St. Jude Medical Responds to Poor Security Claims on its Cardiac Devices | Healthcare Informatics Magazine | Health IT | Information Technology Skip to content Skip to navigation

St. Jude Medical Responds to Poor Security Claims on its Cardiac Devices

August 31, 2016
by Rajiv Leventhal
| Reprints

St. Jude Medical officials have attested that the allegations made regarding the lack of security and safety of the manufacturer’s cardiac devices are “false and misleading.”

The Minnesota-based global medical device manufacturer saw its shares drop last week after a Muddy Waters Capital report noted demonstrations of cyber attacks to two of the company’s cardiac devices.

Specifically, the report from the short selling firm Muddy Waters said they have seen demonstrations of two types of cyber attacks against St. Jude’s implantable cardiac devices: a “crash” attack that causes cardiac devices to malfunction—including by apparently pacing at a potentially dangerous rate; and, a battery drain attack that could be particularly harmful to device dependent users. The report from Muddy Waters admitted that the firm has no experience in cybersecurity, but nonetheless was able replicate in-house key exploits that help to enable these attacks. As such, the firm said that the devices called into question should be “recalled and remediated.”

In a response to these claims, St. Jude’s fired back in an Aug. 26 statement. Regarding the “crashes,” St. Jude’s officials said that “The report has little detail on this simulation and includes many inconsistencies. In fact, the screenshot of the Merlin programmer in the Muddy Water report shows a device that is functioning normally.

And regarding the battery drain allegation, St. Jude said “The report claimed that the battery could be depleted at a 50-foot range. This is not possible since once the device is implanted into a patient, wireless communication has an approximate 7-foot range. This brings into question the entire testing methodology that has been used as the basis for the Muddy Waters Capital and MedSec report.”

St. Jude further said that its software has been evaluated and assessed by several independent organizations and researchers including Deloitte and Optiv. Its statement read, “Our top priority is to reassure our patients, caregivers and physicians that our devices are secure and to ensure ongoing access to the proven clinical benefits of remote monitoring.” It continued, “We recognize the importance of providing physicians with up-to-date and accurate information in a timely and responsible manner so that they can make informed patient care decisions. Our analysis reinforces the need for researchers and manufactures to work together to discuss and resolve potential issues together to avoid unnecessarily alarming patients.”

Get the latest information on Cybersecurity and attend other valuable sessions at this two-day Summit providing healthcare leaders with educational content, insightful debate and dialogue on the future of healthcare and technology.

Learn More

Topics

News

CMS Exploring Potential Behavioral Health Payment and Care Delivery Model

The Center for Medicare & Medicaid Services (CMS) plans to hold a one-day summit in September to solicit feedback and ideas for a potential behavioral health model to improve access, quality and cost of care for beneficiaries with behavioral health conditions.

MEDITECH to Soon Offer CommonWell Health Alliance Services to Customers

MEDITECH, a Westwood, Mass.-based electronic health record (EHR) vendor, has announced that it is set to offer CommonWell interoperability services early next year.

HITRUST CSF Certification Now Includes NIST Cybersecurity Certification

HITRUST has announced that HITRUST cybersecurity framework (CSF) version 9 enhancements now extend an “assess once, report many” approach as a standard security framework for multiple critical infrastructure industries and includes National Institute of Standards and Technology (NIST) Cybersecurity certification.

Premier: Analytics Helping Hospitals Optimize Blood Use

An analysis of 645 hospitals revealed that comparative data analytics to drive performance improvement has the potential to optimize blood use across numerous diagnoses.

Almost 80 Percent of Clinicians Still Use Hospital-Issued Pagers

A study examining the communication technologies used by hospital-based clinicians found that close to 80 percent (79.8 percent) of clinicians continue to use hospital-provided pagers and 49 percent of those clinicians report they receive patient care-related messages most commonly by pager.

Survey: IT Expenses per Physician Continue to Rise to Nearly $19,000

Information technology (IT) expenses for physician practices are on a slow and steady rise for most practices, and last year, physician-owned practices spent between nearly $2,000 to $4,000 more per FTE physician on IT operating expenses than they did the prior year, according to a recent Medical Group Management Association (MGMA) survey.