FDA warns St. Jude's Merlin@home transmitters used in monitoring pacemakers, other cardiac devices are vulnerable to hacking; OTA fix started going out Monday
According to a cybersecurity notice from the Food and Drug Administration, certain pacemakers and cardiac devices are currently vulnerable to hacking.
Context & Ripple Effects
This warning lands eight months after researchers at startup MedSec found security flaws in St. Jude's implantable devices and monetized the finding through a short-selling deal with an investment firm — a disclosure the company disputed. With the FDA now formally confirming that Merlin@home transmitters used to monitor pacemakers and other cardiac devices are vulnerable, the vulnerability has moved from contested claim to regulator-acknowledged fact.
St. Jude's response is an over-the-air fix pushed to the transmitters starting Monday, which matters because the transmitter sits outside the body — unlike the implanted hardware itself, where patching later proved far harder.
First-order effects
- Patients whose pacemakers and cardiac devices communicate through Merlin@home transmitters remain exposed until the OTA fix reaches their unit, while St. Jude must push the patch across its installed base under active FDA scrutiny.
Second-order effects
- The transmitter patch does not reach the implanted devices themselves — the same vulnerability chain culminates months later in the FDA recalling around 465,000 St. Jude pacemaker models for firmware patching, where an OTA fix was not an option.
- After Abbott Labs takes ownership, the patch campaign stalls at the bedside: some doctors are wary of applying the security update out of malfunction risk, hampering adoption even among patients already recalled for patching.
Third-order effects
- The pattern generalizes beyond one vendor: by 2019 DHS warns of vulnerabilities affecting about 750,000 Medtronic implantable defibrillators worldwide, showing implantable-device security is an industry-wide exposure rather than a St. Jude defect.
- Regulators shift from approving devices once to overseeing them across their implanted lifetime — a structural inversion in which the FDA's role becomes policing continuous software updates on hardware patients cannot return.
The trend: Implantable medical devices are becoming long-lived networked software platforms, forcing the FDA into continuous post-market security oversight and manufacturers into patch logistics measured in years.