3DU Homo ex Machina

Lacey Harbour

DEF CON 32 Creator Stage · Day 1 · Creator Stage

Overview

Lacey Harbour's DEF CON 32 talk, "3DU Homo ex Machina," delves into the rapidly evolving landscape of medical device manufacturing, driven by the convergence of artificial intelligence (AI) and 3D printing technologies. Harbour, with a background spanning molecular biology and regulatory affairs, highlights how these advancements are pushing healthcare towards a future of precise, personalized, and point-of-care medicine. The core of her presentation focuses on the concept of the Medical Device Production System (MDPS), an integrated framework for creating custom medical implants and devices directly within or in close proximity to healthcare delivery organizations (HDOs).

Watch on YouTube

Visual summary for 3DU Homo ex Machina by Lacey Harbour
Visual summary for 3DU Homo ex Machina by Lacey Harbour

Key moments

  1. 0:00 Introduction: AI's impact, regulatory and cybersecurity challenges
  2. 1:15 Defining medical devices by 'intended use' and scrutiny
  3. 2:50 Navigating overwhelming global medical device regulatory updates
  4. 4:15 Challenges of data ownership with EHRs and HDOs
  5. 5:05 FDA's proactive engagement with industry and international groups
  6. 6:10 Introduction to the Total Product Life Cycle (TPLC)
  7. 7:25 Simplified TPLC: design controls to mass production

3DU Homo ex Machina

Speakers: Lacey Harbour

Conference: DEF CON 32

YouTube: https://www.youtube.com/watch?v=YvqWlZK_fks

Overview

Lacey Harbour's DEF CON 32 talk, "3DU Homo ex Machina," delves into the rapidly evolving landscape of medical device manufacturing, driven by the convergence of artificial intelligence (AI) and 3D printing technologies. Harbour, with a background spanning molecular biology and regulatory affairs, highlights how these advancements are pushing healthcare towards a future of precise, personalized, and point-of-care medicine. The core of her presentation focuses on the concept of the Medical Device Production System (MDPS), an integrated framework for creating custom medical implants and devices directly within or in close proximity to healthcare delivery organizations (HDOs).

The talk serves as a critical wake-up call for the cybersecurity community and medical device manufacturers alike. Harbour meticulously outlines the inherent regulatory complexities, data ownership challenges, and significant cybersecurity vulnerabilities emerging from this paradigm shift. She argues that while the technology is advancing at an unprecedented pace, the current regulatory frameworks, quality management systems, and data security practices are woefully unprepared for the dynamic, data-intensive, and highly personalized nature of MDPS. The implications extend beyond mere technical concerns, touching upon profound ethical considerations as humanity increasingly leverages technology to "make new humans" through advanced bio-printing and patient-specific interventions.

This presentation is particularly pertinent for anyone involved in medical device development, healthcare IT, regulatory compliance, or cybersecurity. It underscores the urgent need for a collaborative, multi-stakeholder approach to ensure that the promise of personalized medicine is delivered safely, securely, and ethically. Harbour's insights compel us to re-evaluate traditional security perimeters and regulatory paradigms, urging proactive measures to safeguard patient data, device integrity, and ultimately, human lives in this transformative era of healthcare.

Background

▶ Watch: Introduction: AI's impact, regulatory and cybersecurity challenges (0:00)

The foundation of Lacey Harbour's talk is built upon the undeniable impact of AI on the healthcare ecosystem and the unique challenges posed by an aging global population. As traditional models of care become unsustainable, AI is seen as a necessary catalyst for developing new points of care and treatment standards. However, this integration blurs the lines between regulated and unregulated products, as an identical instrument can be classified as a medical device—and thus subject to stringent controls—solely based on its intended use for medical purposes like diagnosis. This distinction, Harbour warns, is becoming increasingly complex as products become more integrated and their uses more dynamic.

Historically, medical device manufacturers primarily focused on satisfying single regulatory bodies, such as the FDA in the US. Today, the landscape is fragmented and exponentially more complex, with numerous global regulatory entities demanding attention. Harbour, a co-leader in an FDA collaborative community, reveals the overwhelming scale of this challenge: their Natural Language Processing (NLP) system, designed to scan reliable global sources, identified 85 significant regulatory updates or materials within a single year. These mandates require exhaustive analysis, executive buy-in, procedure updates, business risk impact assessments, and extensive training down to the manufacturing line—a "damn near impossible" task for many organizations, regardless of size.

Further complicating the environment is the evolving relationship with customers. The traditional view of a physician or patient as the sole customer is obsolete. Medical devices are now deeply integrated into Health Delivery Organizations (HDOs), which have their own complex regulatory requirements. Moreover, the AI-enabled future of medical devices is inherently data hungry. This introduces a critical dilemma: who owns the vast amounts of patient data, particularly from Electronic Health Record (EHR) companies like Epic? These entities are not always eager to share data with device manufacturers, creating significant hurdles for quality product development and continuous improvement.

Recognizing these shifts, the FDA, in collaboration with international bodies like the International Medical Device Regulators Forum (IMDRF), is actively working to adapt its regulatory stance. The goal is to evolve alongside industry advancements, preventing regulations from stifling innovation. Harbour introduces the concept of the Total Product Life Cycle (TPLC), a fundamental quality management system (QMS) that governs a product from inception to end-of-life. She simplifies this into three core phases: design controls, production and process controls, and continuous feedback loops for improvements (e.g., field failures, non-conformances, corrective actions, regulatory updates). This traditional TPLC, typically a linear and controlled process from prototype to mass production and release, forms the baseline against which the future Medical Device Production System (MDPS) must be contrasted. The existing framework, while robust for standardized manufacturing, is proving inadequate for the agile, personalized, and distributed production models now emerging.

Key Findings

▶ Watch: Navigating overwhelming global medical device regulatory updates (2:50)

Lacey Harbour's talk unveils several critical findings regarding the future of medical device manufacturing and its associated security challenges:

  1. Emergence of the Medical Device Production System (MDPS): The central finding is the advent of the MDPS, a paradigm shift towards precise, personalized, and point-of-care medical device production. This system, heavily reliant on AI and 3D printing, allows for the creation of patient-matched devices, often directly within HDOs. While orthopedic applications (e.g., patient-matched trabecular titanium joint implants) are currently leading the way due to their "human carpentry" nature, the technology is rapidly expanding to more complex applications like 3D printing autologous bone.
  1. Inadequacy of Traditional Regulatory and QMS Frameworks: Harbour explicitly states that existing Total Product Life Cycle (TPLC) and Quality Management System (QMS) models, designed for mass production and linear development, are not equipped to handle the dynamic, feedback-loop-intensive nature of MDPS. The rapid iteration and on-demand production inherent in personalized medicine demand a more agile and adaptive regulatory approach that the industry and regulators are still scrambling to define.
  1. Critical Data Transfer Vulnerabilities: A significant finding is the widespread use of insecure data transfer methods for highly sensitive patient-specific data, particularly DICOM data from PACS servers. Harbour highlights practices such as nurses downloading data onto flash drives, transferring it via personal laptops, or using flash drives for machine file transfer in manufacturing. This creates gaping security holes, exposing patient data and potentially compromising device design integrity.
  1. Complex Data Ownership and Interoperability Challenges: The data-hungry nature of AI-enabled devices clashes with the proprietary control of patient data held by EHR companies like Epic. This creates a significant barrier to establishing robust feedback loops for clinical outcomes, which are crucial for the continuous improvement and safety of personalized devices. Manufacturers need to build intricate relationships with HDOs, EHR providers, and other application vendors.
  1. New Security Perimeters and Threat Vectors: The MDPS introduces novel attack surfaces. The journey from a patient's scan to a 3D-printed implant involves multiple digital transformations (STL file generation, conversion to machine file, printer instructions). Each step, including the unique behaviors of different XYZ zones within a 3D printer and the post-processing stages (e.g., CNC milling), presents opportunities for malicious manipulation, potentially leading to device failure or patient harm.
  1. The "Three Customers Down the Road" Mindset: Manufacturers traditionally focus on immediate customers (physicians/HDOs). Harbour emphasizes the need to consider "three customers down the road," implying a broader responsibility that encompasses the patient, the entire HDO ecosystem, and the long-term safety and effectiveness of the device as it integrates into the patient's life and the MDPS feedback loop. This expanded view necessitates a deeper commitment to consent, privacy, and encryption.
  1. Ethical Imperative of "Homo ex Machina": Harbour concludes with a powerful observation: "We are making new humans." This ethical dimension underscores the profound responsibility associated with personalized medicine. The ability to print autologous bone or custom implants necessitates an unprecedented level of assurance regarding safety, efficacy, and ethical governance, as the integrity of these devices directly impacts human biology and quality of life. The technology is here, or "we need it now, we need it yesterday," but the frameworks to ensure its safe deployment are lagging.

Technical Deep Dive

▶ Watch: Challenges of data ownership with EHRs and HDOs (4:15)

The technical core of Harbour's presentation revolves around dissecting the Medical Device Production System (MDPS), contrasting its emerging complexities with the established Total Product Life Cycle (TPLC). While the TPLC relies on a structured sequence from design controls to production, manufacturing, and final release with feedback loops, the MDPS introduces a far more dynamic and distributed model.

At the heart of the MDPS is the 3D printing technology enabling patient-specific devices. The process typically begins with a designer, often a physician, generating an STL file (Stereolithography or Standard Tessellation Language) based on patient imaging data (e.g., DICOM from a PACS server). This STL file, representing the 3D geometry of the desired implant, is then handed over to a production engineer.

The production engineer's role is critical and introduces a significant point of technical complexity and potential vulnerability. They must convert the generic STL file into a specific machine file suitable for the chosen 3D printer. This conversion involves crucial decisions related to demand planning (optimizing print bed usage for multiple patient devices) and, more importantly, determining the printability of the geometry. Harbour emphasizes that 3D printers are not homogenous; their XYZ zones exhibit "different behavior," meaning a design that theoretically looks sound might fail in a specific printer's physical environment. If unprintable, the design is "kicked back" to the physician, initiating a rapid feedback loop that differs significantly from traditional design control changes.

Once printed, the device undergoes post-processing. This often involves removing support structures, typically using tools like CNC machines or saws. This physical manipulation adds another layer where device integrity could be compromised, either accidentally or maliciously. Following post-processing, a rigorous Quality Control (QC) check is performed. This isn't just about external dimensions but crucially about the internal integrity of the device, as flaws can lead to device failure under weight and movement. This requires advanced internal scanning and testing methodologies.

The data flow within this MDPS is a critical technical concern. Patient DICOM data, residing on PACS servers within HDOs, is the raw material. Harbour highlights current, highly insecure methods of transferring this data to medical device manufacturers:

  • Manual Downloads: Nurses or other HDO staff downloading data.
  • Flash Drives: Physical transfer of data via USB drives, a notorious vector for malware and data loss.
  • Personal Laptops: Manufacturers processing sensitive patient data and machine planning on unsecure personal or work laptops, outside of controlled environments.

This ad-hoc data handling is particularly alarming given the "substantial" data processing required for machine planning. The lack of secure, auditable, and encrypted data pipelines between HDOs and manufacturers represents a profound security gap.

Furthermore, the MDPS envisions a future with feedback from the surgical suite directly into the system. This means clinical outcomes data will be fed back to manufacturers, allowing for continuous iteration and improvement of device designs and printing processes. While invaluable for efficacy, this introduces another complex data channel that must be secure, consented, and private.

Harbour uses examples of existing 3D printing applications to illustrate the MDPS:

  • Trabecular titanium joint implants: These patient-matched implants, designed for bone ingrowth, are already being printed in hospitals by medical device manufacturers. This demonstrates the "point-of-care" aspect already in play.
  • Autologous bone printing: A more advanced application where a 3D-printed mold, based on a patient's defect, is used with a bioreactor to grow new bone. This exemplifies the "making new humans" aspect and the expansion beyond simple orthopedic replacements.

The technical takeaway is that the MDPS, while offering unprecedented customization and efficiency, fragments the traditional "factory floor" into a distributed network of design, production, and feedback loops. Each node in this network—from the PACS server, through data transfer, design software, printer firmware, post-processing machinery, and QC systems—becomes a potential point of attack or failure, demanding a holistic and robust cybersecurity strategy.

Demo / Proof of Concept

▶ Watch: Introduction to the Total Product Life Cycle (TPLC) (6:10)

Lacey Harbour's talk did not include a live demonstration or a proof of concept of an exploited vulnerability within a Medical Device Production System. Instead, the presentation focused on outlining the theoretical framework of the MDPS, illustrating its components with schemas and examples of existing 3D-printed medical devices (like trabecular titanium joint implants and concepts for autologous bone printing). The speaker's intent was to describe the current state and future trajectory of medical device manufacturing, highlighting the potential cybersecurity risks and regulatory gaps rather than demonstrating a specific attack vector or exploit in action. The visual aids and descriptions served to explain the complex interdependencies and data flows within this emerging ecosystem.

Defensive Implications

▶ Watch: Simplified TPLC: design controls to mass production (7:25)

The advent of the Medical Device Production System (MDPS) necessitates a complete overhaul of defensive strategies for HDOs, medical device manufacturers, and regulatory bodies. The fragmented, personalized, and data-intensive nature of this new paradigm introduces unique and critical vulnerabilities that demand immediate attention.

  1. Secure Data Pipelines and Protocols: The most glaring defensive imperative is to eliminate insecure data transfer methods. Flash drives, personal laptops, and unencrypted network transfers for sensitive DICOM data must be replaced with robust, end-to-end encrypted, and authenticated data pipelines. This requires standardized, secure protocols for data exchange between PACS servers in HDOs and manufacturer design/production systems. Implement zero-trust architectures for data access, ensuring that only authorized personnel and systems can access patient-specific information and device designs.
  2. Supply Chain Integrity and Trust: The MDPS extends the supply chain into the HDO and beyond. Defenders must apply rigorous security checks at every stage:
  • Design Software: Ensure the integrity of software used to generate STL files. Malicious code could introduce subtle flaws into a patient's implant design.
  • File Conversion: Secure the conversion process from STL to machine-specific files (e.g., G-code). Tampering here could alter print parameters, leading to structural weaknesses or incorrect dimensions.
  • 3D Printer Security: Address the security of the 3D printers themselves. This includes securing printer firmware against unauthorized modifications, implementing access controls to prevent unauthorized print jobs, and monitoring for anomalous behavior in the XYZ zones that could indicate manipulation.
  • Post-Processing Equipment: Secure CNC machines and other tools used for support removal, as these could be exploited to damage or alter the final device.
  • Quality Control Systems: Protect QC systems from data manipulation, ensuring that internal integrity checks are accurate and cannot be bypassed.
  1. Enhanced Data Governance, Privacy, and Consent: Given the highly personalized nature of MDPS, patient data privacy (e.g., HIPAA, GDPR compliance) is paramount. Robust mechanisms for obtaining and managing patient consent for data use, especially for feedback loops from clinical outcomes, are essential. Data must be encrypted at rest and in transit, with strict access controls and anonymization techniques applied where appropriate, particularly when sharing data for research or generalized improvement purposes.
  2. Regulatory Adaptation and Collaboration: Cybersecurity professionals must actively engage with and contribute to evolving regulatory frameworks from bodies like the FDA and IMDRF. This involves advocating for security best practices to be embedded into new guidelines for MDPS, rather than retrofitting them later. Participation in collaborative communities, as highlighted by Harbour, is crucial for shaping future standards.
  3. Threat Modeling and Risk Assessment: HDOs and manufacturers need to conduct comprehensive threat modeling exercises specifically for their MDPS implementations. This includes identifying all potential attack surfaces, from patient data acquisition to device implantation, and assessing the likelihood and impact of various threats, including data breaches, device tampering, and denial of service.
  4. Continuous Monitoring and Incident Response: Implement continuous monitoring solutions across the entire MDPS, looking for anomalies in data transfers, system access, and printer operations. Develop rapid incident response plans tailored to medical device security, recognizing that compromised device integrity can have immediate and severe patient safety implications.
  5. Training and Awareness: Human factors remain a significant vulnerability. HDO staff, production engineers, and all personnel involved in the MDPS must receive rigorous training on cybersecurity best practices, secure data handling, and the critical importance of device integrity. This includes educating them on the risks associated with flash drives and personal devices for sensitive data.
  6. Resilience and Redundancy: Design MDPS architectures with resilience in mind. Implement redundancy for critical systems and data, ensuring that a localized failure or attack does not compromise the entire production or data integrity.
  7. Interoperability Security: As devices plug into HDO networks and EHRs, securing these interfaces is crucial. This involves robust API security, secure integration protocols, and continuous vulnerability management for all connected systems.

Ultimately, defending against threats in the MDPS requires a holistic approach that integrates cybersecurity into every phase of the device lifecycle, from initial design to post-market surveillance, with a constant focus on patient safety and data privacy.

Key Takeaways

  • The Medical Device Production System (MDPS), driven by AI and 3D printing, is transforming healthcare towards precise, personalized, and point-of-care medicine, enabling innovations like patient-matched implants and autologous bone printing.
  • Current regulatory frameworks and Quality Management Systems (QMS), designed for traditional manufacturing, are ill-equipped for the dynamic, distributed, and rapid feedback loops inherent in the MDPS, creating significant compliance and oversight challenges.
  • Pervasive insecure data transfer practices, such as the use of flash drives and personal laptops for sensitive DICOM data, introduce critical cybersecurity vulnerabilities that jeopardize patient privacy and device integrity.
  • Medical device manufacturers must expand their security focus beyond their immediate operations to encompass the entire HDO ecosystem, prioritizing consent, privacy, and encryption across all data flows and considering the long-term implications for the patient.
  • The integrity of the 3D printing process itself, from STL file generation and conversion to machine files, printer firmware, and post-processing, presents new attack surfaces that require robust security controls to prevent malicious tampering and ensure device safety.
  • Proactive and collaborative engagement with evolving regulatory bodies like the FDA and IMDRF is essential for shaping adaptive guidelines that foster innovation while ensuring the safety, security, and ethical governance of these "next-gen humanity" devices.

About the Speaker(s)

Lacey Harbour is an expert with a unique and valuable interdisciplinary background. She began her career in molecular biology, providing her with a deep scientific understanding of biological systems and medical concepts. This foundation then led her into the complex realms of regulatory, quality, and clinical studies within the medical device industry. In her talk, she identifies herself as a co-leader of an FDA collaborative community, indicating her active involvement in shaping the future of medical device regulation and quality assurance. Her expertise bridges the gap between scientific innovation, practical manufacturing, and the intricate regulatory landscape, making her a highly informed voice on the challenges and opportunities presented by emerging medical technologies.

All talks from DEF CON 32 Creator Stage