Philips Product Security Status documents have product-specific vulnerability updates and security-related information such as supported anti-virus software, OS security features, and remote service.
Each product has its own table and the products are separated by modality, i.e. Informatics, Ultrasound, Magnetic Resonance, etc. The Status Documents list known software vulnerabilities, the current status, and Recommended Customer Action.
Revised tables are posted regularly with the latest available information.
As part of our commitment to product security and customer service, Philips Healthcare supplies our customers with information to help assess and address the vulnerabilities and risks associated with products that maintain or transmit ePHI.
Specifically, Philips Healthcare is using the Manufacturer Disclosure Statement for Medical Device Security (MDS²) to provide security information about its products.
The MDS² contains product specific security information such as:
The MDS², a universal reporting form which allows Philips Healthcare to supply its customers with model-specific information, is endorsed by the American College of Clinical Engineering (ACCE), ECRI (formerly the Emergency Care Research Institute), the National Electrical Manufacturers Association (NEMA), and the Healthcare Information and Management Systems Society (HIMSS).
The form also contains security practice recommendations and explanatory notes from the manufacturer as well as detailed.
To register, send an e-mail to incenter@philips.com providing the following information:
Once your request is processed, you will receive an email from GCS Helpdesk with login and passcode information.
Already registered?
Philips Healthcare Product Security Update – Heartbleed Vulnerability
Philips Healthcare is aware of the OpenSSL ‘heartbleed’ security vulnerability. The vulnerability (assigned CVE-2014-0160) impacts OpenSSL versions 1.0.1 – 1.0.1f. The effect of this vulnerability on Philips healthcare products and services is being investigated by the Philips engineering and product security teams. Customers will be notified once a solution is available for any affected product(s).
For our Remote Service solution (PRS) we have reviewed all of our customer facing interfaces and VPN connections to our customer facilities, and can confirm that these are not affected by the Heartbleed issue.
Philips Healthcare and Windows XP End of Support
As part of our continued attention to your security needs, Philips Healthcare wishes to bring to your attention that Microsoft has discontinued support for the Microsoft Windows XP Operating System, following
April 8, 2014.
Where feasible, Philips Healthcare has been developing solutions for products running Windows XP to address continuity of protection against known and emerging security threats and vulnerabilities.
To this end, Philips Healthcare will provide product-specific Statements to assist customers. Where applicable, these Product Statements may provide upgrade or field change order information.
Philips Xper-IM vulnerability information (21 Feb 2013)
Philips Healthcare is aware that researchers at a recent cyber-security conference in Florida presented on a security vulnerability in a system component of the Philips Xper Information Management System. This has been investigated by the responsible Philips engineering and product security experts and we expect to provide a software update within a short period of time once the software validation has been completed. Affected customers will be notified directly once this software update is available.
A related concern regarding the disclosure during the conference of service passwords used on Xper IM systems is already being addressed by a Philips Field Change Order (FCO 83000171) which is currently being distributed to all affected customers. The information provided by this FCO also contains instructions to mitigate the above network-based heap overflow vulnerability in the interim.
Customers with specific questions regarding any security advisory and their Philips Healthcare products are asked to may send an e-mail to productsecurity@philips.com, contact their Philips Service Representative or contact their regional Philips Service Support.
Any media inquiries should be directed to:
Mario Fante, mario.fante@philips.com
or (outside N. America):
Steve Klink, steve.klink@philips.com
Philips manufactures, sells and helps you maintain highly complex medical devices and systems. Per policy, only Philips authorized changes are allowed to be made to these systems, either by Philips personnel or under Philips explicit published direction.
Please contact your Philips service representative for specific information about potential vulnerabilities and the availability of patches for your equipment configuration.
Security Advisory Archive
링크를 클릭하면 공식 Philips Electronics Ltd.("Philips") 웹사이트를 종료하게 됩니다. 이 사이트에 나타날 수 있는 제3자 웹사이트에 대한 링크는 귀하의 편의를 위해서만 제공되며 링크된 웹사이트에서 제공되는 정보의 제휴 또는 보증을 나타내지 않습니다. Philips는 제3자 웹사이트 또는 여기에 포함된 정보와 관련하여 어떠한 종류의 진술이나 보증도 하지 않습니다.
I understandYou are about to visit a Philips global content page
You are about to visit the Philips USA website.
필립스코리아 대표이사 : 김동희 주소 : 서울시 중구 소월로2길 30(남대문로 5가) 사업자등록번호 : 106-81-02284
통신판매업 신고 : 제 2016-서울중구-1138 [사업자정보확인] 의료기기판매업 신고 : 제 2998호
필립스 고객센터 소비자 가전 : 080-600-6600 수면 및 호흡기기 : 080-500-0004 영상 진단 및 분석 의료기기 : 080-372-7777
링크를 클릭하면 공식 Philips Electronics Ltd.("Philips") 웹사이트를 종료하게 됩니다. 이 사이트에 나타날 수 있는 제3자 웹사이트에 대한 링크는 귀하의 편의를 위해서만 제공되며 링크된 웹사이트에서 제공되는 정보의 제휴 또는 보증을 나타내지 않습니다. Philips는 제3자 웹사이트 또는 여기에 포함된 정보와 관련하여 어떠한 종류의 진술이나 보증도 하지 않습니다.
I understandYou are about to visit a Philips global content page
You are about to visit the Philips USA website.
당사 사이트는 최신 버전의 Microsoft Edge, Google Chrome 또는 Firefox에서 가장 잘 볼 수 있습니다.