Boston Scientific has not resumed shipping a week after an Aug. 25 cybersecurity incident disrupted its ordering and manufacturing systems.
The medical device maker said Sept. 1 its confidence in restoring shipping “continues to increase” and it is working toward partial restoration for some products this week, but it gave no firm timeline for full recovery. Hospitals and other customers can still submit orders electronically, including through EDI and local applications, but those orders remain queued until fulfillment systems come back online.
Boston Scientific also said for the first time that it cannot yet confirm whether personal data was compromised in the attack. The company said it is “investigating and working diligently to restore affected functions and systems access,” and will notify affected individuals, regulators and customers if it determines data was exposed. CrowdStrike and other third-party experts are assisting with the forensic investigation.
The company reiterated there is no known impact to devices not connected to its network and no evidence of increased cybersecurity risk to hospital networks using its devices. New remote monitoring activations for cardiac rhythm management devices, including implantable cardioverter-defibrillators and pacemakers, remain affected, though programmer interrogations are unaffected.
The prolonged disruption underscores the supply chain risk hospitals face when a major device manufacturer’s order-and-shipping infrastructure goes down.
At the Becker's 11th Annual IT + Revenue Cycle Conference: The Future of AI & Digital Health, taking place September 14–17 in Chicago, healthcare executives and digital leaders from across the country will come together to explore how AI, interoperability, cybersecurity, and revenue cycle innovation are transforming care delivery, strengthening financial performance, and driving the next era of digital health. Apply for complimentary registration now.