Security Guides
Your device maker holds your data too: what Medtronic device patients should check after the 2026 breach
Medtronic notified more than 3.8 million people after unauthorized access to its corporate IT systems in April 2026, including SSNs and health-related information. What the company and state filings say, what it means for device safety, and what patients should do.
For: patients in the US who use a Medtronic medical device (a pacemaker, for example) and their families, and anyone who handles medical device patient data. This article is based on Medtronic's official statement and SEC filing, US state attorney general filings and the notice letter, and public information from US agencies (the FTC, the IRS and FDA regulations). It does not cover attack methods.
What device patients should do today
Don't change how you use your device; take concerns to your doctor
In its June 29, 2026 update, Medtronic reiterated that the incident did not impact the ability of any Medtronic device to operate safely and deliver intended therapy. There's no need to change device settings or skip appointments on your own because of the breach news. If you're worried about the device itself, talk to your doctor or clinic. The company asks physicians with questions to contact their local Medtronic representative.
Check your letter to see what was involved for you
The company began contacting people whose information may have been impacted on June 29, 2026. The notice letter filed with the California Attorney General is addressed to patients with a Medtronic medical device. Questions go to (888) 289-6806 (Monday to Friday, 9 a.m. to 9 p.m. ET).
Enroll in the free 24-month services before your deadline
The letter offers 24 months of complimentary credit monitoring, dark web monitoring and identity theft restoration services. Your enrollment deadline and activation code are printed on your own letter. Monitoring tells you after something happens, so pair it with the next step.
Protect the SSN: freeze credit at all three bureaus and get an IRS IP PIN
A credit freeze is free and has to be placed with each of Equifax, Experian and TransUnion. An IRS IP PIN is a six-digit number that prevents someone else from filing a tax return using your SSN. For the full US checklist, including children and family members, see what DentaQuest members should do.
Health-related information was involved, so read your benefit statements
The FTC lists a bill or Explanation of Benefits statement for services you didn't get, or a collector calling about medical debt you don't owe, as signs of medical identity theft. If you find one, it recommends requesting copies of your records from the providers and insurers involved and reporting errors to the provider in writing.
Verify any call or email about 'your device' by calling back
The exposed data includes contact and health-related information, so the fact that you use a device may be known. Messages like "your device needs an update, please verify your identity" or "we need your SSN for your warranty" sound credible because they know that much. The letter itself warns people to be cautious of unexpected emails, text messages or phone calls requesting personal information. Hang up and call a number you already have: your letter, your device ID card or your doctor's clinic (see what is phishing?).
Corporate IT systems = accessed
In the notice: name, contact info, date of birth, SSN, health-related info
Separate networks, per the company
Products (devices)
No impact identified to safe operation and therapy
Manufacturing and distribution
No impact identified
Hospital networks
Managed by the hospitals' own IT teams
What patients do
Leave the device alone → protect the list side (SSN, contact info) with freezes and call-backs
What happened (from Medtronic's statements and state filings)
The following is taken from Medtronic's official statement (April 24, 2026, updated June 29) and SEC filing, the notice letter filed with the California Attorney General and the Indiana Attorney General's breach list.
April 13, 2026
Per the notice letter, the date an unauthorized actor began accessing certain corporate IT systems.April 15
The company becomes aware of unusual activity on certain corporate IT systems and launches an investigation with third-party cybersecurity experts.April 19
Per the notice letter, the last day of the access period.April 24
The company publishes its statement and attaches it to a Form 8-K filed with the SEC the same day. It says it has not identified any impact to its products, patient safety, connections to customers, manufacturing and distribution, or financial reporting systems.June 29
The company updates its statement and begins contacting affected individuals. The Indiana and California listings carry the same date.
- Company
- Medtronic Inc. (US medical device maker; its parent Medtronic plc files with the SEC)
- What was accessed
- Data in certain corporate IT systems
- Information involved (notice letter)
- Name, contact information, date of birth, Social Security number, health-related information
- Why it held the data (notice letter)
- For patients with a Medtronic device, collected to provide important product-related updates and to meet legal obligations
- No impact identified
- Product security; patient safety, including the ability of any device to operate safely and deliver therapy; manufacturing and distribution; ability to meet patient and customer needs
- Publication
- The company says it has no evidence the information was posted publicly or exposed on the Internet
- Company response
- Containment, incident response protocols, outside experts, additional safeguards. It says it has worked with law enforcement and is notifying relevant regulatory authorities
- Contact
- (888) 289-6806 (Monday to Friday, 9 a.m. to 9 p.m. ET)
How to read the numbers and the geography
We use 3,834,294, the figure on the Indiana Attorney General's list. Larger numbers circulate online, but they come from the party claiming to have taken the data, and the company has not confirmed them. The company has also not said whether anyone outside the US was affected. The notices and filings we found are with US state authorities, and we did not find a notice aimed at device users in Japan.
Why does a device maker have your SSN?
Plenty of patients will ask why a company that isn't their hospital has their Social Security number. The notice letter itself answers part of it: patient data is collected to provide important product-related updates and to meet legal obligations.
One piece of that background is US device tracking. FDA regulations (21 CFR Part 821) cover devices subject to an FDA order that meet criteria such as being implanted for more than a year, or being likely to cause serious adverse health consequences if they fail. For those, the manufacturer must be able to trace the device from its factory to the patient, so that remedies such as recalls and patient notification work. The required records include the patient's name, address, phone number and Social Security number (if available), along with the prescribing physician.
That is a general description of the rules. The company has not said which records were in the affected systems. But the picture for patients is clear.
The patient list, outside the device
- Name, address, phone number (device registration, ID card, warranty and support)
- Date of birth and SSN (identity and legal records)
- Health-related information (which device you use, for example)
- If exposed, usable for impersonation and scams that sound informed
The device itself
- How the device operates and delivers therapy
- Device weaknesses are handled through the maker's product security information and your clinic
- Here, the company says it has not identified impact to safe operation
- An exposed patient list does not, on its own, give anyone control of a device
This site's view: before unregistering, lock the list
The FDA rules let a patient refuse to release their name, SSN and other identifying information for tracking (21 CFR 821.55). Whether to withdraw is a decision to make with your doctor, not on the breach alone. Tracking exists to get recalls and safety notices to you, and the risk of a notice not reaching you, unlike the risk of an exposed SSN, can't be covered by a freeze or a PIN.
Instead, deal with each item on the list. The SSN: make it useless with a credit freeze and an IRS IP PIN. Contact and health-related information: treat any contact that mentions your device as something to verify. Registration details: keep them current whenever you move or change phone numbers. Remembering that device safety and patient-list safety go through different doors keeps you from panicking.
For makers and companies holding patient data
The company says its product, manufacturing and corporate IT networks are separate. That's an important design for device safety, yet the harm to patients happened on the side of the patient list in corporate IT. For patient data that lives outside the product, three things are worth checking.
Count where patient data lives outside the product
Device registration, warranty, support lines, app accounts, clinical studies, marketing. List where patient data including SSNs or diagnoses sits in places that product security reviews don't cover. The approach is the same as a security inventory: start by writing down where it is, how many records, and who can see it.
Separate where the SSN is needed from where it isn't
Split legally required records from work such as support calls that can be done with a name and device serial number, and reduce the number of systems that hold SSNs. Data you don't hold can't leak.
Prepare the answer to 'is my device safe?' in advance
The company's statement addressed impact to products and patient safety from the very first disclosure. Organizations with patient-facing products should assume that after a corporate IT incident, the first thing patients want to know is whether their device is safe, and be ready to explain the basis for the answer (such as network separation). For the overall approach, see the minimum security baseline for organizations.
Sources (public record)
The facts in this article are based on the public information below. Figures claimed by the party said to have taken the data, and outside estimates, are not used.
- Medtronic, "Medtronic statement on unauthorized system access" (April 24, 2026, updated June 29) — news.medtronic.com
- Medtronic plc, Form 8-K (April 24, 2026, Exhibit 99.1) — sec.gov
- California Attorney General, Medtronic Inc. breach listing (sample notice letter, June 29, 2026) — oag.ca.gov
- Indiana Attorney General, "Data Breach Year to Date Report 2026" (Medtronic Inc: 3,834,294 affected; notices sent June 29, 2026) — in.gov
- Medtronic, "Product security" (product security information and contacts) — medtronic.com
- Code of Federal Regulations, 21 CFR Part 821 (Medical Device Tracking: 821.1, 821.25, 821.55) — ecfr.gov
- Federal Trade Commission, "What To Know About Medical Identity Theft" — consumer.ftc.gov / "Credit Freezes and Fraud Alerts" — consumer.ftc.gov / IdentityTheft.gov
- Internal Revenue Service, "Get an identity protection PIN" — irs.gov
Update history
2026-09-30: First version, based on Medtronic's statement (April 24, 2026, updated June 29) and SEC filing, public information from the California and Indiana attorneys general, FTC and IRS guidance, and FDA regulations. We will update it if the company publishes more.
Read next
- The full US checklist (freezes, IP PIN, children): The DentaQuest breach (SSNs and Medicaid numbers)
- The other front door when a number leaks: The AssuranceAmerica breach (driver's license numbers)
- A notice from a company you never dealt with: The Aesto Health breach (a medical records archive)
- Scams that follow a breach: What is phishing?
- Other 2026 incidents: List of breaches and cyberattacks (Japan and worldwide)
- For operators: The minimum security baseline for organizations / Security inventory
FAQ
QWhat happened in the Medtronic data breach?
On April 24, 2026, Medtronic said an unauthorized party had accessed data in certain Medtronic corporate IT systems, and attached the same statement to a Form 8-K filed with the US Securities and Exchange Commission that day. According to its notice letter, the company became aware of unusual activity on certain corporate IT systems on April 15, and its investigation found that an unauthorized actor accessed them from April 13 to April 19, 2026.
QHow many people were affected?
The Indiana Attorney General's 2026 data breach list shows 3,834,294 people affected in total for Medtronic Inc (90,889 of them Indiana residents), with notices sent on June 29, 2026. The company's sample notice letter says about 12,054 Rhode Island residents were identified.
QWhat information was exposed?
According to the notice letter filed with the California Attorney General: name, contact information, date of birth, Social Security number and health-related information. The company says it has no evidence that any of that information was posted publicly or exposed on the Internet.
QIs my implanted device (a pacemaker, for example) still safe?
Medtronic says it has not identified any impact to product security or patient safety, including the ability of any Medtronic device to operate safely and deliver intended therapy. It says the networks supporting its corporate IT systems, its products and its manufacturing and distribution operations are separate, and that hospital customer networks are separate from Medtronic IT networks. If you have concerns about your device, don't change how you use it on your own; talk to your doctor.
QWhy does a device maker have my Social Security number?
The notice letter says that, for patients with a Medtronic medical device, the company collects data to provide important product-related updates and to meet its legal obligations. In general, US FDA device tracking rules require manufacturers of certain devices subject to an FDA order, such as some implanted devices, to be able to trace them to the patient; the required records include the patient's name, address, phone number and Social Security number (if available). The company has not said which records were in the affected systems.
QI got a notice. What should I do?
Enroll in the 24 months of complimentary credit monitoring, dark web monitoring and identity theft restoration services before the deadline in your letter, place a credit freeze with Equifax, Experian and TransUnion, get an IRS IP PIN, and review your Explanation of Benefits statements for care you didn't receive. The call center is (888) 289-6806, Monday to Friday, 9 a.m. to 9 p.m. ET.
QAre people outside the US affected, for example in Japan?
Medtronic has not said whether people outside the US were affected. The notices and filings we found are with US state authorities, and we did not find a notice aimed at device users in Japan. The pattern, though, applies anywhere: device makers hold patient data, and scams that mention your device deserve a call-back check.