Medical Device & Healthcare Systems Security
I have substantial experience with medical-device security, healthcare information systems, and the protection of patient information. My work includes academic research, production software development, commercial security assessments, and expert-witness analysis. I earned my Ph.D. in Computer Science at Johns Hopkins University, where my dissertation, Securing Medical Devices and Protecting Patient Privacy in the Technological Age of Healthcare, addressed the design of secure healthcare technologies and their integration into practical clinical workflows.
My commercial experience includes writing production code deployed in FDA-regulated medical devices and designing cryptographic protocols implemented in production healthcare environments. At Independent Security Evaluators and Harbor Labs, I performed security assessments of products before and after market release. My assessment work included identifying the security properties and policies a system was intended to preserve, examining their implementation, and designing tests to determine whether those protections could be bypassed. Where appropriate, my work also includes evaluating compliance with applicable regulatory requirements and technical standards.
I have identified and demonstrated vulnerabilities in medical devices, including remote-code-execution vulnerabilities. In an assessment of a commercially deployed infusion-pump system, I identified multiple vulnerabilities and developed a working exploit that achieved arbitrary code execution on the device. This work involved investigating the implemented system and experimentally demonstrating the consequences of its security weaknesses.
My research has also addressed patient privacy and access to electronic medical records. As part of a project integrating auditing with access control, I developed a Hadoop-based application for large-scale statistical analysis of electronic-medical-record audit logs. I also designed a web application that automatically generated reports and visualizations for use in consulting. This work examined how audit information could support enforcement of minimum-necessary access to patient information and led to two U.S. patents concerning healthcare privacy-breach prevention.
I have co-designed and published research on authentication technologies intended to improve both security and usability in healthcare settings. In one project, we developed a secure indoor-location system using Bluetooth Low Energy beacons as a secondary authentication mechanism for access to patient records. The design connected location information to a backend system so that a healthcare provider could be presented with records relevant to nearby patients. The work explored how location-aware access controls could support clinical workflows while protecting sensitive information.
In another project, my co-authors and I designed a wearable authentication device that received a Kerberos credential from a modified computer terminal and transferred that credential to other terminals through low-energy electrical signals transmitted over the wearer’s skin. The device was designed to lose its cryptographic secret when removed from the wearer. Published at Financial Cryptography and Data Security, this work addressed the practical problem of repeated authentication as healthcare providers move among computer terminals.
My medical-device work is supported by extensive experience with firmware and physical-device analysis. I have extracted and reverse engineered firmware from dozens of devices as part of my commercial firmware-security work. I also served as technical and development lead for Firmware IQ, which examined firmware updates for security issues before deployment and firmware extracted from devices for evidence of compromise. I maintain a hardware-analysis laboratory supporting firmware extraction, reverse engineering, signal capture, protocol decoding, and component-level investigation.
My expert-witness engagements have included analysis of cryptographic protections and other technical characteristics of surgical devices, as well as software used in hematology-analysis machines. My work has included source-code review, technical analysis, preparation of expert reports, and deposition testimony. Other healthcare-related engagements have involved examination of software-development practices, development histories, and alleged source-code copying.
My broader work on software quality and validation is also relevant to healthcare systems. I developed a methodology for assessing source-code quality that examines implementation reliability, development practices, testing, error handling, and input validation. I also serve as Secretary of the IEEE 7024 Working Group, which is developing the Standard for the Procurement, Verification and Validation, and Life Cycle Management of Forensic Technologies.
← Expert witness experience · Testimony record · Download CV (PDF)
