• Skip to primary navigation
  • Skip to main content
  • Skip to primary sidebar
  • Skip to footer

MassDevice

The Medical Device Business Journal — Medical Device News & Articles | MassDevice

  • Special Reports
  • Technologies
    • Artificial Intelligence (AI)
    • Cardiovascular
    • Orthopedics
    • Neurological
    • Diabetes
    • Surgical Robotics
  • Business & Finance
    • Wall Street Beat
    • Earnings Reports
    • Funding Roundup
    • Mergers & Acquisitions
    • Initial Public Offering (IPO)
    • Legal News
    • Personnel Moves
    • Medtech 100 Stock Index
  • Regulatory
    • Food & Drug Administration (FDA)
    • Recalls
    • 510(k)
    • Pre-Market Approval (PMA)
    • MDSAP
    • Clinical Trials
  • Resources
    • About MassDevice
    • Leadership in Medtech
    • Manufacturers & Suppliers Search
    • MedTech100 Index
    • Videos
    • Webinars
    • Whitepapers
    • Voices
    • In-Depth Coverage
    • Latest News
  • Attend DeviceTalks
    • Events
      • DeviceTalks Minnesota – May 4
      • DeviceTalks Boston – May 27–28
      • DeviceTalks West
      • DeviceTalks Tuesdays
    • DeviceTalks Podcast Network
      • DeviceTalks Weekly
      • AbbottTalks
      • Boston ScientificTalks
      • DeviceTalks AI
      • IntuitiveTalks
      • MedtechWOMEN Talks
      • MedtronicTalks
      • Neuro Innovation Talks
      • Ortho Innovation Talks
      • Structural Heart Talks
      • StrykerTalks
  • Advertise
  • Subscribe
Home » Government warns on cybersecurity issues with Philips’ e-Alert MRI monitoring system

Government warns on cybersecurity issues with Philips’ e-Alert MRI monitoring system

March 29, 2022 By Sean Whooley

PhilipsThe U.S. Cyber Security & Infrastructure Security Agency (CISA) today issued a notice regarding the e-Alert system from Royal Philips (NYSE:PHG).

CISA called attention to the e-Alert MRI system monitoring platform (version 2.7 and prior) and a potential vulnerability related to “missing authentication for critical function.”

According to the CISA notice, successful exploitation of the vulnerability — in which the software does not perform any authentication for critical system functionality — could allow an unauthorized actor to remotely shut down the system if on the healthcare facility’s network.

Philips plans a new release to remediate the vulnerability before July 2022. For interim mitigation to the vulnerability, Philips recommends that users operate all Philips deployed and supported products within Philips authorized specifications, including physical and logical controls, with only authorized personnel permitted to access the network and devices connected to it.

CISA recommends that users minimize network exposure for all control system devices and/or systems, ensuring that they are not accessible from the internet. Users should also locate control system networks and remote devices behind firewalls and isolate them from the business network.

When remote access is required, CISA said to use secure methods, such as virtual private networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most current version available. VPN is only as secure as its connected devices, CISA noted.

A Philips spokesperson told MassDevice that the company has received no reports of exploitation of the vulnerability and, as the e-Alert hardware is not a medical device, there is no risk to patient safety.

“Philips is a committed leader in medical device cybersecurity,” the spokesperson wrote in a statement. “As part of our global Product Security Policy, the company conducts extensive ongoing analysis of our products, often in collaboration with customers and researchers, to identify and address potential vulnerabilities.”

Filed Under: Business/Financial News, Featured, Health Technology, Imaging, Recalls, Regulatory/Compliance, Software / IT Tagged With: Cybersecurity, Philips, Royal Philips

More recent news

  • Citi downgrades Boston Scientific as cyberattack recovery compounds competitive pressure
  • Autonomix taps former Medtronic FDA counsel head for board of directors
  • Medtronic strengthens robotic surgery position with Cornerstone deal, analysts say
  • Science Corp. names president as it looks to roll out vision-restoring implant
  • Mindray looks to fill hospital ventilator gap left by Philips’ exit

About Sean Whooley

Sean Whooley is a senior editor who mainly produces work for MassDevice, Medical Design & Outsourcing and Drug Delivery Business News. He received a bachelor's degree in multiplatform journalism from the University of Maryland, College Park. You can connect with him on LinkedIn or email him at [email protected].

Primary Sidebar

Cart

“md
EXPAND YOUR KNOWLEDGE AND STAY CONNECTED
Get the latest med device regulatory, business and technology news.

DeviceTalks Weekly

See More >
MDO ad
MDO ad

Footer

MASSDEVICE MEDICAL NETWORK

DeviceTalks
Drug Delivery Business News
Medical Design & Outsourcing
Medical Tubing + Extrusion
Drug Discovery & Development
Pharmaceutical Processing World
MedTech 100 Index
R&D World
Medical Design Sourcing

DeviceTalks Webinars, Podcasts, & Discussions

Attend our Monthly Webinars
Listen to our Weekly Podcasts
Join our DeviceTalks Tuesdays Discussion

MASSDEVICE

Subscribe to MassDevice E-Newsletter
Advertise with us
About
Contact us

Copyright © 2026 · Arrowfly LLC and its licensors. All rights reserved.
The material on this site may not be reproduced, distributed, transmitted, cached or otherwise used, except with the prior written permission of Arrowfly.

Privacy Policy