FDA Clears EBR’s WiSE System After Cybersecurity Review
The FDA has agreed that EBR Systems’ WiSE cardiac pacing system does not require a field corrective action or recall following a February cybersecurity incident. The device maker says it has found no evidence of any impact on the safety or performance of fielded systems, while remediation work continues.
- FDA agrees no WiSE System recall or field corrective action is warranted
- Incident classified as Controlled Risk under FDA postmarket guidance
- No identified impact on fielded device safety or performance
- EBR continues cybersecurity remediation and product hardening
- Corporate controls strengthened through credential, training and monitoring upgrades
FDA Rejects Need for WiSE Recall
EBR Systems, Inc. (ASX:EBR) has cleared the most immediate regulatory hurdle arising from its 2026 cybersecurity incident: the US Food and Drug Administration has agreed that no field corrective action or recall of the WiSE System is warranted.
The FDA reached that position after reviewing EBR’s completed cybersecurity risk assessment, which examined the potential effect of the incident on the safety and effectiveness of its wireless cardiac pacing system. The regulator classified the incident as “Controlled Risk” under Section VI of its 2016 guidance on postmarket cybersecurity in medical devices.
No Impact Identified in Fielded Devices
EBR said it has not identified evidence of any impact on the safety or performance of WiSE CRT Systems already in the field, based on the information reviewed to date. That wording is important: it records the company’s current assessment rather than declaring the cybersecurity matter permanently closed.
The incident was first identified in February 2026 and disclosed to the ASX on 15 April. EBR said it moved to contain the incident, investigate its potential impact and notify relevant regulatory authorities before completing the formal assessment with support from independent cybersecurity specialists.
Remediation Continues After Regulatory Review
Regulatory clearance of the immediate product response does not end EBR’s cybersecurity programme. The company said it has strengthened credential-management controls, introduced anti-phishing training and enhanced endpoint monitoring, while additional product cybersecurity remediation and hardening activities remain under way.
EBR will continue providing progress updates to the FDA as requested. The announcement contains no disclosed financial impact from the incident, leaving the next meaningful test operational: whether the company can complete its remaining product controls without any later change to its assessment of fielded device safety or performance.
Bottom Line?
The FDA’s no-recall position removes the sharpest immediate product risk, but EBR still has to finish remediation and maintain confidence in WiSE devices as the review continues.
Questions in the middle?
- What specific product cybersecurity hardening activities remain outstanding?
- Will the FDA request further information or impose additional postmarket requirements?
- Could any later findings alter EBR’s current assessment of fielded WiSE device safety or performance?