CAUTION
The Stryker ENT Navigation System and computers running Scopis ENT Software with TGS
should only be used in physically protected areas such as the doctor's personal office or the
operating room.
Operators must adhere to the respective national requirements regarding protection
of patient data (e.g. HIPAA). The navigation system may only be used by persons that
have been authorized to do so. Ask your responsible authority for further information
about the patient data security in your country. We recommend protecting the system
from unauthorized use by means of a password.
It is recommended to only use encrypted USB sticks for transferring patient data from
and to the navigation system.
Always use a validated user authentication and authorization scheme such as Win-
dows domain logon to prevent unauthorized access to the navigation system.
Make sure that users have received adequate training on patient data privacy,
are aware of cyber security issues and know about cyber security defenses.
Do use anti-virus software on the navigation system for on-access and full-scans at
regular intervals.
Ensure timely installation of operating system security updates and application up-
dates.
Changes to the system configuration including installation of updates should only be
performed in a controlled manner. Before you make any changes to the system (e.g.
installing anti-virus software) please make sure that you have set restore points.
To ensure confidentiality of patient data, availability and integrity of the device for surgery
and protect from unauthorized access, unauthorized modification or interruption, Stryker
suggests the following:
● Educate user and staff: Make sure that users have received adequate training on patient
data privacy, are aware of cyber security issues such as phishing attacks or USB-based
malware and know about cyber security defenses such as virus scanners and encryption.
● Ensure access control to the device: Install the navigation system/workstation at a loca-
tion with physical access control to prevent theft and use authentication/authorization
to prevent unauthorized download of patient data from the navigation system via media
ports (USB / DVD). Also consider deactivating media ports or installing USB access control
software when physical security is limited.
● Keep device in secure network: Keep the navigation system in an isolated network with
only trusted and controlled devices. Restrict connections from and to the navigation sys-
tem to manually cleared hosts.
● User authentication / authorization using passwords via hospital domain: Avoid unau-
thorized access to patient data by joining the navigation unit into the hospital domain
and using per user authentication and authorization. Avoid that regular users do have
administration rights on the navigation unit.
● Perform changes in a controlled manner and make use of restore points: All changes to
the system configuration and environment such as installing updates and changing the
network may result in new risks. Always perform a new analysis of the resulting risks.
Create restore points at regular intervals and before making changes to the system's con-
figuration.
EN
Safety Information | 6/21