Inspectors with the U.S. Food and Drug Administration on Wednesday slapped St. Jude Medical with a warning letter that says the medical device maker failed to properly investigate whether its lithium implantable defibrillator batteries could die without warning, and failed to make sure that its at-home monitoring equipment was not vulnerable to cyberattack.

The FDA warning letter ties together two controversies that, until Wednesday, had been separate headaches for St. Jude. St. Jude issued a recall notice affecting about 400,000 implantable devices with lithium batteries last October, following reports of two patient deaths and dozens of hospitalizations. In January, the company rolled out a software patch intended to prevent cyberattacks after it was publicly criticized for selling unsecure devices.

St. Jude Medical was a Little Canada-based company when most of the alleged failures to correct the problems took place. The company was acquired in January by Chicago-based Abbott Laboratories in a $25 billion deal. Wednesday’s warning letter is addressed to Michael Rousseau, president of Abbott’s cardiovascular device division and former CEO of St. Jude.

The company didn’t immediately respond to a request for comment. In the past, St. Jude has staunchly defended the safety of its products and even filed a defamation lawsuit against its cybersecurity critics.

Regarding the defibrillator batteries, St. Jude has said that it changed the design of lithium batteries in its implantable defibrillators in 2015, but continued to ship the devices to hospitals until October 2016 because the old units had such a low failure rate.

Wednesday’s FDA warning said St. Jude officials systematically underestimated the true risk to patients for years by basing their evaluations only on “confirmed” cases of battery failures, and disregarding cases in which battery shorts may have been involved. A 2014 patient death wasn’t even presented to medical advisers assessing the risk at the time.

Further, the warning says, the company shipped at least 10 implantable defibrillators after issuing its recall, and seven more units affected by the recall were implanted in patients after the recall was announced.

On cybersecurity, St. Jude has said that it thoroughly investigated allegations from a profit-motivated short seller called Muddy Waters Capital, which publicly accused the company last summer of skipping basic cybersecurity protections in its Merlin@home monitoring devices. The company eventually filed a defamation lawsuit against the short sellers and the security researchers who first discovered the issue.

Wednesday’s warning letter said St. Jude didn’t follow its own internal policies for investigating such problems, including failing to confirm that a root-cause investigation was carried out.

The company responded to the inspectors’ findings in writing, but the FDA did not accept the explanations. The company’s written response wasn’t available Wednesday evening.

“We have reviewed your response and conclude that it is not adequate,” the FDA warning letter says, using language contained in many such warning letters. “You should take prompt action to correct the violations addressed in this letter. Failure to promptly correct these violations may result in regulatory action being initiated by the FDA without further notice.”

FDA inspectors said the devices were considered “adulterated” under the law because of the alleged violations. Abbott has 15 days to respond to the FDA with specific steps to correct the problems and prevent them from happening in the future.