Boston Scientific Says Cyberattack Disrupted Its Manufacturing Operations

The incident has also impacted new remote monitoring activations.

I Stock 1277065333
juststock/iStock

Boston Scientific provided an update on a cyberattack it identified earlier this week that resulted in a network outage and disruption to the company’s operations.

It said the incident is affecting access to certain operating systems and business applications, including the ability to manufacture products, as well as process and ship customer orders. 

"We recognize the importance of cybersecurity for patients, customers and vendor systems. Patients and physicians are at the center of our recovery effort. We are working to maintain continuity of supply. Further, Boston Scientific continues to investigate potential impact to patients’ implanted devices or to devices that connect to networks across our product portfolio and will provide updates as soon as they are available," the company said.

Boston Scientific said its investigation so far has shown no impact to implantable cardiac rhythm management (CRM) device function. It also doesn’t impact the device’s ability to transmit data, or healthcare professionals’ ability to access remote patient management data for CRM devices remotely monitored prior to the network disruption. Additionally, there is no evidence of increased cybersecurity risks or difficulties transferring data from CRM remote monitoring systems to electronic medical records (EMR) systems. 

However, it said new remote monitoring activations are impacted by this disruption: 

  • For new cardiac device implants -- CRM devices other than insertable cardiac monitors (ICM): New remote monitoring communicators cannot be activated, thus available device data will NOT be transmitted to remote patient management systems until the communicator can be activated. Programmer interrogations are not affected by this system disruption. 
  • For new ICM device implants: Newly implanted ICMs must be activated using the Boston Scientific Clinic Assistant app to enable the ICM to properly record episodes. New ICMs are unable to pair to the patient remote monitoring mobile phone, therefore available episode data recorded by the ICM will NOT be transmitted to the remote monitoring system until the ICM can be paired to the patient mobile app. Episodes will continue to be recorded by the ICM and can be transmitted to the remote monitoring system via an in-person interrogation with the Clinic Assistant app by selecting the “Interrogate” button. 

The cyberattack incident at Boston Scientific is just the latest targeting of a medtech firm this year.

Stryker, a medical equipment manufacturer specializing in surgical and orthopedic products, was able to fully restore its production operations in April after suffering a cyberattack in March. Medtronic and Abbott Labs also reported cyberattacks earlier this year.

More in Safety