Boston Scientific remains in a network outage, and operations like manufacturing and shipping products are still disrupted following a cyberattack that was identified this week.
The attack has affected the company’s ability to manufacture products and to ship and process orders, and Boston Scientific still does not have a timeline for full restoration of operations, according to a statement posted Thursday evening to its website. While Boston Scientific previously disclosed that ordering and shipping were disrupted from the attack, it did not disclose that product manufacturing was also disrupted.
The company said that while it cannot process or ship orders, it can still take orders electronically and place them in a queue for future fulfillment.
Boston Scientific said in the Wednesday filing that it has not yet determined whether the incident will have a material impact.
In the statement, Boston Scientific outlined next steps for recovery.
“We are directing resources toward the systems that have the greatest impact on customers and product delivery and have engaged external experts to assist in the restoration and recovery efforts,” the company said in the statement. “Progress is being made in recovering our core business system and we will provide further updates as functionality is restored.”
Boston Scientific disclosed Wednesday that it was hit by a cyberattack that led to global disruption of its operations, including a network outage and disruption to its ordering and shipping. The incident is the latest in a string of attacks that has hit the medtech sector in recent months, including at some of the top companies in the industry.
Most of the attacks did not affect operations. However, Stryker’s ability to manufacture and ship products — as well as customers’ ability to order products — was taken down for weeks from a March attack, and the company is still recovering.
Investigating impact on patients’ connected devices
Boston Scientific is continuing to investigate whether there is a patient impact as a result of the attack, particularly with implanted devices or devices that connect to networks across its product portfolio. The company said it will “provide updates as soon as they are available.”
So far, the investigation has not found any impact on implantable cardiac rhythm management device function. There is also no impact yet found on the devices’ ability to transmit data or healthcare professionals’ ability to access remotely patient data for cardiac rhythm management devices remotely monitored prior to the network disruption.
There is also no evidence of increased cybersecurity risks or difficulties transferring data from remote monitoring systems for cardiac rhythm management devices to electronic medical records.
While Boston Scientific said there is no impact on cardiac rhythm device function, the attack is affecting new remote monitoring activations. For new implants of cardiac rhythm devices other than insertable cardiac monitors, new remote monitoring communicators cannot be activated, meaning that data will not be transmitted to remote patient management systems until the communicator can be activated.
For insertable cardiac device implants, new devices are unable to pair to the patient remote monitoring mobile phone. As a result, episode data recorded by the device will not be transmitted to the remote monitoring system until it can be paired. Boston Scientific said episodes will continue to be recorded by the insertable cardiac device and can be transmitted to the remote monitoring system through an in-person interrogation with the clinic assistant app.
“Once systems are restored and pairing with home monitoring equipment occurs, the device will transmit recorded data to the remote monitoring system,” Boston Scientific said. “Timeline for full restoration is not yet known.”