Under the skin: Privacy engineering of medical devices

No ratings

Presented at BSidesAtlanta 2019 by

"Connected Medical Devices (CMDs) help sustain lives, monitor vital signs, improve medical adherence, and offer non-invasive methods of remote monitoring and auto-diagnosing. To provide these directed functionalities, CMDs collect, store, and share vast amounts of patient PII and PHI (medical data). Amid the benefits CMDs provide, privacy however, has become a matter of dispute. It has raised several ethical questions on data security, data ownership, consent, and data usage as more and more insecure products are released into the market and as conglomerates take a capitalistic approach to data usage (CMD providers are known to sell data to insurance companies and pharmaceutical companies without the knowledge or consent of the CMD consumer). This presentation primarily looks at the current state (the types of data collected, software and hardware issues that compromise privacy), reviews the impacts of privacy loss, and evaluates the challenges in implementing privacy controls from both the technical and non-technical standpoints while making a reference to case studies. It also illustrates technical techniques for preserving and enhancing privacy in medical devices. The presentation will also propose policy improvements based on a gap analysis of existing standards laid out by NIST/FDA,etc, and propose principles for privacy engineering."