kinds of implanted medical devices that communicate over wireless networks. Life is good or at least not as bad as it could be.
Imagine a coven of resentful GenZ teens, hacking those same devices. Life gets bad.
I’m exaggerating for effect, but WHOI, the ABC TV affiliate in Peoria, Illinois, has a solid story on the vulnerabilities of implanted medical devices.
The story, credited to anchor Jen Cristensen, commendably avoids sensationalism. It notes that there are an estimated 25 million Americans with at least one implanted device, that many of them rely on a wireless connection, and an unencrypted protocol, to send and receive data.
The heart of the story is a hacking experiment by scientists from University of Washington, University of Massachusetts Amherst, and Beth Israel Deaconess Medical Center/Harvard Medical School, to find out how easy it is to hack implanted wireless devices. The full study is online and was presented in May at the IEEE’s Symposium on Security and Privacy.
It’s not easy, and the hacking tools have to be very near to the implanted devices, but they were able to do it.
They tested a Medtronic Maximo DR implanted cardiac defibrillator (ICD), which works as both a defibrillator and pacemaker. Using an antenna, radio hardware, and a PC, the research team were able to locate the ICD, get it to disclose patient information, and download data current and stored data on heart rate and rhythm.
More disturbingly, they could change parameters on the device, such as the patient’s name, turn off the device’s therapy mode (so it wouldn’t respond to life-threatening arrhythmias), and even order to deliver an electric shock.
Granted, it took a diverse team of experts, armed with fair amount of gear, including an oscilloscope, to do all this. There’s some comfort in that, though it could just be they don’t have much experience in hacking.
But computer and networking security, and insecurity is constantly evolving. According to the researchers, improving security and privacy for implanted medical devices (IMDs) will be a challenge: “Improving IMD security and privacy is, however, significantly challenging due to rapidly evolving threat models, trends toward longer-range wireless communication, explorations into multi-agent systems of intercommunicating IMDs, and resource constraints of an IMD’s battery, processor, and memory. Moreover, as we previously observed, there is tension between security (restricted access) and safety (open access in emergency scenarios)…”
The study’s authors proposed several possible “zero-power” defenses, basically using the energy harvesting techniques to send out alerts to the patient when a threat manifests, and to support a strong crypto protocol.
Welcome to Digital Life.




