
Imagine you have a case this week.
The implant works.
The surgeon is ready.
The hospital is ready.
The patient is scheduled.
There’s just one problem.
Your company can’t ship the product.
That’s essentially the situation one of the largest medical device companies in the world found itself dealing with last week.
And the more I dug into what happened at Boston Scientific, the more I realized this story is a lot bigger than one cyberattack.
Because Boston Scientific isn’t the first major MedTech company this has happened to this year.
Let’s get into it.
INDUSTRY THROUGH A REP’S LENS
The device doesn’t have to be hacked.
On August 25, Boston Scientific identified a cybersecurity incident that caused a global disruption to parts of its operations.
The company brought in CrowdStrike and other cybersecurity experts and began taking systems offline and restoring them.
The important distinction here is what was actually affected.
Boston Scientific says there is no known impact to implantable-device function and no evidence that its affected network environment created additional cybersecurity risk for hospital networks using Boston Scientific devices.
The attack appears to have been limited to certain internal, on-premise IT infrastructure.
But those systems do a lot.
Boston Scientific said the disruption affected its ability to manufacture products and process and ship customer orders. Customers could continue submitting electronic orders, but those orders were being placed into a queue until fulfillment capabilities returned.
As of September 3, the company says it has restored shipping capabilities for the majority of products at its major distribution centers globally and has begun working through the backlog. Its investigation is still ongoing. (Boston Scientific)
Boston Scientific says implantable cardiac rhythm devices themselves continue to function.
Previously established remote monitoring also wasn’t affected.
But new remote-monitoring activations were.
For certain newly implanted cardiac devices, new home-monitoring communicators couldn’t be activated. Newly implanted insertable cardiac monitors could record episodes but couldn’t pair with the patient’s remote-monitoring phone until systems were restored.
Then there’s the cardiac piece.
In other words, nobody had to “hack the pacemaker” for a cyberattack to interfere with part of the infrastructure surrounding a newly implanted patient. (Boston Scientific)
I think that’s the more interesting story.
We’ve seen this movie before.
Six months ago, Stryker experienced a cyberattack that disrupted its global Microsoft environment.
Stryker’s products weren’t compromised either.
But order processing was.
Manufacturing was.
Shipping was.
And according to reporting at the time, some patient-specific procedures were rescheduled when personalized inventory couldn’t be delivered. (Stryker)
Stryker later disclosed that the disruption resulted in idle production time and additional manufacturing and supply-chain costs. Its SEC filings also described employees losing access to IT systems and the company relying on manual processes and other workarounds during the disruption. (SEC)
Then look at the rest of 2026.
Medtronic discovered unauthorized access to corporate systems in April.
West Pharmaceutical Services experienced a material cyberattack in May involving encrypted systems and stolen data and temporarily took systems offline globally.
iRhythm disclosed a social-engineering attack in June involving patient and proprietary data stored in third-party business applications.
Abbott investigated two separate cyber incidents this summer.
And just this week, Novocure disclosed a cyberattack that exposed records involving more than 1,400 U.S. patients. (Medtronic News)
Not all of these incidents were the same.
That’s important.
Medtronic reported no impact to products, manufacturing, distribution or patient safety.
iRhythm also reported no impact to its devices, clinical systems, manufacturing or distribution.
So I don’t think the conclusion is that every MedTech cyberattack creates a patient-care crisis.
The pattern is simpler.
Medical device companies have become incredibly dependent on the digital infrastructure surrounding the product.
Manufacturing. Inventory. Orders. Shipping.
Remote monitoring. Patient-specific products. Customer communication.
And the thousands of people in the field trying to keep all of it moving.
A medical device doesn’t have to be hacked for a cyberattack to become a medical device problem.
THE REP TAKE
Here’s the part I don’t think gets talked about enough.
When the corporate infrastructure goes down, who does the hospital call?
A lot of the time, us.
The surgeon doesn’t call the cybersecurity team.
The OR doesn’t call CrowdStrike.
They call their rep.
Is tomorrow’s product coming? Can you find another one? Can you transfer inventory from somewhere else? Is the device safe? Can the case still happen? Do we need to change anything?
Boston Scientific actually instructed customers during the disruption to continue communicating with their sales representatives.
That makes sense.
But it also highlights something interesting about our jobs.
The field sales force becomes part of the company’s business-continuity plan whether anyone writes it that way or not.
When systems work, we sell and support products.
When systems don’t work, we’re often the human connection between the customer and everything happening behind the scenes.
That’s probably not changing anytime soon.
CAREER STRATEGY
How much travel is actually normal?
Ask ten medical device reps how much they travel and you’re probably going to get ten different answers.
Part of the problem is the word “travel.”
Driving an hour and a half between hospitals technically counts as travel.
Spending three nights a week in Marriott rooms is something completely different.
So I went through current job postings to see what companies are actually telling candidates.
And the range is huge.
One current Abbott territory role lists daily territory travel but only 5% to 10% overnight travel for meetings.
Multiple Stryker field sales roles list around 20% travel.
A current Johnson & Johnson clinical-sales position lists up to 25%, including overnight travel.
An Intuitive clinical-sales manager role lists 50%.
An Edwards territory-manager role lists up to 60%, including car, air and overnight travel.
And a current Medtronic Acute Care and Monitoring associate position covering New Jersey, New York and Delaware lists 75% travel with more than 40% overnight travel anticipated. (Abbott Careers)
That’s an enormous difference in lifestyle.
Which makes me think we’re asking the wrong question during interviews.
Don’t just ask:
“How much travel is involved?”
Ask:
“How many nights did the person covering this territory spend away from home last year?”
That’s the number I’d want.
Twenty-five percent travel sounds pretty harmless on a job description.
Fifty nights away from your family sounds different.
THE ROOMMATE QUESTION
If the company sends you, should they give you your own room?
I’m probably going to get some disagreement on this one.
I’ve had companies require me to share hotel rooms with coworkers on business trips more than once.
I’ve never liked it.
And at this point in my career, I find it pretty ridiculous.
If I’m traveling because my company requires me to be somewhere overnight, I think a private hotel room should be part of the cost of doing business.
I don’t think that’s asking for luxury.
I’m not asking for the Four Seasons.
I’m asking for a door.
There’s obviously another side to this.
Company meetings get expensive quickly.
Put 300 sales reps in a hotel for four nights and lodging becomes a massive expense. Doubling people up can cut a big part of that bill.
I understand the math.
But employees are also giving something up.
You’re already away from your spouse, kids, house and normal routine because your company asked you to be there.
Then the meeting ends and the one place you should theoretically be able to decompress isn’t private either.
Maybe your roommate snores.
Maybe you do.
Maybe you want to FaceTime your kids.
Maybe you need to answer emails at midnight.
Maybe you have medication to take, a medical condition you don’t want to discuss, a religious practice requiring privacy or you simply don’t want to change clothes three feet away from someone you work with.
Then there are the more obvious HR questions involving managers and direct reports, harassment, accommodations and personal safety.
There doesn’t appear to be a blanket federal rule saying every employee traveling for business is automatically entitled to a private hotel room. Employers generally have significant discretion over travel policy, while existing accommodation and discrimination laws can create additional obligations depending on the employee and circumstances. (SHRM)
So this isn’t really a question of whether companies can make employees share rooms.
It’s whether they should.
My answer is no.
For normal professional business travel, single occupancy should be the default.
If a company decides an employee needs to spend the night somewhere for the company’s benefit, providing that employee with a reasonable private room seems like a pretty basic travel expense.
I’d rather see companies control costs through negotiated hotel rates, meeting locations, shorter events and tighter travel policies than save money by making two grown adults sleep six feet apart.
Maybe I’m in the minority.
I’m genuinely curious.
Reply and tell me.
Speak naturally. Send without fixing.
Wispr Flow turns your voice into clean, professional text you can send the moment you stop talking. Not rough transcription you have to clean up. Actual polished text — ready for email, Slack, or any app.
Speak the way you think. Go on tangents. Change your mind mid-sentence. Flow strips the filler, fixes the grammar, and gives you text that reads like you spent five minutes writing it.
89% of messages sent with zero edits. Millions of professionals use Flow daily, including teams at OpenAI, Vercel, and Clay. Works on Mac, Windows, and iPhone.
THE COMPENSATION SNAPSHOT
We’ve spent a lot of the first four issues talking about compensation.
So rather than throw another table of numbers at you this week, we put the data into something more useful.
The 2026 Med Device Compensation Snapshot is now available.
It’s a free 9-page report built from the anonymous submissions we’ve collected so far covering:
Total W-2 compensation.
Quota attainment.
Compensation structures.
Earnings by experience.
Role and business-unit comparisons.
And anonymous insights directly from people working in the field.
DOWNLOAD THE 2026 MED DEVICE COMPENSATION SNAPSHOT:
The anonymous Compensation Index is also still open. Every new response makes future comparisons more useful across specialties, roles, experience and companies.
FROM THE FIELD
For this issue, I want to hear from you.
Have you ever been required to share a hotel room on a company trip?
How much overnight travel does your role actually require?
And if you’ve worked through one of these major company system outages, what did it look like from the field?
Hit reply.
I read every response.
The Med Device Rep
TheMedDeviceRep.com

