Skip to main content

St Judes Home Monitoring Receives Security Update

Security researchers have identified vulnerabilities within St Jude’s Merlin remote monitoring system, that is used with implantable pacemakers and defibrillator devices.
Report a cyber attack: call 0300 303 5222 or email [email protected]

This content has been archived

This article no longer conforms to NHS Digital's standards for cyber alerts, and may contain outdated or inaccurate information. Use of this information contained in this page is at your own risk

Summary

Security researchers have identified vulnerabilities within St Jude’s Merlin remote monitoring system, that is used with implantable pacemakers and defibrillator devices.

Threat details

For this particular system patches have been issued to address cyber security vulnerabilities.

The vulnerabilities in devices such as pacemakers and defibrillators allow attackers to modify the programming of a device, tampering with heart pacing or shocks and resulting in battery depletion. The communication protocols for the transmitters lack encryption and authentication mechanisms which allows them to be easily compromised. If a patient became the target of a cyber attack they would require immediate medical attention.

From the findings patches have been deployed to address additional validation and verification between the Merlin@home and Merlin.net Patient Care Network, with further updates to follow throughout 2017.


Remediation steps

Type Step
  • Security patches have been released with the updates being implemented over the next couple of months.
  • It’s recommended that patient’s Merlin@home unit is plugged in and connected via landline or Wi-Fi to ensure they receive the latest updates. Patients aren’t required to do anything to receive the updates.
  • Contact your vendor or St. Jude Medical representative with any questions regarding the updates.

Last edited: 17 February 2020 11:39 am