FDA Warns of Cybersecurity Risk with St. Jude Devices

Share

FDA has identified cybersecurity vulnerabilities with St. Jude Medical’s implantable cardiac devices and its Merlin@home Transmitter. If exploited, the vulnerability could allow an unauthorized user to remotely access a patient’s radio frequency (RF)-enabled implanted cardiac device by altering the Merlin@home Transmitter, an agency safety alert says. “The altered Merlin@home Transmitter could then be used to modify programming commands to the implanted device, which could result in rapid battery depletion and/or administration of inappropriate pacing or shocks,” it says. So far, no injury reports related to this have been received.


To fix the problem, St Jude has developed and validated a software patch for the transmitter that addresses and reduces the risk of specific cybersecurity vulnerabilities. “Patients and patient caregivers only need to make sure their Merlin@home Transmitter remains plugged in and connected to the Merlin.net network to receive the patch,” FDA says. The agency conducted an assessment of the benefits and risks of using the Merlin@home Transmitter, and has determined that the health benefits to patients from continued use of the device outweigh the cybersecurity risks.

Read more