St Judes Home Monitoring Receives Security Update
This content has been archived
This article no longer conforms to NHS Digital's standards for cyber alerts, and may contain outdated or inaccurate information. Use of this information contained in this page is at your own risk
Summary
Threat details
The vulnerabilities in devices such as pacemakers and defibrillators allow attackers to modify the programming of a device, tampering with heart pacing or shocks and resulting in battery depletion. The communication protocols for the transmitters lack encryption and authentication mechanisms which allows them to be easily compromised. If a patient became the target of a cyber attack they would require immediate medical attention.
From the findings patches have been deployed to address additional validation and verification between the Merlin@home and Merlin.net Patient Care Network, with further updates to follow throughout 2017.
Remediation steps
Last edited: 17 February 2020 11:39 am