The Report
A pacemaker or an ICD doesn’t need an internet connection to become someone else’s problem. It needs a communications pathway it already trusts, and software willing to obey what arrives on it. That pathway has been tested, publicly, more than once. Here is what was actually found, condensed to the facts that matter.
This isn’t speculation about what a hostile actor could build. It’s a record of what independent researchers and regulators already proved, in devices that were already implanted in people.
The Chain, In Short
Four layers sit between a cardiologist and a patient’s heart: the implant itself, the local wireless link it uses to talk to nearby equipment, a home monitor or clinical programmer that bridges that link to the outside world, and the manufacturer’s servers that receive the data and push updates back down. The implant never touches the internet directly. It doesn’t need to. It only needs to trust the layer immediately next to it, which trusts the layer next to that.
Every documented failure below is a failure somewhere in that chain, not a failure of the internet, 5G, Wi-Fi or Bluetooth specifically. Take away one radio and the trust relationship between the other layers is untouched.
What Was Actually Found
| Year | Device / Vendor | Finding | Outcome |
|---|---|---|---|
| 2016 | St Jude Medical RF-enabled pacemakers & ICDs | Security researchers published claims of remotely exploitable weaknesses in the devices and their home monitors. | Investigated |
| 2017 | St Jude / Abbott – ~465,000 US pacemakers | FDA confirmed an unauthorised user with commercially available equipment could alter programming, risking rapid battery drain or incorrect pacing. | Firmware patched |
| 2018 | Medtronic CareLink & CareLink Encore programmers | FDA and DHS warned that the internet-connected software distribution network feeding these clinical programmers could be abused to alter programmer or device behaviour. | Network access withdrawn |
| 2019 | Medtronic Conexus radio – 20+ ICD & CRT-D models | US CISA rated the flaw 9.3 of 10. Conexus telemetry travelled unencrypted and unauthenticated, letting a low-skill attacker read and write memory on the implant. | Mitigated, not fully closed |
| 2018 | Academic research (multiple institutions) | Published frameworks demonstrating that reprogramming attacks could, in simulation, be tailored to a specific patient’s physiology to disrupt therapy while minimising detection. | Published for defence, not seen in the wild |
What The Pattern Says
None of these devices needed a novel weapon. The battery, the capacitor, the electrodes — all of it was already implanted, already approved, already doing its job. Every one of these failures was a failure of authentication or encryption on the path leading up to that hardware. The 2019 Conexus finding is the starkest version: telemetry with no encryption and no authentication is not a subtle bug. It is a door with no lock, discovered by people who were looking for one.
No case above resulted in a confirmed patient death from a cyberattack. That matters, and it should stay true. It is also not the same as the risk being theoretical. The FDA, DHS/CISA and the device manufacturers themselves treated each of these as serious enough to warrant a recall, a network shutdown or a firmware campaign reaching hundreds of thousands of people.
Regulation Is Catching Up
In the US, the FDA now treats cybersecurity as a standard part of device approval and post-market surveillance, working alongside CISA on advisories. The Heart Rhythm Society has issued its own guidance for clinicians on preparing for cyber incidents in cardiac devices.
In the UK, the MHRA’s post-market surveillance rules, in force from June 2025, now explicitly classify a cybersecurity flaw capable of harming a patient as a reportable serious incident — the same category as a hardware fault. A manufacturer that finds one is obliged to issue a Field Safety Corrective Action, not quietly patch and move on. Dedicated MHRA cybersecurity guidance for software-based medical devices is expected to follow.
What This Means If You Carry One
- Don’t stop using remote monitoring. It catches genuine cardiac events far more often than it introduces risk, and every documented flaw above was found and fixed through the same oversight structures that monitoring depends on.
- Attend firmware update appointments. The 2017 and 2019 fixes only protected patients who actually received them.
- Physical proximity is still a real barrier. Most of the attacks above required the attacker to be within a few metres of the patient, not on the other side of the world. That won’t hold forever, but it holds today.
- Ask your clinical team, not a forum. If a specific advisory affects your device model, your cardiology team will have been notified before you were.
The Part Worth Remembering
The weak point was never the wireless standard. It was whichever link in the chain assumed the next link could be trusted without checking.
That assumption gets fixed one recall at a time.
Slowly. But it gets fixed.