UPDATE 3-J&J warns diabetic patients: Insulin pump vulnerable to hacking
(Adds statement by U.S. Food and Drug Administration, paragraphs 23-24)
By Jim Finkle
Oct 4 (Reuters) - Johnson & Johnson is telling patients that it has learned of a security vulnerability in one of its insulin pumps that a hacker could exploit to overdose diabetic patients with insulin, though it describes the risk as low.
Medical device experts said they believe it was the first time a manufacturer had issued such a warning to patients about a cyber vulnerability, a hot topic in the industry following revelations last month about possible bugs in pacemakers and defibrillators.
J&J executives told Reuters they knew of no examples of attempted hacking attacks on the device, the J&J Animas OneTouch Ping insulin pump. The company is nonetheless warning customers and providing advice on how to fix the problem.
"The probability of unauthorized access to the OneTouch Ping system is extremely low," the company said in letters sent on Monday to doctors and about 114,000 patients who use the device in the United States and Canada.
"It would require technical expertise, sophisticated equipment and proximity to the pump, as the OneTouch Ping system is not connected to the internet or to any external network."
A copy of the text of the letter was made available to Reuters.
Insulin pumps are medical devices that patients attach to their bodies that injects insulin through catheters. Continued...