august

Medical Device Security, 2007–2023

The Muddy Waters Report

Carson Block made his living betting against companies. His firm, Muddy Waters Capital, specialized in researching businesses it judged rotten, taking a short position, publishing the research, and profiting when the stock fell. Block had made his name with earlier reports from his research shop exposing frauds — most famously Sino-Forest, a Chinese forestry company with imaginary trees. On August 25, 2016, Muddy Waters turned the method on a pacemaker manufacturer.

The report claimed that cardiac devices made by St. Jude Medical — pacemakers and implantable defibrillators carried in the chests of hundreds of thousands of patients — could be attacked by radio. The attack surface was the Merlin@home transmitter, the bedside box that interrogates an implanted device while the patient sleeps and relays its data to the clinic. According to the report, a nearby attacker could use the transmitter's protocols to crash implanted devices or run down their batteries. Muddy Waters was short St. Jude when the report went out. The shares closed down roughly 5 percent.

The research came from MedSec, a small security firm led by Justine Bone, whose team said it had spent months testing implantable devices from several major manufacturers and judged St. Jude's the weakest. What made the episode instantly notorious was not the findings but the channel. MedSec had made no disclosure before publication — not to St. Jude, and not to regulators, though it says it briefed the FDA and DHS as the report went out. It had taken the vulnerabilities to a short-seller, under an agreement tying its compensation to the performance of the trade. Bone's defense was blunt: quiet disclosure to a company with a record of dismissing security concerns would produce, at best, years of silence, and quite possibly a lawsuit. The way to make a device manufacturer move, MedSec had concluded, was to price the flaw into its stock.

The timing sharpened everything. St. Jude was months into being acquired by Abbott Laboratories for $25 billion. Patients learned from financial television that the hardware regulating their heartbeats was, allegedly, hackable — announced by a man who stood to profit from their alarm. Cardiologists' phones began ringing that afternoon.

Early Demonstrations

None of it was conceptually new. In 2008, an academic team including Kevin Fu, Tadayoshi Kohno, and the cardiologist William Maisel had published a paper demonstrating wireless attacks on a Medtronic implantable cardioverter-defibrillator in a laboratory. Using a software-defined radio built from commodity parts, they read patient data off the airwaves, reprogrammed the device, disabled its therapies, and commanded it to deliver a defibrillation shock. The attacks worked only at close range and demanded equipment and expertise, and the authors emphasized that patients faced no immediate danger. The paper nonetheless established the field's founding fact: the radio interfaces on implanted devices carried no meaningful authentication, because they had been designed on the assumption that nobody hostile would ever speak their language. Maisel went on to senior roles at the FDA's device center. Fu became the problem's most persistent academic voice.

In 2011 the demonstrations left the lab bench. Jay Radcliffe, a security researcher with type 1 diabetes, stood on stage at the Black Hat conference in Las Vegas and showed how his own Medtronic insulin pump could be manipulated over its radio link by an attacker who knew the device's serial number. An insulin pump is a simpler proposition than a pacemaker: command a large enough dose, or silently suspend delivery, and the harm needs no further engineering.

Later that year Barnaby Jack, a New Zealand-born researcher already famous for making ATMs spew banknotes on stage, went further still, demonstrating that Medtronic insulin pumps could be commandeered from as far as 300 feet with a custom antenna and instructed to empty their entire reservoir. In October 2012, at a conference in Melbourne, he showed an attack that caused a pacemaker to deliver an 830-volt shock, and talked about the possibility of worm code hopping between devices. He was scheduled to present new research on pacemaker security at Black Hat in August 2013. Days before the talk, he was found dead in his San Francisco apartment at 35; the medical examiner ruled the death an accidental drug overdose. The talk was never given, and his slot at the conference was left empty in tribute.

By then the threat had already been taken seriously in at least one examination room. In 2007, the cardiologist Jonathan Reiner had the wireless features of Vice President Dick Cheney's implanted defibrillator disabled, reasoning that a device reprogrammable over the air was a plausible assassination vector for the most protected patient in the country. The precaution stayed private until 2013, when Cheney disclosed it in a television interview — by which time the scenario had already aired as fiction, in an episode of Homeland.

Eight years of laboratory papers and conference demonstrations had preceded MedSec, and had produced no recall, no mandatory standard, and no visible change in how devices shipped. That vacuum is what the short-sellers walked into.

The St. Jude Recall

St. Jude called the report false and misleading and, in September 2016, sued Muddy Waters, MedSec, and their principals in federal court. Researchers at the University of Michigan, where Fu then ran a laboratory devoted to medical-device security, examined the report's most alarming exhibit — a screenshot said to show an implantable device crashed by radio — and observed that the same error display appears when a device sits on a bench with no leads connected. The evidence, they said, was consistent with a machine operating exactly as designed. The security community split, loudly, between those appalled that research had been sold as a trading signal and those pointing out that eight years of responsible behavior had moved nothing.

The litigation generated its own technical record. Bishop Fox, a security consultancy retained by the defense, reported in October 2016 that its testers had reproduced key attacks on St. Jude devices at a range of about ten feet, using a Merlin@home unit as the radio.

Then the referees ruled. On January 4, 2017, Abbott closed its purchase of St. Jude. Five days later the FDA and DHS issued coordinated advisories confirming vulnerabilities in the Merlin@home transmitter, and a software patch went out, pushed automatically to connected units. The agency's guidance to patients was studiedly calm: the health benefits of staying connected to remote monitoring outweighed the cybersecurity risk, and nobody should unplug anything.

The deeper correction came that August, and it was a first. Abbott released a firmware update for the implanted pacemakers themselves — roughly 465,000 devices in the United States — and the FDA announced the action as a recall, widely described as the first cybersecurity recall of implanted cardiac devices. The mechanics of the fix showed why patching a body is unlike patching anything else. The update could not be delivered over the internet; each patient had to visit a clinic, where the new firmware was installed through a programmer in about three minutes, the pacemaker meanwhile running in a backup mode. The update itself carried risk. Drawing on the record of prior firmware updates, the FDA put the chance of complete loss of device function at about three in a hundred thousand — small, unless the device was yours, in which case the remedy for a theoretical assassin was real surgery. The agency told patients to discuss the update at their next routine visit, not to rush in. For an elderly, pacemaker-dependent patient, declining was a defensible choice, and clinicians found themselves performing risk arithmetic no medical school had taught: a malicious radio attack that had never once been observed outside a laboratory, weighed against a small, quantified probability that the cure would stop the device. No exploitation of the vulnerabilities in the wild was ever reported, and no wave of update failures followed either.

Johnson & Johnson and Medtronic

The flaw was never one company's. In October 2016, weeks after the Muddy Waters report, Johnson & Johnson wrote to about 114,000 patients using its Animas OneTouch Ping insulin pump, warning that the pump's unencrypted radio link could in principle let a nearby attacker trigger insulin doses — reported at the time as the first instance of a manufacturer warning patients directly about a cybersecurity flaw in a device. The researcher behind the finding was Jay Radcliffe, by then at the security firm Rapid7, still probing the machines that kept people like him alive.

Medtronic's reckoning ran from 2018 into 2019. At Black Hat in August 2018, researchers Billy Rios and Jonathan Butts demonstrated attacks on Medtronic's CareLink programmers — the clinic carts that interrogate and adjust cardiac devices — and on its insulin pumps, following a disclosure process with the company that they described as glacial. That October, Medtronic responded to the programmer research by simply disabling internet-based software distribution for tens of thousands of CareLink programmers worldwide; rather than secure the update network, it turned the network off, returning software delivery to technicians with physical media.

March 2019 brought the bluntest advisory in the field's short history. DHS warned that Conexus, the proprietary radio protocol Medtronic used for telemetry among certain of its implanted defibrillators, home monitors, and programmers, contained no authentication and no encryption whatsoever. Anyone in radio range with the right equipment could read data from an implanted defibrillator or write to its memory. The advisory scored the vulnerability 9.3 out of 10 on the standard severity scale; press accounts put the affected devices on the order of 750,000. There was no quick fix, because the protocol was the product. Regulators again advised patients to keep using their home monitors, since remote monitoring is associated with longer survival.

Three months later, the FDA announced a recall of Medtronic's MiniMed 508 and Paradigm insulin pumps — models whose radio links could allow a nearby attacker to change settings, deliver insulin, or stop it. Roughly 4,000 patients in the United States were using them. These pumps could not be patched at all, so where the 2017 pacemaker action had delivered a fix in the guise of a recall, this recall pulled the hardware itself: Medtronic offered replacement with newer models, and the agency told patients to switch. A medical device had been withdrawn from the market because its software could not be made safe, not because it had failed clinically.

Hospital Device Fleets

Implants are the emotive edge of a much larger estate. A modern hospital contains thousands of networked devices — infusion pumps, telemetry monitors, imaging systems, laboratory analyzers — most of them ordinary computers wearing clinical enclosures, many running operating systems their vendors froze at certification and will never update. In 2015 the security firm TrapX published research it called MEDJACK, for medical device hijack, after finding malware persisting inside equipment at three hospitals, a blood-gas analyzer among them, along with imaging and archiving systems. The intruders had no interest in blood gases. They wanted a beachhead: a machine inside the perimeter where no antivirus agent could legally be installed, no administrator had visibility, and no patch would ever arrive, from which to reach the systems holding patient records worth selling.

This is where device insecurity stops being hypothetical. No one has been caught attacking a pacemaker in the wild; hospital devices, by contrast, have repeatedly been found serving as staging points for the theft and extortion economy that runs through the rest of this book. Decade-long lifecycles, unpatchable stacks, radio and network interfaces that trust whatever speaks to them: the same properties that alarmed the implant researchers made the wider fleet a permanent soft interior. As chronicled in the WannaCry chapter, the unpatchable clinical estate is what turned flat hospital networks into kindling in 2017, and network segmentation became the canonical compensating control precisely because the device fleet cannot be secured directly. Old software persists throughout a hospital, and some of it sits inside the patients.

FDA Guidance and Section 524B

The FDA had not been idle, only unarmed. It issued premarket cybersecurity guidance in 2014, describing what new device submissions ought to address, and postmarket guidance in 2016, describing how manufacturers should monitor and patch what they had already sold. Guidance, in regulatory language, binds no one; it records the agency's current thinking, and a manufacturer could acknowledge that thinking and ship the old design anyway. Through the St. Jude and Medtronic episodes, the agency's tools were safety communications, advisories, and negotiation.

Statutory authority finally arrived, as American policy often does, inside a spending bill. The omnibus appropriations act signed in December 2022 added section 524B to the Food, Drug, and Cosmetic Act, effective March 2023. Manufacturers of "cyber devices" must now submit a software bill of materials, an ingredients list of the code inside so that the next library-level vulnerability can be traced to the devices that contain it. They must also design devices that can be updated and patched, maintain a coordinated vulnerability-disclosure process, and monitor and address vulnerabilities after sale. From October 2023, the FDA began refusing to accept submissions that omit these elements.

Fifteen years separate the 2008 defibrillator paper from the statute. A pacemaker implanted the year the paper appeared would have exhausted its battery and been replaced, possibly twice, before the law caught up with its radio. Section 524B governs new submissions only; the installed base ages on under the old rules, in wards and in chests, for another decade or more.

Lessons

The implant fight differs from every other story in this book: its lessons concern design, disclosure, and time, not casualties.

Devices live on hardware time; their software lives on internet time. An implanted device runs seven to fifteen years on its battery; hospital equipment is bought on ten-to-twenty-year lifecycles. Every security assumption made at design — about protocols, cryptography, and who might be listening — will be obsolete long before the device is retired. The only durable design treats its own eventual compromise as a specification: fieldable updates, replaceable credentials, an ingredients list. Section 524B eventually made that mandatory. Almost nothing shipped before 2017 possessed it.

Disclosure turned out to be an economics problem, and the market solved it rudely. Eight years of peer-reviewed papers and stage demonstrations produced no recall; a short position produced federal confirmation within five months and a firmware recall about a year later. Researchers profiting from patient fear, findings released without giving the manufacturer a chance to fix them, at least one headline claim that did not survive scrutiny — the Muddy Waters trade drew condemnation on all these counts. It also worked, and the two facts sit uneasily side by side. The lesson that stuck for manufacturers: a company that gives researchers a credible, responsive channel denies the short-sellers their edge. A company that stonewalls is betting that nobody will ever find the price signal, and after 2016 that bet was off.

The airwaves, meanwhile, had been designed as if they were a private wire. Conexus carried no authentication and no encryption; the Merlin ecosystem trusted its own protocols; insulin pumps accepted commands from anything that knew a serial number. Some of this reflected deliberate clinical logic rather than mere neglect — an unconscious stranger arrives in an emergency department, and the cardiologist must be able to interrogate the device without a password ceremony, since a pacemaker that locks out a rescuer is its own hazard. But the 2008 paper had already sketched middle paths between open and locked, and for a decade the industry shipped none of them. Emergency access explains the absence of a lock on the front door. It never explained the absence of a log of who walked through it.

The absence of attacks is real evidence, though it still is not safety. There is no publicly confirmed case of a malicious in-the-wild attack on an implanted device harming a patient, and there are sound reasons to think such attacks rare: they require proximity and skill, and someone who wants to harm one identifiable victim has easier methods available. Patients were, on the actuarial record, right not to panic, and clinicians feared panic more than hackers, because a patient who abandons remote monitoring over a headline incurs a real risk to avoid a speculative one. But the insecurity imposed costs without a single attack ever occurring: the vice presidential defibrillator with its telemetry disabled, the recall arithmetic laid on 465,000 patients, the replacement of pumps that could not be fixed. Whether cyberattacks kill patients is a question this book takes up elsewhere, and it concerns hospitals, not implants.

Regulation moved at the speed of embarrassment. Guidance in 2014, stronger guidance in 2016, statute in 2022 — each step followed a public spectacle rather than the research that had preceded the spectacle by years. As with the enforcement lesson of the WannaCry chapter, advice without consequence changed little; the refuse-to-accept authority of 2023 changed submissions because it could stop them. Fifteen years from demonstration to mandate is the benchmark the field now has to beat: the next foundational flaw, in a hospital protocol, an AI diagnostic, a wearable, is presumably already published, waiting for its own spectacle.

What a realistic adversary wants from a medical device is the MEDJACK foothold, and healthcare's device fleets guarantee one. That is why segmentation, inventory, and the assumption of a compromised interior became the sector's working doctrine. The pacemaker panic bought attention that a blood-gas analyzer never could on its own, and that attention, however misdirected at the time, ended up funding the defenses the analyzer actually needed.

An implanted device has always had to be more trustworthy than the organ it replaces. For half a century that standard was enforced on hardware — batteries, leads, welds — through registries and recalls built from the accumulated record of failures. Between 2008 and 2023, the academics, the diabetic testing his own pump, the showman who died before his biggest demonstration, and the short-seller forced software into that same standard. It may be the only class of implant defect ever brought under regulation before it hurt anyone, and what forced the issue was not a clinical failure but a television interview about a Vice President's defibrillator, an 830-volt stage demonstration, and a stock trade timed to a report. Institutions in this book tend to pay for the failure that has already happened. They pay late, and only under duress, for the one that hasn't happened yet.