- Physicians in Congress propose Medicare payment overhaul
- 2 men sentenced in $522M fraud, kickback scheme
- What 3 ASC leaders are saying about cardiology’s race to outpatient
- Hospital at home linked to better outcomes: 7 notes
- Long-established Florida physician practice acquired
- Facilitating Access to Trump Accounts
- HCA Tennessee hospital taps COO
- WellSpan Health to open 4-room ASC in Pennsylvania
- Colorado hospital names new CEO
- Yale New Haven hospital president to retire
- Ascension Tennessee hospital names COO
- Nurses fret AI overreliance could erode care, call for more guardrails
- ‘Dynamics we haven’t experienced before’: Hospitals absorb costs as patients lose coverage, skip Medicaid
- Fatality risk grows 8% per added med-surg nurse patient: Study
- TriHealth hospital hit with $10M verdict in psychiatric unit death
- HCA Texas hospital COO heads to Kansas
- Surgery Partners increases same-facility revenue by 4% in Q1: 10 notes
- Fixing Failures to Communicate
- Dr. Nisha D’Silva installed as president of the American Association for Dental, Oral and Craniofacial Research
- PDS Health, CareQuest partner to expand blood pressure screenings in dental offices
- 5 hospitals, health systems investing in ASCs
- Bankruptcy, PE debt and a $3.9B Ascension deal: A 30-year breakdown of AmSurg
- Henry Schein increases global dental sales by 9% in Q1: 7 notes
- Heartland Dental expands in 7 states
- Ohio woman charged with practicing unlicensed dentistry
- 15 physician deals in 40 days
- Psych hospital eases security tool restrictions after violent incidents
- For nonprofit hospitals, pricey management consultants haven't yielded better performances: study
- TriHealth hospital hit with $10M verdict in psychiatric unit death
- Supreme Court Issues Stay, Keeping Abortion Pill Mifepristone Available by Mail For Now
- From 1st-in-state to 1st-in-world: 5 surgical milestones to know
- 3 dental mergers, acquisitions in April
- Statement on Proposing Release for Semiannual Reporting
- Quarterly Questions: Statement on the Proposed Amendments to Allow Semiannual Reporting
- HHS outlines plan to ‘curb psychiatric overprescribing’: 5 things to know
- Former Oklahoma dental assistant sentenced to prison for assaulting patients
- Statement on Proposing Semiannual Reporting
- Transforming Behavioral Healthcare Delivery through the Collaborative Care Model
- Tennessee dental practice to close due to financial strain
- Listen to the Latest ‘KFF Health News Minute’
- Lifepoint Health taps new vice president of finance from Acadia
- UnitedHealthcare to reduce prior auth requirements by 30%
- ‘Retire one-and-done interventions’: Wellstar achieves 40% drop in physician distress
- Newer Migraine Drugs Reduce Headache Days With Fewer Side Effects
- Pfizer delivers strong Q1 but keeps guidance steady amid COVID seasonality
- CVS to expand biosimilar formulary adoptions to improve affordability, accessibility
- New Drug Combo Effective Against Treatment-Resistant IBD, Trials Show
- New Warning Labels Might Help People Cut Back On Drinking
- Novartis to close German manufacturing site, cutting 220 jobs
- BioNTech to slash 1,860 jobs, exit sites in Germany and Singapore in major manufacturing pullback
- After Alzheimer's agitation nod, Axsome jacks up Auvelity's peak sales projection to $8B
- Ozempic Can Curb Cravings in Alcohol Use Disorder, Landmark Trial Finds
- US on the Brink of Losing Measles-free Status, Study Warns
- Delays in Visa Program Threaten Doctor Placements in Underserved Areas
- Sanofi expands AI capabilities, investing $294M to scale Toronto hub
- States Eye Aid To Prop Up Distressed Hospitals Amid Federal Medicaid Cuts
- Assort Health rolls out outbound AI agent for personalized patient outreach
- Neurocrine cites work disruption data to make case for timely movement disorder diagnosis
- Eyeing CAR-T autoimmune first, Kyverna hires pharma veteran as CCO
- Newly formed Keenova launches ‘Don't Be a Viking’ campaign for Dupuytren’s contracture
- Supreme Court Puts Brakes on Abortion Pill Restrictions
- Cytokinetics' Myqorzo succeeds in landmark cardiomyopathy trial
- Why state dental boards are scrutinizing DSOs
- 6 dental leadership moves to know
- Child Mind Institute names chief clinical officer
- UMass Memorial behavioral health provider to lay off 78 employees
- Prolific Machines sets monoclonal antibody manufacturing record with light-controlled platform
- Healthcare Dealmakers—UConn Health grows, Centene subsidiaries merge and more
- Acadia Healthcare revenue rises 7.6% as net income dips: 6 notes
- New York hospital expands behavioral health capacity to 60 beds
- FDA Green Lights Expanded Access to Pancreatic Cancer Drug, Daraxonrasib
- American Hospital Association, West Health Institute partner to help health systems scale new tech
- Alignment CEO expects short delay for CMS' proposed risk adjustment changes
- WakeMed Health's plans to join Atrium Health face swift pushback from NC officials
- Online Misinformation Adding To Americans' Skin Cancer Risk, Survey Finds
- Medtronic’s Updated Mitral Valve, Mosaic Neo, Gets FDA approval
- Medtronic’s Updated Mitral Valve, Mosaic Neo, Gets FDA approval
- Social Media Videos, Easy Access Raise Risk of Teen Inhalant Use
- Staff Statement Regarding Pooled Employer Plans
- SCOTUS temporarily restores online access to abortion pill after appeals court ruling
- SCOTUS temporarily restores online access to abortion pill after appeals court ruling
- Sonire Therapeutics Initiates First U.S. Clinical Study of Ultrasound-Guided HIFU Therapy for Pancreatic Cancer
- Sonire Therapeutics Initiates First U.S. Clinical Study of Ultrasound-Guided HIFU Therapy for Pancreatic Cancer
- Edwards Lifesciences Shares Ten-Year Pivotal Data Supporting Long-Term Durability of Resilia Tissue
- Edwards Lifesciences Shares Ten-Year Pivotal Data Supporting Long-Term Durability of Resilia Tissue
- Nearly half of reproductive age women with Medicaid coverage live in states restricting abortion: KFF
- 'Fitspirational' Posts Can Be More Harmful Than Motivational, Review Concludes
- CDMO Samsung Biologics estimates $102M impact stemming from ongoing union strike
- After March cuts, Novartis trims another 60 roles at US headquarters
- Parents’ Stress Tied to Children’s Mental Health, New Survey Finds
- Surgeon Multitasking Increases Death Risk Of Organ Transplantees
- Bristol Myers Squibb ties science to soccer in World Cup campaign voiced by Ali Krieger
- When Natural Disasters Strike, Another Crisis Hits Those Recovering From Opioid Addiction
- She Survived 2 Shootings. Research Helps Explain Why Her Pain Persists Years Later.
- HHS’ Healthy Food Agenda Puts Hospitals on Notice About Patients’ Meals
- Amgen channels another $300M into US outlay, bolstering Puerto Rico biologics expansion
- Journalists Share Latest on Baby Formula Safety, Estrogen Patches, and Postcancer Costs
- Prevention Efforts Increasingly See Suicide Through a Broader Lens
- FDA Recalls Several Ghirardelli Powdered Beverages Over Potential Contamination
- FDA hands Pfizer, Arvinas’ Veppanu early approval for breast cancer subtype
- High-Intensity Exercise After Breast Cancer Surgery Helps Speed Recovery
- Omada signs on with Optum Rx's GLP-1 management program
- Trump Offers Third Candidate For Surgeon General After Pulling Dr. Casey Means' Nomination
- Industry Voices—Value-based care won the policy argument. Now it has to deliver
- Senators introduce clean extension to cost-based payments for some rural hospitals
- Beth Israel Lahey Health taps Heidi for system-wide AI scribe rollout
- Johnson & Johnson Enters Agreement to Acquire Atraverse Medical
- Johnson & Johnson Enters Agreement to Acquire Atraverse Medical
- enVVeno Medical Receives FDA IDE Approval for Non-Surgical Replacement Venous Valve
- enVVeno Medical Receives FDA IDE Approval for Non-Surgical Replacement Venous Valve
- Medtronic Gains CE Mark for Stealth AXiS surgical system
- Medtronic Gains CE Mark for Stealth AXiS surgical system
- Medtronic Continues Cardiovascular Care Growth with Completion of CathWorks Acquisition
- Medtronic Continues Cardiovascular Care Growth with Completion of CathWorks Acquisition
- Cleveland Clinic taps startup Luminai to test how AI can run hospital operations
- Look out Rexulti, Axsome's Auvelity has its nod for Alzheimer's agitation
- Cardio drug developer Esperion to go private in potential $1.1B buyout by ArchiMed
- Union workers at Korean CDMO Samsung Biologics kick off strike
- Summit's PD-1xVEGF interim trial miss surprises analysts, shares tumble
- Health Tech Weekly Rundown: Sage launches Tasking for senior care workflows; St. Luke’s taps Auxira Health for cardiologist support
- Confusion Continues Over Age To Start Breast Cancer Screening, Survey Finds
- Senses, Not Muscles, Key to Speech Recovery After Stroke
- Antibiotics Not Linked To Celiac Disease Risk, Study Argues
- Common Knee Surgery Doesn't Help, Might Actually Make Things Worse, Clinical Trial Reports
- States Rush To Figure Out How To Enforce Trump's Medicaid Work Requirements
- Gavin Newsom, Early Champion of Single-Payer, Moderates in the Face of Fiscal Limits
- Delays in Visa Program Threaten Placement of Hundreds of Doctors in Underserved Areas
- FDA Permits Expanded Access for Investigational Pancreatic Cancer Drug Daraxonrasib
- From Prototype to Production: Building a Validation Strategy That Scales with Manufacturing Volume
- From Prototype to Production: Building a Validation Strategy That Scales with Manufacturing Volume
- Managing AI in Medical Technology: From Innovation to Compliance
- Managing AI in Medical Technology: From Innovation to Compliance
- Seven Things Every Medical Device Manufacturer Must Know Before Integrating AI
- Seven Things Every Medical Device Manufacturer Must Know Before Integrating AI
- New Medical Guidelines Urge More Fiber, Less Bathroom Scrolling on Your Phone
- Sleep and Anxiety Medications in Pregnancy Appear to Pose Little Harm
- Trump's Medicaid Work Mandate Debuting in Nebraska to Much Dismay
- Nasal Spray Flu Vaccines Create 'Battlefield' In Adults' Noses
- Prehabilitation Slashes Post-Op Complications By Half, Review Says
- Understanding Emotions Could Be Key To Quelling Chronic Pain
- Meth Caused 1 In 6 Heart Attacks Over A Decade, Study Finds
- When Natural Disasters Strike, Another Crisis Hits Those Recovering From Opioid Addiction
- States Rush To Figure Out How To Enforce Trump’s Medicaid Work Requirements
- Rising Stars: Axplora’s Arsalan Khan gets technical on marketing
- Orchestrating Affordability: The Critical New Role of the Health Plan
- The Case for a More Proactive Payment Integrity Program
- AI Tool May Help Identify ADHD in Kids Long Before Typical Diagnosis
- FDA Moves to Real-Time Clinical Trial Patient Monitoring, Faster Drug Review
- Dementia Screening Safe For Families, Trial Finds
- Online Program Soothes Post-Trauma Stress In Injured Children
We used to think it was bad that IV pumps reset when visitors ignored "No cell phones" warnings. Healthcare Brew reports today's evolved version of the problem.
https://www.healthcare-brew.com/stories/2025/06/10/recalled-ventilator-easy-hack
Recalled ventilator was so easy to hack, ‘a teenager’ could have done it
‘Secure by design’ isn’t just a tech buzzword.
By Caroline Catherman | June 10, 2025There’s a cybersecurity problem breathing down the healthcare industry’s neck.
On April 7, Baxter Healthcare pulled all 4,100+ Welch Allyn Life2000 ventilators due to severe cybersecurity concerns. The FDA labeled this a Class I recall, meaning these issues threatened patients’ lives, though the agency hasn’t reported any injuries or deaths.
Naomi Schwartz, a former FDA employee and VP of services for MedCrypt, a cybersecurity firm for medical device manufacturers, told Healthcare Brew this recall should be a lesson for the medical technology industry.
This is one of several device recalls in recent years prompted by cybersecurity concerns, and in her opinion, Baxter did the right thing fast. The global medtech company first flagged these weaknesses in November, noting that there hadn’t been any hacks up to that point. An April market removal is a relatively short turnaround, she added.
But the vulnerabilities were easily avoidable with a development framework known as secure by design, the idea that companies—not consumers—are responsible for cybersecurity, and products should have features like multi-factor authentication.
The issues. On a scale of “you have to have a PhD” to “a teenager” could hack the system, Baxter’s ventilator security was more toward the latter, Schwartz said. Let’s run through some of the issues:
- No encryption. For one, the ventilators didn’t encrypt sensitive information, like passwords, according to Baxter’s November security advisory. “If I’m just issuing all my data in plain text, that’d be like me sending you an email saying, ‘Hey, my front door is unlocked. Walk into my house, why don’t you?’” Schwartz said.
- Physical ports. All a hacker needed to do to access the device was walk into a hospital and plug a piece of hardware into a physical port on the ventilator, Schwartz explained.
- Few authentication requirements. The software used to test and calibrate the ventilators didn’t require authentication from the user either, so anyone could have tweaked the ventilator settings. This flaw was severe enough to earn a score of 10/10 on a scale used by the government to measure vulnerabilities—“a nightmare scenario,” Schwartz said.
Learning opportunities. These issues should prompt other companies to double-check their own ventilators’ security—especially legacy devices that were made many years ago, Schwartz said.“These are very common problems, and they’re all things that a secure-by-design set of practices would have prevented,” she said.
The good news is Schwartz thinks Baxter responded quickly and appropriately once it discovered these flaws.
“The people out there who are producing and selling these products are doing their due diligence. They’re going back and checking older systems. They’re making sure that things are good and secure, and when they’re not, they’re taking appropriate action,” she said.
This incident comes after the FDA and Congress have ramped up medical device cybersecurity requirements in recent years.
For instance, in March 2023, the Protecting and Transforming Cyber Healthcare Act started requiring medical device manufacturers to address cybersecurity requirements in their submissions for market approval.
Get MHF Insights
News and tips for your healthcare freedom.
We never spam you. One-step unsubscribe.














