patients, pacemakers, and implantable defibrillators · patients, pacemakers, and implantable...

37
Patients, Pacemakers, and Implantable Defibrillators: Human Values and Security for Wireless Implantable Medical Devices Tamara Denning 1 , Alan Borning 1 , Batya Friedman 1 , Brian Gill 2 , Tadayoshi Kohno 1 , William H. Maisel 3

Upload: others

Post on 24-Sep-2020

27 views

Category:

Documents


0 download

TRANSCRIPT

Page 1: Patients, Pacemakers, and Implantable Defibrillators · Patients, Pacemakers, and Implantable Defibrillators: Human Values and Security for Wireless Implantable Medical Devices Tamara

Patients, Pacemakers, and Implantable Defibrillators:

Human Values and Security for

Wireless Implantable Medical Devices

Tamara Denning1, Alan Borning1, Batya Friedman1,

Brian Gill2, Tadayoshi Kohno1, William H. Maisel3

Page 2: Patients, Pacemakers, and Implantable Defibrillators · Patients, Pacemakers, and Implantable Defibrillators: Human Values and Security for Wireless Implantable Medical Devices Tamara

Implantable Medical Devices

2

Over 25 million US citizens depend upon

them for life critical functions (2001)

Pacemakers, ICDs, Neurostimulators,

Drug Pumps

Wireless

Page 3: Patients, Pacemakers, and Implantable Defibrillators · Patients, Pacemakers, and Implantable Defibrillators: Human Values and Security for Wireless Implantable Medical Devices Tamara

Unique Characteristics

3

Physicality External DeviceExternal

EnvironmentEmbodied

Opt-Out Yes – Turn it offYes – Leave the

environmentNo – Implanted in

the body

Usage At will When presentAlways – Even

when unconscious

Page 4: Patients, Pacemakers, and Implantable Defibrillators · Patients, Pacemakers, and Implantable Defibrillators: Human Values and Security for Wireless Implantable Medical Devices Tamara

Unique Characteristics

4

Physicality External DeviceExternal

EnvironmentEmbodied

Opt-Out Yes – Turn it offYes – Leave the

environmentNo – Implanted in

the body

Usage At will When presentAlways – Even

when unconscious

Page 5: Patients, Pacemakers, and Implantable Defibrillators · Patients, Pacemakers, and Implantable Defibrillators: Human Values and Security for Wireless Implantable Medical Devices Tamara

Unique Characteristics

5

Physicality External DeviceExternal

EnvironmentEmbodied

Opt-Out Yes – Turn it offYes – Leave the

environmentNo – Implanted in

the body

Usage At will When presentAlways – Even

when unconscious

Page 6: Patients, Pacemakers, and Implantable Defibrillators · Patients, Pacemakers, and Implantable Defibrillators: Human Values and Security for Wireless Implantable Medical Devices Tamara

Unique Characteristics

6

Physicality External DeviceExternal

EnvironmentEmbodied

Opt-Out Yes – Turn it offYes – Leave the

environmentNo – Implanted in

the body

Usage At will When presentAlways – Even

when unconscious

Page 7: Patients, Pacemakers, and Implantable Defibrillators · Patients, Pacemakers, and Implantable Defibrillators: Human Values and Security for Wireless Implantable Medical Devices Tamara

Access Control: System Goals

Authorized Clinical Access

Emergency Access

Security

7

Page 8: Patients, Pacemakers, and Implantable Defibrillators · Patients, Pacemakers, and Implantable Defibrillators: Human Values and Security for Wireless Implantable Medical Devices Tamara

8

Is security necessary?

Page 9: Patients, Pacemakers, and Implantable Defibrillators · Patients, Pacemakers, and Implantable Defibrillators: Human Values and Security for Wireless Implantable Medical Devices Tamara

Unauthorized Wireless Changes: Can Someone Do It?

(Halperin et al. [2008])

• Obtain serial number, patient name, diagnosis

• Turn off therapies

• Induce cardiac fibrillation

9

Unauthorized wireless communications using custom hardware at short range (centimeters):

(Risk to patients today is low)

Page 10: Patients, Pacemakers, and Implantable Defibrillators · Patients, Pacemakers, and Implantable Defibrillators: Human Values and Security for Wireless Implantable Medical Devices Tamara

Unauthorized Wireless Changes: Would Someone Do It?

10

March 28, 2008

Hackers Assault Epilepsy Patients via Computer“RyAnne Fultz, 33, says she suffered her worst epileptic attack in a year when she clicked on the wrong post at a forum run by the nonprofit Epilepsy Foundation.”

January 11, 2008

Polish teen derails tram after hacking train network: Turns city network into Hornby set“He treated it like any other schoolboy might a giant train set, but it was lucky nobody was killed. Four trams were derailed, and others had to make emergency stops that left passengers hurt.”

Page 11: Patients, Pacemakers, and Implantable Defibrillators · Patients, Pacemakers, and Implantable Defibrillators: Human Values and Security for Wireless Implantable Medical Devices Tamara

11

Technical Approaches (Cherukuri et al. [2003], Denning et al. [2008],

Gupta et al. [2006], Rasmussen et al. [2009], Schechter [2010])

• Passwords

• Physical Tokens (e.g., key card)

• Fail-Open

• Proximity-Based Authentication

• Physiological Keying

• Criticality-Aware

Page 12: Patients, Pacemakers, and Implantable Defibrillators · Patients, Pacemakers, and Implantable Defibrillators: Human Values and Security for Wireless Implantable Medical Devices Tamara

How do we decide?

12

Page 13: Patients, Pacemakers, and Implantable Defibrillators · Patients, Pacemakers, and Implantable Defibrillators: Human Values and Security for Wireless Implantable Medical Devices Tamara

The Human Factor

Real people in their daily lives

13

http://www.flickr.com/photos/dharmasphere/http://www.flickr.com/photos/walkingthedeepfield/

Page 14: Patients, Pacemakers, and Implantable Defibrillators · Patients, Pacemakers, and Implantable Defibrillators: Human Values and Security for Wireless Implantable Medical Devices Tamara

Value Sensitive Design(Friedman et al. [2006], Miller et al. [2007])

Methodology to incorporate human values into design

14

Methodologies

Value Dams and Flows

Values

Sustainability

Affordability

Equality

Aesthetics

Autonomy

Solitude

Page 15: Patients, Pacemakers, and Implantable Defibrillators · Patients, Pacemakers, and Implantable Defibrillators: Human Values and Security for Wireless Implantable Medical Devices Tamara

13 interviews with pacemaker and ICD patients (+3 pilot

interviews)

• 8 male, 5 female

• Age 67.9

• 9 pacemakers, 4 ICDs

• ~2nd device

• 7.8 years with IMD

15

Semi-structured Interview

• Would you say that you like any of these systems?

• Would you say that you dislike any of these systems?

• If you were given a choice of systems, which system or system would you choose?

• Value questions (e.g., privacy, autonomy, safety, security, health)

QUESTIONS DEMOGRAPHICS

Page 16: Patients, Pacemakers, and Implantable Defibrillators · Patients, Pacemakers, and Implantable Defibrillators: Human Values and Security for Wireless Implantable Medical Devices Tamara

16

System Mockups

Security Approach

Mockup System

Password & Body Modification

Patient Behavior Change

Patient-Passive

Page 17: Patients, Pacemakers, and Implantable Defibrillators · Patients, Pacemakers, and Implantable Defibrillators: Human Values and Security for Wireless Implantable Medical Devices Tamara

Passwords + Body Modifications: Medical Alert Bracelet

17

Medical alert bracelet with engraved password – using password gives access to IMD

Page 18: Patients, Pacemakers, and Implantable Defibrillators · Patients, Pacemakers, and Implantable Defibrillators: Human Values and Security for Wireless Implantable Medical Devices Tamara

18

Passwords + Body Modifications: Tattoo

Tattoo with password as scannable 2D barcode – scanning barcode gives access to IMD

Page 19: Patients, Pacemakers, and Implantable Defibrillators · Patients, Pacemakers, and Implantable Defibrillators: Human Values and Security for Wireless Implantable Medical Devices Tamara

19

Passwords + Body Modifications: UV-Visible Tattoo

Tattoo with password as scannable 2D barcode, tattooed with ink that is only visible under a UV light – scanning barcode password gives access to IMD

(Schechter [2010])

Page 20: Patients, Pacemakers, and Implantable Defibrillators · Patients, Pacemakers, and Implantable Defibrillators: Human Values and Security for Wireless Implantable Medical Devices Tamara

20

Passwords + Body Modifications: UV-Visible Tattoo

Tattoo with password as scannable 2D barcode, tattooed with ink that is only visible under a UV light – scanning barcode password gives access to IMD

(Schechter [2010])

Page 21: Patients, Pacemakers, and Implantable Defibrillators · Patients, Pacemakers, and Implantable Defibrillators: Human Values and Security for Wireless Implantable Medical Devices Tamara

RegularEmergency and

WarningPatient-Specified

Functionality

Wristband acts as access control – remove wristband for emergency access

21

Patient Behavior Change: Wristbands(Denning et al. [2008])

Page 22: Patients, Pacemakers, and Implantable Defibrillators · Patients, Pacemakers, and Implantable Defibrillators: Human Values and Security for Wireless Implantable Medical Devices Tamara

22

Passive with Respect to the Patient: Criticality-Aware IMD

IMD auto-detects emergency situations (GPS location; patient position, e.g. prone; pulse rate) and allows access in emergencies

(Gupta et al. [2006])

Page 23: Patients, Pacemakers, and Implantable Defibrillators · Patients, Pacemakers, and Implantable Defibrillators: Human Values and Security for Wireless Implantable Medical Devices Tamara

23

Passive with Respect to the Patient: Proximity-Based Authentication

Equipment carried by medical personnel (in ambulances and emergency rooms) is placed on patient to gain access

(Cherukuri et al. [2003], Rasmussen et al. [2009])

Page 24: Patients, Pacemakers, and Implantable Defibrillators · Patients, Pacemakers, and Implantable Defibrillators: Human Values and Security for Wireless Implantable Medical Devices Tamara

24

Values that Were Important to Patients

Security

Safety

Privacy

Aesthetics

Psychological Welfare

Convenience

Cultural and Historical Associations

Self-Image and Public Persona

Autonomy and Notification

Page 25: Patients, Pacemakers, and Implantable Defibrillators · Patients, Pacemakers, and Implantable Defibrillators: Human Values and Security for Wireless Implantable Medical Devices Tamara

25

Values that Were Important to Patients

Security

Safety

Privacy

Aesthetics

Psychological Welfare

Convenience

Cultural and Historical Associations

Self-Image and Public Persona

Autonomy and Notification

“I don’t like the idea of wearing the wristband...I already have a defibrillator. Why do I have to wear something on my hand...to show that I have-, that I have a defibrillator, that there’s something wrong with me. No.”

Page 26: Patients, Pacemakers, and Implantable Defibrillators · Patients, Pacemakers, and Implantable Defibrillators: Human Values and Security for Wireless Implantable Medical Devices Tamara

26

Values that Were Important to Patients

Security

Safety

Privacy

Aesthetics

Psychological Welfare

Convenience

Cultural and Historical Associations

Self-Image and Public Persona

Autonomy and Notification

“It would make me feel like an invalid...That I had this thing, like the Scarlet Letter or [laughs].”

Page 27: Patients, Pacemakers, and Implantable Defibrillators · Patients, Pacemakers, and Implantable Defibrillators: Human Values and Security for Wireless Implantable Medical Devices Tamara

27

Values that Were Important to Patients

Security

Safety

Privacy

Aesthetics

Psychological Welfare

Convenience

Cultural and Historical Associations

Self-Image and Public Persona

Autonomy and Notification

“Well, I mean for-, because I’m Jewish it-, I’m not-, a tattoo on the arm to me means a concentration camp. So right away that’s the immediate horror.”

Page 28: Patients, Pacemakers, and Implantable Defibrillators · Patients, Pacemakers, and Implantable Defibrillators: Human Values and Security for Wireless Implantable Medical Devices Tamara

Security Approach

Mockup System Liked(n=11)

Disliked (n=11)

Would choose (n=11)

Password & Body Modification

Medical Alert Bracelet 0% 27% 0%

Visible Tattoo 9% 55% 9%

UV-Visible Tattoo 18% 27% 18%

Patient Behavior Change

Regular 0% 36% 0%

Emergency and Warning 45% 27% 27%

Patient-Selected Functionality 0% 36% 9%

Patient-Passive

Criticality-Aware IMD 27% 18% 27%

Proximity-Based Authentication 27% 0% 27%

28

Mockup Evaluation: Results

Page 29: Patients, Pacemakers, and Implantable Defibrillators · Patients, Pacemakers, and Implantable Defibrillators: Human Values and Security for Wireless Implantable Medical Devices Tamara

Security Approach

Mockup System Liked(n=11)

Disliked (n=11)

Would choose (n=11)

Password & Body Modification

Medical Alert Bracelet 0% 27% 0%

Visible Tattoo 9% 55% 9%

UV-Visible Tattoo 18% 27% 18%

Patient Behavior Change

Regular 0% 36% 0%

Emergency and Warning 45% 27% 27%

Patient-Selected Functionality 0% 36% 9%

Patient-Passive

Criticality-Aware IMD 27% 18% 27%

Proximity-Based Authentication 27% 0% 27%

29

Mockup Evaluation: Results

Page 30: Patients, Pacemakers, and Implantable Defibrillators · Patients, Pacemakers, and Implantable Defibrillators: Human Values and Security for Wireless Implantable Medical Devices Tamara

Security Approach

Mockup System Liked(n=11)

Disliked (n=11)

Would choose (n=11)

Password & Body Modification

Medical Alert Bracelet 0% 27% 0%

Visible Tattoo 9% 55% 9%

UV-Visible Tattoo 18% 27% 18%

Patient Behavior Change

Regular 0% 36% 0%

Emergency and Warning 45% 27% 27%

Patient-Selected Functionality 0% 36% 9%

Patient-Passive

Criticality-Aware IMD 27% 18% 27%

Proximity-Based Authentication 27% 0% 27%

30

Mockup Evaluation: Results

Page 31: Patients, Pacemakers, and Implantable Defibrillators · Patients, Pacemakers, and Implantable Defibrillators: Human Values and Security for Wireless Implantable Medical Devices Tamara

Security Approach

Mockup System Liked(n=11)

Disliked (n=11)

Would choose (n=11)

Password & Body Modification

Medical Alert Bracelet 0% 27% 0%

Visible Tattoo 9% 55% 9%

UV-Visible Tattoo 18% 27% 18%

Patient Behavior Change

Regular 0% 36% 0%

Emergency and Warning 45% 27% 27%

Patient-Selected Functionality 0% 36% 9%

Patient-Passive

Criticality-Aware IMD 27% 18% 27%

Proximity-Based Authentication 27% 0% 27%

31

Mockup Evaluation: Results

Page 32: Patients, Pacemakers, and Implantable Defibrillators · Patients, Pacemakers, and Implantable Defibrillators: Human Values and Security for Wireless Implantable Medical Devices Tamara

Security Approach

Mockup System Liked(n=11)

Disliked (n=11)

Would choose (n=11)

Password & Body Modification

Medical Alert Bracelet 0% 27% 0%

Visible Tattoo 9% 55% 9%

UV-Visible Tattoo 18% 27% 18%

Patient Behavior Change

Regular 0% 36% 0%

Emergency and Warning 45% 27% 27%

Patient-Selected Functionality 0% 36% 9%

Patient-Passive

Criticality-Aware IMD 27% 18% 27%

Proximity-Based Authentication 27% 0% 27%

32

Mockup Evaluation: Results

Page 33: Patients, Pacemakers, and Implantable Defibrillators · Patients, Pacemakers, and Implantable Defibrillators: Human Values and Security for Wireless Implantable Medical Devices Tamara

Security Approach

Mockup System Liked(n=11)

Disliked (n=11)

Would choose (n=11)

Password & Body Modification

Medical Alert Bracelet 0% 27% 0%

Visible Tattoo 9% 55% 9%

UV-Visible Tattoo 18% 27% 18%

Patient Behavior Change

Regular 0% 36% 0%

Emergency and Warning 45% 27% 27%

Patient-Selected Functionality 0% 36% 9%

Patient-Passive

Criticality-Aware IMD 27% 18% 27%

Proximity-Based Authentication 27% 0% 27%

33

Mockup Evaluation: Results

Page 34: Patients, Pacemakers, and Implantable Defibrillators · Patients, Pacemakers, and Implantable Defibrillators: Human Values and Security for Wireless Implantable Medical Devices Tamara

Achieving Coverage: 3 Systems

The Least Disliked: Proximity-Based Authentication

The Most Liked: Emergency and Warning Wristband

Satisfying the Stragglers: UV-Visible Tattoo

34

Page 35: Patients, Pacemakers, and Implantable Defibrillators · Patients, Pacemakers, and Implantable Defibrillators: Human Values and Security for Wireless Implantable Medical Devices Tamara

Multiple System Options: Revisiting the Idea

• Decreased Usability Means Decreased Safety

• Cost of FDA Approval

• Burden of Training

• Expense of Providing, Acquiring, and Maintaining Equipment

• Mental Stress and Complications of Choice35

Page 36: Patients, Pacemakers, and Implantable Defibrillators · Patients, Pacemakers, and Implantable Defibrillators: Human Values and Security for Wireless Implantable Medical Devices Tamara

Contributions

New HCI problem domain: Implantable Medical Devices

Interviews with implantable medical device patients

Qualitative suggestions for security systems for wireless cardiac implantable medical devices

Adaptation of value dams and flows method for choosing complementary systems to maximize patient satisfaction/minimize patient dissatisfaction

36

Page 37: Patients, Pacemakers, and Implantable Defibrillators · Patients, Pacemakers, and Implantable Defibrillators: Human Values and Security for Wireless Implantable Medical Devices Tamara

Questions?

37