D0N0H4RM Cyber STEM Storytime
Panel
DEF CON 32 Creator Stage · Day 1 · Creator Stage
Overview
The "D0N0H4RM Cyber STEM Storytime" panel at DEF CON 32 brought together a distinguished group of experts from regulatory bodies, federal agencies, and the non-profit sector to address the escalating crisis in healthcare cybersecurity. This critical discussion focused on the increasingly sophisticated and frequent cyberattacks targeting the healthcare ecosystem, the direct impact these attacks have on patient safety and clinical care, and the systemic challenges posed by legacy infrastructure and complex supply chains. The panel emphasized that the threat has evolved beyond mere data privacy concerns to directly jeopardize human lives and the continuity of essential medical services.

Key moments
- 0:00 Introduction to healthcare cybersecurity, medical devices, whistleblowing
- 1:00 Former FDA official on medical device cybersecurity guidance
- 2:00 Theranos whistleblower shares experience and support for others
- 3:00 Arpa H and Darpa's focus on healthcare AI security
- 5:00 Alarming increase in cyberattacks against healthcare sector
- 6:15 Analyzing global supply chain vulnerabilities for medical devices
D0N0H4RM Cyber STEM Storytime
Speakers: Matt Hazlett, Chief Regulatory Officer at Medsec; Erica Chung, Executive Director of Ethics and Entrepreneurship; Andrew Carney, Program Manager at ARPA-H; Nitin Natarajan, Deputy Director of CISA
Conference: DEF CON 32
YouTube: https://www.youtube.com/watch?v=fs0QR7fPnJg
Overview
The "D0N0H4RM Cyber STEM Storytime" panel at DEF CON 32 brought together a distinguished group of experts from regulatory bodies, federal agencies, and the non-profit sector to address the escalating crisis in healthcare cybersecurity. This critical discussion focused on the increasingly sophisticated and frequent cyberattacks targeting the healthcare ecosystem, the direct impact these attacks have on patient safety and clinical care, and the systemic challenges posed by legacy infrastructure and complex supply chains. The panel emphasized that the threat has evolved beyond mere data privacy concerns to directly jeopardize human lives and the continuity of essential medical services.
The talk served as a stark call to action for the cybersecurity community, particularly hackers and researchers, to re-engage with the unique vulnerabilities of medical devices and healthcare infrastructure. Featuring insights from former FDA officials, a prominent whistleblower, and leaders from CISA and ARPA-H, the discussion highlighted the urgent need for collaborative efforts, robust regulatory frameworks, and innovative defensive strategies. It underscored the ethical imperative to protect a sector traditionally considered immune to kinetic warfare, now facing a relentless barrage of digital threats that necessitate a fundamental shift in how cybersecurity is perceived and implemented within healthcare.
Background
▶ Watch: Introduction to healthcare cybersecurity, medical devices, whistleblowing (0:00)
Historically, healthcare institutions, often symbolized by the Red Cross, were universally protected during times of conflict, maintaining a sacred status that transcended geopolitical divides. This long-standing convention of non-aggression against hospitals and medical providers has, however, been shattered in the digital age. As Deputy Director Nitin Natarajan of CISA starkly articulated, "Today we're seeing attacks against healthcare organizations throughout the country," marking a significant and disturbing departure from centuries of established norms. This shift has propelled the healthcare sector into a new era of vulnerability, where cyberattacks are not just an operational nuisance but a direct threat to human life.
The problem is exacerbated by several factors, chief among them the widespread prevalence of legacy systems and mounting technical debt. As highlighted by the panel, it's not uncommon to encounter systems running on outdated platforms, metaphorically akin to "Windows 95" or "Clippy from Office," which lack modern security features and are difficult to patch or upgrade. This creates a vast and easily exploitable attack surface. Furthermore, the healthcare sector's intricate and often opaque supply chains for pharmaceuticals and medical devices present significant challenges. While a 2013 Department of Commerce report began to shed light on global supply chain issues for these critical components, a comprehensive, coalesced understanding of the entire ecosystem's interdependencies remains elusive, making it difficult to identify and mitigate systemic risks.
The issue of medical device safety and integrity also has a compelling backstory, exemplified by the infamous Theranos fraud scandal. Erica Chung, a key whistleblower in the $9 billion fraud, recounted her experience reporting the company to regulators, which ultimately prevented the use of faulty devices on patients. This incident underscores the critical role of individuals willing to speak up against corporate malfeasance and the direct link between device integrity and patient safety. Over the past 15 years, the hacker community has made significant contributions to medical device cybersecurity research, with pioneers like Jack, Jay Radcliffe, Billy Rios, and Kevin Foo famously demonstrating vulnerabilities in pacemakers, insulin pumps, and other devices at conferences like Defcon and Black Hat. Their work spurred significant advancements in FDA policy and national conversations around medical device security, setting a precedent for the impact that independent research can have on public safety.
Key Findings
▶ Watch: Theranos whistleblower shares experience and support for others (2:00)
The panel revealed several critical findings that underscore the severity and evolving nature of cyber threats to healthcare. First and foremost, the volume, frequency, and complexity of attacks against the healthcare sector are increasing globally. CISA Deputy Director Nitin Natarajan emphasized that healthcare consistently ranks among the top three to five sectors targeted by adversaries, including nation-states, cyber terrorists, and cyber criminal organizations. These attackers are motivated by the rich trove of data available—personally identifiable information (PII), billing details, and sensitive patient records—making healthcare facilities a "one-stop shop" for lucrative data breaches.
Crucially, the impact of these attacks has transcended mere data privacy and financial repercussions to directly threaten clinical care and human life. Panelists shared alarming anecdotes from social media forums, where doctors and nurses recounted their experiences during ransomware attacks. These included hospitals being forced to revert to paper charting, nursing staff communicating patient medications from memory, canceled appointments, and patients being unable to access nearby hospitals due to system outages. One nurse's lament, "Vermont here, they never taught me how to paper chart in nursing school. I'm fucked," poignantly illustrated the unpreparedness and direct impact on frontline medical professionals. This represents a significant escalation, where cyber incidents are no longer abstract IT problems but immediate patient safety crises.
The vulnerability is particularly acute in rural America, where healthcare systems are often more critical due to limited access to alternative care, making the consequences of disruption even greater. The panel also highlighted the pervasive issue of technical debt and legacy devices. Many healthcare organizations operate with outdated IT infrastructure, some metaphorically running on "Windows 95," which introduces significant security risks. While some healthcare organizations are beginning to factor cyber risk into merger and acquisition (M&A) processes, budgeting millions to bring acquired systems up to standard, this practice is still a small fraction of overall discussions.
Finally, the panel observed a concerning decline in public, high-profile medical device cybersecurity research from the hacker community in recent years. While venues like the Biohacking Village at DEF CON provide hands-on opportunities, there was a consensus that the impactful, stage-level demonstrations seen a decade ago have become less frequent. This raised the question of whether hackers need more access to medical devices to continue driving critical security advancements, mirroring the past efforts of researchers who significantly influenced FDA policy.
Technical Deep Dive
▶ Watch: Arpa H and Darpa's focus on healthcare AI security (3:00)
The technical challenges facing the healthcare sector are multifaceted, stemming from a unique combination of deeply entrenched legacy infrastructure, complex interdependencies, and a rapidly evolving threat landscape. A central theme emphasized by the panel was the pervasive nature of legacy systems and technical debt. Nitin Natarajan vividly described the presence of systems akin to "Windows 95" or even "Clippy from Office" still in operation. This isn't merely an aesthetic issue; it signifies a massive installed base of hardware and software that is often unpatched, unsupported, and inherently vulnerable to modern cyber threats. The difficulty in upgrading these systems is compounded by their integration into critical clinical workflows, where downtime can have immediate and severe patient safety implications.
The problem of technical debt extends into merger and acquisition (M&A) processes within healthcare. As organizations consolidate, they often inherit disparate IT environments with varying levels of cybersecurity maturity. The panel noted that while some organizations are now budgeting significant sums—"two million, three million, four million" dollars—to remediate the cybersecurity posture of acquired entities, this is far from a universal practice. This financial outlay for remediation underscores the technical complexity of integrating and securing diverse, often outdated, systems post-acquisition. The challenge lies not just in applying patches but in fundamentally modernizing entire IT stacks without disrupting ongoing patient care.
Another critical technical concern is the lack of comprehensive understanding regarding supply chain interdependencies. The healthcare sector relies on a vast network of manufacturers, distributors, pharmaceutical companies, labs, and IT providers. While a 2013 Department of Commerce report examined global supply chain issues for pharmaceuticals and some medical devices, the panel lamented the current inability to "coalesce" information and effectively map these intricate relationships across the entire sector. Without this understanding, identifying single points of failure or entities with disproportionately large market shares—whose compromise could cascade across the entire healthcare ecosystem—remains a significant hurdle. This lack of visibility prevents proactive risk mitigation strategies at a systemic level.
From a regulatory standpoint, Matt Hazlett's work at the FDA highlighted efforts to instill security by design principles into new medical devices. His involvement in writing and implementing the pre-market cybersecurity guidance and training reviewers signifies a foundational shift towards mandating security controls before devices enter clinical use. This guidance is a technical framework outlining requirements for secure development lifecycles, vulnerability management plans, and software bill of materials (SBOMs), aiming to prevent the introduction of new vulnerabilities. However, this primarily addresses new devices, leaving the vast installed base of legacy devices as a persistent technical challenge.
Andrew Carney's role at ARPA-H focusing on healthcare cybersecurity and patient data privacy, alongside his background as a vulnerability researcher and CTF player, indicates a federal push towards advanced technical solutions. His "offensive kind of mindset" is being applied to "supercharge" defensive efforts, suggesting an approach that leverages deep technical understanding of attack vectors to build more resilient systems. This includes exploring novel technologies and methodologies to protect sensitive patient data and ensure the operational integrity of healthcare IT. The call for providing security researchers with better access to medical devices, akin to Apple's programs, further emphasizes the need for technical expertise from the hacker community to uncover vulnerabilities that manufacturers might miss, thus contributing to a more robust vulnerability disclosure program ecosystem for healthcare.
Demo / Proof of Concept
▶ Watch: Alarming increase in cyberattacks against healthcare sector (5:00)
As a panel discussion rather than a technical presentation, "D0N0H4RM Cyber STEM Storytime" did not feature a live technical demonstration or proof of concept. The focus was on a high-level discussion of the challenges, impacts, and strategic directions for healthcare cybersecurity, drawing on the collective expertise and experiences of the panelists.
Defensive Implications
▶ Watch: Analyzing global supply chain vulnerabilities for medical devices (6:15)
The panel outlined several crucial defensive implications and strategies necessary to safeguard the healthcare sector against the rising tide of cyberattacks. A foundational element is the strengthening of regulatory frameworks. Matt Hazlett's insights into the FDA's pre-market cybersecurity guidance and new statutory authorities are paramount. These regulations aim to ensure that new medical devices are designed and manufactured with cybersecurity in mind, embedding security controls from the outset and providing clearer pathways for review and approval. While this addresses future devices, it sets a standard that will gradually improve the overall security posture of the ecosystem.
CISA's role, as articulated by Nitin Natarajan, is to build resilience across the entire healthcare spectrum. This extends beyond hospitals to include medical manufacturing, distribution, pharmaceuticals, labs, blood banks, biotech, health IT, and insurance providers. CISA's efforts involve messaging the evolving threat landscape and fostering collaboration to protect this broad and interconnected infrastructure. The goal is to move beyond reactive measures to proactive resilience building, ensuring that even when attacks occur, critical services can rapidly recover and continue operating.
A significant area for improvement lies in merger and acquisition (M&A) due diligence. The panel stressed that organizations must integrate cyber risk and technical debt assessments into M&A discussions. This means thoroughly evaluating the cybersecurity posture of target entities and explicitly factoring in the costs and efforts required to bring their IT systems up to acceptable security standards. By doing so, organizations can avoid inheriting massive, unmanaged vulnerabilities that could later lead to costly breaches or operational disruptions.
Crucially, there is an urgent need for better mapping of dependencies across the healthcare supply chain. Identifying key entities with large market shares or critical interdependencies is essential for understanding systemic risks. This allows for targeted efforts to "buy down" risk collectively or develop contingency plans for potential failures. Without this comprehensive visibility, the sector remains vulnerable to cascading impacts from the compromise of a single, widely used component or service.
Perhaps one of the most compelling defensive implications was the direct appeal to the hacker community. The panel called for greater hacker engagement in healthcare cybersecurity, echoing the impactful research of earlier generations who exposed critical medical device vulnerabilities. The sentiment was clear: the skills of security researchers are invaluable. To facilitate this, there's a need to increase access to medical devices for researchers, potentially through programs similar to Apple's, or by expanding initiatives like the Biohacking Village. This would empower hackers to identify and responsibly disclose vulnerabilities, thereby driving manufacturers to improve product security.
Finally, the discussion highlighted the indispensable role of whistleblowers and the need for robust support structures. Erica Chung's work with Ethics and Entrepreneurship, Whistleblowers of America, and the Signals Network demonstrates the critical services required for individuals who come forward. These services include mental health support, legal advice, safe housing, and job placement, acknowledging the immense personal and professional toll whistleblowing can take. Investing in infrastructure to address concerns early and protect whistleblowers is a vital defensive measure, as they often provide the earliest warnings of systemic failures or unethical practices that could lead to security compromises or patient harm.
Key Takeaways
- Healthcare is a Prime Target with Dire Consequences: Cyberattacks against the healthcare sector are increasing in volume, frequency, and complexity, directly impacting patient safety, clinical care, and even human life, moving beyond traditional concerns of data privacy and financial loss.
- Legacy Systems and Technical Debt are Systemic Vulnerabilities: The widespread presence of outdated IT infrastructure and significant technical debt creates vast attack surfaces, making healthcare organizations particularly susceptible to modern cyber threats.
- Regulatory Frameworks are Evolving but Need Broader Impact: New FDA pre-market cybersecurity guidance is a positive step for future devices, but comprehensive strategies are needed to address the security of the vast installed base of legacy medical devices and broader healthcare IT.
- Collaborative Resilience is Essential: Building resilience across the entire healthcare ecosystem—from manufacturing and pharma to IT and insurance—requires coordinated efforts from government agencies like CISA, industry stakeholders, and the cybersecurity community.
- Hackers are Critical for Driving Change: The expertise of the hacker community in identifying vulnerabilities is invaluable, and increased access to medical devices and platforms for security research is crucial to accelerate security improvements.
- Whistleblower Support is a Defensive Imperative: Robust support systems for whistleblowers are vital for early detection of systemic issues and ethical breaches, underscoring the human element in cybersecurity defense.
About the Speaker(s)
The "D0N0H4RM Cyber STEM Storytime" panel featured a diverse group of experts, each bringing a unique perspective to the critical discussion of healthcare cybersecurity.
- Matt Hazlett serves as the Chief Regulatory Officer at Medsec. Prior to this role, he dedicated eight and a half years to the FDA, where he was instrumental in developing and implementing the pre-market cybersecurity guidance for medical devices. His work included writing significant portions of this guidance and overseeing the training of reviewers on how to assess cybersecurity given the FDA's new statutory authorities.
- Erica Chung is the Executive Director of the non-profit organization, Ethics and Entrepreneurship. Her journey into medical device safety began with her experience as a key whistleblower in the infamous $9 billion Theranos fraud scandal. She reported the company to regulators, ultimately preventing the use of faulty devices on patients. Erica is also a board member of Whistleblowers of America, which provides mental health services and peer support, and an advisor to the Signals Network, assisting whistleblowers with legal advice, safe housing, funding, and job placement.
- Andrew Carney is a Program Manager at ARPA-H, a relatively new federal agency, where he focuses on healthcare cybersecurity and patient data privacy. He also holds the position of Program Manager for the AI Cyber Challenge at DARPA. With over 15 years of experience as a vulnerability researcher and a "painful CTF player," Andrew brings a strong offensive security mindset to his current defensive efforts aimed at safeguarding the healthcare sector.
- Nitin Natarajan is the Deputy Director of CISA. His career uniquely bridges healthcare and cybersecurity, having started as a hospital administrator and flight medic. This background provides him with a deep understanding of the operational realities and critical importance of securing the healthcare sector.