Pacemakers get update after security flaw found

There have been no known attacks using the flaw, with a firmware update now being rolled out

Three-quarters of a million pacemakers have a vulnerability that could let hackers access the implanted equipment, running down the battery or meddling with the pacing.

The US Food and Drug Administration (FDA) issued a warning that anyone with a specific model of radio frequency-enabled pacemaker from manufacturer Abbott needs to visit a medical professional to have the firmware updated.

There are no reports of the flaws being used to hack a pacemaker, the FDA and Abbott stressed. "There are no known reports of patient harm related to the cybersecurity vulnerabilities in the 465,000 (US) implanted devices impacted," the alert said. Alongside the half million pacemakers in use in the US, the company told the BBC that there were a further 280,000 used in other countries. 

The firmware update highlights the issues raised by connecting everything from home appliances to medical equipment to the internet, although the latter could have much more serious repercussions. Abbott stressed that security affects all industries and noted its devices were having a "significant positive impact for patients and their health".

Advertisement
Advertisement - Article continues below
Advertisement - Article continues below

Unlike other industries, medical updates are complicated as they need to be approved by the FDA first, to ensure code doesn't brick the hardware not unheard of with other smart devices that receive updates.

The FDA has approved the firmware update, but it can't be installed over-the-air, requiring patients to visit their doctors. "The update process will take approximately three minutes to complete," the alert notes. "During this time, the device will operate in backup mode (pacing at 67 beats per minute), and essential, life-sustaining features will remain available."

The alert warns that there's a tiny risk of losing data or settings, but it's below 1%. However, it warned that the update should be run for patients dependent on the device at a facility that can offer temporary cardiac pacing in case of any failures.

The firmware isn't only patching the vulnerabilities, Abbot said, but boosting security via encryption and network connectivity management tools. "To further protect our patients, Abbott has developed new firmware with additional security measures that can be installed on our pacemakers," said Robert Ford, executive vice president of medical devices at Abbott, in a statement.

It isn't clear why the update is being rolled out. Abbott said it was "scheduled" while the FDA said it had "reviewed information concerning potential cybersecurity vulnerabilities," but didn't say where the information came from. 

The warning applies to a specific set of devices made by Abbott, formerly known as St Jude Medical. The FDA alert has the full details here.

Featured Resources

What you need to know about migrating to SAP S/4HANA

Factors to assess how and when to begin migration

Download now

Your enterprise cloud solutions guide

Infrastructure designed to meet your company's IT needs for next-generation cloud applications

Download now

Testing for compliance just became easier

How you can use technology to ensure compliance in your organisation

Download now

Best practices for implementing security awareness training

How to develop a security awareness programme that will actually change behaviour

Download now
Advertisement

Recommended

Visit/security/internet-security/354417/avast-and-avg-extensions-pulled-from-chrome
internet security

Avast and AVG extensions pulled from Chrome

19 Dec 2019
Visit/security/354156/google-confirms-android-cameras-can-be-hijacked-to-spy-on-you
Security

Google confirms Android cameras can be hijacked to spy on you

20 Nov 2019

Most Popular

Visit/policy-legislation/data-governance/354496/brexit-security-talks-under-threat-after-uk-accused-of
data governance

Brexit security talks under threat after UK accused of illegally copying Schengen data

10 Jan 2020
Visit/microsoft-windows/32066/what-to-do-if-youre-still-running-windows-7
Microsoft Windows

What to do if you're still running Windows 7

14 Jan 2020
Visit/hardware/laptops/354533/dell-xps-13-new-9300-hands-on-review-chasing-perfection
Laptops

Dell XPS 13 (New 9300) hands-on review: Chasing perfection

14 Jan 2020
Visit/operating-systems/25802/17-windows-10-problems-and-how-to-fix-them
operating systems

17 Windows 10 problems - and how to fix them

13 Jan 2020