Security bulletins
MiniMed™ 508 and MiniMed™ Paradigm™ series insulin pumps
Potential security vulnerabilities have been identified in select Medtronic insulin pumps, including MiniMed™ 508 and the MiniMed™ Paradigm™ series.
Updated Jan 5, 2023: recommended upgrade pump from MiniMed™ 670G to 770G in Mitigations section.
Original publication date: June 27, 2019
Based on earlier work performed by external researchers including Nathanael Paul, Jay Radcliffe, and Barnaby Jack, and from recent work performed by external researchers Billy Rios, Jonathan Butts and Jesse Young, potential security vulnerabilities have been identified in select Medtronic insulin pumps. Based on additional internal testing, Medtronic is publicly disclosing this matter.
The vulnerability allows a potential attacker with special technical skills and equipment to potentially send radiofrequency (RF) signals to a nearby insulin pump to change settings, impacting insulin delivery. This change could result in a patient experiencing hypoglycemia (if additional insulin is delivered) or hyperglycemia (if not enough insulin is delivered).
Affected products are listed at the end of this document.
As of the date of this bulletin, we have received no confirmed reports of unauthorized persons changing settings or controlling insulin delivery because of this vulnerability.
Medtronic recommends that patients and physicians continue to use these devices as prescribed and intended, along with taking the following required actions:
For U.S. patients:
Due to this potential cybersecurity issue, Medtronic recommends that patients who are currently using the affected products speak with their healthcare provider about changing to a newer model insulin pump with increased cybersecurity protection, such as the MiniMed™ 770G insulin pump.
For patients outside the U.S.:
Patients will receive a notification letter with instructions based on their country of residence. Medtronic recommends that patients speak with their healthcare provider to discuss the cybersecurity issue and the steps they can take to protect themselves.
If you live in a country that does not have a newer model Medtronic insulin pump available, Medtronic recommends taking the cybersecurity precautions below to minimize the potential for a cybersecurity attack and to continue to take advantage of the benefits of insulin pump therapy.
In the meantime, Medtronic recommends that all patients using affected pump models follow the cybersecurity precautions included below.
Action recommended for all patients:
The complete advisory issued by ICS-CERT can be found here.
The following pump models ARE vulnerable to this potential issue:
| Insulin pump | Software versions |
|---|---|
| MiniMed™ 508 pump | All |
| MiniMed™ Paradigm™ 511 pump | All |
| MiniMed™ Paradigm™ 512/712 pumps | All |
| MiniMed™ Paradigm™ 712E pump | All |
| MiniMed™ Paradigm™ 515/715 pumps | All |
| MiniMed™ Paradigm™ 522/722 pumps | All |
| MiniMed™ Paradigm™ 522K/722K pumps | All |
| MiniMed™ Paradigm™ 523/723 pumps | Software versions 2.4A or lower |
| MiniMed™ Paradigm™ 523K/723K pumps | Software versions 2.4A or lower |
| MiniMed™ Paradigm™ Veo™ 554/754 pumps | Software versions 2.4A or lower |
| MiniMed™ Paradigm™ Veo™ 554CM/754CM pumps | Software versions 2.4A or lower |
To find the software version for the MiniMed™ Paradigm™ pumps:
If you have any questions or concerns about this issue, please contact Medtronic using the contact information indicated below.
U.S.: Please call our 24-hour Technical Support Team at: 888-646-4633.
International: Please contact your local Medtronic representative. A list of international contacts can be found here.