As per Boston Scientific’s Aug. 30 update, “the unauthorized activity is limited to certain on-premises systems,” providing the clearest indication yet of the scope of the cybersecurity incident that has disrupted the medical device maker’s global network and business operations.
Boston Scientific said the investigation into the disruption remains ongoing, with third-party cybersecurity experts. Based on its investigation to date, the company said it has found no indication of unauthorized activity in its environment related to the incident since Aug. 25.
The company also clarified that its cloud-based systems and applications have not been affected. The unauthorized activity identified so far is confined to only limited on-premises systems.
The clarification comes as Boston Scientific continues working to restore systems supporting manufacturing, ordering and shipping. The company has not established a timeline for a full return to normal operations.
Boston Scientific said its confidence in restoring ordering, shipping and related system access “continues to increase” and that it is working toward a partial restoration of shipping for some products during the week following its Aug. 30 update.
The company said it expects ordering and shipping to ramp up to full capacity once it can demonstrate that the restored operations are fully functional.
For now, customers can continue to submit orders electronically through Electronic Data Interchange (EDI) and local applications. Those orders can be placed into a queue for future fulfillment, including orders submitted through the Global Health Exchange (GHX).
The latest update indicates that the company’s ability to receive orders electronically has remained intact even while systems required to fulfill and ship those orders have been disrupted.
Boston Scientific has not provided a specific date for when full ordering and shipping capacity will return.
Boston Scientific has not said that the cybersecurity incident resulted in a confirmed data breach. Its investigation remains focused on determining the nature, scope, and impact of the unauthorized activity.
The Aug. 30 update also provides a more specific picture of the affected technology environment. While certain on-premises systems have been impacted, Boston Scientific said there has been no impact to its cloud-based systems and applications.
The company previously said it had found no indication of unauthorized activity in its environment related to the incident since Aug. 25. It has not disclosed whether data was exfiltrated or whether ransomware was involved.
Boston Scientific previously said the incident had not affected devices that are not connected to a Boston Scientific network or clinicians’ ability to use those devices.
For Cardiac Rhythm Management (CRM) products, the company reported no known impact on implantable device function, remote monitoring for devices that were already being remotely monitored before the disruption, or programmer interrogations.
However, new remote-monitoring activations have been affected.
For new CRM implants other than insertable cardiac monitors (ICMs), remote-monitoring communicators cannot currently be activated. As a result, available device data cannot reach remote patient-management systems until activation is possible.
Newly implanted ICMs must be activated through the Boston Scientific Clinic Assistant app, but new ICMs cannot currently pair with patients’ remote-monitoring mobile phones. Recorded episodes can still be transmitted through an in-person interrogation using the app’s “Interrogate” function.
Boston Scientific said that once its systems are restored and home-monitoring equipment is paired, recorded data will be transmitted to the remote-monitoring system.
The company has also said there is no evidence that the affected network environment has increased cybersecurity risks for hospital networks through Boston Scientific devices.
Boston Scientific said it continues to work with CrowdStrike and other external cybersecurity specialists as the investigation and recovery effort proceeds.
The company has been prioritizing systems with the greatest impact on customers and product delivery while working to recover its core business systems. Customers can continue communicating with sales representatives and other Boston Scientific employees through normal channels, including email, established digital platforms and existing connections.
The company has acknowledged the potential challenges for customers, patients and suppliers as the disruption continues and thanked them for their patience and partnership.
Boston Scientific disclosed the incident in an 8-K filing with the U.S. Securities and Exchange Commission on Aug. 26. The company said it will provide additional updates as appropriate.
For now, the latest disclosure narrows the known technical scope of the incident: Boston Scientific says the unauthorized activity is limited to certain on-premises systems, while cloud-based systems and applications remain unaffected. At the same time, the continued disruption to manufacturing, order fulfillment, and shipping means the operational consequences of the attack remain significant as the investigation and recovery effort continue.