FDA clears EBR’s cybersecurity review with no recall required
EBR Systems has received a favourable outcome from the U.S. Food and Drug Administration (FDA) following a cybersecurity incident first disclosed to the ASX on 15 April 2026. The FDA reviewed EBR’s completed cybersecurity risk assessment and agreed that no field corrective action or recall relating to the WiSE® System is warranted.
The FDA also advised that the incident aligns with a “Controlled Risk” classification under Section VI of the FDA’s 2016 guidance, Postmarket Management of Cybersecurity in Medical Devices. Based on information reviewed to date, no evidence has been identified of any impact to fielded WiSE CRT System safety or performance.
The announcement closes out a review process that began when EBR became aware of the incident in February 2026. The company promptly contained the incident, investigated the potential impact, notified relevant regulatory authorities, and commissioned independent cybersecurity specialists to complete a formal risk assessment.
When big ASX news breaks, our subscribers know first
What the FDA’s “Controlled Risk” classification means for investors
As medical devices have become increasingly connected and software-enabled, the FDA requires manufacturers to actively manage cybersecurity risk after a device receives market approval. This postmarket framework provides a structured way to assess and respond to incidents, with outcomes tiered according to the severity of the risk identified.
A “Controlled Risk” classification sits at the lower end of that risk spectrum. In practical terms, it indicates that the identified threat does not require immediate corrective action in the field. The regulator’s agreement with EBR’s own assessment also validates the methodology the company applied and confirms the FDA is satisfied with EBR’s response to the incident.
Why no recall is the key investor takeaway
A device recall or field corrective action carries meaningful consequences: direct financial cost, reputational damage, and potential disruption to commercial operations. None of those apply here. The FDA’s determination that no recall is warranted effectively removes the most adverse outcome that investors might have anticipated when the incident was first disclosed.
EBR’s handling of the process reflects strong regulatory discipline. The company acted promptly to contain the incident, engaged independent cybersecurity specialists, completed a formal risk assessment, and maintained active communication with the FDA throughout.
Remediation underway and regulatory engagement continues
EBR has already implemented a series of corporate cybersecurity improvements in response to the incident, including:
- Strengthened credential management controls
- Anti-phishing training
- Enhanced endpoint monitoring
In addition to these corporate-level measures, product cybersecurity remediation and hardening activities are continuing through EBR’s established quality and regulatory processes. The company has confirmed it will continue providing progress updates to the FDA as requested.
John McCutcheon, President & Chief Executive Officer
“Patient safety, device integrity and responsible postmarket management remain EBR’s highest priorities. Following submission of EBR’s completed cybersecurity risk assessment, the FDA has advised that the incident aligns with a Controlled Risk classification and has agreed with EBR’s response. We continue to focus on best practices for cybersecurity through our established quality and regulatory processes.”
Investment case intact as EBR moves forward
The resolution of this cybersecurity review removes a near-term regulatory overhang that has been present since the 15 April 2026 ASX disclosure. The incident is now formally classified, the FDA is satisfied with EBR’s response, and no recall risk remains outstanding.
For investors less familiar with the company, EBR Systems describes itself as the developer of the world’s only wireless cardiac pacing device for heart failure. Its WiSE technology is designed for patients requiring Cardiac Resynchronisation Therapy (CRT), stimulating the heart’s left ventricle without the need for a coronary sinus lead. WiSE is currently available for sale in the US, while remaining an investigational device in most other markets.
Beyond the cybersecurity resolution, a National Coverage Determination review formally initiated by CMS on 3 June 2026 represents the most consequential near-term catalyst for EBR, with a projected Final NCD date of 3 March 2027 that could establish uniform national Medicare coverage for eligible heart failure patients.
With FDA engagement described as constructive, cybersecurity controls being actively strengthened, and no safety or performance impact identified in fielded devices, the company’s commercial and regulatory priorities appear to remain on track.
The WiSE commercial rollout has continued to build momentum in parallel with the cybersecurity review, with 46 implants completed in Q2 2026, cumulative totals reaching 117 across 30 activated hospital accounts, and more than half of those accounts recording three or more procedures.
The key resolution facts are summarised below.
| Detail | Information |
|---|---|
| Incident first identified | February 2026 |
| ASX disclosure date | 15 April 2026 |
| FDA classification | Controlled Risk (Section VI, FDA 2016 Postmarket Cybersecurity Guidance) |
| Recall or field corrective action required | None |
| Safety or performance impact identified | None |
Don’t Miss the Next Healthcare Breakthrough on the ASX
Big News Blast delivers FREE breaking ASX healthcare news directly to your inbox within minutes of release, complete with in-depth analysis already done for you. Over 20,000 subscribers rely on it to stay ahead of market-moving announcements. Click the “Free Alerts” button to start receiving real-time coverage the moment news breaks.
