How AI + Hardware can Transform Point of Care Workflows

PamirAI

DEF CON 33 · Day 1 · Main Stage

Overview

In a compelling presentation at DEF CON, Dr. Shiferlay Olen Brock, affectionately known as Jen Su, delivered a powerful "call to action from the front lines of healthcare," advocating for the strategic integration of smart technology and artificial intelligence (AI) to close critical patient safety gaps. Drawing from her diverse background as a trauma nurse, patient experience leader, and cybersecurity consultant, Dr. Su illuminated the inherent fragility of current healthcare infrastructure and passionately argued that cyber incidents need not escalate into medical emergencies. Her talk served as a stark reminder that while healthcare advances in treatment, its underlying technological foundation often lags, creating vulnerabilities that AI and modern hardware can, and must, address.

Watch on YouTube

Visual summary for How AI + Hardware can Transform Point of Care Workflows by PamirAI
Visual summary for How AI + Hardware can Transform Point of Care Workflows by PamirAI

Key moments

  1. 0:00 Speaker introduction and passion for closing patient safety gaps
  2. 2:00 Analyzing healthcare's fragile, layered, and often outdated infrastructure
  3. 4:00 Describing a cyber attack's devastating impact on patient care
  4. 6:00 Examining critical ESI triage challenges in emergency departments
  5. 7:40 How AI improves ESI triage accuracy and clinical decision-making

How AI + Hardware can Transform Point of Care Workflows

Speakers: Dr. Shiferlay Olen Brock (Jen Su), Cybersecurity Consultant, Provisio Insights

Conference: DEF CON

YouTube: https://www.youtube.com/watch?v=jVFOiYCBcvc

Overview

In a compelling presentation at DEF CON, Dr. Shiferlay Olen Brock, affectionately known as Jen Su, delivered a powerful "call to action from the front lines of healthcare," advocating for the strategic integration of smart technology and artificial intelligence (AI) to close critical patient safety gaps. Drawing from her diverse background as a trauma nurse, patient experience leader, and cybersecurity consultant, Dr. Su illuminated the inherent fragility of current healthcare infrastructure and passionately argued that cyber incidents need not escalate into medical emergencies. Her talk served as a stark reminder that while healthcare advances in treatment, its underlying technological foundation often lags, creating vulnerabilities that AI and modern hardware can, and must, address.

Dr. Su's core thesis revolved around the transformative potential of AI to enhance clinical workflows, improve diagnostic accuracy, streamline operations, and ultimately save lives, all while operating within a meticulously secured environment. She challenged the audience to move beyond normalizing the current state of technical debt and embrace purposeful modernization, particularly in high-acuity areas like the emergency department. The presentation meticulously detailed various applications, from AI-powered triage and diagnostic support to advanced imaging, immersive training, humanoid robots, and pervasive home monitoring, painting a vivid picture of a future where technology is a seamless and secure partner in patient care.

The significance of this talk at a cybersecurity conference like DEF CON cannot be overstated. Dr. Su masterfully bridged the gap between clinical urgency and technological imperative, underscoring that the benefits of AI in healthcare are inextricably linked to robust cybersecurity practices. Her insights provide a crucial framework for security professionals, healthcare administrators, and technologists to collaborate on building resilient, intelligent, and safe patient care systems, emphasizing that every technological advancement must be underpinned by a proactive, defensive posture to protect both data and human lives.

Background

▶ Watch: Speaker introduction and passion for closing patient safety gaps (0:00)

The foundation of modern healthcare, as Dr. Su eloquently described, is akin to an "onion" – complex, multi-layered, and often inducing tears. This intricate infrastructure begins with basic utilities like power and buildings, extending to specialized medical equipment, and critical transportation systems for trauma centers. Layered upon this are the hardware components, frequently characterized by aging servers, unpatched devices, and pervasive technical debt. The network layer often suffers from flat architectures, spotty Wi-Fi, and alarmingly, in some areas, open remote access, creating glaring security vulnerabilities. Sitting atop these layers are critical systems such as Electronic Health Records (EHRs), Picture Archiving and Communication Systems (PACS) for imaging, and billing platforms – all interconnected yet inherently fragile.

This legacy technological landscape, where devices are often "built for function but not necessarily security," presents significant challenges. Patching cycles are notoriously slow, and many vital systems operate on unsupported software, amplifying risk. Dr. Su humorously, yet pointedly, highlighted this fragility with sardonic jokes: "patch Tuesday is celebrated annually," "half the biomedical devices run on unsupported Windows, the other half just run vibes," and "the only zero trust in the building is between IT and clinical staff." While presented with levity, these observations underscore a grim reality: the normalization of fragility in healthcare IT.

The consequences of this brittle infrastructure are severe. Dr. Su recounted firsthand experiences where a cyberattack transformed into a medical emergency, leading to monitors going black, ransom demands, halted care, and patients being diverted by the hundreds. Such incidents are not mere inconveniences; they directly impact patient outcomes, demonstrating that "when hospital systems crash like this, patients do too." This critical context forms the bedrock of Dr. Su's call for purposeful modernization, emphasizing that investing in scalable, secure infrastructure and strategically piloting AI is not just an IT initiative but a patient safety imperative, especially in time-sensitive environments like the emergency department.

Key Findings

▶ Watch: Analyzing healthcare's fragile, layered, and often outdated infrastructure (2:00)

Dr. Su's presentation meticulously outlined several key findings regarding AI's current and future impact on healthcare, emphasizing its role in enhancing rather than replacing human clinicians:

  • Improved Triage Accuracy: A study of nearly a million triage encounters revealed that nurses' adherence to the ESI (Emergency Severity Index) algorithm was as low as 60%. AI models, however, have demonstrated the ability to outperform traditional triage models, tightening this gap and providing precision support to nurses, leading to more consistent and accurate patient prioritization.
  • Enhanced Diagnostic Support: While not a sweeping statement for all medicine, internal and narrow use cases by Microsoft have shown their AI systems diagnosing patients four times more accurately than human doctors in specific contexts. This highlights AI's potential to significantly enhance decision-making when paired with clinical judgment and compassion.
  • Real-time Clinical Cue Detection via AI Cameras: Beyond traditional security, AI-powered cameras can be trained to detect clinical cues in real-time. Examples include monitoring pulse, breathing, and signs of escalation in mental health settings, acting as a "digital first responder." They can also detect stroke signs using algorithms like FAST (Face droop, Arm weakness, Speech difficulty, Time) and integrate with EHRs via secure APIs to trigger smart alerts for events like seizures or elopements.
  • Future Trauma Bay with 3D AI Modeling: The concept of a future trauma bay involves AI overlaying real-time 3D models of the human body, integrating vitals, medical history, PACS imaging, and EHR data. This system could simulate injuries from various mechanisms (falls, motor vehicle accidents, crush injuries, penetrating trauma) and predict the cascade of physiological effects, highlighting injury zones and modeling potential damage pathways.
  • Transformative Healthcare Education: AI is revolutionizing medical training through immersive AI simulation labs, digital twins, and personalized feedback. This allows students to replay disease progression, test interventions, and visualize the impact of their decisions, fostering deeper clinical growth.
  • Emergence of Humanoid Robots in Clinical Care: Humanoid robots like China's GR1 and the US's Digit are moving from lab demos to real-world deployments. In healthcare, they are envisioned for roles such as triage support, behavioral de-escalation, non-invasive patient monitoring, and even providing family presence. These robots are expected to be market-ready within the next five years, necessitating new HR policies and a rethinking of human-humanoid relationships.
  • Streamlined Nurse Handoffs: A Cleveland Clinic study demonstrated that digital handoff reports could save 15 minutes per nurse handoff, potentially returning 10 hours back to the clinical team over a period, significantly improving efficiency and reducing communication errors.
  • Personalized Patient Experience: Hospitals can leverage AI to provide curated patient experiences, pushing updates on labs, imaging, and vitals to patient-facing screens. Patients could securely access their data with PINs, adhering to principles of least privilege, TLS encryption, VLAN segmentation, and auto-log off, enhancing communication and satisfaction.
  • Expanded Telemedicine and Remote Care: Telemedicine is extending beyond post-discharge care, facilitating real-time virtual consults with specialists within the hospital. Post-discharge, AI-supported coaching for chronic conditions like diabetes and heart failure, coupled with expanded access for behavioral health, is improving health equity by reaching underserved populations.
  • Adaptive AI Rehabilitation and Home as Healthcare Hub: AI-driven rehab programs offer tailored care that adapts in real-time to patient progress, utilizing wearables, VR-based gamified therapy, and AI-powered exoskeletons like ExoNr for gait and limb retraining. Furthermore, homes are transforming into "healthcare hubs" with smart devices, IoT sensors, and predictive tools like Beam O, which provides hospital-grade vital sign monitoring, lung sound listening, and EHR integration, bringing continuous care directly to the patient's living room.

Technical Deep Dive

▶ Watch: Describing a cyber attack's devastating impact on patient care (4:00)

The technical underpinning of Dr. Su's vision for AI-transformed healthcare relies on a robust and secure digital infrastructure, a stark contrast to the existing "fractured" landscape. The talk highlighted several critical technical components and architectural considerations for integrating AI and advanced hardware:

The existing healthcare infrastructure was analogized to the OSI model, but from a clinical perspective, emphasizing its fragility. This includes physical layers (power, buildings, medical equipment), hardware layers (aging, unpatched servers and devices running unsupported operating systems), and network layers (often flat, with spotty Wi-Fi and even open remote access). The upper layers, comprising systems like EHRs, PACS, and billing, are interconnected but vulnerable due to underlying technical debt and a lack of security-by-design. Deploying AI on top of this necessitates a fundamental architectural shift.

AI-powered cameras represent a significant technical advancement. These systems employ clinical algorithms (e.g., ESI for triage, FAST for stroke detection) to process video feeds in real time. Their detection capabilities involve training AI models to recognize specific clinical cues, such as facial droop, arm weakness, or signs of agitation. For deployment, these AI models can run either on the edge (processing data locally on the camera or a proximate device) or in the cloud, offering flexibility based on latency and privacy requirements. Crucially, they push alerts through secure APIs into existing clinical systems like EHRs or specialized clinical dashboards (e.g., in ED, OR, ICU). These alerts can be granular, notifying specific code teams for events like seizures, fights, or patient elopement, and can even integrate with provider approval workflows for automated actions. The ultimate goal is clinical automation, where AI detects, alerts, and potentially triggers predefined responses to enhance safety and efficiency.

The "trauma bay of the future" envisions an advanced real-time 3D AI model of the human body. This system would technically integrate disparate data sources: vitals from monitoring devices, the patient's medical history from the EHR, PACS imaging (CT, MRI scans), and other relevant data from the EHR. AI algorithms would then fuse this information to construct a dynamic, personalized 3D representation. This model could then simulate injuries based on various mechanisms of trauma (e.g., specific forces in a motor vehicle accident, crush injury dynamics, penetrating wound trajectories), predicting the cascade of physiological effects. Technically, this would involve complex computational fluid dynamics, biomechanical modeling, and predictive analytics, highlighting zones of injury and modeling injury pathways in real-time, providing unprecedented insight for clinical decision-making.

For humanoid robots, technical integration into hospitals involves navigating regulatory pathways and ensuring secure operation. Like any medical device, they must undergo FDA classification, which categorizes devices based on their invasiveness and criticality. A triage assistant robot, for instance, might be a Class II device, while a surgical robot like the Da Vinci system is a Class III device due to its direct life-sustaining or highly invasive function. The technical challenges include robust mobility and navigation algorithms, task-based execution capabilities, human-robot interaction (HRI) design for safe and effective communication, and stringent cybersecurity controls to prevent manipulation or unauthorized access. The emergence of robots like GR1 (China) and Digit (US) signifies advancements in actuation, sensing, and AI for autonomous decision-making in complex environments.

Patient-facing technologies, such as personalized screens for accessing health data, require robust cybersecurity measures. Technical specifications include adherence to the principle of least privilege, ensuring patients only access their own relevant data. TLS encryption is paramount for securing data in transit, protecting sensitive health information from interception. VLAN segmentation would isolate patient-facing networks from critical clinical systems, minimizing the blast radius of any security breach. Furthermore, auto-log off features and strong authentication mechanisms like PINs are essential to prevent unauthorized access to patient data, especially in public or semi-public hospital settings.

Finally, the concept of the "home as a healthcare hub" leverages IoT sensors, smart devices, and predictive AI tools. Devices like Beam O exemplify this by integrating hospital-grade monitoring capabilities (tracking vital signs, listening to lung sounds) with the patient's EHR, creating a continuous feedback loop. Technically, this involves secure device pairing, encrypted data transmission from home devices to cloud platforms or hospital systems, and AI algorithms that analyze continuous data streams for early warning signs of health decline. The scalability of these solutions hinges on secure, interoperable communication protocols and robust data privacy frameworks.

Throughout these technical advancements, Dr. Su stressed the critical importance of ethics, which translates into technical requirements for strong consent models, algorithmic transparency (allowing for auditability and explainability of AI decisions), the input of ethics boards with clinician representation, and fundamentally, secure infrastructures to protect patient data and ensure the integrity of AI-driven care.

Demo / Proof of Concept

▶ Watch: Examining critical ESI triage challenges in emergency departments (6:00)

The talk did not feature a live demonstration or a specific proof of concept developed by the speaker. Instead, Dr. Su presented a comprehensive overview of existing and emerging AI and hardware applications in healthcare, drawing upon numerous studies and industry developments to illustrate their practical implementation and future potential. Her discussion served as a conceptual demonstration of how these technologies could integrate into and transform clinical workflows, supported by evidence from research and current market trends for devices like humanoid robots and home monitoring systems.

Defensive Implications

▶ Watch: How AI improves ESI triage accuracy and clinical decision-making (7:40)

For a DEF CON audience, the defensive implications of integrating AI and advanced hardware into healthcare are paramount, transforming the traditional cybersecurity landscape into one with direct, life-or-death consequences. Dr. Su's talk, while focused on innovation, implicitly highlighted an expanded attack surface and the urgent need for proactive security measures.

Firstly, the pervasive legacy tech and technical debt in healthcare infrastructure represent a massive vulnerability. Defenders must prioritize comprehensive auditing of existing systems, identifying and remediating unsupported operating systems, unpatched devices, and insecure configurations. The call to "break down silos" and "invest in infrastructure that can actually scale" directly translates to modernizing network architectures, implementing zero-trust principles, and ensuring robust network segmentation (e.g., extensive use of VLANs) to isolate critical medical devices and patient data from less secure segments. The "flat network" joke is a stark warning that must be addressed with deliberate architectural hardening.

The introduction of AI-powered cameras and IoT sensors (e.g., for home monitoring, wearables) vastly increases the number of edge devices in the clinical environment. Each of these devices represents a potential entry point for attackers. Defenders need to implement rigorous device security protocols, including secure boot, firmware integrity checks, strong authentication for device management, and secure update mechanisms. Data transmitted from these devices to EHRs via secure APIs must be protected with TLS encryption and validated for integrity. The potential for these devices to be compromised and used for surveillance, data exfiltration, or even to trigger erroneous clinical alerts (e.g., false stroke alerts) demands a robust threat modeling approach specific to medical IoT.

The advent of humanoid robots introduces entirely new vectors for attack. These physical systems, once "badged" and integrated into workflows, could be targeted for manipulation, disruption, or even physical harm. Defenders must consider the security of their control systems, firmware, communication protocols, and AI decision-making logic. Preventing unauthorized access, ensuring the integrity of their programming, and protecting against denial-of-service attacks that could render them inoperable are critical. Furthermore, the ethical implications Dr. Su mentioned – algorithmic transparency and consent models – have defensive counterparts in ensuring AI models are not biased, exploitable, or used for malicious purposes, necessitating robust AI security and auditing frameworks.

Patient-facing technologies, such as personalized data screens and telemedicine platforms, require stringent data privacy and access controls. Implementing least privilege access, multi-factor authentication, and granular authorization policies is essential. TLS encryption for data in transit and encryption at rest for sensitive patient information are non-negotiable. The integration of telemedicine platforms, especially for underserved populations, must guarantee secure communication channels and protect against data breaches that could expose vulnerable individuals.

Finally, Dr. Su's core message – "cyber doesn't need to be a medical emergency" – serves as the ultimate defensive imperative. This means shifting from a reactive posture to a proactive one. Healthcare organizations must invest in incident response planning that specifically addresses clinical impact, conducting regular tabletop exercises involving both IT and clinical staff. Continuous vulnerability management, penetration testing, and security awareness training for all staff (clinical and technical) are vital. The ultimate defense lies in building a culture where cybersecurity is understood as a fundamental component of patient safety, driving purposeful modernization and secure integration of AI and hardware to "stop this bleeding before it happens."

Key Takeaways

  • Proactive Infrastructure Modernization is Critical: Healthcare's fragile, legacy IT infrastructure, plagued by technical debt and unpatched systems, must be modernized with purpose before AI can be safely and effectively integrated.
  • AI Augments, Not Replaces, Clinicians: AI's primary role is to provide precision support, enhancing human capabilities in areas like triage (e.g., improving ESI adherence from 60%), diagnosis, and real-time monitoring, rather than replacing clinical judgment.
  • Transformative Hardware is Emerging: AI-powered cameras, immersive simulation labs, humanoid robots (like GR1 and Digit expected within 5 years), wearables, and home monitoring devices (e.g., Beam O) are poised to redefine care delivery across the entire patient journey.
  • Security and Ethics are Non-Negotiable: The deployment of AI and smart hardware in healthcare demands strong consent models, algorithmic transparency, ethics board oversight, and robust, secure infrastructures to protect patient data and ensure responsible innovation.
  • AI Impacts Key Business and Quality Metrics: Successful AI integration directly translates to improved ED throughput, shortened length of stay, reduced readmission rates, enhanced accreditation compliance, and ultimately, better patient outcomes, aligning with critical organizational objectives.
  • Cybersecurity is Patient Safety: Cyber incidents are medical emergencies. A proactive, defensive posture — through auditing, breaking silos, and investing in scalable, secure tech — is essential to prevent system failures from directly harming patients.

About the Speaker(s)

Dr. Shiferlay Olen Brock, known as Jen Su, is a cybersecurity consultant with Provisio Insights, bringing a unique and invaluable perspective to the intersection of healthcare and technology. Her extensive professional journey spans a wide array of roles, from a dedicated trauma nurse on the front lines of emergency care to a strategic cybersecurity expert. Dr. Su has been deeply involved in shaping healthcare policy and standards, serving on national committees for organizations such as the Emergency Nurses Association (contributing to position statements) and the Society of Trauma Nursing Government Affairs. She has also held leadership positions in patient experience, managed ANCC Pathway to Excellence coordination for hospitals, and received recognition as a reviewer for the Journal of Emergency Nursing. Her diverse background makes her a passionate advocate for leveraging smart technology and AI to enhance patient safety, drawing directly from her lived experiences in both clinical and cyber security domains.

Reviews

Dr. Zero (Offensive Security Researcher) — WEAK

A well-intentioned talk from someone with genuine clinical credentials, but it's a healthcare technology survey dressed up as a DEF CON talk. There's no original research, no demonstrated exploits, no novel defensive architecture — just a tour of vendor products and AI use-case speculation with cybersecurity vocabulary sprinkled on top.

Heather Calloway (CISO) — WEAK

A genuinely compelling speaker with a rare clinical-plus-security background, but the talk reads more as a hopeful technology tour than a security analysis. The governance architecture — who owns the risk, who is accountable when these systems fail — is almost entirely absent, and the defensive content is surface-level.

→ Top-rated talks at DEF CON 33

All talks from DEF CON 33