Two Numbers Moved on Tuesday
Boston Scientific told investors it is unlikely to meet the sales growth and adjusted earnings targets it set in July, for both the third quarter and the full year, because of the cyberattack that hit its systems in late August.
The disclosure came in a filing with the Securities and Exchange Commission and was reported by MedTech Dive. The company determined that the incident is likely to have a material effect on third-quarter and full-year results. Its shares fell more than four percent to $45.73 in Tuesday morning trading.
The second number matters more to patients than the first. The company has said the interruption that prevented new patients from activating remote monitoring for their cardiac devices has been resolved, as reported by The Register.
That gap was the clinical heart of this story. For roughly two weeks, people who received a new pacemaker, defibrillator, or implantable cardiac monitor could not get the home equipment that transmits their heart data to their clinic. The device worked. The data simply did not travel.
Patients Implanted During the Gap Have One Thing to Check
If you or a family member had a Boston Scientific cardiac device implanted between late August and early September, the practical question is whether the home monitor is now connected and sending.
For most cardiac rhythm devices, that means a bedside communicator that needs to be activated. For insertable cardiac monitors, it means pairing the device with the patient's phone. During the outage, neither could happen, though the devices themselves kept recording. The company said stored data would transmit once systems were restored and pairing occurred.
A short call to the implanting clinic is the reasonable step. Ask whether remote monitoring is showing transmissions, and whether an in-office check is needed to upload anything the device stored during the gap. Patients who were told to expect a communicator in the mail and never received one should say so.
What did not happen is worth stating just as plainly. In the company's update on the incident, Boston Scientific reported no impact on the function of implanted devices, no impact on in-person device checks at a clinic, and no impact on remote monitoring for patients already enrolled before the outage. Nobody should have their device checked or replaced because of this incident.
MedicalDaily reported on the initial disclosure that the attack disrupted order processing and shipping, when the central question was whether an implanted device could itself be compromised. It could not, and nothing since has changed that. What has changed is the scale of the operational damage and the fact that the company has now put a financial number on it.
The Guidance the Company Now Expects to Miss
The targets in question were issued with the company's second-quarter results on July 29. For the full year, Boston Scientific estimated net sales growth of roughly 5.5 to 6.5 percent on a reported basis and 5 to 6 percent organically, with adjusted earnings per share of $3.28 to $3.32, according to its second-quarter earnings release. Third-quarter guidance was 3 to 5 percent growth with adjusted earnings of $0.80 to $0.82.
The company said it "anticipates recovering some portion of the impacted revenue" as it ramps operations back up, but that the full effects are not yet known. A revised outlook is scheduled for the third-quarter earnings call on October 28. Boston Scientific also said it does not expect the incident to materially affect its long-term financial condition.
On recovery, the company said its distribution network is substantially restored, with major distribution centers processing and shipping at or above normal levels, sterilization facilities operational, and manufacturing resumed across most global sites. It has identified no evidence of ongoing unauthorized access, though the investigation remains open.
Much remains undisclosed. The company has not said how the attackers got in, whether ransomware was involved, who was responsible, or whether any patient or employee data was taken. It has not given a date for full operational recovery.
Hospitals, Not Households, Absorb the Rest
For most people, the remaining risk from this incident is not about a device already implanted. It is about scheduling.
Boston Scientific supplies stents, catheters, pacemakers, defibrillators, and endoscopy equipment to hospitals worldwide. When order processing and shipping stop at a supplier that size, procedures planned around specific devices can slip, because a physician has usually selected a particular product for a particular patient and a substitute is not always interchangeable.
No hospital or health system has publicly reported canceled procedures tied to this incident. Patients with a scheduled cardiac or endoscopic procedure in the coming weeks can ask whether the device intended for them is already in the hospital's inventory. That is a normal question and does not imply anything is wrong.
The wider pattern deserves attention from anyone who follows health policy. Medical device companies including Stryker, Medtronic, Intuitive, and Abbott have all disclosed cybersecurity incidents this year, part of a run of cyberattacks across the medtech industry. An attack does not need to touch an implanted device to affect patient care. It only needs to interrupt the systems that get devices to hospitals and data to clinics.
That is the durable lesson here, and it points to a question regulators have not answered: how health systems should plan for a major supplier going offline. MedicalDaily will report the revised financial outlook when it is released in late October, and any further disclosure about data exposure.
Key Questions Answered
What is new in this report? Boston Scientific disclosed it is unlikely to meet its third-quarter and full-year 2026 sales and earnings targets, and said the interruption affecting new remote monitoring activations has been resolved.
Are implanted devices at risk? No. The company has reported no impact on the function of implanted cardiac devices, on in-person device checks, or on remote monitoring established before the outage.
Who was actually affected? Patients who received a new cardiac device during the outage, whose home monitoring equipment could not be activated or paired. Their devices continued recording data.
What should those patients do? Call the implanting clinic to confirm remote monitoring is transmitting and ask whether an in-office upload is needed for data stored during the gap.
Was patient data stolen? The company has not said. It has not disclosed the attacker, the method, whether ransomware was involved, or whether any data was taken.
Could procedures be delayed? Possibly, through shipping backlogs. No hospital has publicly reported cancellations. Patients with upcoming procedures can ask whether the device is already in hospital inventory.
When will more be known? Boston Scientific plans to give a revised financial and operational outlook with its third-quarter earnings on October 28.