Medical Device Data Management Software Affected by Unauthorized Service Credential Access
Service credentials for BD EpiCenter Data Management System were accessed by an unauthorized actor. This creates a risk of unauthorized access to the software and associated data until credentials are updated.
What this means for you
Real risk of harm even if no illness or injury has been reported yet. Stop using the product and follow the agency's guidance.
Our severity reasoning: This is a Class II FDA-regulated medical device with a cybersecurity vulnerability affecting data access and integrity. Although no unauthorized access incidents or patient harm have been reported, the credential compromise represents a risk-of-harm situation qualifying for Score 3 as a risk-of-harm product without reported injury.
Plain-English summary
BD EpiCenter Data Management System (Version 440981) has been recalled due to a cybersecurity vulnerability. According to the manufacturer, product service credentials used by BD technical support teams were accessed by an unauthorized actor. This creates a risk of unauthorized access to the software.
Until these credentials are updated, there is a potential risk of unauthorized access that may impact the confidentiality, integrity, and availability of the software and associated data. BD is recommending that users update their product service credentials.
Approximately 7,974 units of the software have been distributed worldwide, including 2,517 in the United States and 5,457 units internationally. Users should contact BD technical support immediately to obtain updated credentials and implement security measures to prevent unauthorized access to their systems.
The recalled product
- Product
- BD EpiCenter Data Management System, Multi User Software Version or Model: 440981 Catalog Number: 440981
- Manufacturer
- Becton Dickinson & Co.
Is your product affected?
Check your packaging against the codes below. If any of them match, the product is part of this recall.
Lot numbers (20)
- Catalog No: 440981
- UDI-DI: 00382904409814
- Serial Numbers: 6GF3TD2
- 2MJHML1
- 697JFF3
- HSB9WV1
- YL00QYF9
- GMWYLN2
- 1TR5JL2
- GD6XCP2
- HGKCXQ2
- FH62RP2
- GDBZCP2
- GD92DP2
- CPQ77X2
- H3JQ3Y2
- 20HJ4Z2
- 5D2BSZ2
- DXMWG13
- DXP1H13
Distribution
Distributed nationwide across the United States.
Part of a larger recall action
This product is one of 13 recalled by Becton Dickinson & Co. under a single FDA (Devices) recall action. The agency files each product separately, so the size of the action is not visible from this page alone.
See all 13 products in this recall →Related recalls
Same manufacturer · Becton Dickinson & Co.
See all →- ModerateBD GasPak EZ Campy Pouch System Recall for Below-Specification Gas Production
FDA (Devices) · 2026-05-06
- ModerateBD GasPak EZ CO2 Pouch System gas generating sachets underperforming
FDA (Devices) · 2026-05-06
- ModerateLaboratory cuvette arrays recalled over barcodes the analyser cannot read
FDA (Devices) · 2025-11-19
- HighAutomated microbiology systems recalled after service credentials were accessed by unauthorized actor
FDA (Devices) · 2025-10-29
- HighBlood culture systems recalled after service credentials were accessed by unauthorized actor
FDA (Devices) · 2025-10-29
Same hazard · unauthorized access
See all →- HighBiometric Firearm Safes Recalled Due to Unauthorized-Access Hazard
CPSC · 2026-07-09
- HighFirearm chamber locks recalled because they can be forcibly removed
CPSC · 2025-09-04
- HighMUSE 5 Cardiovascular Systems Recall Administrator Credential Access
FDA (Devices) · 2025-06-18
- SevereLifeShield Infusion Safety Software Recalled for Drug Library Defects
FDA (Devices) · 2025-05-21
- HighGE Healthcare Cardiology CA1000 Security Vulnerability Could Allow Patient Data Access
FDA (Devices) · 2025-04-09