Skip to content

Menu

LexBlog, Inc. logo
NetworkSub-MenuBrowse by SubjectBrowse by PublisherJoin the NetworkGet StartedSubscribeSupportContact
Search
Close

Hackers Intend to Cause Physical Harm with Seizure Inducing Images

By Robert E. Slavkin & Beth Alcalde on December 19, 2019
Email this postTweet this postLike this postShare this post on LinkedIn
brain-scan-of-head-and-skull-with-hand-pointing-picture-id187272969

Computer hacking, and the permutation of crimes that can be committed by hackers, generally does not spur images of infliction of physical harm. However, in a chilling turn of events, computer hackers have opened a new front in the damage that can be inflicted through cybercrime. In a nefarious series of developments, cyber-liabilities now arise from remote manipulation of the operation of implanted medical devices or from social media-based messaging that is calculated to cause physical harm to the curated audience. In short, promising technological advances have been leveraged by bad actors in a fashion not primarily intended to extract money, but rather intended to cause actual physical harm to individuals.

In an attack that appears motivated more in an attempt to inflict physical harm, as opposed to simply hacking for financial gain, the Epilepsy Foundation announced on December 16, 2019 that it had filed a formal criminal compliant after the organization’s Twitter feed was hacked. The Foundation reported that a series of attacks were ‘designed to trigger seizure(s)’. The hacking of the foundation’s Twitter account was used to post GIFs and videos that had seizure-inducing strobe and flashing lights. People with epilepsy are prone to having seizures being triggered through viewing of flickering images and strobe lights.  Perhaps the most twisted aspect of this crime is that it happened during National Epilepsy Awareness Month, when the largest number of people with epilepsy are likely to view the foundation’s social media outlets. 

It is rare for hackers to inflict physical harm on their intended victims, but it is not unprecedented. Previously, in 2008, the Epilepsy Foundation was the victim of hackers who gained access to the Epilepsy Foundation’s website, bombarding it with hundreds of pictures and links to pages of rapidly flashing images. Within some of the posts were small flashing pictures or links, disguised as helpful links, that when clicked on took the viewer to pages of pulsating images with a myriad of colors. The breach triggered migraines and near-seizure reactions for some site viewers.

Additionally, in June of this year, in a proactive move designed to prevent a malevolent hack, the FDA issued a recall for two insulin pumps manufactured by Medtronic. The FDA took this action, stating that the devices that feature wireless remote access for dose adjustment, could be hacked and accessed by someone other than the pump’s user or caregiver or medical provider, and could deliver unsafe, possibly lethal, doses of insulin. The FDA’s message in this recall was that while increased use of wireless technology and software provides safer, more convenient healthcare delivery, there is cause for increased vigilance in this new modern era of healthcare and technology.

What is most remarkable about the FDA’s actions is that it was proactive. Most government action relative to cybercrime, until now, has been reactive in nature, with government agencies taking remedial action once a cybercrime has been perpetrated. Given the frightening implications of possibly hacking an insulin pump, along with the cybercrimes committed through the Epilepsy Foundation’s social media platforms, we may be witnessing the beginning of more steps towards increased oversight in this arena by government agencies.

To further illustrate how such attacks can strike anyone, one of this blog’s co-authors, who serves as a board member for not-for-profit Epilepsy Florida, shares, as an illustration of these high-tech medical risks, that the co-author’s minor child happens to experience seizures if exposed to strobe lights, and also carries an implanted medical device that can be operated and programmed remotely by the child’s medical team. Therefore the risks highlighted above are particularly poignant and real not just to the co-authors, but to thousands of similarly situated individuals nationwide. While not minimizing the financial liabilities in the cybersecurity space, these latest trends serve as a useful reminder to the entire medical research, development, and health service industries that a high priority should be placed on ongoing vigilance and securing sound security counseling resources.

 

 

Photo of Robert E. Slavkin Robert E. Slavkin

Robert Slavkin is the chair of the Healthcare Practice Group, a multidisciplinary team recognized nationally for representing sector participants in regulatory compliance, insurance, and transactional issues. A former healthcare corporate counsel, compliance, and privacy officer for a publicly traded healthcare company, Robert represents…

Robert Slavkin is the chair of the Healthcare Practice Group, a multidisciplinary team recognized nationally for representing sector participants in regulatory compliance, insurance, and transactional issues. A former healthcare corporate counsel, compliance, and privacy officer for a publicly traded healthcare company, Robert represents a variety of clients within the healthcare sector, providing guidance on complex issues and compliance with all appropriate federal and state statutes and regulations. These include federal anti-kickback, Stark laws, Medicare, Medicaid, HIPAA, and FDA regulations, as well as providing guidance on daily operational and compliance issues facing healthcare entities. Robert has significant experience with the Affordable Care Act and the ever-evolving role accountable care plays in U.S. health reform. Additionally, Robert counsels clients on Medicare Managed Care and the Part D programs. He possesses a keen understanding of the momentous legislative changes of this sector as well as potential resulting implications.

Read more about Robert E. SlavkinEmail
Show more Show less
Photo of Beth Alcalde Beth Alcalde

A noted employee benefits lawyer, author, and speaker, Beth Alcalde represents Fortune 500 companies and other public and private entities, including those in the hospitality, healthcare, and higher education sectors, throughout the United States. As a leader within the firm, Beth is a…

A noted employee benefits lawyer, author, and speaker, Beth Alcalde represents Fortune 500 companies and other public and private entities, including those in the hospitality, healthcare, and higher education sectors, throughout the United States. As a leader within the firm, Beth is a longtime member of Akerman’s Board of Directors, and is also a current member of Akerman’s Executive Committee. Previously she chaired the firm’s Professional Development Committee, and served as office managing partner of the firm’s Palm Beach County offices. Noted in Chambers USA as “terrific at coming up with imaginative solutions,” Beth provides counsel on employer-sponsored benefit plans, from compliance with ERISA, the Affordable Care Act, and other federal regulations, to internal audits and benefits-related implications of corporate transactions. She assists clients in defending and responding to audits conducted by the Internal Revenue Service (IRS), U.S. Department of Labor (DOL), and U.S. Department of Health and Human Services (HHS). Of particular emphasis, Beth has represented group health plan sponsors in responding to audits of the quantitative and non-quantitative treatment limitations within their plans, as required by the Mental Health Parity and Addiction Equity Act.

Read more about Beth AlcaldeEmail
Show more Show less
  • Posted in:
    Privacy and Cybersecurity
  • Blog:
    Health Law Rx
  • Organization:
    Akerman LLP
  • Article: View Original Source

Call us at 1-800-913-0988 or email sales@lexblog.com.

Facebook LinkedIn Twitter RSS
The Library at LexBlog
  • About LexBlog
  • The Field We Built
  • Library at LexBlog
  • Our Beliefs
  • Our Team
  • Contact LexBlog
  • Disclaimer
  • Editorial Policy
  • Terms of Service
  • Get Started
  • Publishing Solutions
  • Compass
  • Submit a Request
  • Support Center
  • System Status
Copyright © 2026, LexBlog, Inc. All Rights Reserved.
Law blog design & platform by LexBlog LexBlog Logo