THANK YOU FOR SUBSCRIBING
A featured contribution from Leadership Perspectives: a curated forum reserved for leaders nominated by our subscribers and vetted by our Healthcare Tech Outlook Advisory Board.



Eddie Myers, the current director of cybersecurity at Crothall Healthcare, oversees national cybersecurity programs and initiatives for Crothall Healthcare and for the organizations that avail their services. Being in the healthcare space for 12 years, Eddie gained outstanding acumen in healthcare information technologies, PACS, and healthcare technology management. The team led by Eddie at Crothall Healthcare offers various services, including project management, IT consulting, technical support and security management services to clinical field operations.
Started as a senior field service technician at CHRISTUS Health over a decade ago, Eddie handled various job responsibilities ranging from PACS administrator to program manager, clinical technology services before joining Crothall Healthcare. The program manager role at CREST services has helped him learn more about/focus more on HIPAA regulations and compliance, which led him down the path of cybersecurity.
In an interview with the Healthcare Tech Outlook magazine, Eddie sheds light on some of the current challenges prevailing in the global medical device security space and how companies can convert those challenges into unique opportunities.
What, according to you, are some of the challenges that medical device security companies face today?
One of the major challenges medical device security organizations face today is educating and getting their clients’ IT departments on board with an understanding that there is a substantial difference between handling medical devices and typical IT controls. Patching a medical device is a complex process as it requires OEMs to find and approve the patches.
Forming strategic partnership with a company named Asimily helped Crothall Healthcare overcome this prevailing challenge in the medical device security space. Asimily’s passive asset discovery tools collect real-time insights into hospital traffic and build out unique device profiles for medical devices. Asimily brings Crothall Healthcare clients laser-sharp visibility into their connected medical device profiles. Asimily’s threat detection tools assess risks, prioritize actions, and develop mitigation strategies to reduce security vulnerabilities through state-of-the-art machine learning and help Crothall Healthcare walk away from conventional methods of relying on computers to control medical devices, figure out the operating system and current patches, and reach out to the OEMs for the MDS.
Can you please walk us through some of the latest projects you have been working on?
Rolling out Asimily to a good chunk of our clients gives us real-time visibility into the client’s data, which helps us build out unique device profiles and match them up with our CMMS. In addition, it enables us to differentiate between identical devices in the same organization. Conducting a thorough gap analysis with Asimily in our CMMS will lead to ultimately integrating these device profiles into our CMMS.
As a medical device security expert, how do you respond to a cyberattack event?
Crothall Healthcare is an independent service organization, and we do not own medical devices or the network. During the event of cyberattacks, we ensure that we are operating under our clients’ incident response plan and a vital part of it. We would fill in where needed during an incident response.
“One of the major challenges medical device security organizations face today is educating and getting their clients' IT departments on board with an understanding that there is a substantial difference between handling medical devices and typical IT controls”
How do you make sure that these medical devices are secure?
The first step of securing medical devices during cyberattacks is ensuring that you take them off the network and figure out what exactly happened. There were many past incidents where government agencies showed up and took the hard drive for forensic analysis during such events. Knowing how to handle this is the next step toward ensuring medical device security. Having the wherewithal to bring that piece of equipment back up and ensuring that it is clean of any malware can help to put it back on the network and patient care safely.
On top of that, our strategic partners, including Asimily, proactively follow a plethora of threat intelligence agencies such as CISA that are relentlessly on a mission to track device vulnerabilities and put them into their algorithms. We leverage these algorithms to warn our clients beforehand about potential vulnerabilities with their devices.
How do you envision the future of the medical device security industry?
The medical device security industry will gain more traction in the coming years. Employing “security-by-design” thinking to incorporate cybersecurity features into new products is going to be the next big thing in this era of connected devices, unlike in the past when medical device manufacturers were completely unconcerned about the security part. It is inevitable to initiate productive discussions on the same to bring this into action.
Where do you think the medical devices are heading when using technologies such as IoT, AI, or any latest technologies?
Hospitals are leveraging technologies such as AI and IoT to make operations more hassle-free. The increase in the use of wireless connected devices and their growing popularity is a positive trend in this direction. Unfortunately, these wireless devices are not free from system failures and can be manipulated. Therefore, it is critical for hospitals to make sure that the end user knows how to use them during a system failure, as it might be a life-or-death situation. A backup plan should be in place to beat the situation.
What piece of advice would you like to give to your fellow peers in the medical device security space?
Securing medical devices will become a priority when we connect them with our family’s security. Considering that our families will also be beneficiaries of the same will make us ensure that they are error-free and stay ahead of the game. It is crucial to ensure that medical devices are free from vulnerabilities to protect the lives of people, including our dear ones.