This is a temporary program designed to give our customers the option to exchange or upgrade their current legacy device.
Urgent Field Safety Notification
MiniMed™ 508 Insulin Pump and MiniMed™ Paradigm™ Series Insulin Pumps Cybersecurity Concerns
Program Terms
If you are interested in in discussing your options but you are not sure if you are in warranty, submit your request and we will confrm your warranty status when we reach out to you to discuss your alternatives.
OUT-OF-WARRANTY customer options:
Option 1. Upgrade purchase through your current insurance provider for a new insulin pump with a full 4-year warranty.
Option 2. Exchange your current insulin pump for a refurb MiniMed™ 670G insulin pump with an upfront fee of $399.
IMPORTANT NOTES:
By clicking this button, I am acknowledging that I have read and understood the Cybersecurity Program Options and Out of Warranty terms outlined above.
SUBMIT YOUR EXCHANGE REQUEST FORM |
IN-WARRANTY CUSTOMER:
Exchange current pump for the MiniMed™ 670G insulin pump
IMPORTANT NOTES:
CUSTOMERS USING A CGM TRANSMITTER WITH THEIR CURRENT PUMP:
Customers with an In-warranty CGM transmitter:
Customers with an Out-of-warranty CGM transmitter:
If you have additional questions regarding the Program contact us:
Monday – Friday, 8AM to 6PM Central at (866) 222-2584.
By clicking this button, I am acknowledging that I have read and understood the Cybersecurity Program Options and Out of Warranty terms outlined above.
SUBMIT YOUR EXCHANGE REQUEST FORM |
Q. Why am I receiving this notice?
Medtronic takes customer safety and device security very seriously. Due to this potential cybersecurity issue, Medtronic is recommending customers speak with their healthcare provider (HCP) about changing to a newer model insulin pump. To help with this, we have created the Legacy Exchange Program, which gives our customers the opportunity to exchange or upgrade their legacy device to a newer model insulin pump with increased cybersecurity protection, like the MiniMed™ 670G insulin pump.
Q. Is MiniMed™ 530G insulin pump vulnerable to these cybersecurity risks?
No, the MiniMed™ 530G insulin pump is not impacted by this cybersecurity issue.
Q. Does my pump require replacement?
Due to this potential cybersecurity issue, Medtronic is recommending customers speak with their healthcare provider
(HCP) about changing to a newer model insulin pump with increased cybersecurity protection, like the MiniMed™ 670G
insulin pump.
To help with this, we are offering a program for eligible people to upgrade to a newer insulin pump model or obtain a lower cost product exchange. In the meantime, we recommend you take the cybersecurity precautions to minimize the potential risks.
For countries outside of the US:
You will receive or should have already received a notification letter with instructions based on the country you live in. We recommend that you speak with your healthcare provider to discuss the cybersecurity issue and the steps you can take to protect yourself. In the meantime, we recommend you take the cybersecurity precautions included in the letter.
Q. What is the cybersecurity concern?
The MiniMed™ 508 insulin pump and the MiniMed™ Paradigm™ series insulin pumps are designed to communicate using a wireless radio frequency (RF) with other devices such as a blood glucose meter, glucose sensor transmitters, and CareLink™ USB devices.
Security researchers have identified potential cybersecurity vulnerabilities related to the communication protocol in these insulin pumps. An unauthorized person with special technical skills and equipment could potentially connect wirelessly to a nearby insulin pump to change settings and control insulin delivery. This could lead to hypoglycemia (if additional insulin is delivered) or hyperglycemia and diabetic ketoacidosis (if not enough insulin is delivered).
Q. How do I find the software version of my pump?
Q. What actions is Medtronic taking to address this cybersecurity concern?
We have notified the appropriate regulatory authorities, published an advisory about this potential security concern, and informed healthcare professionals and patients about precautionary steps that can be taken to protect the security of their pump.
Q. My safety is important, what is Medtronic doing to anticipate security concerns and build-in safeguards to prevent them from happening?
As part of our commitment to customer safety and device security, Medtronic works closely with industry regulators and researchers to anticipate and respond to potential risks. In addition to our ongoing work with the security community, we have already made several important changes to enhance device security with our newer devices available in some countries today. We will continue to take steps to collaborate with industry researchers and regulators to improve device safety.
Q. Has a Medtronic insulin pump ever been manipulated?
Medtronic has not received any confirmed reports of an insulin pump being manipulated in this way by an unauthorized person.
Q. How would I know if someone manipulated my insulin pump?
Several factors must occur for any pump to be potentially affected. We recommend that you continue to pay attention to any pump notifications, alarms and alerts. You should also immediately cancel any unintended boluses and monitor your blood glucose levels closely and taking appropriate actions as needed.
Q. How and when will Medtronic fix this concern?
Medtronic takes customer safety and device security very seriously. We have already introduced a new generation of insulin pumps that is not affected by this issue.
Q. Should I stop using my pump given there are other alternatives to a Medtronic pump?
Of course, every person with diabetes should make these personal decisions along with the consultation of their healthcare team, but there haven’t been any conrmed reports of this security risk. Your safety is our priority and we hope that you’re able to continue to experience the benets of insulin pump therapy. If you are concerned, you can take note of the tips that we’ve shared.
Q. Does this impact the MiniMed™ 600 series insulin pumps? How are the MiniMed™ 600 series insulin pumps different?
No. This vulnerability does not impact the MiniMed™ 600 series insulin pumps because they use encrypted communication which is completely different from the communication used by the Paradigm pump models. The MiniMed™ 600 series insulin pumps include the MiniMed™ 620G, MiniMed™ 630G, MiniMed™ 640G and MiniMed™ 670G systems. Not all these systems are sold on the US market.
Q. How worried should I be?
Medtronic has not received any confirmed reports of a product being manipulated in this way by an unauthorized person.
Q. What do you recommend I do now to protect my insulin pump security?
If you feel concerned:
Q. Should I replace my pump with a new 600 series pump?
Every person with diabetes should make decisions about their insulin pump therapy along with their healthcare team. We recommend you talk about this with your healthcare team.
Q. Didn’t we just receive a letter about cybersecurity concerns?
You may have received information on cybersecurity concerns with the remote controller. This is a separate notification. With the growing amount of attention to cybersecurity in the medical device industry, we felt that it was important for our customers to understand the issues and risks in greater detail.
In the case of the remote controller, an unauthorized individual in close proximity to an insulin pump customer could potentially copy the wireless radio frequency (RF) signals from their remote controller (while they are in the process of delivering a remote bolus) and play the RF signals back at a later time to deliver an involuntary bolus of insulin to the customer. This notice refers to the ability of an unauthorized person with special technical skills and equipment who could potentially send RF signals to a nearby insulin pump to change settings and control insulin delivery.
SUBMIT YOUR EXCHANGE REQUEST FORM |