Medtronic Minimed Insulin Pump Recall Issued Over Cybersecurity Risks

Federal health officials indicate that certain Medtronic insulin pumps may contain cybersecurity flaws, which could allow hackers to gain access and change settings, exposing patients to a serious risk of injury or death.

The U.S. Food and Drug Administration (FDA) announced a Medtronic MiniMed insulin pump recall on June 27, after it was discovered that the wireless communication system used to control insulin doses lack proper security protocols.

The recalled insulin pumps are small, computerized devices that deliver insulin to a patient throughout the day, via a catheter implanted under the skin. The devices are wirelessly connected to both the patient’s blood glucose meter and monitoring system to track glucose levels. The pumps connect to a CareLink USB thumb-sized wireless device that can be used to deliver insulin doses and download data about the patient’s glucose levels to monitor progress.

"*" indicates required fields

"*" indicates required fields

The FDA warns that the design of the Medtronic MiniMed 508 pump and MiniMed Paradigm series insulin pumps could allow someone other than the patient or healthcare provider to change insulin delivery settings and alter glucose level data.

The threat of a hacker changing these settings could be life threatening for a patient. If a diabetic patient is given too much insulin it could result in the development of severe hypoglycemia. If a patient does not receives an under dose of insulin is could lead to high blood sugar and diabetic ketoacidosis.

The FDA is instructing patients to talk with their healthcare provider about a prescription to switch to different insulin pump model with better cybersecurity protocols. Patients are being directed not to switch insulin delivery systems without first consulting with their doctor first.

Until patients are prescribed a new insulin delivery system, FDA officials are warning patients to be attentive to pump notifications, alarm and alerts and to never share the serial number of the device. Patients should only connect their Medtronic insulin pump to other Medtronic devices and software and disconnect the CareLink USB device from the computer when you are not using it to download data from the pump.

Medtronic announced they will be offering an alternative insulin pump to approximately 4,000 patients who are currently using the recalled models across the U.S. According to the recall, a fast and effective software upgrade to add proper cybersecurity to the impacted devices is not readily available.

This is not the first time Medtronic implants were linked to cybersecurity concerns. Earlier this year in March, the FDA issued a safety communication about vulnerabilities with Medtronic ICDs or cardiac resynchronization therapy defibrillators (CRT-Ds), after discovering the wireless telemetry system used to communicate and alter the implanted devices could be hacked due to a lack of security protocols.

Late last year in October 2018, Medtronic issued an Urgent Medical Device Correction to physicians, notifying them that more than 34,000 implantable pacemakers were vulnerable to hacking. Medtronic disconnected the devices from internet access for software updates as a result.

Written by: Russell Maas

Managing Editor & Senior Legal Journalist

Russell Maas is a paralegal and the Managing Editor of AboutLawsuits.com, where he has reported on mass tort litigation, medical recalls, and consumer safety issues since 2010. He brings legal experience from one of the nation’s leading personal injury law firms and oversees the site’s editorial strategy, including SEO and content development.

Image Credit: Image via <a href="http://www.shutterstock.com/gallery-931246p1.html?cr=00&pl=edit-00">Ken Wolter</a> / <a href="http://www.shutterstock.com/editorial?cr=00&pl=edit-00">Shutterstock.com</a>



0 Comments


This field is for validation purposes and should be left unchanged.

Share Your Comments

This field is hidden when viewing the form
I authorize the above comments be posted on this page
Post Comment
Weekly Digest Opt-In

Want your comments reviewed by a lawyer?

To have an attorney review your comments and contact you about a potential case, provide your contact information below. This will not be published.

NOTE: Providing information for review by an attorney does not form an attorney-client relationship.

MORE TOP STORIES

A federal judge has set key scheduling deadlines for the four first bellwether trials over claims that BioZorb breast markers are defectively designed.
Parties in federal Depo-Provera meningioma lawsuits seek closer coordination with Delaware and New York state courts, proposing a synchronization of general causation schedules.
As sports-betting apps like DraftKings and FanDuel grow in popularity, treatment providers nationwide are reporting a surge in young adults seeking help for gambling addiction fueled by targeted algorithms, brain chemistry and aggressive marketing.