Cyberattacks on Boston Scientific and McKesson expose a growing healthcare risk, affecting connected heart-device monitoring, operations and sensitive patient data.

Healthcare Cyberattacks Now Threaten Pacemakers, Patient Records and Medical Supply Chains

The420 Web Correspondent
7 Min Read

Cyberattacks targeting healthcare companies are moving beyond stolen passwords and patient databases. Recent incidents involving medical-device maker Boston Scientific and healthcare giant McKesson show how a digital intrusion can disrupt medical operations, affect remote monitoring of heart devices and potentially expose highly sensitive patient information.

The two incidents are separate, but together they highlight a growing problem for the healthcare industry. Hospitals, medical-device companies and healthcare suppliers increasingly depend on connected computer systems, making cybersecurity failures capable of affecting both information and real-world medical services.

Algoritha Security Launches ‘Make in India’ Cyber Lab for Educational Institutions

What Are Connected Medical Devices and Patient Data Breaches?

Modern medical devices can communicate with computer systems to record, transmit or monitor patient information. In the case of some cardiac devices, remote monitoring allows information about a patient’s heart rhythm to be sent from home to a healthcare provider.

A patient-data breach is different. It occurs when unauthorised individuals gain access to information such as names, contact details, medical records or treatment information. In healthcare, such data can be particularly sensitive because it may reveal a person’s medical condition, appointments or treatment history.

Boston Scientific Attack Disrupts Remote Monitoring

Boston Scientific identified a cybersecurity incident on August 25 that caused a network outage and disrupted several business operations. The company said certain on-premise systems were affected, while its cloud-based systems and applications were not impacted.

The incident also affected some newly implanted cardiac devices. Boston Scientific said new cardiac rhythm management implants could not activate their remote monitoring communicators, meaning device information could not be transmitted to remote patient-management systems until the affected systems were restored.

For certain insertable cardiac monitors, recorded heart-rhythm episodes continued to be stored on the device. Patients could still have the information transmitted through an in-person process using the company’s Clinic Assistant application.

The company has not said that the devices themselves were hacked or that patients’ implanted devices became unsafe. It said there was no known impact on devices that were not connected to its network or on clinicians’ ability to use those devices.

The cyberattack nevertheless disrupted manufacturing, ordering and shipping. Boston Scientific has brought in CrowdStrike and other cybersecurity specialists to investigate and restore affected systems, but has not provided a final timeline for complete recovery.

McKesson Confirms Patient Data Was Stolen

A separate incident involving McKesson has raised a different concern: the theft of healthcare information.

McKesson confirmed that unauthorised access occurred in certain third-party applications connected with its Oncology & Multispecialty and Medical-Surgical businesses. The company has not yet disclosed how many patients were affected or exactly what information was taken. It said distribution centres remained operational and that it had reasonable assurance the attackers had been removed from the affected environments.

The ShinyHunters extortion group has claimed responsibility and alleged that more than 284 million patient records were compromised. It has demanded $55.2 million from McKesson in exchange for not releasing the information.

That figure remains an allegation by the attackers and has not been independently confirmed by McKesson. Cybersecurity experts have previously warned that criminal groups’ claims about stolen data can be exaggerated, making independent verification important.

According to ShinyHunters, the allegedly stolen information includes names, addresses, phone numbers, dates of birth, Social Security numbers, appointment information and sensitive medical details. The group also claimed that it accessed private communications between doctors and patients.

The attackers said they gained access through voice phishing, a technique in which criminals use phone calls or conversations to trick employees into revealing information or granting access. The same group has previously claimed attacks against healthcare organisations, including Medtronic and Exact Sciences.

Healthcare Cybersecurity Is Now a Patient-Safety Issue

The incidents show why healthcare cybersecurity cannot be treated simply as an IT problem.

A stolen database can expose a person’s most private information, while an attack on connected medical infrastructure can interfere with monitoring, manufacturing or supply operations. Even when there is no evidence that a medical device itself has been compromised, disruption to the systems surrounding it can still create practical problems for patients and healthcare providers.

Recent attacks on Medtronic and other medical companies show that this is not an isolated pattern. Medtronic said in June that its April cybersecurity incident had affected some corporate IT systems, although it had found no impact on product safety, patient safety, manufacturing or distribution.

For healthcare companies, the challenge is therefore becoming broader: protecting patient information while ensuring that the digital systems supporting medical devices, manufacturing and treatment remain available.

For patients, the immediate lesson is equally important. A healthcare organisation’s cyberattack does not automatically mean that a medical device has been hacked or that every patient has been affected. But when a company reports a breach or system disruption, patients should pay attention to official updates, particularly if they use connected devices or receive communications about their personal information.

What this means for you: If your healthcare provider or medical-device company reports a cyber incident, follow only its official patient instructions and do not respond to unexpected calls, emails or messages asking for medical, identity or financial information. If you receive a suspicious communication after a healthcare breach, verify it directly with the provider before sharing any details.

Stay Connected