Claroty
Healthcare cybersecurity platform, delivered as Medigate by Claroty (also positioned as Claroty xDome for Healthcare). Purpose built to discover, profile, and protect connected medical devices (IoMT), IoT, and building management systems on hospital networks, using passive deep packet inspection and light active techniques across a reported 500+ device protocols, with an Advanced Anomaly Threat Detection module that adds clinical context to prioritize threats. Protects a reported 20 million plus devices across 2,000+ hospital facilities and has been named Best in KLAS for Healthcare IoT Security multiple years. Claroty acquired Medigate in 2022.
Capability Axes
An AI Health Index grade measures what a buyer can verify from public sources on the date shown. It is not a rating of how good the product is. A vendor can build an excellent system and grade low on an axis because it publishes nothing an outsider can check. How grades read
AI does the detection work: anomaly threat detection and device profiling across IoMT and IoT, using deep packet inspection and behavioral models with clinical context. Held back from A because the platform is a broader cybersecurity suite (visibility, inventory, vulnerability management, secure access) in which AI anomaly detection is one important layer rather than the whole product.
Positioned explicitly as a move from dashboards a human operates to agentic execution with a human in the loop, and the agent's actions are described as deterministic rather than probabilistic, which is a meaningful claim in a security context. Real autonomy is on offer: triaging alerts, generating segmentation policies for automatic application at the firewall or network access control layer, and auto generating and submitting tickets into internal systems.
Held below the top of the band because the oversight half is asserted rather than specified. Nothing describes which actions require approval before execution, what an operator can override or roll back, or how actions are logged for audit. Parts of the capability are also described in future tense, so a buyer should establish what is generally available today. In a hospital environment, an agent that can apply firewall policy to a segment containing infusion pumps or imaging systems is a change control question as much as a security one.
The training corpus is described with more numeric specificity than most vendors offer: a domain specific language model built on more than ten years of accumulated data spanning tens of thousands of deployed sites, thousands of distinct device vendors and dozens of industrial sectors.
Device intelligence is also credited in part to direct partnerships with medical device manufacturers, which supply confirmed vulnerability information and manufacturer guidance on exploitability rather than inference. That provenance claim is unusual and checkable in principle.
Held below the top of the band because no model architecture, base model or evaluation methodology is disclosed, no accuracy or false positive figures are published for either detection or the AI agent, and superlative framing about the model stands unsupported. Worth asking for detection performance figures and how the model is validated before release.
The privacy infrastructure here is independently checkable and includes the artifact this axis asks for. A certified privacy information management system, a published data processing agreement, a public sub processor list, privacy impact assessments and penetration testing available under agreement together give a buyer a set of documents rather than a set of assurances, and a public sub processor list is the single most useful of them because it names parties rather than describing controls.
The corpus is also described with more numeric specificity than most vendors offer, spanning more than a decade of accumulated data across tens of thousands of deployed sites, thousands of distinct device vendors and dozens of sectors, and device intelligence is credited in part to direct partnerships with medical device manufacturers supplying confirmed vulnerability information and manufacturer guidance on exploitability rather than inference.
Naming the provenance of intelligence as manufacturer confirmed rather than derived is unusual and checkable in principle. Held below the top grade because the model layer is unnamed, with no base model or architecture disclosed, and because what the platform retains from a hospital environment is undescribed.
That last question is live rather than hypothetical: the agent is marketed as trained on data drawn from the installed base, so a customer's own environment plausibly improves a product sold to others. Ask which attributes are captured, how long they persist, whether anything leaves the tenant, and whether it feeds the models.
Deployment scale is well documented and third party corroborated (reported 20 million plus devices, 2,000+ hospital facilities) and the healthcare product has been named Best in KLAS for Healthcare IoT Security multiple years, an independent recognition. Held back from A because detection efficacy is not published as an independent performance benchmark.
The privacy infrastructure is strong and independently checkable: a certified ISO 27701 privacy information management system, a published data processing agreement, a public sub processor list, privacy impact assessments and penetration testing available under NDA. What is not published is what the platform actually retains from a hospital environment.
The product discovers and monitors connected medical devices by observing network activity, so the practical questions are which device and traffic attributes are captured, how long they persist, whether anything leaves the customer tenant, and whether that data feeds the vendor's own models. The last question is live rather than hypothetical, because the AI agent is marketed as trained on data drawn from the installed base. Worth resolving all four in contract.
Substantially more than an assertion. The HIPAA Privacy Rule policy is published as a downloadable document rather than listed as a badge, and it sits alongside an ISO 27701 certified privacy information management system, which is an audited privacy programme rather than a claim. A data processing agreement is published, a privacy impact assessment is available, and a third party sub processor list is public.
Taken together this is a more complete and more verifiable privacy position than any comparable vendor in this category. The one thing left open is the business associate agreement itself, which is never named or described. Worth confirming whether a BAA is offered as standard and, given the platform monitors clinical network traffic rather than clinical records, whether the vendor takes the position that it processes protected health information at all.
The most complete published security position in this category, and unusually the evidence is open rather than gated. The trust center carries SOC 2 Type 2 evaluated across all five trust services criteria, ISO 27001:2022, ISO 27701:2019 for privacy information management, the German BSI C5 cloud controls catalogue, CSA STAR with a listing on the Cloud Security Alliance public registry, and SOCI alignment for Australian critical infrastructure.
TISAX and the Spanish CCN standards are listed as in progress. Two things separate this from peers who hold comparable certificates. The ISO 27001 and ISO 27701 certificates are published as direct downloads rather than released only under an access request, and a product security incident response team operates with a published reporting address and a public vulnerability disclosure dashboard. External audit reports and recent penetration test results are available under NDA. A buyer can verify most of this without contacting sales, which is rare.
This is a security platform rather than a medical device, so it holds no FDA clearance and needs none. The grade should be read against what does govern the category, not against a clearance that would never apply. On that basis there is genuine substance: a coordinated vulnerability disclosure process with a published reporting channel, a public vulnerability disclosure dashboard maintained by the company's threat research team, partnerships with medical device manufacturers that supply confirmed vulnerability data, and documented alignment with Australian critical infrastructure legislation.
What is missing is the frame a US health system buys against. Nothing published addresses how the platform supports a customer's obligations under federal medical device cybersecurity requirements, health sector cybersecurity performance goals, or recognised health industry practices. Worth asking how the product maps to those specifically.
The gap here is conspicuous because everything around it is so thorough. A trust center carrying eight compliance programmes contains no AI governance content at all, while the company markets an agentic AI security product. The product page raises the training question itself, under a heading stating that what AI is trained on matters, and answers it with scale drawn from the installed base: a model trained on more than a decade of accumulated data across tens of thousands of deployed sites.
That is presented as a competitive advantage rather than as a disclosure, and nothing addresses tenant isolation, whether customer environments can be excluded from model training, or what consent applies. There is also no published evaluation, error rate or false positive characterisation for the agent, and no AI specific governance certification. Human oversight is asserted at the level of positioning. Worth asking whether a customer's environment data trains the shared model and whether opting out is possible.
One provenance choice does real work here and it is worth distinguishing from the usual claims. Device intelligence is credited in part to direct partnerships with medical device manufacturers, who supply confirmed vulnerability information and guidance on exploitability rather than the platform inferring both from network observation.
For a product whose output drives segmentation and patching decisions, intelligence confirmed by the party that built the device is materially better than intelligence deduced about it, and it is the sort of sourcing a buyer can verify by asking which manufacturers participate. That is the basis for the grade. Nothing measures the result.
No accuracy or false positive figures were located for detection or for the agent, no evaluation methodology is published, and superlative framing about the model stands unsupported. The consequence pattern this index recorded for a peer applies here too: a device classified wrongly produces a wrong risk rating and then a wrong network policy, and a policy that isolates a clinical device that needed connectivity is a patient safety event arising from a security control.
No warranty, indemnity or remediation commitment was located. Ask which manufacturers supply confirmed intelligence and what proportion of the catalogue that covers, for classification accuracy, and for the false positive rate at the recommended configuration.
Broad, named and correctly targeted at the systems that matter in this category, which are not EHRs. Integration spans SIEM through Splunk and Microsoft Sentinel, IT service management through ServiceNow, biomedical inventory and maintenance management through TRIMEDX and Accruent, and enforcement at the firewall and network access control layer.
The biomedical inventory link is the most specific documented in this lane: more than sixty device attributes are passed, including identification, location, operating system, application and firmware versions, serial number, network status, security posture and utilisation. That is the record a biomedical engineering team actually works from, and passing that depth connects the security team's risk view to the people who physically maintain the devices.
There is no EHR integration and none is claimed, which is the right scope here rather than a shortfall. Integrations are named partner connectors rather than standards based interfaces, so a buyer running a platform outside that list should confirm coverage.
Modular, SaaS based platform that integrates with existing hospital IT and security infrastructure. Deployment model clearly described; specific data residency and tenancy isolation commitments not retrieved this pass.
No pricing, rate card or cost structure is published. The product is described as modular and delivered as software as a service, with cost reduction framed against consolidating multiple point products, but nothing quantifies licensing, whether pricing scales by device count, site or bandwidth, or what a multi site health system would pay. Third party recognition is used in place of commercial detail, including analyst placement and repeated category awards.
That is the norm rather than the exception in this category, where every comparable vendor is equally opaque, so the grade reflects a category wide practice rather than an outlier. Worth requesting the pricing metric early, since device count based licensing behaves very differently from site based licensing across a multi facility system.
Precisely scoped: connected device security for healthcare delivery organizations, spanning IoMT (from IV pumps to ultrasound machines), IoT, and building management systems. Clear, specific coverage.
Compared With
Each comparison carries a written verdict, the buyer conditions that favor each vendor, and a graded side by side. Pairs that cross a category boundary are grouped separately, and their verdicts state where the boundary sits rather than manufacturing a head to head.
Announced Deployments
Publicly announced health system deployments and partnerships. This is a record of announcements, not an assessment of deployment success or scale.
Pricing
Vendor-published figures are labeled as such. Figures labeled “Estimated” are derived from third-party sources and have not been confirmed by the vendor.
| Entry Price | Pricing Basis | BAA Tier | Implementation | Source |
|---|---|---|---|---|
|
Contact the vendor
|
Enterprise subscription; per bed or per license models reported | — | — | Third Party Estimated |
Third party coverage indicates an enterprise subscription with some reports of per bed or per license structures. No published rate card; pricing is quote based.