
A company that makes pacemakers and defibrillators is refusing to tell patients whether a cyberattack on its systems puts them at risk. That alone should alarm you. Boston Scientific, the Massachusetts-based medical device maker, confirmed in a filing with the U.S. Securities and Exchange Commission that it began experiencing “disruptions and limitations of access” to its IT systems and business applications on Tuesday.
The company described the incident as causing an ongoing “global disruption” to its operations. Its ability to ship and process orders has been affected. Beyond that, Boston Scientific is saying almost nothing. When TechCrunch asked spokesperson Chanel Hastings whether patients with implanted devices are at risk, whether the company has any guidance for those patients, or what kind of attack this actually was, the response was a public statement and nothing more. That is not transparency. That is a communications team doing damage control.
Boston Scientific treats around 48 million patients a year. These are not software users who can log out and wait for a patch. Many of them have the company’s devices physically implanted in their bodies. The refusal to address patient safety questions publicly is a serious problem, and regulators should be paying close attention.
Local media in Ireland reported that thousands of employees at Boston Scientific’s Cork campus were sent home on Tuesday after network communications went down across the site. The company has not confirmed the cause of the attack and says a timeline for restoring systems is not yet known. According to public internet records, Boston Scientific relies heavily on Microsoft and Amazon Web Services for its corporate infrastructure.
This attack does not exist in isolation. It is part of a pattern that has been building throughout the year. The health technology sector has taken hit after hit:
- Abbott Laboratories was hacked earlier this year
- Medtronic also suffered a breach
- Iranian-backed hackers attacked Stryker, remotely wiping tens of thousands of employee devices by exploiting a Microsoft device management portal
The medical device industry holds some of the most sensitive data imaginable, and its IT infrastructure has consistently proved to be underprepared. These companies invest heavily in regulatory compliance for their physical products, but their digital security has repeatedly shown cracks under real-world pressure.
So the question that nobody in Boston Scientific’s PR team wants to answer remains open: are patients affected? Until the company answers that directly, the 48 million people who rely on its devices have every right to be asking it themselves.