Hack Disrupts Remote Activation of Boston Scientific’s New Cardiac Devices
What Happened — A cyber‑attack this week knocked out Boston Scientific’s global IT infrastructure, preventing the activation of remote‑monitoring communicators for newly implanted cardiac rhythm management (CRM) devices and insertable cardiac monitors (ICMs). Existing implants continue to function and transmit data, but any new device cannot pair with the Boston Scientific Clinic Assistant mobile app until the outage is resolved.
Why It Matters for Compliance & Audit Readiness
- The event illustrates a gap in Business Continuity and Disaster Recovery (BC/DR) controls that SOC 2 ‑ CC6 (System Operations) expects organizations to document, test, and evidence continuously.
- Without auditable proof that remote‑monitoring activation processes are resilient, a breach‑or‑disruption finding can jeopardize the “Availability” and “Security” trust service criteria.
- Verisq’s Control Mapping capability can automatically capture configuration baselines, outage‑response run‑books, and remediation evidence to satisfy SOC 2 auditors and regulators.
Who Is Affected – Medical‑device manufacturers, health‑tech SaaS platforms, and healthcare providers that rely on remote cardiac‑device monitoring.
Recommended Actions
- Map the remote‑monitoring activation workflow to SOC 2 CC6 controls and record the current outage as an exception.
- Capture logs, run‑books, and communication records in a tamper‑evident repository for audit evidence.
- Validate BC/DR test results for the remote‑monitoring subsystem and update the incident‑response playbook.
Technical Notes – The attack’s vector has not been disclosed; no ransomware, data exfiltration, or credential theft was reported. The disruption is limited to network‑level services that enable device‑to‑app pairing. Source: DataBreachToday