Johnson & Johnson’s Abiomed told customers on October 5 about vulnerabilities in the operating system of the Automated Impella Controller, tied to network and physical access, that could end in loss of device control or an unexpected pump stop. FDA published the recall on October 14 and classified it Class I, the category reserved for potential serious injury or death. Five products are covered. No harm and no attacks have been reported.
The fix sequence says a lot about connected device reality. Field representatives are disabling network capabilities on deployed controllers, customers got instructions to do the same themselves, and the devices stay on the market while security updates are developed for an eventual reconnection.
The vulnerabilities came out of Abiomed’s own routine cybersecurity risk assessments, and it is the third Impella recall since June, after a run of purge pressure notices. Finding your own flaws and taking the recall is what the postmarket half of FDA’s framework looks like when it works, and it still costs a Class I headline.