EBR Systems Clears FDA Cybersecurity Review With No Recall Required

The FDA has cleared EBR Systems' cybersecurity review with no recall required and a low-risk 'Controlled Risk' classification — removing the key regulatory overhang from the WiSE cardiac device investment case.
By Josua Ferreira -
  • The FDA has formally classified EBR's cybersecurity incident as 'Controlled Risk' under its 2016 Postmarket Cybersecurity Guidance, the lowest-severity tier, and confirmed no recall or field corrective action is required.
  • No safety or performance impact has been identified in any fielded WiSE CRT System, validating the device's integrity throughout the incident and review period.
  • EBR has already implemented strengthened credential management, anti-phishing training, and enhanced endpoint monitoring, with product-level cybersecurity hardening continuing through established quality processes.
  • The cybersecurity resolution clears the path for EBR's most consequential near-term catalyst: a CMS National Coverage Determination review initiated 3 June 2026, with a projected Final NCD date of 3 March 2027 that could establish uniform national Medicare coverage.
  • WiSE commercial momentum continued through the review period, with 46 implants completed in Q2 2026, cumulative totals reaching 117 across 30 activated hospital accounts, and more than half of those accounts recording three or more procedures.
Summarise with AI:

FDA clears EBR’s cybersecurity review with no recall required

EBR Systems has received a favourable outcome from the U.S. Food and Drug Administration (FDA) following a cybersecurity incident first disclosed to the ASX on 15 April 2026. The FDA reviewed EBR’s completed cybersecurity risk assessment and agreed that no field corrective action or recall relating to the WiSE® System is warranted.

The FDA also advised that the incident aligns with a “Controlled Risk” classification under Section VI of the FDA’s 2016 guidance, Postmarket Management of Cybersecurity in Medical Devices. Based on information reviewed to date, no evidence has been identified of any impact to fielded WiSE CRT System safety or performance.

The announcement closes out a review process that began when EBR became aware of the incident in February 2026. The company promptly contained the incident, investigated the potential impact, notified relevant regulatory authorities, and commissioned independent cybersecurity specialists to complete a formal risk assessment.

EBR Systems Cybersecurity Incident Resolution Timeline

What the FDA’s “Controlled Risk” classification means for investors

As medical devices have become increasingly connected and software-enabled, the FDA requires manufacturers to actively manage cybersecurity risk after a device receives market approval. This postmarket framework provides a structured way to assess and respond to incidents, with outcomes tiered according to the severity of the risk identified.

A “Controlled Risk” classification sits at the lower end of that risk spectrum. In practical terms, it indicates that the identified threat does not require immediate corrective action in the field. The regulator’s agreement with EBR’s own assessment also validates the methodology the company applied and confirms the FDA is satisfied with EBR’s response to the incident.

Why no recall is the key investor takeaway

A device recall or field corrective action carries meaningful consequences: direct financial cost, reputational damage, and potential disruption to commercial operations. None of those apply here. The FDA’s determination that no recall is warranted effectively removes the most adverse outcome that investors might have anticipated when the incident was first disclosed.

EBR’s handling of the process reflects strong regulatory discipline. The company acted promptly to contain the incident, engaged independent cybersecurity specialists, completed a formal risk assessment, and maintained active communication with the FDA throughout.

Remediation underway and regulatory engagement continues

EBR has already implemented a series of corporate cybersecurity improvements in response to the incident, including:

  • Strengthened credential management controls
  • Anti-phishing training
  • Enhanced endpoint monitoring

In addition to these corporate-level measures, product cybersecurity remediation and hardening activities are continuing through EBR’s established quality and regulatory processes. The company has confirmed it will continue providing progress updates to the FDA as requested.

John McCutcheon, President & Chief Executive Officer

“Patient safety, device integrity and responsible postmarket management remain EBR’s highest priorities. Following submission of EBR’s completed cybersecurity risk assessment, the FDA has advised that the incident aligns with a Controlled Risk classification and has agreed with EBR’s response. We continue to focus on best practices for cybersecurity through our established quality and regulatory processes.”

Investment case intact as EBR moves forward

The resolution of this cybersecurity review removes a near-term regulatory overhang that has been present since the 15 April 2026 ASX disclosure. The incident is now formally classified, the FDA is satisfied with EBR’s response, and no recall risk remains outstanding.

For investors less familiar with the company, EBR Systems describes itself as the developer of the world’s only wireless cardiac pacing device for heart failure. Its WiSE technology is designed for patients requiring Cardiac Resynchronisation Therapy (CRT), stimulating the heart’s left ventricle without the need for a coronary sinus lead. WiSE is currently available for sale in the US, while remaining an investigational device in most other markets.

Beyond the cybersecurity resolution, a National Coverage Determination review formally initiated by CMS on 3 June 2026 represents the most consequential near-term catalyst for EBR, with a projected Final NCD date of 3 March 2027 that could establish uniform national Medicare coverage for eligible heart failure patients.

With FDA engagement described as constructive, cybersecurity controls being actively strengthened, and no safety or performance impact identified in fielded devices, the company’s commercial and regulatory priorities appear to remain on track.

The WiSE commercial rollout has continued to build momentum in parallel with the cybersecurity review, with 46 implants completed in Q2 2026, cumulative totals reaching 117 across 30 activated hospital accounts, and more than half of those accounts recording three or more procedures.

The key resolution facts are summarised below.

Detail Information
Incident first identified February 2026
ASX disclosure date 15 April 2026
FDA classification Controlled Risk (Section VI, FDA 2016 Postmarket Cybersecurity Guidance)
Recall or field corrective action required None
Safety or performance impact identified None

Don’t Miss the Next Healthcare Breakthrough on the ASX

Big News Blast delivers FREE breaking ASX healthcare news directly to your inbox within minutes of release, complete with in-depth analysis already done for you. Over 20,000 subscribers rely on it to stay ahead of market-moving announcements. Click the “Free Alerts” button to start receiving real-time coverage the moment news breaks.


Frequently Asked Questions

What does the FDA's 'Controlled Risk' classification mean for EBR Systems?

A 'Controlled Risk' classification under the FDA's 2016 Postmarket Cybersecurity Guidance indicates the identified cybersecurity threat sits at the lower end of the risk spectrum and does not require immediate corrective action in the field — in EBR's case, the FDA confirmed no recall or field corrective action is warranted.

Has the EBR Systems cybersecurity incident affected the WiSE device's safety or performance?

No. Based on information reviewed to date, the FDA and EBR have identified no evidence of any impact to the safety or performance of fielded WiSE CRT Systems.

What cybersecurity improvements has EBR Systems implemented following the incident?

EBR has implemented strengthened credential management controls, anti-phishing training, and enhanced endpoint monitoring at the corporate level, with product-level cybersecurity remediation and hardening activities continuing through the company's established quality and regulatory processes.

What is the next major catalyst for EBR Systems after the cybersecurity resolution?

The most consequential near-term catalyst is a National Coverage Determination review formally initiated by CMS on 3 June 2026, with a projected Final NCD date of 3 March 2027 that could establish uniform national Medicare coverage for eligible heart failure patients using the WiSE system.

How is the WiSE commercial rollout progressing in 2026?

EBR completed 46 WiSE implants in Q2 2026, bringing cumulative totals to 117 procedures across 30 activated hospital accounts, with more than half of those accounts having recorded three or more procedures — indicating accounts are moving from initial trial to routine clinical use.

Josua Ferreira
By Josua Ferreira
Partnership Director
Josua Ferreira holds a Bachelor of Commerce in Marketing and Advertising and brings a background in publication, business development, and ASX market storytelling. He has worked with listed companies across the resource sector and broader market, combining sharp commercial instincts with a genuine commitment to keeping investors informed.
Learn More
Companies Mentioned in Article

Breaking ASX Alerts Direct to Your Inbox

Join +20,000 subscribers receiving alerts.

Join thousands of investors who rely on StockWire X for timely, accurate market intelligence.

About the Publisher