Key result
Only ~4% of pacemaker patients elect cybersecurity firmware upgrades in a real-world cohort.
Why the study?
Potential cybersecurity vulnerabilities in St Jude Medical pacemakers were publicly disclosed without prior direct notification to the manufacturer or FDA, raising safety concerns and prompting firmware upgrades with associated procedural risks.
Observational (n=155)
No
A very low percentage of patients (3.9%) elected to undergo a pacemaker firmware upgrade for cybersecurity vulnerabilities when risks and benefits were fully explained.
Pacemaker cybersecurity vulnerabilities warrant clinician vigilance in device selection; leaves open real-world clinical impact and optimal mitigation strategies.
◼ security measures ◼ United States Food and Drug I n August of 2016, Muddy Waters Capital LLC released a short-sell report outlining potential cybersecurity vulnerabilities in several St Jude Medical (now Abbott) pacemaker models after demonstrations of a crash attack and a battery drain attack by vulnerability research firm MedSec. 1 The motivation behind the release of this report does not appear to have been focused on patient safety.Rather than inform Abbott or the US Food and Drug Administration directly, the information was released to the public sector. 2 This event was followed by a safety communication issued by the US Food and Drug Administration in January of 2017 describing the vulnerabilities and informing the public of a software patch.3 Shortly thereafter, the US Food and Drug Administration issued a warning letter to Abbott in April of 2017.In response to these events, Abbott released a firmware upgrade with enhanced cybersecurity.Installation of this firmware upgrade is noninvasive and takes a few minutes to complete.During the installation procedure, the pacemaker may temporarily change its pacing mode, leaving open the possibility that patients may become symptomatic during the upgrade.4 In addition, Abbott identified several other small risks associated with the upgrade, including a complete loss of function (0.003%), loss of device settings (0.023%), and failure of the update (0.161%) 2 (accessible at https://www.sjm.com/~/me-dia/galaxy/hcp/resources-reimbursement/technical-resources/product-adviseriesarchive/cybersecurity-pacemaker-firmware/pacemaker-firmware-update-doctorletter-aug2017-us.pdf).Changes to device settings are usually transient, however; complete loss of function may require urgent action (temporary pacing) and definitive solution with a battery replacement.Other less dramatic changes such as a transient shift to unipolar mode may not require specific action.On the basis of these risks, it has been recommended that these firmware upgrades be performed in a center with the ability to perform urgent temporary pacing.4 It is important to note that the adverse event rates reported by Abbott are based on estimates derived from other circumstances, and the true adverse events rate may not be known until after completion of many upgrades.Clinicians are responsible for identifying patients with devices who may be at risk and explaining the risks and benefits associated with the firmware upgrade.At our large tertiary care center with 5 electrophysiologists, 155 patients were identified with affected devices and offered the firmware upgrade between November 17, 2017, and February 13, 2018.This study was approved by the institutional review committee, and the subjects gave informed consent.Out of 155 patients seen in clinic, 6 (3.9%) elected to receive the firmware upgrade once the risks and benefits were fully explained in a systematic manner using recommendations devised by Abbott and endorsed by the Canadian Heart Rhythm Society.During the upgrade, 1 patient with a dual-chamber pacemaker (programmed in VVIR mode) exhibited a transient 3 second pause followed by a
No takes yet. Share an insight, caveat, or question.
Baranchuk et al. (2018) conducted an observational in Patients with pacemakers subject to cybersecurity vulnerabilities (n=155). Cybersecurity firmware upgrade was evaluated on Election to receive the firmware upgrade. Among 155 patients with affected pacemakers, only 3.9% (6 patients) elected to receive the cybersecurity firmware upgrade, during which 1 patient experienced a transient 3-second pause.
Synapse has enriched 5 closely related papers on similar clinical questions. Consider them for comparative context: