Medtronic CareLink 2090 Programmer Recalled for Cyber Vulnerabilities
Medtronic is recalling 23,180 CareLink 2090 Programmer devices worldwide due to improper access control and cleartext transmission of sensitive information.
What this means for you
Real risk of harm even if no illness or injury has been reported yet. Stop using the product and follow the agency's guidance.
Our severity reasoning: The recall involves a medical device with cyber vulnerabilities that pose a risk of harm (data breach/unauthorized access) but the source text does not report any actual injuries, illnesses, or deaths, fitting the 'High' criteria for risk-of-harm products where injury has not yet been reported.
Plain-English summary
Medtronic Inc. is recalling 23,180 units of the CareLink 2090 Programmer, a device used to interrogate and program Medtronic and Vitatron implantable devices such as pacemakers, ICDs, and CRTs. The recall is due to the discovery of two primary cyber vulnerabilities in the associated Medtronic Conexus Telemetry system: improper access control and the cleartext transmission of sensitive information.
The affected devices have been distributed worldwide, including in the United States, Puerto Rico, and numerous countries across the Americas, Europe, Asia, Africa, and Oceania. The recall covers all serial numbers of Product Number 2090.
Consumers and healthcare providers should contact Medtronic for further instructions on how to address these vulnerabilities. The source text does not specify a particular consumer action beyond the recall notification.
The recalled product
- Product
- Medtronic CareLink 2090 Programmer. Used to interrogate and program Medtronic and Vitatron implantable devices, such as pacemaker/ICD/CRT.
- Affected units
- 23,180
Is your product affected?
Check your packaging against the codes below. If any of them match, the product is part of this recall.
Lot numbers (20)
- Product Number 2090
- All Serial Numbers
- Known Model Numbers: a. Model Number 2090
- GTIN (Lot Numbers): 00721902546341 (PKK002840R)
- 00721902246234 (PKK012608R)
- 00721902246234 (PKK013358R)
- 00721902569517 (PKK017436R)
- 00613994580955 (PKK204009R)
- 00643169537828 (PKK001072R)
- 00613994175397 (PKK001076R)
- 00613994175397 (PKK001135R)
- 00613994175397 (PKK001172R)
- 00613994175120 (PKK001321R)
- 00613994175106 (PKK001322R)
- 00721902246234 (PKK001324R)
- 00721902246227 (PKK001327R)
- 00613994175212 (PKK001328R)
- 00613994175106 (PKK001331R)
- 00643169537828 (PKK001332R)
- 00721902246234 (PKK001335R)
Distribution
Part of a larger recall action
This product is one of 2 recalled by Medtronic Inc., Cardiac Rhythm and Heart Failure (CRHF) under a single FDA (Devices) recall action. The agency files each product separately, so the size of the action is not visible from this page alone.
See all 2 products in this recall →Related recalls
Same manufacturer · Medtronic Inc., Cardiac Rhythm and Heart Failure (CRHF)
See all →- CriticalMedtronic CRT-D Defibrillators: Rare Energy Output Failure Risk During Therapy
FDA (Devices) · 2023-06-28
- SevereMedtronic Implantable Cardioverter Defibrillators Recalled for Reduced Therapy Output
FDA (Devices) · 2023-06-28
- SevereMedtronic Implantable Defibrillators Recalled for Potential Therapy Delivery Failure
FDA (Devices) · 2023-06-28
- SevereImplantable Cardioverter Defibrillators at Risk of Reduced Energy Output
FDA (Devices) · 2023-06-28
- SevereMedtronic Implantable Cardioverter Defibrillator may lose energy output during therapy
FDA (Devices) · 2023-06-28
Same hazard · cyber vulnerability
See all →- HighMedtronic CareLink Encore Programmer Recalled for Cyber Vulnerabilities
FDA (Devices) · 2020-03-25