US Warns of Unusual Cyber-Security Flaw in Pacemakers, Defibrillators

Advertisement
By Associated Press | Updated: 11 January 2017 17:28 IST

The Homeland Security Department warned Tuesday about an unusual cyber-security flaw for one manufacturer's implantable heart devices that it said could allow hackers to remotely take control of a person's defibrillator or pacemaker.

Information on the security flaw, identified by researchers at MedSec Holdings in reports months ago, was only formally made public after the manufacturer, St. Jude Medical, made a software repair available Monday. MedSec is a cyber-security research company that focuses on the health-care industry.

The government advisory said security patches will be rolled out automatically over months to patients with a device transmitter at home, as long as it is plugged in and connected to the company's network. The transmitters send heart device data back to medical professionals.

Advertisement

Abbott Laboratories' St. Jude said in a statement it was not aware of deaths or injuries caused by the problem. The Food and Drug Administration also said there was no evidence patients were harmed.

Advertisement

The federal investigation into the problem started in August.

MedSec CEO Justine Bone said on Twitter that St. Jude's software fix did not address all problems in the devices.

Advertisement

St. Jude's devices treat dangerous irregular heart rhythms that can cause cardiac failure or arrest. Implanted under the skin of the chest, the devices electronically pace heartbeats and shock the heart back to its normal rhythm when dangerous pumping patterns are detected.

The company's Merlin@home Transmitter electronically sends details on the device's performance to a website where the patient's physician can review the information. But that device can also be hacked.

Advertisement

The FDA's review is ongoing, agency spokeswoman Angela Stark said. Its investigation confirmed the vulnerabilities of the home transmitter, which could potentially be hacked and used to rapidly deplete an implanted device battery, alter pacing and potentially administer inappropriate and dangerous shocks to a person's heart.

The software patch issued by St. Jude "addresses vulnerabilities that present the greatest risk to patients," Stark said.

Stark said the company is working to address remaining vulnerabilities quickly. She said any new cardiac devices submitted to the FDA for review that use the affected transmitter will not be cleared or approved without the software update.

St. Jude disclosed details about the problem after it merged with Abbott. The company has previously denied findings that their devices could be hacked and filed a lawsuit against Muddy Waters LLC and MedSec, alleging that they tried to manipulate the markets to profit from the vulnerability research disclosures.

The revelations about a hacker's ability to potentially gain remote access and affect even the workings of a human heart shed light on the pressing problems of cybersecurity in an increasingly networked world. The advisory also highlights the dilemma for security researchers who may feel an obligation to inform the public of possible dangers but don't want to cause unnecessary panic.

"Your average patient isn't going to be targeted by assassins," said Matthew Green, an assistant professor for computer science at Johns Hopkins University. He was hired by Muddy Waters to help validate the MedSec findings after St. Jude filed its lawsuit. "An attack on this level is low-probability but very high-impact." He called it "probably the most impactful vulnerability I've ever seen."

Green said many of the more severe vulnerabilities identified by MedSec for the devices themselves have not been fixed, but the new software would make the home system a little more secure.

The FDA has been urging manufacturers to update their products, software and security measures since at least 2013. However, agency guidelines issued last year are not binding. The FDA does not review the vast majority of cyber security updates made to devices, under its own rules intended to streamline medical device upgrades.

In 2015 the FDA issued two separate safety alerts to hospitals over drug pumps made by Hospira, now owned by Pfizer.

In the second notice, regulators told hospitals to stop using the company's Symbiq Infusion System after the company confirmed the system could be remotely hacked, allowing an outside party to potentially reprogram the drug pumps. The devices are used to slowly dose intravenous drugs for pain, infection, nutrition and other uses and are usually programmed through a wireless hospital network.

No patient injuries were reported in connection with the issue, but the agency urged users "to begin transitioning to alternative infusion systems as soon as possible."

Hospira discontinued the pumps for unrelated reasons prior to the FDA announcement, according to the agency.

 

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Further reading: Internet, Cyber Security, US
Advertisement

Related Stories

Popular Mobile Brands
  1. MacBook Air (2025) With M4 Chip Available at This Discounted Price
  2. Motorola Edge 70 With 5,000mAh Battery Launched in India at This Price
  3. OnePlus 15R Storage Options Leaked: Here's How Much It Might Cost in India
  4. Oppo Reno 15c With Snapdragon 7 Gen 4 SoC Launched at This Price
  5. Jio Launches Happy New Year 2026 Prepaid Plans: Check Price, Benefits
  6. Logitech MX Master 4 Launches in India With These Features
  7. Pixel 10 Series Gets Price Cuts During Google's End of Year Sale: See Offers
  8. Game of the Year Winner Clair Obscur: Expedition 33 Gets New Major Update
  9. Apple Fitness+ Service Is Now Available in India: See Features
  10. Samsung Might Build 2nm Process Chipsets for AMD
  1. Clair Obscur: Expedition 33 Gets New 'Thank You' Update After Winning at The Game Awards
  2. Apple Fitness+ Now Available in India With Custom Workout Programmes: Price and Other Details
  3. Samsung Could Reportedly Strike a Deal With AMD to Build Future 2nm Process Chipsets
  4. Pixel 10 Series, Pixel Accessories Get Price Cuts in India During Google's End of Year Sale
  5. Alexa's Popular Requests in 2025 Included K-Pop, Bollywood, Podcasts and Details About Celebrities
  6. Logitech MX Master 4 Launched in India With 8,000 DPI Sensor and Multi-Pairing Support
  7. Amazon Introduces Ask This Book AI Feature for the Kindle App, Provides Spoiler-Free Answers
  8. MacBook Air (2025) With M4 Chip Available With Over Rs. 10,000 Discount in India: Here Are the Details
  9. Oppo Reno 15c Launched With Snapdragon 7 Gen 4 SoC, 6,500mAh Battery: Price, Specifications
  10. Star Wars: Fate of the Old Republic Will Launch Before 2030, Game Director Confirms
Gadgets 360 is available in
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2025. All rights reserved.