Some doctors are wary of applying security update to St. Jude pacemakers, which are now owned by Abbott Labs, due to malfunction risk, thus hampering adoption
Some doctors are wary of software patch that prevents unauthorized access to Internet-connected devices, worried about risk of malfunction
Context & Ripple Effects
The St. Jude security saga has been running since MedSec researchers found vulnerabilities and paired their disclosure with a short position in 2016, followed by the FDA's warning that Merlin@home transmitters were hackable and an over-the-air fix rollout. In August the agency escalated to recalling around 465,000 implanted pacemakers for firmware patching, because an OTA fix was not an option for those models.
Now the follow-through is stalling: with Abbott Labs owning St. Jude, some doctors are declining to apply the security patch because they fear a malfunction more than a remote attack. That hesitation matters because the devices are already inside patients — every unpatched unit is both a vulnerability and a liability.
First-order effects
- Adoption of Abbott's pacemaker security patch slows as implanting physicians weigh malfunction risk against hacking risk, leaving patched-vulnerable devices in patients' chests.
- The FDA's recall-based patching path proves cumbersome in practice — pulling hundreds of thousands of patients through clinics for a fix many doctors won't apply.
Second-order effects
- Rivals selling connected cardiac and diabetes devices inherit the same bind: Medtronic's later insulin pump recall shows what happens when devices can't be updated at all, pushing vendors toward hardware redesign rather than software fixes.
- Insurers and hospital procurement start pricing cybersecurity track record into device selection, since a vendor's patch history now carries clinical consequences.
Third-order effects
- If doctor hesitancy persists, the industry shifts toward secure-by-design implants — updatable architectures validated before implantation — and regulators formalize premarket cybersecurity requirements instead of post-market recalls.
- Security research on medical devices normalizes beyond the MedSec-style disclosure-and-short model, forcing manufacturers to treat vulnerability handling as a standing regulatory obligation rather than a one-off crisis.
The trend: Connected medical devices are moving from patch-after-deployment security toward design-stage upgradability, with physician trust — not just FDA approval — becoming the adoption bottleneck.