/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

← → days · ↑ ↓ browse · Enter similar · o open

FDA warns St. Jude's Merlin@home transmitters used in monitoring pacemakers, other cardiac devices are vulnerable to hacking; OTA fix started going out Monday

According to a cybersecurity notice from the Food and Drug Administration, certain pacemakers and cardiac devices are currently vulnerable to hacking.

Engadget Andrew Dalton

Context & Ripple Effects

This warning lands eight months after researchers at startup MedSec found security flaws in St. Jude's implantable devices and monetized the finding through a short-selling deal with an investment firm — a disclosure the company disputed. With the FDA now formally confirming that Merlin@home transmitters used to monitor pacemakers and other cardiac devices are vulnerable, the vulnerability has moved from contested claim to regulator-acknowledged fact.

St. Jude's response is an over-the-air fix pushed to the transmitters starting Monday, which matters because the transmitter sits outside the body — unlike the implanted hardware itself, where patching later proved far harder.

First-order effects

  • Patients whose pacemakers and cardiac devices communicate through Merlin@home transmitters remain exposed until the OTA fix reaches their unit, while St. Jude must push the patch across its installed base under active FDA scrutiny.

Second-order effects

  • The transmitter patch does not reach the implanted devices themselves — the same vulnerability chain culminates months later in the FDA recalling around 465,000 St. Jude pacemaker models for firmware patching, where an OTA fix was not an option.
  • After Abbott Labs takes ownership, the patch campaign stalls at the bedside: some doctors are wary of applying the security update out of malfunction risk, hampering adoption even among patients already recalled for patching.

Third-order effects

  • The pattern generalizes beyond one vendor: by 2019 DHS warns of vulnerabilities affecting about 750,000 Medtronic implantable defibrillators worldwide, showing implantable-device security is an industry-wide exposure rather than a St. Jude defect.
  • Regulators shift from approving devices once to overseeing them across their implanted lifetime — a structural inversion in which the FDA's role becomes policing continuous software updates on hardware patients cannot return.

The trend: Implantable medical devices are becoming long-lived networked software platforms, forcing the FDA into continuous post-market security oversight and manufacturers into patch logistics measured in years.