- Indiana board rejects IU Health hospital drug diversion settlement deal
- 5 updates on GLP-1 drugs: Pricing, access, FDA scrutiny
- New Hampshire hospital taps Chicago system exec as CEO
- Monument Health using generative AI tools in Epic
- Recently launched Massachusetts system taps 2 executives
- HCA Florida hospital promotes CFO to CEO
- What the largest DSOs accomplished in Q1
- Sutter Health expands wearable ultrasound use
- The procedure gold mine ASCs are sitting on
- Google, J&J Foundation invest $10M in rural healthcare AI training
- AI regrets? Health systems learn lessons from the early boom
- Amazon Health adds strategic growth leader
- ADA updates CDT codes for 2027: 5 notes
- Where the ASC industry is getting the anesthesia conversation wrong
- The payer policies driving the most friction in musculoskeletal care
- Ohio system opens $27.5M outpatient center
- Cleveland Clinic expands pediatric treatments for esophageal disorder
- 4 states disciplining dentists
- Meat Consumption Rises as Protein Trend Grows, Experts Warn
- Physicians’ broken wRVU model
- Where 2 interstate dental compacts stand in 2026
- Nuts.com Recalls 10,000+ Pounds of Candy Over Allergy Risk
- The unsolved problem plaguing ASCs
- 43 states have mental health insurance disparities: 4 trends
- R1 RCM launches AI tools for AR recovery, denials
- The compensation divide between self-employed, employed physicians is shrinking
- The new playbook for clinician well-being
- CFOs as strategists: How finance leaders are rewriting their role
- Listen to the Latest ‘KFF Health News Minute’
- The dual payoff of dental AI
- Estados cambian leyes para evitar que hijos de inmigrantes detenidos entren al sistema de cuidado temporal
- Sam’s Club Recalls Children’s Pajamas Due to Fire Hazard
- CPIhealth acquires Indiana spine ASC
- Small Talk? It May Be Better Than You Think
- 5 anesthesia staffing models ASCs are adopting in 2026
- Ohio long-term acute care hospital to close, lay off 116
- Mount Sinai, Anthem reach 3-year agreement
- Days cash on hand at 50 health systems
- Cómo hacer que un plan de salud con deducible alto funcione para tí
- J&J, chasing $100B year, sports immunology ‘dual powerhouse’ of Tremfya and new launch Icotyde
- Long-Term Opioid Prescriptions Fall By About A Quarter
- Marriage's Hidden Benefit? A Lower Risk Of Cancer
- Young Cancer Survivors Face Doubled Risk Of Subsequent New Cancer
- Gut Bacteria Might Drive Rare Food Allergy in Children, Study Finds
- Stents Can Ease Long-Term Symptoms Of Deep Vein Thrombosis, Trial Shows
- Para muchos pacientes que salen de terapia intensiva, la lucha apenas comienza
- Does Your Child Have Nightmares? Here's One Solution
- Novo taps OpenAI to deploy AI across R&D, manufacturing and corporate functions
- Los estados se enfrentan a otro reto con las nuevas reglas laborales de Medicaid: la falta de personal
- States Change Custody Laws To Keep Children of Detained Immigrants Out of Foster Care
- New Orleans Takes Steps To Assess and Clean Lead in Playgrounds After Investigation
- WebMD Ignite rolls out program to help providers get Rural Health Transformation efforts off the ground
- Pfizer rebuked by FDA for misleading Adcetris ads on Facebook
- Maine enacts law expanding scope of practice for independent dental hygienists
- NewYork-Presbyterian to enact behavioral health reforms, pay $500K in wake of investigation
- NYU awarded $5.5M to expand oral health center
- Smile Partners USA partners with Illinois dentist
- Mississippi hospital could close June 15
- FDA Reminds More Than 2,200 Sponsors and Researchers to Disclose Trial Results
- FDA Reminds More Than 2,200 Sponsors and Researchers to Disclose Trial Results
- California behavioral health hospital to add inpatient beds
- Freedom of Associations
- When “Fail First” Fails Patients: Why Step Therapy Exception Requests Matter More Than Ever
- Why corporate dentistry gets a bad rap
- ECU dental school expands dental hygienist pipeline with new degree
- Pioneering exposure therapy psychologist dies
- Interfacing with our Inner Demons: Comments on the Division of Trading and Markets' Statement on Certain User Interfaces
- New Mental Health Parity Index highlights where disparities persist
- How University Hospitals swung to $190M in operating income after years of losses
- CMS taps 150 digital health companies, providers for ACCESS Model
- 10 providers seeking RCM talent
- Optum allows mental health NPs to offer transcranial magnetic stimulation
- National behavioral health association taps president, CEO
- Healthcare spending varies widely between metropolitan areas: HCCI
- CMS’ proposed pay bump inadequate, hospitals say
- Wavelet Medical, Aegis Ventures partner on first AI non-invasive fetal EEG monitoring platform
- Staff Statement Regarding Broker-Dealer Registration of Certain User Interfaces Utilized to Prepare Transactions in Crypto Asset Securities
- New Rules May Allow Broader Picks for CDC Vaccine Panel
- Second Meningitis Vaccine Doses Offered After U.K. Outbreak
- Crackdown on Vapes Falling Short, Report Finds
- Jasmine Rice Recalled Nationwide Over Possible Contamination
- AI speeds up prior auth, coding while driving higher costs for health systems: PHTI report
- ‘The next opioid epidemic’: Gambling legalization outpaces public health response to addiction
- Thinking About A GLP-1 Drug? Your Genetics Might Determine How Well You'll Fare
- Fighting High Blood Pressure? Having A Team On Your Side Can Help
- Radon Gas Increases Risk Of Ovarian Cancer, Study Says
- Your Doctor Might Be Using The Wrong Test To Track Your Cholesterol, Study Says
- Losing Teeth May Lead to Weight Gain, Researchers Report
- Heart Risk Worse With Sleep Apnea That Varies Night-By-Night
- Lilly’s Jaypirca shows fixed-duration power in ‘ambitious’ phase 3 CLL trial win
- How To Make a High-Deductible Health Plan Work for You
- Pennsylvania Town Faces Fallout From Trump’s Environmental Rule Rollback
- CMS showcases first wave of digital health tools as questions about 'last mile' of adoption remain
- ViiV launches ‘Still Here’ campaign aimed at reminding young people about HIV
- Regeneron rides into radiopharma via $2.1B biobucks pact with Australia’s Telix
- How to Limit The Health Risks Posed by Polluted Air
- U.S. States Warm, But Not As Expected
- Rovner Recaps Medicaid Cuts’ Impact on Hospitals and Fields Caller Questions on Affordability
- UHS’ CEO-to-worker pay ratio over the past 5 years
- 5 new university programs tackling behavioral health workforce gaps
- Texas Children’s gets $5M gift for behavioral health services
- CMS proposes 2.4% hospital pay increase, nationwide mandatory model rollout
- Proposed CMS rule would set prior auth deadlines for drugs
- How Evernorth's new Delaware specialty pharmacy facility highlights a broader care coordination approach
- HHS, after legal setback, updates ACIP charter to put more emphasis on vaccine safety
- HHS, after legal setback, updates ACIP charter to put more emphasis on vaccine safety
- Costco Recalls Cookies Over Missing Nut Allergy Warning
- CDC Pauses Release of COVID Vaccine Effectiveness Study
- Demand Surge Leads to Shortages of Estrogen Patches
- Statement Regarding Staff No-Action Letter to Bank of England
- Op-ed: Administrative fragility is costing healthcare more than we think
- UPDATED: Replimune to reduce workforce following 'disappointing' second rejection for melanoma prospect
- Title X Funding Restored, but New Rules Raise Concerns
- Function Health acquires mobile healthcare platform Getlabs to provide members with at-home lab tests
- The Healthcare Burnout Backlash (pt 3): How Workflow Redesign Is Helping Healthcare Organizations Offset Staffing Shortages
- The Healthcare Burnout Backlash (pt 3): How Workflow Redesign Is Helping Healthcare Organizations Offset Staffing Shortages
- BD Announced Application of CE Mark for the Liverty TIPS Stent Graft
- BD Announced Application of CE Mark for the Liverty TIPS Stent Graft
- Blackstone and TPG Complete Acquisition of Hologic; Names New CEO
- Blackstone and TPG Complete Acquisition of Hologic; Names New CEO
- Endospan Receives FDA Approval for the NEXUS Aortic Arch Stent Graft System
- Endospan Receives FDA Approval for the NEXUS Aortic Arch Stent Graft System
- InVera Medical Receives FDA Clearance for Non-Thermal Chronic Venous Disease Device
- InVera Medical Receives FDA Clearance for Non-Thermal Chronic Venous Disease Device
- How CVS Caremark is using innovative technology to simplify the prior authorization process
- Starting material sourcing bottlenecks increase US drug shortage risks: report
- Novartis cuts 114 more jobs at New Jersey HQ as restructuring rolls on
- Charles River flows into Boston to help AHA bridge cardiovascular health divide
- Your Brain Cares If Your Plant-Based Diet Is Unhealthy, Researchers Report
- Your Neighborhood Might Help Make You Old Before Your Time
- Heavy 'Forever Chemical' Exposure Before Birth Increases Childhood Asthma Risk, Study Finds
- High-Tech Magnets Offer New Hope for Veterans Battling Combat PTSD
- Early Diagnosis Key To ADHD Child's Academic Success, Study Finds
- Study Reveals Who Americans Think Should Pay for Elder Care
- Envision hires ConcertAI, IQVIA alum Nick Jones as its med comms president
- The top 10 pharma R&D budgets of 2025
- Bial launches ‘Dialogues with Parkinson’s’ campaign aimed at identifying early symptoms
- Novartis pumps up community health footprint to tackle heart disease and cancer
- Abbott survey finds ‘information overload, confusion and cost’ affecting health choices in US
- FDA accuses Amneal, BioCorRx of producing ‘false and misleading’ drug promos
- Epic rolls out health alerts to flag rising rates of illness at the county level
- Hospital M&A roars back to life in Q1 2026; Operating performances fray in February
- Fierce Pharma Asia—Takeda-Denali split-up; Merck, Zhifei's revised deal; Shionogi's made-in-US plan
- Brain Scans Reveal How Psychedelics Change Perception
- Benefits leaders report increased operational, financial costs amid 'digital health vendor sprawl': Solera survey
- Vanda initiates study of motion sickness drug Nereus in GLP-1 users
- Judge Allows Abortion Pill, Mifepristone, To Continue Being Mailed for Now
- Bangladesh Measles Outbreak Kills 100+ Kids, Emergency Shots Begin
- Regulatory burdens continue to mount for physician practices
- Omnichannel Has an Access Problem. Compliant AI Fixes It.
We used to think it was bad that IV pumps reset when visitors ignored "No cell phones" warnings. Healthcare Brew reports today's evolved version of the problem.
https://www.healthcare-brew.com/stories/2025/06/10/recalled-ventilator-easy-hack
Recalled ventilator was so easy to hack, ‘a teenager’ could have done it
‘Secure by design’ isn’t just a tech buzzword.
By Caroline Catherman | June 10, 2025There’s a cybersecurity problem breathing down the healthcare industry’s neck.
On April 7, Baxter Healthcare pulled all 4,100+ Welch Allyn Life2000 ventilators due to severe cybersecurity concerns. The FDA labeled this a Class I recall, meaning these issues threatened patients’ lives, though the agency hasn’t reported any injuries or deaths.
Naomi Schwartz, a former FDA employee and VP of services for MedCrypt, a cybersecurity firm for medical device manufacturers, told Healthcare Brew this recall should be a lesson for the medical technology industry.
This is one of several device recalls in recent years prompted by cybersecurity concerns, and in her opinion, Baxter did the right thing fast. The global medtech company first flagged these weaknesses in November, noting that there hadn’t been any hacks up to that point. An April market removal is a relatively short turnaround, she added.
But the vulnerabilities were easily avoidable with a development framework known as secure by design, the idea that companies—not consumers—are responsible for cybersecurity, and products should have features like multi-factor authentication.
The issues. On a scale of “you have to have a PhD” to “a teenager” could hack the system, Baxter’s ventilator security was more toward the latter, Schwartz said. Let’s run through some of the issues:
- No encryption. For one, the ventilators didn’t encrypt sensitive information, like passwords, according to Baxter’s November security advisory. “If I’m just issuing all my data in plain text, that’d be like me sending you an email saying, ‘Hey, my front door is unlocked. Walk into my house, why don’t you?’” Schwartz said.
- Physical ports. All a hacker needed to do to access the device was walk into a hospital and plug a piece of hardware into a physical port on the ventilator, Schwartz explained.
- Few authentication requirements. The software used to test and calibrate the ventilators didn’t require authentication from the user either, so anyone could have tweaked the ventilator settings. This flaw was severe enough to earn a score of 10/10 on a scale used by the government to measure vulnerabilities—“a nightmare scenario,” Schwartz said.
Learning opportunities. These issues should prompt other companies to double-check their own ventilators’ security—especially legacy devices that were made many years ago, Schwartz said.“These are very common problems, and they’re all things that a secure-by-design set of practices would have prevented,” she said.
The good news is Schwartz thinks Baxter responded quickly and appropriately once it discovered these flaws.
“The people out there who are producing and selling these products are doing their due diligence. They’re going back and checking older systems. They’re making sure that things are good and secure, and when they’re not, they’re taking appropriate action,” she said.
This incident comes after the FDA and Congress have ramped up medical device cybersecurity requirements in recent years.
For instance, in March 2023, the Protecting and Transforming Cyber Healthcare Act started requiring medical device manufacturers to address cybersecurity requirements in their submissions for market approval.
Get MHF Insights
News and tips for your healthcare freedom.
We never spam you. One-step unsubscribe.


















