Boston Scientific stopped shipping. McKesson lost data. Both hit healthcare in the same fortnight and impacted patients' ability to receive the treatment and care they need.

 

What happened

Cardiac patients who received a Boston Scientific implant on or after August 25, 2026 cannot be enrolled in remote monitoring because the cyberattack that hit the manufacturer that day prevents new communicators from being activated, Healthcare Dive reported. Devices implanted before that date continue transmitting normally, and the company says implant function itself is unaffected.

Days later, McKesson disclosed unauthorized access to third-party applications tied to its Oncology and Multispecialty and Medical-Surgical businesses, with ShinyHunters claiming 284 million patient records and demanding $55.2 million. Neither company is a hospital. Both sit between hospitals and patients.

 

Going deeper

Attacks on device manufacturers split into two categories that reach patients by different routes. Boston Scientific lost operations, which stopped manufacturing, order processing, and shipping while leaving patient records alone. McKesson lost data, which exposed records while distribution centers kept running. Specifically, in the Boston Scientific case, insertable cardiac monitors implanted since the outage cannot pair with the patient's monitoring phone, so recorded heart rhythm episodes stay on the device rather than reaching the clinic, according to MedTech Dive. Those episodes can still be retrieved through an in-person interrogation using the clinic assistant application. A patient who would have been monitored from home is now monitored only when they come in.

 

What was said

"Our investigation to date demonstrates no impact to implantable cardiac rhythm management device function," Boston Scientific said in an update, adding that the incident does not affect a device's ability to transmit data or clinicians' ability to reach remote patient management data for devices enrolled before the disruption, as reported by BankInfoSecurity. The company has declined to say whether the attack involved ransomware or to name any group, The Register reported.

 

In the know

Medtech has absorbed a run of these through 2026, and the pattern is now visible across the sector. Stryker was hit in March, losing ordering, shipping, and manufacturing for weeks and still recovering months afterward, with attackers reaching it through a centralized device management portal they used to wipe tens of thousands of employee machines. Intuitive was hit the same month, and AdaptHealth in June. Abbott's cancer diagnostics business and Medtronic both suffered data theft claimed by the same group now claiming McKesson. Baxter disclosed unauthorized activity in third-party applications in August, and ShinyHunters published 7.1 million records days later. Six manufacturers, two distinct impact types, and one common entry pattern in the data-theft cases, which is a phone call to an employee rather than an exploit.

 

The big picture

Clinical teams are the ones absorbing this, and the Boston Scientific case shows what that looks like in practice. The British Heart Rhythm Society issued guidance to member centers after clinics began fielding calls from worried patients, telling teams that implant function is unaffected while confirming that patients implanted on or after August 25 cannot yet be enrolled for remote monitoring, in an update published for clinical teams. Those patients need a follow-up plan built around in-clinic checks until enrolment reopens, and someone has to track who they are. Hospitals should be asking which of their suppliers could produce a similar gap, what the manual fallback is for each, and who inside the organization would notice that a cohort of patients had quietly dropped out of remote surveillance. Supplier cyber incidents arrive as a clinical workflow problem before they arrive as a compliance one.

 

FAQs

Can an attack on a manufacturer affect an implanted device directly?

Nothing in these incidents indicates so. Implanted devices operate independently of the manufacturer's corporate network, and the disruption sits in the systems that enrol devices for monitoring and relay their data. The distinction matters clinically, since a device continues working while the visibility into it does not.

 

What does remote monitoring provide that in-clinic checks do not?

Continuous surveillance between appointments, which surfaces arrhythmias, device faults, and lead problems within days rather than at the next scheduled visit. Losing it delays detection rather than removing it, though for some conditions, that delay carries clinical weight.

 

Does a manufacturer have to notify hospitals about a cyber incident?

No general obligation exists. Publicly traded companies disclose material incidents to investors, which is how most surface, and contracts may add notification terms. Neither route guarantees a clinical team hears in time to adjust patient follow-up.

 

Why do the same attackers keep succeeding against different manufacturers?

The data-theft cases share an entry method rather than a vulnerability, with operators calling employees while posing as internal support and talking their way into credential resets or new device enrolments. No patch addresses that, which is why identity verification procedures matter more than software updates here.

 

What should a hospital do about patients caught in a monitoring gap?

Identify who was implanted during the affected window, document that remote enrolment is pending, and schedule interim in-clinic checks appropriate to each patient's risk. Re-enrolling them once the manufacturer restores service needs an owner if the gap persists after the outage ends.