• Home
  • Latest
  • Fortune 500
  • Finance
  • Tech
  • Leadership
  • Lifestyle
  • Rankings
  • Multimedia
HealthFortune 500

Johnson & Johnson Warns Patients of an Insulin Pump Cyber Bug

By
Reuters
Reuters
and
Michelle Toh
Michelle Toh
Down Arrow Button Icon
By
Reuters
Reuters
and
Michelle Toh
Michelle Toh
Down Arrow Button Icon
October 4, 2016, 7:30 AM ET
Johnson & Johnson Products Ahead Of Earnings
The Johnson & Johnson logo is arranged for a photograph in New York, U.S., on Monday, April 15, 2013. Johnson & Johnson is scheduled to release earnings data on April 16. Photographer: Scott Eells/Bloomberg via Getty ImagesPhotograph by Scott Eells/Bloomberg via Getty Images

Johnson & Johnson is telling patients that it has learned of a cyber security bug in one of its insulin pumps that a hacker could exploit to overdose diabetic patients with insulin, though it describes the hacking risk as low.

Medical device experts said they believe it was the first time a manufacturer had issued such a warning to patients about a cyber vulnerability, a hot topic in the industry following revelations last month about possible vulnerabilities in pacemakers and defibrillators.

J&J (JNJ) executives told Reuters they knew of no examples of attempted attacks on the device, the J&J Animas OneTouch Ping insulin pump. The company is nonetheless warning customers and providing advice on how to fix the problem.

“The probability of unauthorized access to the OneTouch Ping system is extremely low,” the company said in letters mailed out on Monday to doctors and about 114,000 patients in the United States and Canada who use the device. A copy of the text of the letter was made available to Reuters.

The warning is being delivered a month after a prominent short seller and cyber security research firm went public with allegations of potentially life-threatening cyber vulnerabilities in heart devices from St. Jude Medical Inc .

St. Jude said the allegations were false as its shares tumbled and the U.S. Food and Drug Administration began an investigation.

The U.S. Food and Drug Administration is preparing to release formal guidance on how medical device makers should handle reports about cyber vulnerabilities. J&J said it reviewed the matter with the FDA before sending the letter.

An early draft of that guidance, which was released in January for public comments, calls for device makers to work with security researchers, identify steps to mitigate risks, and provide patients with information about bugs so they can “make informed decisions” about device use.

The FDA declined comment on J&J’s handling of the vulnerability in the insulin pump, a medical device that patients attach to their bodies that injects insulin through catheters.

J&J executives told Reuters that they worked on the security problems with Jay Radcliffe, a diabetic and well-known medical-device hacking researcher with cyber security firm Rapid7 who reported vulnerabilities in the pump to the company in April.

For more on healthcare, watch Fortune’s video:

The Animas OneTouch Ping is sold with a wireless remote control that patients can use to order the pump to dose insulin so that they do not need access to the device itself, which is typically worn under clothing and could be awkward to reach.

Radcliffe said he identified ways for a hacker to spoof communications between the remote control and the OneTouch Ping insulin pump, potentially forcing it to deliver unauthorized insulin injections. Dosing a patient with too much insulin could cause hypoglycemia, or low blood sugar, which in extreme cases can be life threatening, said Brian Levy, chief medical officer with J&J’s diabetes unit.

The system is vulnerable because those communications are not encrypted, or scrambled, to prevent hackers from gaining access to the device, Radcliffe said.

Company technicians were able to replicate Radcliffe’s findings, confirming that a hacker could order the pump to dose insulin from a distance of up to 25 feet, Levy said. He said such attacks are difficult to pull off because they require specialized technical expertise and sophisticated equipment.

“We believe the OneTouch Ping system is safe and reliable. We urge patients to stay on the product,” Levy said.

J&J’s letter said that if patients were concerned, they could take several steps to thwart potential attacks. They include discontinuing use of a wireless remote control and programming the pump to limit the maximum insulin dose.

Radcliffe said he believed that OneTouch Ping users would be safe if they followed the steps outlined in the letter from J&J.

“They can give peace of mind to the patient or parent of a child using the device,” he said.

J&J Chief Information Security Officer Marene Allison said her team would make sure other J&J products do not have similar bugs.

Radcliffe said he found vulnerabilities in the Animas OneTouch Ping, but not the Animas Vibe line of insulin pumps.

Suzanne Schwartz, an FDA official responsible for reviewing bugs in medical devices, said in a statement that she encourages collaboration between researchers and device manufacturers to identify, remediate and alert the public to vulnerabilities.

“It enables all stakeholders to better address device safety with the interest of patient health in mind,” she said.

The FDA has said it knows of no cases where hackers have exploited cyber vulnerabilities to harm a patient.

The agency last year issued multiple warnings about cyber bugs in infusion pumps from Hospira, which has since been acquired by Pfizer Inc.

About the Authors
By Reuters
See full bioRight Arrow Button Icon
By Michelle Toh
See full bioRight Arrow Button Icon

Latest in Health

Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025

Most Popular

Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Fortune Secondary Logo
Rankings
  • 100 Best Companies
  • Fortune 500
  • Global 500
  • Fortune 500 Europe
  • Most Powerful Women
  • World's Most Admired Companies
  • See All Rankings
  • Lists Calendar
Sections
  • Finance
  • Fortune Crypto
  • Features
  • Leadership
  • Health
  • Commentary
  • Success
  • Retail
  • Mpw
  • Tech
  • Lifestyle
  • CEO Initiative
  • Asia
  • Politics
  • Conferences
  • Europe
  • Newsletters
  • Personal Finance
  • Environment
  • Magazine
  • Education
Customer Support
  • Frequently Asked Questions
  • Customer Service Portal
  • Privacy Policy
  • Terms Of Use
  • Single Issues For Purchase
  • International Print
Commercial Services
  • Advertising
  • Fortune Brand Studio
  • Fortune Analytics
  • Fortune Conferences
  • Business Development
  • Group Subscriptions
About Us
  • About Us
  • Press Center
  • Work At Fortune
  • Terms And Conditions
  • Site Map
  • About Us
  • Press Center
  • Work At Fortune
  • Terms And Conditions
  • Site Map
  • Facebook icon
  • Twitter icon
  • LinkedIn icon
  • Instagram icon
  • Pinterest icon

Latest in Health

death
Environmentclimate change
Meet ‘Green Death’: the burial practices for activists worried about climate change and carbon footprint
By Dorany Pineda and The Associated PressMay 2, 2026
9 hours ago
drinks
CommentaryFood and drink
We need a new way of thinking about drinking: Time to replace the ‘standard drink’ with advice people can actually use
By Justin KissingerMay 2, 2026
15 hours ago
Simple App Review (2026): Expert Tested and Reviewed
Healthmeal delivery
Simple App Review (2026): Expert Tested and Reviewed
By Emily PharesApril 30, 2026
2 days ago
Premium card perks are ‘designed to create a win-win-win for everyone’ but customers are paying with heavy annual fees and data
Personal FinancePersonal Finance Evergreen
Premium card perks are ‘designed to create a win-win-win for everyone’ but customers are paying with heavy annual fees and data
By Catherina GioinoApril 30, 2026
2 days ago
hoskins
Commentaryoffices
Gensler Co-Chair: Hot-desking was supposed to save money. It may be costing you your culture
By Diane HoskinsApril 30, 2026
3 days ago
raw milk
Politicsmilk
Risk of paralysis, bacteria, even death is no match for Americans’ thirst for raw milk
By Laura Ungar, Jonel Aleccia and The Associated PressApril 29, 2026
3 days ago

Most Popular

Scott Bessent on financial literacy: 'it drives me crazy' to see young men in blue-collar construction jobs playing the lottery
Personal Finance
Scott Bessent on financial literacy: 'it drives me crazy' to see young men in blue-collar construction jobs playing the lottery
By Fatima Hussein and The Associated PressMay 1, 2026
1 day ago
A Chick-fil-A worker got fired and then showed up behind the register to allegedly refund himself over $80,000 in mac and cheese
Law
A Chick-fil-A worker got fired and then showed up behind the register to allegedly refund himself over $80,000 in mac and cheese
By Catherina GioinoMay 1, 2026
1 day ago
Current price of oil as of May 1, 2026
Personal Finance
Current price of oil as of May 1, 2026
By Joseph HostetlerMay 1, 2026
1 day ago
Gen Z is rebelling against the economy with ‘disillusionomics,’ tackling near 6-figure debt by turning life into a giant list of income streams
Economy
Gen Z is rebelling against the economy with ‘disillusionomics,’ tackling near 6-figure debt by turning life into a giant list of income streams
By Jacqueline MunisMay 2, 2026
10 hours ago
China dominates the world's lithium supply. The U.S. just found 328 years' worth in its own backyard
North America
China dominates the world's lithium supply. The U.S. just found 328 years' worth in its own backyard
By Jake AngeloApril 30, 2026
2 days ago
Apple cofounder Ronald Wayne—whose stake would be worth up to $400 billion had he not sold it in 1976—says that at 91, he has no regrets
Success
Apple cofounder Ronald Wayne—whose stake would be worth up to $400 billion had he not sold it in 1976—says that at 91, he has no regrets
By Preston ForeApril 27, 2026
5 days ago

© 2026 Fortune Media IP Limited. All Rights Reserved. Use of this site constitutes acceptance of our Terms of Use and Privacy Policy | CA Notice at Collection and Privacy Notice | Do Not Sell/Share My Personal Information
FORTUNE is a trademark of Fortune Media IP Limited, registered in the U.S. and other countries. FORTUNE may receive compensation for some links to products and services on this website. Offers may be subject to change without notice.