Explore our Topics:

Medtech breaches keep hitting corporate IT, not devices — and that’s a blind spot in hospital vendor risk

Abbott, Stryker, Intuitive, Medtronic and other medtech companies disclosed cyberattacks this year. None involved a device — and the pattern should reshape how hospitals assess vendor risk.
By admin
Aug 17, 2026, 3:22 PM

Seven medical technology companies disclosed cyberattacks in the first half of 2026, and not one involved a compromised device. Instead, attackers are opting for corporate IT — internal applications, billing systems, customer portals and, in one case, a third-party platform sitting two steps away from any hospital.

“The Hollywood version of medical device cybersecurity is hacking the pacemaker, but the everyday reality is hacking the company that makes the pacemaker,” said Daniel Bardenstein, CEO and co-founder of Manifest Cyber and Aspen Policy Academy fellow.

And the pace is picking up. Health care providers remain a popular target, but attacks on health care businesses — pharmaceutical companies, billing companies and health care technology providers — jumped 35% in the first half of this year compared to the second half of 2025, according to Comparitech.

Stryker, Abbott, Intuitive, Medtronic, UFP Technologies and iRhythm have all disclosed attacks this year, according to company statements. Nearly every disclosure carried the same reassurance — no products were impacted — which is true as far as it goes, but the systems attackers did reach are the ones that hold hospital and patient data and keep billing, orders and deliveries moving.

Why medtech companies

Like other parts of the health care supply chain, medtech companies safeguard valuable data and provide services the industry can’t operate without, which makes them attractive to financially motivated groups. One of the groups claiming an Abbott attack was ShinyHunters — and the cybersecurity information sharing nonprofit Health-ISAC recently warned that ShinyHunters is having increased success targeting medical technology companies, according to BleepingComputer.

Jamie Singer, a senior managing director at FTI Consulting, told DHI that most attacks she has observed on medtech companies have some element of data access and extortion. “They’re [attackers] trying to get paid, and when they don’t, then they make it very miserable for the organization,” she said. “Not all have the disruptive nature, but most that we’re seeing certainly have the data theft piece.”

For other threat actors, disruption is the goal rather than a byproduct. “When you’re talking about nation state actors, I do think there is a goal of disruption to critical infrastructure in the US,” Singer said. The Handala claim on the Stryker attack fits that pattern.

What it costs hospitals

Medtech companies sit inside a tightly interconnected health care ecosystem, and the impact of an attack rarely stays inside the company’s walls.

“If a hospital gets breached through a medical device or otherwise, not only do those medical devices not work but the whole system may not work,” said Sean Kelly, MD, chief medical officer at Imprivata, a digital identity security company, and a practicing ER physician.

Kelly has received patients diverted from hospitals disrupted by cyberattacks. “When that happens, patients arrive and you don’t have access to their data,” he said. “We’re starting over trying to understand what their meds are, what their problems are, how to treat them.” The result, according to Kelly: care delays, higher risk of errors and increased costs.

Regulation mirrors the blind spot

Regulators have taken steps, though largely on the side of the equation attackers are avoiding. The FDA’s premarket cybersecurity requirements focus on the device itself, while HHS’s Cybersecurity Performance Goals for the health care and public health sector, released in 2024, remain voluntary.

“There has been work [done] to identify: how do we establish a minimum, and how do we do the basics better across the sector?” Bardenstein said. “I think there needs to be an increase in what is mandatory and not what is aspirational.”

“It means that despite the millions of dollars that security leaders at the medtech companies are currently spending, the tooling or the processes they have aren’t enough,” he added.

For hospitals, the same question applies to their own side of the relationship. Most vendor risk assessments still focus on the device — whether it’s patched, segmented and hardened against attack. This year’s attacks point somewhere else entirely: to the security of the company that makes the pacemaker.


Carrie Pallardy, a Chicago-based freelance writer and editor, began her career covering healthcare more than a decade ago. Her work has taken into many different industries, but covering healthcare delivery remains a constant focus. She can be reached at [email protected] or on LinkedIn.


Show Your Support

Subscribe

Newsletter Logo

Subscribe to our topic-centric newsletters to get the latest insights delivered to your inbox weekly.

Enter your information below

By submitting this form, you are agreeing to DHI’s Privacy Policy and Terms of Use.