Boston Scientific identified a cybersecurity incident on August 25, 2026, affecting certain IT systems and causing a global network disruption.

 

What happened

According to the company’s SEC filing, the incident limited access to systems and business applications supporting its operations, including order processing and shipping, while the full scope and potential financial impact remained under investigation. In a subsequent company update, Boston Scientific said the unauthorized activity was confined to certain on-premises systems and that it had found no indication of related unauthorized activity after August 25.

The company reported no impact to its cloud-based systems, existing implantable cardiac rhythm management devices, programmer interrogations, or remote monitoring already established before the outage. However, the disruption prevented new remote-monitoring activations. Communicators for newly implanted cardiac rhythm management devices could not be activated, meaning available device data would not reach remote patient management systems until activation became possible.

Newly implanted insertable cardiac monitors couldn’t pair with patients’ mobile phones. Boston Scientific said those monitors would continue recording episodes, which clinicians could retrieve through an in-person interrogation using the Clinic Assistant app. The company engaged CrowdStrike and other cybersecurity specialists while restoring manufacturing, order-processing, shipping, and affected system access across its global operations.

 

What was said

According to the SEC filing, “The incident has caused, and is expected to continue to cause, disruptions and limitations of access to certain of the Company’s information systems and business applications that support aspects of the Company’s operations, including the ability to process and ship customer orders. While the Company is working diligently to restore affected functions and systems access, the timeline for a full restoration is not yet known.”

 

Why it matters

The Boston Scientific incident resembles the March 2026 cyberattack on medical-device manufacturer Stryker, which disrupted internal systems, order processing, manufacturing, shipping and distribution even though Stryker said its connected products remained safe. NHS England responded by asking healthcare organizations to assess their dependence on Stryker products, monitor local stock, arrange immediate mutual aid and use an interim ordering process based on clinical priority.

Boston Scientific presents the same continuity risk, but with a clinical-workflow consequence. Communicators for new non-ICM cardiac devices could not be activated, while new insertable cardiac monitors could not pair with patients’ phones. Existing devices and established monitoring continued operating. This distinction matters because a cyberattack does not need to compromise an implanted device to affect care. It can interrupt supporting applications, supply processes and data connections clinicians rely on to monitor patients and obtain equipment.

A study on healthcare cybersecurity published by the National Library of Medicine explains, “Successful cyberattacks in healthcare can have severe consequences, such as compromised patient privacy, disrupted healthcare services, and even patient harm.” Healthcare organizations should include medical-device manufacturers in business continuity planning, identify patients awaiting monitoring activation, preserve in-person interrogation procedures, verify delayed transmissions after restoration, and maintain alternative ordering and communication channels during vendor outages.

See also: HIPAA Compliant Email: The Definitive Guide (2026 Update)

 

FAQs

Does a business associate agreement (BAA) transfer all breach-response responsibility to the vendor?

No, a BAA defines the vendor’s duties, but the healthcare organization remains responsible for evaluating its own HIPAA obligations and protecting affected patients.

 

How can an organization determine whether a vendor incident constitutes a reportable HIPAA breach?

The organization must establish whether unsecured PHI was impermissibly accessed or disclosed and complete the required risk assessment unless the incident clearly falls within an exception.

 

Should healthcare organizations disconnect every vendor immediately after learning of an attack?

Organizations should restrict connections according to the verified risk because indiscriminate disconnection could unnecessarily interrupt essential clinical services.

 

What evidence should a vendor provide before connections are fully restored?

Healthcare organizations should request evidence of containment, credential resets, access reviews, vulnerability remediation, system validation, and monitoring for continuing unauthorized activity.