Healthcare Cybersecurity
A

Asimily

Exposure management platform for connected device environments spanning IoMT, IoT, OT and IT, with healthcare delivery organisations as its founding and strongest vertical. Founded 2017, headquartered in Sunnyvale. The defining capability is contextual vulnerability prioritisation rather than discovery alone, which addresses the problem that actually defeats hospital security teams: a large hospital may run 10,000 to 25,000 connected medical devices representing 30 to 40 percent of all networked endpoints, and a raw vulnerability list across that fleet is unusable.

Asimily evaluates each vulnerability in the context of the specific device's configuration and network environment, and prioritises by likelihood of exploitation and clinical or business impact, so remediation effort goes where risk is real. The company states this is necessary because IoT and IoMT devices exhibit network behaviour unlike conventional IT endpoints, leaving general purpose security tools unable to distinguish genuine risk from false alarms.

The platform maintains an extensive knowledge base of connected and standalone medical devices, protocols, vulnerability research and manufacturer capability documents, and extends beyond assessment into orchestrated segmentation and risk mitigation, plus pre-purchase device evaluation so risk can be assessed before procurement. Ranked first in the KLAS 2026 Healthcare IoT Security report with a score of 96.6. Also ranked 13th fastest-growing cybersecurity company on the 2023 Deloitte Technology Fast 500 on reported 773 percent revenue growth, and selected for the US Department of Energy Clean Energy Cybersecurity Accelerator. Integrates with CMMS platforms including MediMizer bidirectionally, enriching its machine learning with medical device context while feeding security incidents into maintenance remediation workflows.

AI Health Index verifiedJuly 21, 2026
Compare Asimily with other vendors
Founded
2017
Headquarters
Sunnyvale, California, United States
Website
www.asimily.com
Categories
healthcare-cybersecurity, healthcare-admin-automation
Assessment

Capability Axes

An AI Health Index grade measures what a buyer can verify from public sources on the date shown. It is not a rating of how good the product is. A vendor can build an excellent system and grade low on an axis because it publishes nothing an outsider can check. How grades read

AI Capability
BB on AI CentralityThe model is the engine of a core module. The platform carries other value, but this capability does not exist without it.
Third Party Estimated

Deliberate B, and this axis needs care across the whole cybersecurity category because AI language is applied loosely in security marketing. Asimily's machine learning is real and specifically located: contextual vulnerability evaluation against each device's configuration and network environment, exploit likelihood analysis, and behavioural anomaly detection, with the ML explicitly enriched by medical device context through CMMS integration.

But the platform's substantive moat is the knowledge base, described as the most extensive collection of connected and standalone medical device profiles, protocols, vulnerability research and manufacturer capability documents. That is a curated data asset, and device discovery leans on pre-existing device profiles alongside algorithms.

Same principle applied to Reveleer's retrieval network and the credentialing lane: where the moat is the proprietary dataset rather than the model, AI Centrality is graded down. Not C, because the prioritisation reasoning is genuinely algorithmic rather than a lookup.

BB on Autonomy and Oversight ModelThe oversight structure is described and one part is missing, commonly the threshold at which the system stops or what happens after it is wrong.
Third Party Estimated

Sits deliberately at the advisory end of a spectrum the category makes explicit. Independent comparison characterises Asimily as a visibility and exposure management leader whose enforcement is delivered through guidance and integration rather than direct architectural isolation, meaning it tells you what to segment rather than segmenting the network itself.

The company describes continuously orchestrating segmentation and mitigation actions without disrupting operations, so automation exists but acts through integrated infrastructure rather than unilaterally. That is the appropriate design choice in clinical environments where automated isolation of a misidentified infusion pump is a patient safety event, not merely an outage. Graded B rather than A because the boundary between recommended and automatically enforced action is not precisely stated.

BB on Model and Technology TransparencyThe approach or the suppliers are named without the version and update discipline behind them.
Third Party Estimated

Better than the category norm. The company names its mechanism specifically, evaluating vulnerabilities in the context of each device's configuration and network environment rather than by CVSS score alone, and describes passive monitoring, exploit analysis and the parameter plus device profile approach to discovery. Third party analysis identifies proprietary AI, ML and NLP as the basis for contextual vulnerability evaluation.

Graded B rather than A because the prioritisation logic itself is not published in auditable form, and the category editorial for this index specifically warns that AI detection claims should be backed by named detection methodologies rather than marketing language; Asimily is above that bar but not fully transparent.

CC on Model Supply Chain DisclosureThe architecture is described and no provider is named.
Vendor Published

The architecture bounds this axis structurally and one residual is unaddressed. Monitoring is passive, observing network traffic and device behaviour rather than ingesting clinical content, so the data surface is device telemetry, protocol metadata and configuration rather than patient records, and no agents are installed on medical devices at all.

That second point has a clinical dimension worth crediting: agents on regulated devices can invalidate manufacturer support, and avoiding them keeps a hospital's warranty and regulatory position intact. Both are design choices rather than policies, which makes them the durable kind. The residual is specific and it is the reason this does not sit higher.

Network traffic in clinical environments can carry protected health information inside device protocol payloads, particularly imaging and monitoring data, so a passive monitor observing that traffic sees patient content incidentally even though it is not the point of the product. No published statement on how incidental protected health information is handled was located, and that is the question a privacy office will ask first.

Nothing else is named either: no model or provider, no hosting arrangement, no sub processor list. Ask what happens to payload content the monitor observes, what is retained, and for a sub processor list.

BB on Clinical and Operational EvidenceNamed deployments with dated outcome figures and enough method to test them, or published research short of independent validation.
Third Party Estimated

The best third party validation available in this category, though not clinical evidence in the usual sense. Ranked FIRST in the KLAS 2026 Healthcare IoT Security report with a score of 96.6, which is independent customer-sourced research rather than vendor claim, and is the single most useful comparator in this lane since KLAS surveys actual health system users.

Selection for the US Department of Energy Clean Energy Cybersecurity Accelerator is independent technical validation from outside healthcare. Deloitte Technology Fast 500 placement at 13th fastest-growing cybersecurity company reflects commercial traction rather than efficacy.

Graded B rather than A because vendor claims such as reducing vulnerabilities 10 times faster with half the resources carry no disclosed methodology, and no published breach-prevention or incident-reduction outcome data exists.

BB on AI Safety and PHI StewardshipCategorical commitments are published, such as no training on customer data, without the retention schedule or the safety engineering behind them.
Third Party Estimated

Structurally favourable rather than policy-based. The platform monitors network traffic and device behaviour passively rather than ingesting clinical content, so the data surface is device telemetry, protocol metadata and configuration rather than patient records. Passive monitoring also means no agents installed on medical devices, which matters because agents on regulated devices can invalidate manufacturer support.

Graded B rather than A because network traffic in clinical environments can carry PHI in device protocol payloads, notably imaging and monitoring data, and no published statement on how such incidental PHI is handled was located.

Regulatory and Compliance
AA on HIPAA and BAA PostureBusiness associate status is stated, the agreement is available, the tier it applies at is clear, and the subprocessors it covers are disclosed.
Third Party Estimated

The clearest architectural answer to this question in the category, and it is stated on a formal security page rather than implied. The company states that neither personally identifiable information nor electronic protected health information is transmitted out of the on site Edge appliance to cloud or on premises servers, that data processed at the Edge is never written to disk or persisted, and that what does travel is technical in nature, such as addresses and device classifications.

Where no ePHI reaches the vendor, the business associate question is substantially answered rather than deferred. Supporting commitments reinforce it: cloud instances are dedicated per customer with multi tenancy explicitly ruled out, stored data remains in the country of origin, nothing is shared with third parties without explicit customer authorisation, and a fully on premises deployment is offered for organisations that want nothing in the cloud at all.

A dedicated HIPAA resource also exists for customers. The business associate agreement itself is still never named, so a buyer should confirm whether one is offered and get the ePHI boundary written into contract rather than relying on a published claim.

BB on Security Certifications and Trust CenterA recognised certification is named in the vendor own material without the artefact, or with a scope or renewal question the buyer has to raise. A certification has a scope and a clock, and both are part of this grade.
Vendor Published

An unusual profile: narrow on certificates, exceptionally deep on disclosure. The audited position is SOC 2 Type II, with the type specified where several competitors leave it ambiguous, plus C5 and adherence to Cloud Security Alliance practice. There is no trust center and no ISO 27001.

What compensates is the level of engineering detail published openly, which exceeds anything else in this category: named cipher suites for each data path, single tenant cloud instances with multi tenancy explicitly ruled out, geo fencing on data access, OWASP practice with static and dynamic analysis, Tenable scanning, internal and external penetration testing, ITIL change control with rollback, and build integrity protection where deployed executables are cryptographically verified against the authorised build.

Google Cloud is named as the provider, with AWS and Oracle for non US regions, and vendors are risk assessed before onboarding. Held below the top of the band because breadth of independent attestation, not description, is what a security review can rely on. Worth requesting the SOC 2 Type II report and confirming its scope.

AA on FDA and Regulatory StatusThe regulatory position is unambiguous and verifiable: a clearance or authorisation identifiable in the public databases, with the version and indication it actually covers.
Regulatory Filing

The strongest regulatory positioning in this category, and the only one that addresses the healthcare frame directly rather than by adjacency. This is a security platform and not a regulated device, so it holds no FDA clearance and needs none, but it maps to the regulations a hospital is actually measured against.

Dedicated resources exist for eleven frameworks including FDA, HIPAA, NIST CSF 2.0, CMMC, NERC CIP, NIS2, DORA, PCI DSS, Zero Trust and MITRE ATT&CK. Recall management is a named capability, parsing FDA and manufacturer recall directives into searchable, assignable work with compatibility assessment.

Most distinctively, risk is differentiated across the four dimensions of the ANSI/AAMI/IEC 80001 framework for medical device network risk management, covering patient safety, clinical effectiveness, data and network security, and business impact, and manufacturer security disclosure statements are ingested into the analysis. Both are healthcare specific instruments that competitors in this category do not reference.

Worth asking how the 80001 mapping is evidenced in reporting for an accreditation survey.

CC on AI Governance and Bias DisclosureResponsible artificial intelligence is committed to in policy language with no evaluation behind it. Most of the index sits here.
Vendor Published

The gap stands out because the company's own security documentation is otherwise unusually forthcoming about how data is handled, yet says nothing about the models. Machine learning is described as patented and grounded in MITRE ATT&CK analysis alongside in house research, and two oversight features are genuinely relevant here: policy effects can be previewed through simulation before segmentation is applied, and a risk simulator estimates the effect of an action before it is taken.

Modelling a change before committing to it is a meaningful control in an environment full of clinical devices. What is absent is everything else. There is no AI governance framework or certification, no description of model architecture or training data, no accuracy or false positive figures for vulnerability prioritisation despite prioritisation being the core claim, and no statement on whether customer environment data contributes to model development. Worth asking for prioritisation accuracy figures and whether device data from one customer informs models used for others.

CC on AI Liability and RecourseMechanisms exist that let someone challenge an output, such as audit trails, source traceability or review before commit, with nothing standing behind the output and no route for the harmed party.
Vendor Published

The mechanism is named specifically and it is a real methodological improvement rather than a marketing distinction. Vulnerabilities are evaluated in the context of each device's configuration and network environment rather than by raw severity score alone, which is the difference between telling a hospital that a device has a critical vulnerability and telling them whether that vulnerability is actually reachable on their network.

That distinction is the whole value of the category, because a hospital cannot patch everything and the question is always what to do first. Passive monitoring, exploit analysis and a parameter plus device profile approach to discovery are described alongside it.

Held at C because the prioritisation logic itself is not published in auditable form, so a hospital receiving a ranked list cannot reconstruct why one device outranked another or check the reasoning against its own knowledge of the environment. That matters more for a prioritisation product than a raw accuracy figure would, since the output is an ordering and an ordering is only useful if its basis can be argued with.

No accuracy, false positive or classification precision figures were located, and no warranty, indemnity or remediation commitment. Ask for the prioritisation logic in auditable form, classification accuracy by device class, and what a hospital can override.

Integration and Deployment
AA on EHR and Interoperability DepthNamed bidirectional integrations with major record systems, verifiable in marketplace listings or integration documentation, with evidence the connection runs in production.
Third Party Estimated

Strong and correctly targeted at the systems that matter in this category, which are not EHRs. The platform integrates with firewalls, network access control providers, SIEM and notably Computerized Maintenance Management Systems, with the MediMizer integration described as bidirectional: Asimily's machine learning is enriched by medical device context from the CMMS while the CMMS receives real-time security incident data to drive remediation workflows.

That CMMS linkage is the important one, because it connects the security team's risk view to the biomedical engineering team that physically maintains the devices, and those two functions are usually disconnected in hospitals. Enforcement is delivered through integration with existing infrastructure rather than by replacing it.

BB on Deployment Model and Data ResidencyOptions and residency are stated with isolation or the processing path left open.
Third Party Estimated

Passive, agentless monitoring means deployment does not require software on clinical devices, which is essential in an environment where installing agents on regulated equipment may void manufacturer support or validation. Cloud platform with recognised cloud architecture. Independent comparison notes faster time to value on device visibility than NAC-based alternatives. Graded B rather than A because no data residency terms or on-premise option were located.

Commercial
CC on Commercial TransparencyNo price is published and the posture is discoverable: a buyer can establish how the product is sold and what drives the cost before contacting the vendor. Most of the index sits here.
Third Party Estimated

No pricing published and no pricing basis disclosed. Category context makes this consequential: independent analysis reports that enterprise configuration costs for a competing platform in this lane can reach very high figures, so cost variance between vendors is large and undisclosed. Buyers cannot compare cost per device or per site across this category from public information.

AA on Setting and Specialty CoverageWhere the product is validated to operate is named and supported, settings and specialties both, whether the coverage is broad or deliberately narrow.
Third Party Estimated

Broad across both asset classes and industries while retaining healthcare depth. Covers IoMT, IoT, OT and IT within a single platform, spanning medical, laboratory and general connected device fleets, and serves healthcare systems alongside manufacturing enterprises and financial institutions, with international reach through channel partnerships in Australia and the Nordics.

Capability spans the full lifecycle: pre-purchase device evaluation, discovery and classification, vulnerability prioritisation, segmentation orchestration, and forensic incident response. Pre-purchase evaluation is a genuinely differentiated capability, since it moves security assessment upstream of procurement rather than inheriting risk after installation.

Comparisons

Compared With

Each comparison carries a written verdict, the buyer conditions that favor each vendor, and a graded side by side. Pairs that cross a category boundary are grouped separately, and their verdicts state where the boundary sits rather than manufacturing a head to head.

Commercial

Pricing

Vendor-published figures are labeled as such. Figures labeled “Estimated” are derived from third-party sources and have not been confirmed by the vendor.

Entry Price Pricing Basis BAA Tier Implementation Source
Not published
Undisclosed. Likely per-device or per-site; enforcement depends on existing network infrastructure so licence is not total cost. Third Party Estimated

No pricing published and no pricing basis disclosed, which is the norm across healthcare cybersecurity but has unusually large consequences in this category. Independent analysis of this lane reports that enterprise configuration costs for at least one competing platform can reach figures in the six digits, indicating very wide cost variance between vendors for what buyers may perceive as comparable capability.

A health system cannot compare cost per connected device, per site or per bed across this category from public information. The natural pricing unit is per device monitored or per site, and buyers should establish which, since a large hospital may run 10,000 to 25,000 connected medical devices and per-device pricing scales very differently from a site licence at that fleet size. Two further diligence points specific to this vendor.

First, because enforcement is delivered through integration with existing firewall, NAC and SIEM infrastructure rather than by direct isolation, the total cost of a working deployment includes whatever enforcement infrastructure the organisation already has or must acquire, so the platform licence is not the whole spend. Second, the pre-purchase device evaluation capability and the CMMS integration may be licensed separately from core discovery and should be confirmed rather than assumed. The KLAS 2026 Healthcare IoT Security report, in which Asimily ranked first at 96.6, is the most useful independent comparator available for this decision and is worth obtaining.