The communications protocol for the Medtronic MiniMed 600 Series Insulin Pump System could allow an unauthorized person to access the pump to deliver too much or too little insulin, the Food and Drug Administration alerted users today. The agency said it is not aware of any reports related to this cybersecurity vulnerability. Medtronic recommends users take certain actions and precautions to protect their device from unauthorized access.

John Riggi, AHA’s national advisor for cybersecurity and risk, said, “The health care field is rapidly expanding the use of network- and internet-connected medical technologies, which help improve patient outcomes and increase clinical and business efficiencies. However, the increased use of network and internet connections also expand our cyber ‘attack surface,’ allowing many more potential entry points into our networks if not properly secured — and in this case, potentially impacting the operational safety of a patient-connected medical device. Last week the FBI issued an alert warning that cyber threat actors are exploiting medical device vulnerabilities, which could potentially adversely impact health care facilities’ operational functions, patient safety, and data confidentiality and data integrity. Given this heightened medical device cyber threat environment, it is essential that the biomedical engineering and cybersecurity functions in hospitals and health systems work in close coordination to efficiently identify and patch cyber vulnerabilities in medical devices.” 

For more information on this or other cyber and risk issues, contact Riggi at jriggi@aha.org.

Headline
FBI Co-deputy Director Andrew Bailey discussed a rise in cyber and physical threats impacting health care. He discussed health care as the top critical…
Headline
Health care and public health was the top sector targeted for cyberthreats in 2025, according to the FBI’s latest annual report on internet crimes. There were…
Headline
The Cybersecurity and Infrastructure Security Agency released an alert March 27 on a vulnerability in F5 BIG-IP Access Policy Manager software that is being…
Headline
The FBI released an alert March 20 warning of a technique used by cyber actors working on behalf of the Iranian government to conduct malicious cyber activity…
Headline
The Cybersecurity and Infrastructure Security Agency March 18 released an alert urging U.S. organizations to harden their endpoint management systems following…
Headline
The Health Sector Coordinating Council Cyber Working Group and Health-ISAC (Information Sharing and Analysis Center) will host a joint cybersecurity event July…