Medtech firms consistently underinvest in corporate network cybersecurity because almost all their security and compliance spending goes to device safety requirements, not IT hardening. This is exactly the kind of gap wiper attacks target.
Which in itself wouldn't be too bad, if mobile platforms had proper backup facilities that allowed individuals and enterprises to easily get all their devices to the exact backed up state they were before being wiped. But that seems to be unwanted by Apple and Google...