US Warns of Unusual Cyber-Security Flaw in Pacemakers, Defibrillators

Advertisement
By Associated Press | Updated: 11 January 2017 17:28 IST

The Homeland Security Department warned Tuesday about an unusual cyber-security flaw for one manufacturer's implantable heart devices that it said could allow hackers to remotely take control of a person's defibrillator or pacemaker.

Information on the security flaw, identified by researchers at MedSec Holdings in reports months ago, was only formally made public after the manufacturer, St. Jude Medical, made a software repair available Monday. MedSec is a cyber-security research company that focuses on the health-care industry.

Advertisement

The government advisory said security patches will be rolled out automatically over months to patients with a device transmitter at home, as long as it is plugged in and connected to the company's network. The transmitters send heart device data back to medical professionals.

Abbott Laboratories' St. Jude said in a statement it was not aware of deaths or injuries caused by the problem. The Food and Drug Administration also said there was no evidence patients were harmed.

Advertisement

The federal investigation into the problem started in August.

MedSec CEO Justine Bone said on Twitter that St. Jude's software fix did not address all problems in the devices.

Advertisement

St. Jude's devices treat dangerous irregular heart rhythms that can cause cardiac failure or arrest. Implanted under the skin of the chest, the devices electronically pace heartbeats and shock the heart back to its normal rhythm when dangerous pumping patterns are detected.

The company's Merlin@home Transmitter electronically sends details on the device's performance to a website where the patient's physician can review the information. But that device can also be hacked.

Advertisement

The FDA's review is ongoing, agency spokeswoman Angela Stark said. Its investigation confirmed the vulnerabilities of the home transmitter, which could potentially be hacked and used to rapidly deplete an implanted device battery, alter pacing and potentially administer inappropriate and dangerous shocks to a person's heart.

The software patch issued by St. Jude "addresses vulnerabilities that present the greatest risk to patients," Stark said.

Stark said the company is working to address remaining vulnerabilities quickly. She said any new cardiac devices submitted to the FDA for review that use the affected transmitter will not be cleared or approved without the software update.

St. Jude disclosed details about the problem after it merged with Abbott. The company has previously denied findings that their devices could be hacked and filed a lawsuit against Muddy Waters LLC and MedSec, alleging that they tried to manipulate the markets to profit from the vulnerability research disclosures.

The revelations about a hacker's ability to potentially gain remote access and affect even the workings of a human heart shed light on the pressing problems of cybersecurity in an increasingly networked world. The advisory also highlights the dilemma for security researchers who may feel an obligation to inform the public of possible dangers but don't want to cause unnecessary panic.

"Your average patient isn't going to be targeted by assassins," said Matthew Green, an assistant professor for computer science at Johns Hopkins University. He was hired by Muddy Waters to help validate the MedSec findings after St. Jude filed its lawsuit. "An attack on this level is low-probability but very high-impact." He called it "probably the most impactful vulnerability I've ever seen."

Green said many of the more severe vulnerabilities identified by MedSec for the devices themselves have not been fixed, but the new software would make the home system a little more secure.

The FDA has been urging manufacturers to update their products, software and security measures since at least 2013. However, agency guidelines issued last year are not binding. The FDA does not review the vast majority of cyber security updates made to devices, under its own rules intended to streamline medical device upgrades.

In 2015 the FDA issued two separate safety alerts to hospitals over drug pumps made by Hospira, now owned by Pfizer.

In the second notice, regulators told hospitals to stop using the company's Symbiq Infusion System after the company confirmed the system could be remotely hacked, allowing an outside party to potentially reprogram the drug pumps. The devices are used to slowly dose intravenous drugs for pain, infection, nutrition and other uses and are usually programmed through a wireless hospital network.

No patient injuries were reported in connection with the issue, but the agency urged users "to begin transitioning to alternative infusion systems as soon as possible."

Hospira discontinued the pumps for unrelated reasons prior to the FDA announcement, according to the agency.

 

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Further reading: Internet, Cyber Security, US
Advertisement

Related Stories

Popular Mobile Brands
  1. Smartphones Launched in India (August 2026): See List
  2. Apple Could Make Its Next Apple Watch a Much Better Health Tracker
  3. Poco F9 Ultra May Cost Nearly Twice as Much as Poco F9 Pro
  4. Realme P4s vs iQOO Z11 vs Nothing Phone 4b Compared
  1. Poco F9 Ultra May Cost Nearly Twice as Much as Poco F9 Pro, Tipster Claims
  2. Apple Watch Series 12, Ultra 4 Could Get Two Major Health Upgrades, New Finishes: Report
  3. Vivo X500 Pro Max Display Details Officially Teased Ahead of Launch
  4. Apple Maps Gets Transit Support in India With Public Transport Directions and More
  5. Google Is Changing How You Sign In to Android Apps
  6. Sneaky Sasquatch Gets Subway Surfers+ Crossover, Birdwatching Update on Apple Arcade
  7. YouTube Adds Amazon Product Tags to Shorts, Videos and Livestreams
  8. Poco X8 5G and X8 Power 5G India Launch Date Set for September 4
  9. Acer Swift Neo 14 Refreshed in India With Up to Intel Core Ultra 7 CPU: Price, Features
  10. Samsung Odyssey G Series Gaming Monitors Unveiled at Gamescom 2026 With Curved OLED, 1,100Hz Panel
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2026. All rights reserved.