한국어

Chapter 4: Security and Privacy

Protecting Medical IoT Systems and Patient Data

4.1 The IoMT Security Challenge

Medical IoT devices dramatically expand the healthcare attack surface. Each connected device represents a potential entry point for cyber threats, while the data they generate requires stringent privacy protection. The consequences of IoMT security failures range from privacy breaches to patient harm.

Unlike traditional IT systems, IoMT devices often have limited computing resources for security functions, long operational lifespans spanning 10-20 years, and physical deployment in uncontrolled environments. Security must be designed into IoMT systems from the start, not added as an afterthought.

82%
Healthcare Orgs Attacked
53%
IoMT Devices Vulnerable
$10.9M
Avg Healthcare Breach Cost
72%
Lack Device Inventory

4.2 Threat Landscape

IoMT systems face diverse threat vectors across the device ecosystem:

Threat Categories

Threat Type Description IoMT Impact
Ransomware Encryption of systems for payment Device unavailability, patient harm
Data Theft Exfiltration of health data Privacy breach, regulatory fines
Device Hijacking Unauthorized device control Altered therapy, false readings
Man-in-the-Middle Intercepting communications Data manipulation, credential theft
Denial of Service Overwhelming device/network Service disruption
Supply Chain Compromised components/updates Backdoors, malicious code

⚠️ Real-World IoMT Attacks

In 2017, the WannaCry ransomware affected medical devices in UK NHS hospitals, forcing cancellation of surgeries. Researchers have demonstrated vulnerabilities in insulin pumps and pacemakers that could alter therapy delivery. Hospitals have experienced ransomware attacks that entered through vulnerable IoT devices. These incidents underscore that IoMT security is literally a matter of life and death.

4.3 Security Framework

A comprehensive IoMT security program addresses multiple layers:

Defense in Depth

Layer Controls Technologies
Device Secure boot, hardening TPM, secure elements
Communication Encryption, authentication TLS 1.3, mTLS, certificates
Network Segmentation, monitoring VLANs, firewalls, IDS/IPS
Platform Access control, audit IAM, SIEM, logging
Data Encryption at rest, DLP AES-256, tokenization
Physical Tamper detection Secure enclosures, alerts

4.4 Device Security

Securing devices at the endpoint is foundational to IoMT security:

Device Hardening

Authentication and Authorization

Zero Trust for IoMT

Zero Trust architecture assumes no implicit trust—every device, user, and network flow must be authenticated and authorized. For IoMT, this means: never trust devices based solely on network location; continuously verify device identity and health; encrypt all communications; and apply least-privilege access. Zero Trust is especially critical as IoMT extends beyond hospital perimeters.

4.5 Communication Security

Securing data in transit between devices, gateways, and platforms:

Encryption Requirements

Protocol Use Case Minimum Standard
TLS HTTPS, API calls TLS 1.2+, prefer 1.3
DTLS UDP-based protocols DTLS 1.2+
BLE Bluetooth devices LE Secure Connections, AES-CCM
MQTT IoT messaging TLS transport, client certs
CoAP Constrained devices DTLS, OSCORE

4.6 Privacy Protection

IoMT generates sensitive health data requiring robust privacy protections:

Privacy Controls

Regulatory Compliance

Regulation Scope Key Requirements
HIPAA US covered entities Privacy Rule, Security Rule, Breach Notification
GDPR EU residents' data Consent, data rights, DPO, breach reporting
CCPA/CPRA California consumers Disclosure, deletion rights
PIPA (Korea) Korean data subjects Consent, localization, breach notification

4.7 Vulnerability Management

Continuous identification and remediation of security weaknesses:

Vulnerability Lifecycle

Legacy Device Challenge

Many IoMT devices run legacy operating systems (Windows XP, outdated Linux) that no longer receive security updates. When patching is impossible, implement compensating controls: network segmentation, application whitelisting, enhanced monitoring, and data encryption. Plan for device replacement in procurement cycles.

4.8 Incident Response

Preparation for security incidents specific to IoMT environments:

IoMT Incident Response Plan

✓ IoMT Security Best Practices

Maintain complete device inventory with risk classification; implement network segmentation from day one; require encryption for all data in transit; enforce strong authentication including MFA for administrators; establish patch management processes including legacy device handling; conduct regular security assessments and penetration testing; train staff on IoMT-specific security risks; and develop IoMT-aware incident response procedures.

📌 Key Takeaways

📝 Review Questions

  1. Why do IoMT devices present unique security challenges compared to traditional IT systems?
  2. Describe the major threat categories affecting medical IoT and give examples of each.
  3. Explain the defense-in-depth model and its six layers for IoMT security.
  4. What is Zero Trust architecture and why is it particularly important for IoMT?
  5. How should organizations handle security vulnerabilities in legacy medical devices?
  6. What privacy regulations apply to IoMT data and what are their key requirements?

Korea Digital Transformation Detailed Mapping

Korea operates digital transformation through a comprehensive governance system. Digital Government: Digital Platform Government Committee (established September 2022, under the President)·Ministry of the Interior and Safety Digital Government Bureau·e-Government Support Center·Gov.kr·National Citizen Service·KDIS (Korea Digital Information Society)·NIA (National Information Society Agency)·MOIS (Ministry of the Interior and Safety). K-DNS Infrastructure: Korea Internet & Security Agency (KISA) Korea Internet Center·KISA DNS Root Server·KRNIC (Korea Network Information Center)·BGP Korea·National Cyber Security Center (NCSC)·KCC (Korea Communications Commission)·MSIT (Ministry of Science and ICT)·NIA·NIPA. Korean Cloud Infrastructure: KT Cloud·NAVER Cloud (NCloud)·Samsung SDS Cloud·LG U+ Cloud·NHN Cloud·Kakao Enterprise Cloud·SK Telecom Cloud·KISA Cloud Security Assurance Program (CSAP)·KCMVP-validated cloud·ISMS-P (Information Security & Personal Information Management System). Korean Security Certifications: KISA ISMS-P certification·KCMVP (Korean Cryptographic Module Validation Program)·NIS (National Intelligence Service) "National Cryptographic Technology Operation Standards"·NCSC "National Cyber Security Strategy 2024-2028"·CC (Common Criteria) Korean evaluation bodies·EAL4·EAL5·KS X ISO/IEC 15408·19790·24759 Korean Profile. Korean Data Standards: NIA AI Hub·National Data Standardization Committee·Statistics Korea (KOSTAT)·MyData 4 Designated Combination Specialists (Samsung SDS, KICI, KOSTAT, KFTC)·National Institute of Korean Language·National Law Information Center·National Spatial Information Platform·National Spatial Data Center·Korean Spatial Information Standards. Finance and Fintech Standards: FSC (Financial Services Commission)·FSS (Financial Supervisory Service)·FIU (Financial Intelligence Unit)·BOK (Bank of Korea)·FSEC (Financial Security Institute)·KFTC (Korea Financial Telecommunications)·KSD (Korea Securities Depository)·KRX (Korea Exchange) 8-agency cooperation. 5G/6G Communications Infrastructure: 5G subscribers 35 million (2024)·5G base stations 350,000·6G commercialization target 2028·5G dedicated networks 16 operators·6G Acceleration Council (MSIT, 2024). K-Content: KOCCA (Korea Creative Content Agency)·MCST (Ministry of Culture, Sports and Tourism)·KCA (Korea Communications Agency)·Korea Culture Information Service Agency·Korean Film Archive·Korea Publishing Industry Promotion Agency. Data 3 Acts (Personal Information Protection Act·Credit Information Act·Telecommunications Network Act, 2020 enforcement)·Data Industry Act (2021)·Public Data Act (2013)·AI Framework Act (2026)·Digital Platform Government Framework Act (2024 proposed) — Korea digital transformation core legislation.

Korea Industrial, Research, Education Infrastructure Mapping

Korea operates its industrial ecosystem and standardization system through the following core infrastructure. Korea Top 5 Groups: Samsung, Hyundai Motor, LG, SK, Lotte. Each group operates standardization committees and ISO/IEC TC Korean secretariats. Samsung Electronics (semiconductors, displays, home appliances, telecom)·Hyundai Motor (automobiles, mobility)·LG Electronics (home appliances, displays, OLED)·SK hynix (memory)·LG Energy Solution·Samsung SDI (batteries)·POSCO Future M (materials)·Hyundai Mobis (parts). Korean IT Big Tech: NAVER (search, cloud, AI HyperCLOVA)·Kakao (messenger, payment, mobility, banking)·Coupang (e-commerce, logistics)·Karrot Market·Toss·Woowa Brothers. Korea Telcos: SK Telecom·KT·LG U+. 5G·5G dedicated networks·B2B cloud·AI businesses operating. Korea Top 7 Research Universities: Seoul National University·KAIST·POSTECH·Yonsei University·Korea University·UNIST·DGIST·GIST. All serve as standardization R&D bases and ISO/IEC/IEEE Korean chairs. Korea Government-affiliated National Research Institutes (26): KIST, KAERI, KIMM, KIER, KFRI, KRICT, KRIBB, KARI, KASI, KIGAM, KICT, KISTI, KETI, ETRI, NIMS, KIMS, KISDI, KOTRA, STEPI, KOEN, KICCE, KIET, KIPF, KIHASA, KICJ, KLRI. Korea Industrial Complexes / Tech Valleys: Pangyo Techno Valley·Dongtan·Gwanggyo·Songdo IBD·Yeouido·Gangnam·Sihwa·Banwol·Gumi·Ulsan·Changwon·Geoje·Yeosu·Onsan·Cheongju·Iksan·Gwangyang·POSCO Gwangyang Steel Mill·Asan Bay·Seosan·Songdo·Incheon Airport·Sejong·Cheongna·Geomdan. Korea Trade and Finance Infrastructure: Korea International Trade Association (KITA)·Korea Trade-Investment Promotion Agency (KOTRA)·Export-Import Bank of Korea (KEXIM)·Bank of Korea·Kookmin Bank·Shinhan·Hana·Woori·NH Nonghyup·IBK Industrial Bank·SC First Bank·Citi Bank Korea·HSBC Korea·DBS Korea — 14 Korean major banks and foreign banks. Korea K-POP / K-Content: HYBE·SM·YG·JYP 4 major entertainment companies·CJ ENM·tvN·MBC·KBS·SBS·EBS·YTN·Yonhap News TV·JTBC Korean broadcasting·NETFLIX Korea·Disney Plus·TVING·Wavve·Watcha·Coupang Play. Korea Gaming Industry: Nexon·NCsoft·Krafton·Netmarble·Kakao Games·Pearl Abyss·Com2uS·Gamevil·NHN·Smilegate·Webzen. Korea Automotive / Battery: Hyundai Motor·Kia·Genesis·LG Energy Solution·Samsung SDI·SK On·POSCO Future M·EcoPro·L&F battery cathode material suppliers. Korea Semiconductor: Samsung Electronics (HBM3E·HBM4)·SK hynix (HBM3E 12-Hi)·DB HiTek·SK siltron·SK Enpulse·Dongjin Semichem·Seoul Semiconductor·Simmtech·Samsung Display·LG Display.

Korea Industrial Cluster, National Strategic Technologies, Workforce Development

Korea operates a comprehensive industrial cluster system. Korea Top 12 National Strategic Technologies (5th Science and Technology Master Plan 2023-2027): (1) Semiconductors and Displays (2) Secondary Batteries (3) Advanced Mobility (autonomous driving, UAM) (4) Next-Generation Nuclear (SMR) (5) Advanced Bio (6) Aerospace and Marine (7) Hydrogen (8) Cybersecurity (9) Artificial Intelligence (10) Next-Generation Communications (11) Advanced Robotics and Manufacturing (12) Quantum. 12 fields receive direct investment of 5 trillion KRW annually, cumulative 30 trillion KRW by 2030. Korea Major Industrial Clusters: Pangyo IT Cluster (1,300+ companies, 100 trillion KRW revenue), Gangnam Fintech (200+ companies), Songdo BT Bio Cluster, Daegu Medical Cluster, Ulsan Industry (shipbuilding, petrochemicals, automotive), Changwon Machinery, Changwon National Industrial Complex, Siheung and Banwol (SME manufacturing), Yeosu Petrochemicals, Pyeongtaek Semiconductor (Samsung Electronics Pyeongtaek Campus), Icheon and Cheongju Semiconductor (SK hynix Icheon and Cheongju Campuses), Asan Display (Samsung Display Asan Campus), Gumi Mobile (Samsung Gumi Campus), Pohang Steel (POSCO Pohang Steel Mill), Gwangyang Steel (POSCO Gwangyang Steel Mill), Dangjin Steel (Hyundai Steel Dangjin), Ulsan Automotive (Hyundai Motor Ulsan Plant), Asan Automotive (Hyundai Asan Plant), Kia Gwangju and Sohari, POSCO Gwangyang and Pohang Steel Mills, SK hynix Icheon and Cheongju, Samsung Electronics Hwaseong, Giheung, Pyeongtaek, Onyang, Cheonan, Asan Semiconductor Facilities. Major Industrial Complexes and Techno Valleys: Pangyo Techno Valley (1st 800 companies, 2nd 600 companies, 3rd 1,200 companies), Dongtan Techno Valley, Gwanggyo Techno Valley, Songdo IBD, Yeouido Financial District, Gangnam Teheran-ro Valley, Sihwa, Banwol, Gumi, Ulsan, Changwon, Geoje, Yeosu, Ulsan Mipo, Onsan, Cheongju, Iksan, Gwangyang, Yeosu, POSCO Gwangyang Steel Mill, Asan Bay, Seosan, Songdo, Incheon Airport, Sejong, Cheongna, Geomdan, Pyeongtaek Automotive Industrial Complex, Giheung Semiconductor Complex, Icheon Semiconductor Complex, Asan Display Complex, Gumi Mobile Complex, Changwon National Industrial Complex, Ulsan Mipo National Industrial Complex, Yeosu National Industrial Complex, Onsan National Industrial Complex. Korea Workforce Statistics: STEM undergraduate students 700,000 (26% of all university students), STEM graduate students 170,000, PhD researchers 140,000, STEM doctorates conferred 8,000 annually (Seoul National University 1,200, KAIST 800, POSTECH 400, Yonsei University 700, Korea University 600, UNIST 250, DGIST 100, GIST 200, KISTI 50, KIST and ETRI postdoctoral programs 1,000), information security experts 300,000 (KISA-trained and private), AI experts 50,000 (NIA, IITP, NIPA, Samsung, LG, SK, NAVER, Kakao trained), semiconductor experts 260,000 (Samsung Electronics 60,000, SK hynix 30,000, DB HiTek, SK siltron). National R&D Project Operation: National R&D projects 100,000+ annually (MSIT 35,000, MOTIE 25,000, MSS 20,000, MOE 15,000, others 5,000), R&D participating institutions 25,000+, R&D participating researchers 530,000, National R&D output (papers, patents) 540,000 annually. Korea Corporate R&D Investment Top 10 (2024): Samsung Electronics 28 trillion KRW, LG Electronics 9 trillion KRW, SK hynix 8 trillion KRW, Hyundai Motor 6 trillion KRW, Kia 4 trillion KRW, LG Chem 3.5 trillion KRW, LG Display 3.2 trillion KRW, POSCO 3 trillion KRW, Samsung SDI 2.7 trillion KRW, SK Innovation 2.5 trillion KRW.

📐 시뮬레이터 패널 3