
Boston Scientific is still working through a network outage that has disrupted its manufacturing, shipping, and order processing after a cyberattack was identified this week. The company said Thursday evening that it does not yet have a timeline for when operations will be fully restored.
The company initially disclosed that ordering and shipping were affected, but the latest statement confirms that product manufacturing has also been disrupted. Even with those limitations, Boston Scientific said it can still take orders electronically and hold them in a queue for future fulfillment.
Recovery efforts underway, but no timeline yet
In its statement, Boston Scientific said it is directing resources toward the systems that matter most for customers and product delivery. The company has also brought in outside experts to help with restoration.
“Progress is being made in recovering our core business system and we will provide further updates as functionality is restored,” the company said.
Related: Philips invests $33.7M to develop stroke robot
A filing from Wednesday noted that Boston Scientific has not yet determined whether the incident will have a material impact on its finances. The attack is the latest in a string of incidents to hit the medtech sector in recent months, affecting even some of the industry’s largest players.
Most of those attacks did not disrupt operations. But Stryker, for example, saw its ability to manufacture and ship products taken down for weeks after a March attack, and that company is still recovering.
For hospitals and clinics that rely on Boston Scientific devices, the practical effect of this outage is still unclear. The company can queue orders but cannot fill them, which could mean delays for procedures that depend on its products.
Investigating impact on connected devices
Boston Scientific is also looking into whether the attack affected patients, particularly those with implanted devices or devices that connect to networks. So far, the investigation has not found any impact on the function of implantable cardiac rhythm management devices.
Related: FDA Sets Guidelines for Wearable Technology
There is also no evidence yet of problems with the devices’ ability to transmit data, nor with healthcare professionals’ ability to remotely access patient data for cardiac rhythm management devices that were being monitored before the network went down. The company said it has not seen increased cybersecurity risks or issues transferring data from remote monitoring systems to electronic medical records.
However, the attack is affecting new remote monitoring activations. For new implants of cardiac rhythm devices other than insertable cardiac monitors, new remote monitoring communicators cannot be activated, meaning data will not be transmitted to remote patient management systems until the communicator is up and running.
For insertable cardiac device implants, new devices cannot pair with the patient’s remote monitoring mobile phone. Episode data recorded by the device will not be transmitted to the remote monitoring system until pairing is possible. Boston Scientific said those episodes will continue to be recorded and can be transmitted through an in-person interrogation with the clinic assistant app.
“Once systems are restored and pairing with home monitoring equipment occurs, the device will transmit recorded data to the remote monitoring system,” Boston Scientific said. The company repeated that a timeline for full restoration is not yet known.