惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More
H
Help Net Security
云风的 BLOG
云风的 BLOG
Apple Machine Learning Research
Apple Machine Learning Research
H
Hackread – Cybersecurity News, Data Breaches, AI and More
Hugging Face - Blog
Hugging Face - Blog
博客园_首页
D
Docker
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
Blog — PlanetScale
Blog — PlanetScale
Cyber Security Advisories - MS-ISAC
Cyber Security Advisories - MS-ISAC
GbyAI
GbyAI
博客园 - Franky
B
Blog RSS Feed
Stack Overflow Blog
Stack Overflow Blog
L
LangChain Blog
量子位
V
Visual Studio Blog
Y
Y Combinator Blog
小众软件
小众软件
N
Netflix TechBlog - Medium
博客园 - 三生石上(FineUI控件)
Microsoft Security Blog
Microsoft Security Blog
雷峰网
雷峰网

News and Events Feed by Topic

NIST Sesame Reference Material Initiative – Call to Collaborate NIST/NIBIB Symposium on Medical Metrology and Standards for American Healthcare and Commerce NIST Receives New Patent for Microbe-Killing Water Heater Spotlight: How NIST Helps Make Sure the Fish You Catch Are Safe to Eat NIST Expands Its Library of ‘Chemical Fingerprints’ to Identify Unknown Substances SRM Story: SRM 1947a Great Lakes Fish Tissue SRM Story: SRMs 3672a and 3673a Organic Contaminants in Smokers’ and Nonsmokers’ Urine Space: The Final Frontier for Standards NIST’s ‘Living Reference Material’ Could Accelerate R&D of Lifesaving Biological Drugs NIST Awards Over $1.8 Million to Small Businesses Advancing AI, Semiconductors, Additive Manufacturing and More SRM Story: SRM 965c Glucose in Frozen Human Serum Second Seminar on Building an In-Space Circular Economy New NIST Reference Material to Strengthen Quality Control for Biological Drugs NIST Releases Trove of Genetic Data to Spur Cancer Research New NIST Research Grade Test Material to support mRNA therapeutics NIST Shares Preliminary Findings From Hurricane Maria Investigation New NIST Standard Helps Deliver the Right Dosage of Cancer-Fighting Drugs Second Series of Workshops on Measurements and Standards for Advanced Therapy NIST Researcher Addresses London Healthcare Innovation Forum NIST Releases Reference Material to Aid Gut Microbiome Research NIST Researchers Develop Material for Measuring Arsenic in Shellfish 2025 NIST Workshop on Rapid Microbial Testing Methods An SRM for Accuracy in Electrolyte Panel Clinical Tests Study Highlights Need for Standardized Measurement Methods in Gene Therapy NIST Develops Genetic Material for Validating H5N1 Bird Flu Diagnostic Tests PFAS Found in Firefighter Gloves, Hoods and Wildland Gear AI and Flow Cytometry Workshop Genome Editing Consortium Workshop Social Spotlight: Engineered Cells as a Shoebox NIST Scientists Use DNA Origami on a Chip to Detect Biomolecules
Securing Smart Speakers for Home Health Care: NIST Offers...
Chad Boutin · 2025-12-17 · via News and Events Feed by Topic
  • Smart home devices, such as voice-activated digital assistants, are increasingly used to support home health care.
  • Cybersecurity and privacy risks can threaten patient confidentiality, as smart home systems may not be able to support recommended data protection practices.
  • New NIST guidelines — such as enabling message encryption for home health care systems — can help mitigate these risks, benefiting providers as well as telehealth patients.
A cylindrical smart speaker sits on a wooden table in a living room.

Credit: Gorodenkoff/Shutterstock

Smart speakers are commonly used to answer questions, control thermostats and play music. Now consumers are calling on them for home health care — to talk to a provider, refill a prescription or schedule an appointment. Telehealth can benefit patients, but the threats are numerous as well: An attacker could alter a prescription, steal confidential medical data or connect the patient to an impostor.

To reduce the cybersecurity risks these interactions carry, the National Institute of Standards and Technology (NIST) has released guidelines that can help protect patients and providers alike.

The newly finalized guidelines, Mitigating Cybersecurity and Privacy Risks in Telehealth Smart Home Integration, build on NIST’s prior work in telehealth cybersecurity. The publication examines privacy and cybersecurity risks associated with home telehealth, using smart speakers — also called voice-activated digital assistants — as an example of a device that patients at home might use to communicate with providers.

“Certain people might not be able to reach a hospital, but they can talk to their smart speaker,” said Ron Pulivarti, a cybersecurity specialist at NIST’s National Cybersecurity Center of Excellence (NCCoE). “Telehealth patients and their providers exchange confidential information over the network, and we want to show what can go wrong and what we can do to protect them.”

Smart speakers are networked Internet of Things (IoT) devices that respond to voice commands. Generally linked to AI assistant software, they can be combined with hospital-grade medical devices that monitor a patient’s vitals to provide an inpatient care experience at home.

This combination of consumer and hospital-grade devices is a form of telehealth called a hospital-at-home (HaH) program. The patient can use the smart speaker to interact with a health care provider and perform actions such as completing a daily check-in or viewing test results. Once the patient activates the voice assistant to perform an action, a recording of their voice is sent to the voice assistant platform for processing — one point where patient information could be exposed to an attacker.

“Certain people might not be able to reach a hospital, but they can talk to their smart speaker. Telehealth patients and their providers exchange confidential information over the network, and we want to show what can go wrong and what we can do to protect them.” —Ron Pulivarti, cybersecurity specialist at NIST’s National Cybersecurity Center of Excellence

“HaH programs can benefit a homebound patient, but they have vulnerabilities because of their connection to public computer networks,” Pulivarti said. “Smart speakers may not have capabilities that support recommended privacy and security practices, and they may be used as pivot points for attackers to gain access to a hospital’s system.”

This publication considers telehealth solutions that use voice assistants in the patient’s home as well as all the network devices and systems needed to connect the patient’s home to the hospital health information systems. The publication offers several examples of threat scenarios. Among the potential threats are:

  • Data exfiltration: intercepting unencrypted communications from a voice assistant to obtain personal identifiable information (PII) or protected health information.
  • Data manipulation: compromising patient data integrity by intercepting and manipulating data.
  • Denial of service: disrupting availability and predictability.
  • Operating system or application disruption: altering voice commands sent to the health care provider, leading to incorrect processing of patient requests.
  • Unauthorized access: compromising patient data by accessing a patient’s voice assistant device through their home network or weak physical authorization controls.

Many of the recommended guidelines for mitigating these threats draw upon several other NIST publications including the NIST Cybersecurity Framework (CSF 2.0), the NIST Privacy Framework (PF 1.0) and the Profile of the IoT Core Baseline for Consumer IoT Products (NISTIR 8425).

The recommendations include enabling encryption of messages and limiting access to authorized individuals and devices. An overarching theme is for providers to ensure what is known as “network segmentation” between medical or biometric devices and other parts of the home and health care systems. Network segmentation divides the network into subsections using hardware such as firewalls, impeding an attacker’s ability to compromise a weak spot and affect other devices.

Although the guidelines are aimed primarily at technical specialists and information security professionals, Pulivarti said that patients also would benefit from knowing about them.

“Patients can turn around and educate their caregivers, who may not have encountered these guidelines,” he said. “By implementing the mitigations we offer here, health care providers can reduce their security and privacy risks while providing valued services to their patients.”