Digital forensics in healthcare: An analysis of data associated with a CPAP machine

IF 2 4区 医学 Q3 COMPUTER SCIENCE, INFORMATION SYSTEMS
Veronica Schmitt, Emlyn Butterfield
{"title":"Digital forensics in healthcare: An analysis of data associated with a CPAP machine","authors":"Veronica Schmitt,&nbsp;Emlyn Butterfield","doi":"10.1016/j.fsidi.2023.301661","DOIUrl":null,"url":null,"abstract":"<div><p>The need for digital forensic services across all sectors is not a new concept, nor is the increasing demand seen globally. However, the devices on which we perform digital forensics have changed and continue to evolve. For each device new approaches need to be developed or adapted to facilitate the secure preservation and analysis of the data it contains. The healthcare sector has seen particular adoption of a range of devices, from traditional through to cutting edge. The Covid-19 pandemic facilitated the need for a more boundary-agnostic level of care for patients, and medical devices are becoming increasingly more interconnected to facilitate remote care. This presents challenges in that devices are no longer “secured” in medical premises and will often be found in patient's homes, making them more exposed to attack, but also in a position to record significant amounts of personal data. The integration of information technology in medical environments has influenced the need for the development of a digital forensic process to perform analysis on medical devices. One such device is a continuous positive airway pressure (CPAP) machine, used by patients who suffer from Obstructive Sleep Apnea (OSA). It is estimated that 3-9% of the world's population suffer from this disorder, the normal medical treatment is the use of some form of CPAP machine. The research undertaken focuses on the ResMed AirSense 10 CPAP machine and a complete forensic postmortem analysis of the data contained and recorded by the device. The application of digital forensics to a traditional medical device, such as a CPAP machine, requires an adapted version of digital forensics, but in general the same tools and processes can be used. Through the analysis conducted, all patient data was located on a removable FAT32 formatted SD card, allowing the recovery of specific medical information about the device and personally identifiable information about the patient. The recovered data was then visualised using a variety of tools and systems. Information that can be derived from the visualisations include a sequence of events, to some extent how the device was operating, and the clinical information recorded on the device.</p></div>","PeriodicalId":48481,"journal":{"name":"Forensic Science International-Digital Investigation","volume":null,"pages":null},"PeriodicalIF":2.0000,"publicationDate":"2023-12-06","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"https://www.sciencedirect.com/science/article/pii/S2666281723001804/pdfft?md5=b12d26ad2eba434e2e50386f4c137ab6&pid=1-s2.0-S2666281723001804-main.pdf","citationCount":"0","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"Forensic Science International-Digital Investigation","FirstCategoryId":"3","ListUrlMain":"https://www.sciencedirect.com/science/article/pii/S2666281723001804","RegionNum":4,"RegionCategory":"医学","ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"Q3","JCRName":"COMPUTER SCIENCE, INFORMATION SYSTEMS","Score":null,"Total":0}
引用次数: 0

Abstract

The need for digital forensic services across all sectors is not a new concept, nor is the increasing demand seen globally. However, the devices on which we perform digital forensics have changed and continue to evolve. For each device new approaches need to be developed or adapted to facilitate the secure preservation and analysis of the data it contains. The healthcare sector has seen particular adoption of a range of devices, from traditional through to cutting edge. The Covid-19 pandemic facilitated the need for a more boundary-agnostic level of care for patients, and medical devices are becoming increasingly more interconnected to facilitate remote care. This presents challenges in that devices are no longer “secured” in medical premises and will often be found in patient's homes, making them more exposed to attack, but also in a position to record significant amounts of personal data. The integration of information technology in medical environments has influenced the need for the development of a digital forensic process to perform analysis on medical devices. One such device is a continuous positive airway pressure (CPAP) machine, used by patients who suffer from Obstructive Sleep Apnea (OSA). It is estimated that 3-9% of the world's population suffer from this disorder, the normal medical treatment is the use of some form of CPAP machine. The research undertaken focuses on the ResMed AirSense 10 CPAP machine and a complete forensic postmortem analysis of the data contained and recorded by the device. The application of digital forensics to a traditional medical device, such as a CPAP machine, requires an adapted version of digital forensics, but in general the same tools and processes can be used. Through the analysis conducted, all patient data was located on a removable FAT32 formatted SD card, allowing the recovery of specific medical information about the device and personally identifiable information about the patient. The recovered data was then visualised using a variety of tools and systems. Information that can be derived from the visualisations include a sequence of events, to some extent how the device was operating, and the clinical information recorded on the device.

医疗保健领域的数字取证:与 CPAP 机器相关的数据分析
各行各业对数字取证服务的需求并不是一个新概念,全球范围内日益增长的需求也并非如此。然而,我们进行数字取证的设备已经发生了变化,并将继续发展。每种设备都需要开发或调整新的方法,以便安全地保存和分析其中包含的数据。医疗保健行业特别采用了一系列从传统到尖端的设备。Covid-19 大流行促使人们需要为病人提供更加无国界的医疗服务,医疗设备之间的互联性也越来越强,以促进远程医疗。这就带来了挑战,因为医疗设备不再 "安全 "地存放在医疗场所,而是经常出现在病人家中,这就使它们更容易受到攻击,同时也能记录大量的个人数据。信息技术在医疗环境中的整合影响了开发数字取证程序对医疗设备进行分析的需求。阻塞性睡眠呼吸暂停(OSA)患者使用的持续气道正压(CPAP)机就是这样一种设备。据估计,全球有 3-9% 的人患有这种疾病,通常的医疗方法是使用某种形式的 CPAP 机器。本次研究的重点是瑞思迈 AirSense 10 CPAP 机器,以及对该设备所包含和记录的数据进行完整的法医尸检分析。将数字取证应用于传统医疗设备(如 CPAP 机器)需要对数字取证进行调整,但一般来说可以使用相同的工具和流程。通过分析,所有患者数据都被定位到一张可移动的 FAT32 格式 SD 卡上,从而恢复了设备的特定医疗信息和患者的个人身份信息。然后,利用各种工具和系统对恢复的数据进行了可视化处理。可从可视化中获得的信息包括事件序列、设备在一定程度上的运行方式以及设备上记录的临床信息。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
求助全文
约1分钟内获得全文 求助全文
来源期刊
CiteScore
5.90
自引率
15.00%
发文量
87
审稿时长
76 days
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
确定
请完成安全验证×
copy
已复制链接
快去分享给好友吧!
我知道了
右上角分享
点击右上角分享
0
联系我们:info@booksci.cn Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。 Copyright © 2023 布克学术 All rights reserved.
京ICP备2023020795号-1
ghs 京公网安备 11010802042870号
Book学术文献互助
Book学术文献互助群
群 号:481959085
Book学术官方微信