RSS
TwitterFacebook

Boston Scientific Cybersecurity Incident: What Patients, Employees and Others Should Know Featured

Unauthorized activity disrupted Boston Scientific systems worldwide, while the company continues investigating whether personal information was compromised.

Boston Scientific is investigating a major cybersecurity incident that disrupted portions of the medical device company’s global computer network and business operations.

The company identified the incident on August 25, 2026. Boston Scientific later confirmed that unauthorized activity occurred on certain company systems and caused a network outage affecting operating systems and business applications.

The incident interfered with manufacturing, order processing and product shipments and prompted Boston Scientific to take steps to contain the threat and investigate what happened.

For people whose personal information may be maintained by Boston Scientific, however, an important question remains unanswered: Was personal information accessed or taken during the cyberattack?

What Happened in the Boston Scientific Cybersecurity Incident?

Boston Scientific first publicly disclosed the cybersecurity incident on August 26.

According to the company, certain information technology systems were affected, resulting in a global disruption to its operations. Boston Scientific activated its incident-response procedures and brought in outside cybersecurity specialists, including CrowdStrike, to investigate.

The company subsequently disclosed that the incident involved unauthorized activity on certain systems.

Boston Scientific reported that the unauthorized activity affected certain internal systems and business applications. The disruption temporarily affected the company’s ability to manufacture products, process orders and ship medical devices to customers.

Boston Scientific has said it found no indication of continued unauthorized activity following August 25.

Boston Scientific Operations Have Been Restored

The incident had a significant operational impact.

During the disruption, Boston Scientific experienced problems involving manufacturing, distribution, shipping and certain business applications. There was also a temporary disruption involving activation of some LATITUDE remote-monitoring services used with cardiac devices.

Boston Scientific has said there was no indication that the incident impaired the function or quality of its medical devices.

By September 9, the company reported that manufacturing, order fulfillment and shipping operations had been fully restored. Boston Scientific said its distribution network was operating at or above normal levels while it worked through outstanding orders.

Was Personal Information Compromised?

That remains one of the most important unanswered questions.

Boston Scientific has not publicly confirmed that personal information was stolen or exposed.

During its investigation, the company acknowledged questions about whether personal information may have been compromised. Boston Scientific stated that if its investigation determines personal data was affected, it would take appropriate steps to notify affected individuals, customers and regulators and provide support as required by privacy laws.

The absence of a public notification at this stage does not necessarily establish whether personal information was or was not involved. Cybersecurity investigations can take time as forensic investigators determine which systems were accessed, what information those systems contained and whether information was viewed, copied or removed.

Who Should Pay Attention?

People who believe Boston Scientific may have maintained their personal information should watch for additional announcements and any direct notification from the company.

This could potentially include certain:

  • Current or former Boston Scientific employees;
  • Patients whose information may have been provided to or maintained by Boston Scientific;
  • Healthcare professionals or providers;
  • Customers;
  • Vendors or suppliers; and
  • Other individuals whose personal information may have been stored in affected Boston Scientific systems.

At this time, Boston Scientific has not publicly identified specific categories of personal information as having been compromised.

People should therefore be cautious about reports that particular information—such as Social Security numbers, medical information or financial information—was exposed unless and until that information is confirmed.

What Should You Do If You Believe You May Be Affected?

If you have received a notice concerning the Boston Scientific incident, keep a copy of it.

You should also consider monitoring your financial accounts, credit reports and other accounts for unusual activity. Be particularly cautious about unexpected emails, telephone calls or text messages asking you to provide passwords, financial information or other sensitive information.

Cybercriminals sometimes use information obtained during security incidents to make fraudulent communications appear more convincing.

You may also wish to keep records of any expenses, fraudulent activity, lost time or other problems that you believe resulted from misuse of your information.

Were You Potentially Affected by the Boston Scientific Cybersecurity Incident?

We are investigating the Boston Scientific cybersecurity incident and are interested in hearing from people who believe their personal information may have been affected.

If you received a notice from Boston Scientific, worked for the company, were a patient or healthcare provider whose information may have been maintained by Boston Scientific, or otherwise believe your personal information may have been involved, please complete the form on this page.

Providing information through the form can help attorneys evaluate the scope of the incident and determine what information may have been affected.

There is no obligation to pursue a claim simply by submitting the form.


Tags:            

Leave a Reply

Your email address will not be published. Required fields are marked *