3,000 Hospitals Vulnerable Due to Pneumatic Tube Flaws

80 percent of hospitals in North America use system

By Chris Miller, Assistant Editor, Facility Market


Vulnerabilities have been discovered in a pneumatic tube system used by more than 3,000 hospitals worldwide, according to the U.S. Cybersecurity and Infrastructure Security Agency (CISA). The report referred to nine critical weaknesses in the tube systems that allow for a complete cyber hijacking of the translogic nexus control panel, which powers the systems created by Swisslog Healthcare. More than 80 percent of hospitals in North America use the system, according to Xtelligent Healthcare Media. Pneumatic tube systems play a critical role in patient care to deliver medications, blood products, and various lab samples across multiple departments. 

A vulnerability could let in complex ransomware attacks while allowing attackers to leak sensitive hospital information. The vulnerabilities in the system, which are called PwnedPiper, can be taken advantage of to access a hospital’s network and take over Nexus control panel stations without proper verification. There has not been any evidence that cyber attackers have abused these newfound vulnerabilities.

Researchers from Armis, a California-based security vendor, found these vulnerabilities and reported them to Swisslog Healthcare on May 1, according to Becker’s Hospital Review. CISA is encouraging all hospitals with this system to take immediate defensive measures against potential cyber attacks. 

Armis gave several examples of the tube systems features and how they could be hacked.

First, the system allows for the authentication of staff members using their RFID cards, and this puts staff records and credentials at risk to potential cyber attackers if the system were to be compromised.

Second, the system supports variable speed transactions which allow for express shipment of more urgent items in one respect, and in another allow for the slow transfer of sensitive items like blood products. If an attacker infiltrated the system, he or she could alter its speed restrictions, which could then damage sensitive items.

Third, the pneumatic tube system has an alert messaging feature that integrates with hospital communications, enabling the notification and tracking of delivered carriers. If an attacker were to exploit this feature, he or she could interfere with the hospital’s workflows.



August 9, 2021


Topic Area: Information Technology


Recent Posts

AI and FM: Insights from the Front Lines

Standford Medicine’s facilities management team discusses the opportunities for and challenges of its efforts to apply AI to projects and processes.


Chippewa Valley Health Cooperative to Build Nonprofit Hospital in Lake Hallie

The facility is projected to open in fall 2027.


84 Percent of Healthcare Organizations Detected a Cyberattack in Past Year

Healthcare facilities remain a target among cyber criminals.


Current Trends in Healthcare Architecture

Key trends include balancing flexible spaces with patient comfort and healing.


North Los Angeles County Regional Center Targeted by Ransomware

There is currently no evidence of identity theft or fraud in relation to this incident.


 
 


FREE Newsletter Signup Form

News & Updates | Webcast Alerts
Building Technologies | & More!

 
 
 


All fields are required. This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.

 
 
 
 

Healthcare Facilities Today membership includes free email newsletters from our facility-industry brands.

Facebook   Twitter   LinkedIn   Posts

Copyright © 2023 TradePress. All rights reserved.