Keeping Code Healthy: How to accelerate software development in the healthcare industry
The pandemic increased the pressure on healthcare providers in obvious and in some hidden ways. In the former category, the need to treat patients with COVID-19 overloaded many hospitals and impacted other clinical interventions, which caused waiting lists to grow.
What’s not so well known outside of the clinical sector is that cybercriminals took the opportunity of the pandemic to increase their attacks against healthcare providers. The move to telemedicine, and the need for many healthcare admin staff to work remotely, prompted a significant and rapid deployment of new IT systems to support remote work. This deployment had a clinical focus for obvious reasons, with security a secondary consideration. As a result, the attack surface that cybercriminals could target increased. And the attackers took advantage, as shown by the number of ransomware attacks against healthcare providers.
Healthcare Organisations are a Tempting Target
Healthcare organisations are a tempting target for criminals for many reasons. Firstly, a successful ransomware attack has a higher than average chance of eliciting a payment as unusable healthcare systems can result in adverse health outcomes for patients or even deaths. Secondly, the information that healthcare organisations store is, by definition, personally sensitive information (PII). There is also a good chance that healthcare providers will be holding intellectual property information from clinical trials or other commercially sensitive projects. Attackers who can breach system security and copy PII or commercial data can sell it for a high price on the dark web or other forums.
Protecting clinical information from attackers is vital. In addition to the need to protect PII and any commercially sensitive information, there are also stringent regulations that cover the healthcare sector. GDPR defines healthcare data as a special category, and as a result, it is subject to a higher standard of protection and reporting than other data. No healthcare provider in the public or private sector wants to be subject to a GDPR complaint and handle the resulting negative reputational and financial impact.
Protecting Healthcare Systems is Vital
The need to protect healthcare systems from attackers was demonstrated by the successful ransomware attack against Ireland’s Health Service Executive (HSE) systems in 2021. This attack took many departmental and healthcare providers’ systems offline. It led to many cancelled medical procedures in the immediate aftermath, and the effects of the attack were still being dealt with months later.
The Irish Government commissioned an urgent review of the HSE IT systems by PWC. This review produced a report that stated an urgent need to completely transform the HSE’s approach to IT, Operations Technology (OT), and Cybersecurity.
Development Teams Are Under Extreme Pressure
One area needing robust cybersecurity is within the software development teams that build and update medical systems within HSE and frontline healthcare providers. Development teams within the healthcare providers and third-party development teams that work with them are under extreme pressure to deliver improvements. This leads to a tension between the rapid creation and deployment of new code to update systems and the need for extensive cybersecurity testing of that code before it’s rolled out to production systems. This can lead to shortcuts in the required testing time to relieve the pressure from clinicians and management clamouring to get new systems up and running for patients.
Most development teams will use as much third-party code as they can to reduce the amount they have to write from scratch. This imported code, or precompiled libraries, can introduce security vulnerabilities into systems that developers can’t check. This is especially true if they are under time pressure and can’t painstakingly review all the third-party code, even if they have access to it (which they might not have if it’s a precompiled library from a commercial vendor).
Checkmarx Can Help Relieve the Pressure
Automation and managed services are transforming many aspects of the modern IT landscape. This is true in the world of software development as well. Technical solutions backed up with skilled managed service provider consulting teams can help relieve the pressure on healthcare development teams.
The Checkmarx Application Security Platform (AST) with SAST, SCA, IAST, training and consultancy services is ideal for any healthcare development team to allow them to check the code they write or import for known and common security vulnerabilities. Organisations can tune the policies used with AST to match particular regulatory frameworks that medical systems may operate under (GDPR, HIPAA etc.).
AST delivers a multi-layered approach that can bring automated checking and expert systems to bear on new code and any third-party libraries in use. In a modern software development environment, this means:
- Static Application Security Testing (SAST) - incremental scans that look for vulnerabilities in newly written code.
- Software Composition Analysis (SCA) - check open-source libraries and code for known issues.
- Interactive Application Security Testing (IAST) - optimised testing of running applications and code by Test/QA teams as part of a broader DevSecOps process.
AST integrates seamlessly with developers’ preferred IDE and gets configured to scan code automatically at critical points in the development process, delivering results directly into the IDE along with best-fix advice. This IDE integration lets developers gain confidence in the code checking and the advice provided over time, making it much more likely that they will respect the advice and act on it to reduce security issues in the code they are getting ready to deploy.
To assist development teams in getting the best use out of the AST platform, Checkmarx has a dedicated AppSec Accelerator program that provides experts in AST to work with healthcare organisations (and those in other sectors) to get them up to speed with the solution. So that cybersecurity improvements can be delivered to patients and clinicians as quickly as possible.
Find Out More
Renaissance partners with Checkmarx to make their AST platform and consulting solutions available within the Irish marketplace. Contact us today to find out more and arrange to chat with an expert.

