Skip to content Skip to navigation

Muddy Waters Report: St. Jude Medical’s Cardiac Devices Vulnerable to Cyber Attacks

August 29, 2016
by Rajiv Leventhal
| Reprints

St. Jude Medical, a Minnesota-based global medical device manufacturer, saw its shares drop last week after a Muddy Waters Capital report noted demonstrations of cyber attacks to two of the company’s cardiac devices.

According to an Aug. 25th report from CNBC, shares briefly fell more than 8 percent on that day, but ended up recovering though still finishing the day down 5 percent. Meanwhile, the report from the short selling firm Muddy Waters said they have seen demonstrations of two types of cyber attacks against St. Jude’s implantable cardiac devices: a “crash” attack that causes cardiac devices to malfunction—including by apparently pacing at a potentially dangerous rate; and, a battery drain attack that could be particularly harmful to device dependent users. The report from Muddy Waters admitted that the firm has no experience in cybersecurity, but nonetheless was able replicate in-house key exploits that help to enable these attacks.

The firm’s report stated that, “Based on conversations with industry experts, we estimate remediation would take at least two years. Even lacking a recall, the product safety issues we present in this report offer unnecessary health risks and should receive serious notice among hospitals, physicians and cardiac patients.”

What’s more, the report noted that the devices’ vulnerabilities are more worrying than the medical device hacks that have been publicly discussed in the past. “These attacks take less skill, can be directed randomly at any STJ Cardiac Device within a roughly 50 foot radius, theoretically can be executed on a very large scale, and most gallingly, are made possible by the hundreds of thousands of substandard home monitoring devices STJ has distributed,” the report stated. “The STJ ecosystem, which consists of Cardiac Devices, STJ’s network, physician office programmers, and home monitoring devices, has significant vulnerabilities. These vulnerabilities highly likely could be exploited for numerous other types of attacks,” it concluded.

In a Bloomberg report, Phil Ebeling, St. Jude’s chief technology officer, insisted that “The allegations are absolutely untrue.” He added, “There are several layers of security measures in place. We conduct security assessments on an ongoing basis and work with external experts specifically on Merlin@home and on all our devices.” Even so, the Bloomberg report predicted that if proven, the company’s planned purchase by Abbott Laboratories “could be derailed.”

Get the latest information on Cybersecurity and attend other valuable sessions at this two-day Summit providing healthcare leaders with educational content, insightful debate and dialogue on the future of healthcare and technology.

Learn More

Topics

News

Healthcare Data Breaches: A Year in Review

The latest year-in-review Breach Barometer report from Protenus paints a stark picture—2016 average at least one health data breach per day, affecting more than 27 million patient records.

Healthcare Industry Could Save $9.4B with Full Adoption of Electronic Transactions

The healthcare industry continues to make modest progress toward full adoption of electronic business transactions, but significant gaps remain, representing an opportunity for $9.4 billion in savings, according to new data from the 2016 CAQH Index.

ONC Announces Phase 2 Winners of Consumer, Provider App Challenges

ONC today announced the Phase 2 winners for the Consumer Health Data Aggregator Challenge and the Provider User Experience Challenge.

Health Affairs: ACOs with High Numbers of Minority Patients Struggle in Quality

Accountable care organizations (ACOs) that have a high proportion of minority patients were associated with low scores on about three-fourths of Medicare quality performance measures, according to new research published in Health Affairs.

Trump Taps David Shulkin, an Obama Appointee, for VA Secretary

President-elect Donald Trump announced yesterday that David Shulkin, M.D.—an Obama administration appointee and current VA undersecretary—will lead the Department of Veterans Affairs.

NIST Publishes Draft Update to Cybersecurity Framework

The National Institute of Standards and Technology (NIST) has published proposed updates to the Framework for Improving Critical Infrastructure Cybersecurity—also known as the Cybersecurity Framework.