Click to chat
  • Solutions
    • Solutions
    • Artificial Intelligence
    • Data Analytics
    • Epicor for Distribution
    • Epicor for Manufacturing
    • IT Support
    • Managed Services
    • Microsoft 365
    • Microsoft Azure
    • Microsoft Licensing Support
    • Security
  • Innovation
    • Innovation
    • AI for Epicor
    • Cybersecurity
    • Data Analytics
    • Epicor in Azure
    • Epicor Kinetic ERP
    • Microsoft 365
    • Microsoft Azure
    • SaaS
  • Helpdesk
  • Resources
    • Resources
      • Resources
      • 2W Conversations
      • News Releases
      • Product Demo’s
      • Quick Tech Talks
      • Webinars
    • Blogs
  • About 2W
    • About Us
    • Contact Us
    • IT News
  • Join the Team
  • Client Login
  • Solutions
    • Solutions
    • Artificial Intelligence
    • Data Analytics
    • Epicor for Distribution
    • Epicor for Manufacturing
    • IT Support
    • Managed Services
    • Microsoft 365
    • Microsoft Azure
    • Microsoft Licensing Support
    • Security
  • Innovation
    • Innovation
    • AI for Epicor
    • Cybersecurity
    • Data Analytics
    • Epicor in Azure
    • Epicor Kinetic ERP
    • Microsoft 365
    • Microsoft Azure
    • SaaS
  • Helpdesk
  • Resources
    • Resources
      • Resources
      • 2W Conversations
      • News Releases
      • Product Demo’s
      • Quick Tech Talks
      • Webinars
    • Blogs
  • About 2W
    • About Us
    • Contact Us
    • IT News
  • Join the Team
  • Client Login
Contact Us
Home / IT News / Hospitals Need to Strengthen Cybersecurity for Networked Medical Devices

Hospitals Need to Strengthen Cybersecurity for Networked Medical Devices

07/08/21
Categories:
  • Cyberattacks
  • Cybersecurity
  • Cybersecurity compliance program
  • HITRUST
  • NIST
  • Ransomware

According to a recent report from the Department of Health and Human Services (HHS) Office of Inspector General (OIG), Medicare accreditation organizations (AO) need to drastically improve their cybersecurity posture. The report found the Medicare AOs, which derive their requirements from the Conditions of Participation and oversee most Medicare-participating hospitals, rarely use their discretion to examine the cybersecurity of networked devices during their hospital surveys. As a result, Medicare lacks consistent oversight of networked device cybersecurity in hospitals.

The OIG conducted telephone interviews with leadership at the four AOs and sent written questions to Centers for Medicare & Medicaid (CMS) to develop this report. Based on the findings, the OIG recommends that CMS identify and implement an appropriate way to address cybersecurity of networked medical devices in its quality oversight of hospitals in consultation with HHS partners and others.  

Networked medical devices connect to the internet, hospital networks and other medical devices to provide features that improve healthcare and increase the ability of healthcare providers to treat patients. Examples of such devices include systems that obtain archive and communicate with pictures on networks within healthcare facilities like MRIs, systems that monitor patient activity like EKGs, and systems that communicate with clinical laboratory analyzers.  

One expert estimated that a large hospital may have as many as 85,000 medical devices connected to its network, providing a massive attack surface for cybercrooks. In fact, cyberattacks on hospitals increased in 2020, and the first death resulting from a ransomware attack occurred in Germany last September when an attack forced a hospital to turn away a patient in need of a critical care.  

The OIG suggests CMS should work with partners inside and outside the HHS to determine the best method for addressing cybersecurity of networked medical devices in hospitals. For external partners, the National Institute of Standards and Technology (NIST) and the Health Information Trust Alliance (HITRUST) are two cybersecurity agencies CMS should work with. AOs are also available for assistance.  

HITRUST and NIST frameworks can be overwhelming for any organization to tackle on their own. If you need assistance, contact 2W Tech. We have a robust Cybersecurity Compliance Program that will make sure you comply with your industry’s regulations, including HIPAA, HITRUST and NIST. Contact us today to get started.

Read More:

Music Mode Coming to Microsoft Teams

Turn on Multi-Factor Authentication. NOW!

Back to IT News

Copyright © 2025, 2W Technologies, Inc.

2W Tech is a leading technology service provider specializing in cutting-edge solutions for the manufacturing and distribution industry, including Epicor ERP, Epicor P21, IT support and infrastructure, Azure cloud services, Microsoft 365, cybersecurity, artificial intelligence, data analytics, and comprehensive managed technology programs.

Epicor in AzureTM and ResolveIQTM are registered trademarks of 2W Technologies, INC.

As an esteemed Epicor Platinum Elite Partner and a Microsoft Tier 1 Cloud Services Partner, we are dedicated to delivering unparalleled service and support. For more information, please contact us at 262-686-5070 or visit our website here.