Skip to main content
Top
Published in:

17-02-2022 | Original Paper

A Cyber-Security Risk Assessment Methodology for Medical Imaging Devices: the Radiologists’ Perspective

Authors: Tom Mahler, Erez Shalom, Arnon Makori, Yuval Elovici, Yuval Shahar

Published in: Journal of Imaging Informatics in Medicine | Issue 3/2022

Login to get access

Abstract

Medical imaging devices (MIDs) are exposed to cyber-security threats. Currently, a comprehensive, efficient methodology dedicated to MID cyber-security risk assessment is lacking. We propose the Threat identification, ontology-based Likelihood, severity Decomposition, and Risk assessment (TLDR) methodology and demonstrate its feasibility and consistency with existing methodologies, while being more efficient, providing details regarding the severity components, and supporting organizational prioritization and customization. Using our methodology, the impact of 23 MIDs attacks (that were previously identified) was decomposed into six severity aspects. Four Radiology Medical Experts (RMEs) were asked to assess these six aspects for each attack. The TLDR methodology’s external consistency was demonstrated by calculating paired T-tests between TLDR severity assessments and those of existing methodologies (and between the respective overall risk assessments, using attack likelihood estimates by four healthcare cyber-security experts); the differences were insignificant, implying externally consistent risk assessment. The TLDR methodology’s internal consistency was evaluated by calculating the pairwise Spearman rank correlations between the severity assessments of different groups of two to four RMEs and each of their individual group members, showing that the correlations between the severity rankings, using the TLDR methodology, were significant (P < 0.05), demonstrating that the severity rankings were internally consistent for all groups of RMEs. Using existing methodologies, however, the internal correlations were insignificant for groups of less than four RMEs. Furthermore, compared to standard risk assessment techniques, the TLDR methodology is also sensitive to local radiologists’ preferences, supports a greater level of flexibility regarding risk prioritization, and produces more transparent risk assessments.
Appendix
This content is only visible if you are logged in and have the appropriate permissions.
Literature
This content is only visible if you are logged in and have the appropriate permissions.
Metadata
Title
A Cyber-Security Risk Assessment Methodology for Medical Imaging Devices: the Radiologists’ Perspective
Authors
Tom Mahler
Erez Shalom
Arnon Makori
Yuval Elovici
Yuval Shahar
Publication date
17-02-2022
Publisher
Springer International Publishing
Published in
Journal of Imaging Informatics in Medicine / Issue 3/2022
Print ISSN: 2948-2925
Electronic ISSN: 2948-2933
DOI
https://doi.org/10.1007/s10278-021-00562-y

How can your team use biomarkers to improve management of AD? (Link opens in a new window)

Our experts explore using biomarker tests and interpreting results, establishing a shared decision-making approach with patients and caregivers, and applying biomarker testing to guide treatment strategies.

This content is intended for healthcare professionals outside of the UK.

Supported by:
  • Lilly
Developed by: Springer Healthcare IME
Register your interest

How can you integrate PET into your practice? (Link opens in a new window)

1.5 AMA PRA Category 1 Credit(s)™

PET imaging is playing an increasingly critical role in managing AD. Our expert-led program will empower you with practical strategies and real-world case studies to effectively integrate it into clinical practice.

This content is intended for healthcare professionals outside of the UK.

Supported by:
  • Lilly
Developed by: Springer Healthcare IME
Register your interest