Healthcare Cybersecurity
C

Claroty

Healthcare cybersecurity platform, delivered as Medigate by Claroty (also positioned as Claroty xDome for Healthcare). Purpose built to discover, profile, and protect connected medical devices (IoMT), IoT, and building management systems on hospital networks, using passive deep packet inspection and light active techniques across a reported 500+ device protocols, with an Advanced Anomaly Threat Detection module that adds clinical context to prioritize threats. Protects a reported 20 million plus devices across 2,000+ hospital facilities and has been named Best in KLAS for Healthcare IoT Security multiple years. Claroty acquired Medigate in 2022.

AI Health Index verifiedJuly 12, 2026
Compare Claroty with other vendors
Founded
2015
Headquarters
New York, New York
Website
claroty.com
Categories
healthcare-cybersecurity
Indexed Products
Medigate by Claroty, Claroty xDome for Healthcare, Advanced Anomaly Threat Detection Module
Buyer Segments
Large IDN, Community Health System, Academic Medical Center
Assessment

Capability Axes

An AI Health Index grade measures what a buyer can verify from public sources on the date shown. It is not a rating of how good the product is. A vendor can build an excellent system and grade low on an axis because it publishes nothing an outsider can check. How grades read

AI Capability
BB on AI CentralityThe model is the engine of a core module. The platform carries other value, but this capability does not exist without it.
Vendor Published

AI does the detection work: anomaly threat detection and device profiling across IoMT and IoT, using deep packet inspection and behavioral models with clinical context. Held back from A because the platform is a broader cybersecurity suite (visibility, inventory, vulnerability management, secure access) in which AI anomaly detection is one important layer rather than the whole product.

BB on Autonomy and Oversight ModelThe oversight structure is described and one part is missing, commonly the threshold at which the system stops or what happens after it is wrong.
Vendor Published

Positioned explicitly as a move from dashboards a human operates to agentic execution with a human in the loop, and the agent's actions are described as deterministic rather than probabilistic, which is a meaningful claim in a security context. Real autonomy is on offer: triaging alerts, generating segmentation policies for automatic application at the firewall or network access control layer, and auto generating and submitting tickets into internal systems.

Held below the top of the band because the oversight half is asserted rather than specified. Nothing describes which actions require approval before execution, what an operator can override or roll back, or how actions are logged for audit. Parts of the capability are also described in future tense, so a buyer should establish what is generally available today. In a hospital environment, an agent that can apply firewall policy to a segment containing infusion pumps or imaging systems is a change control question as much as a security one.

BB on Model and Technology TransparencyThe approach or the suppliers are named without the version and update discipline behind them.
Vendor Published

The training corpus is described with more numeric specificity than most vendors offer: a domain specific language model built on more than ten years of accumulated data spanning tens of thousands of deployed sites, thousands of distinct device vendors and dozens of industrial sectors.

Device intelligence is also credited in part to direct partnerships with medical device manufacturers, which supply confirmed vulnerability information and manufacturer guidance on exploitability rather than inference. That provenance claim is unusual and checkable in principle.

Held below the top of the band because no model architecture, base model or evaluation methodology is disclosed, no accuracy or false positive figures are published for either detection or the AI agent, and superlative framing about the model stands unsupported. Worth asking for detection performance figures and how the model is validated before release.

BB on Model Supply Chain DisclosureSubstantial partial disclosure, or a chain that is structurally short: an in house build, a cleared model that cannot be quietly swapped, or a deployment where the transfer does not occur at all. Naming only the hosting provider sits at the top of this band rather than in A.
Vendor Published

The privacy infrastructure here is independently checkable and includes the artifact this axis asks for. A certified privacy information management system, a published data processing agreement, a public sub processor list, privacy impact assessments and penetration testing available under agreement together give a buyer a set of documents rather than a set of assurances, and a public sub processor list is the single most useful of them because it names parties rather than describing controls.

The corpus is also described with more numeric specificity than most vendors offer, spanning more than a decade of accumulated data across tens of thousands of deployed sites, thousands of distinct device vendors and dozens of sectors, and device intelligence is credited in part to direct partnerships with medical device manufacturers supplying confirmed vulnerability information and manufacturer guidance on exploitability rather than inference.

Naming the provenance of intelligence as manufacturer confirmed rather than derived is unusual and checkable in principle. Held below the top grade because the model layer is unnamed, with no base model or architecture disclosed, and because what the platform retains from a hospital environment is undescribed.

That last question is live rather than hypothetical: the agent is marketed as trained on data drawn from the installed base, so a customer's own environment plausibly improves a product sold to others. Ask which attributes are captured, how long they persist, whether anything leaves the tenant, and whether it feeds the models.

BB on Clinical and Operational EvidenceNamed deployments with dated outcome figures and enough method to test them, or published research short of independent validation.
Third Party Estimated

Deployment scale is well documented and third party corroborated (reported 20 million plus devices, 2,000+ hospital facilities) and the healthcare product has been named Best in KLAS for Healthcare IoT Security multiple years, an independent recognition. Held back from A because detection efficacy is not published as an independent performance benchmark.

BB on AI Safety and PHI StewardshipCategorical commitments are published, such as no training on customer data, without the retention schedule or the safety engineering behind them.
Vendor Published

The privacy infrastructure is strong and independently checkable: a certified ISO 27701 privacy information management system, a published data processing agreement, a public sub processor list, privacy impact assessments and penetration testing available under NDA. What is not published is what the platform actually retains from a hospital environment.

The product discovers and monitors connected medical devices by observing network activity, so the practical questions are which device and traffic attributes are captured, how long they persist, whether anything leaves the customer tenant, and whether that data feeds the vendor's own models. The last question is live rather than hypothetical, because the AI agent is marketed as trained on data drawn from the installed base. Worth resolving all four in contract.

Regulatory and Compliance
AA on HIPAA and BAA PostureBusiness associate status is stated, the agreement is available, the tier it applies at is clear, and the subprocessors it covers are disclosed.
Vendor Published

Substantially more than an assertion. The HIPAA Privacy Rule policy is published as a downloadable document rather than listed as a badge, and it sits alongside an ISO 27701 certified privacy information management system, which is an audited privacy programme rather than a claim. A data processing agreement is published, a privacy impact assessment is available, and a third party sub processor list is public.

Taken together this is a more complete and more verifiable privacy position than any comparable vendor in this category. The one thing left open is the business associate agreement itself, which is never named or described. Worth confirming whether a BAA is offered as standard and, given the platform monitors clinical network traffic rather than clinical records, whether the vendor takes the position that it processes protected health information at all.

AA on Security Certifications and Trust CenterCertifications named with their type and version and presented as retrievable artefacts, usually through a trust portal a buyer can open without asking.
Vendor Published

The most complete published security position in this category, and unusually the evidence is open rather than gated. The trust center carries SOC 2 Type 2 evaluated across all five trust services criteria, ISO 27001:2022, ISO 27701:2019 for privacy information management, the German BSI C5 cloud controls catalogue, CSA STAR with a listing on the Cloud Security Alliance public registry, and SOCI alignment for Australian critical infrastructure.

TISAX and the Spanish CCN standards are listed as in progress. Two things separate this from peers who hold comparable certificates. The ISO 27001 and ISO 27701 certificates are published as direct downloads rather than released only under an access request, and a product security incident response team operates with a published reporting address and a public vulnerability disclosure dashboard. External audit reports and recent penetration test results are available under NDA. A buyer can verify most of this without contacting sales, which is rare.

CC on FDA and Regulatory StatusNo device claim is made and the product is scoped accordingly. Most administrative and operational products sit here and are not penalised for it, because this axis grades the appropriateness of the positioning rather than possession of a clearance.
Vendor Published

This is a security platform rather than a medical device, so it holds no FDA clearance and needs none. The grade should be read against what does govern the category, not against a clearance that would never apply. On that basis there is genuine substance: a coordinated vulnerability disclosure process with a published reporting channel, a public vulnerability disclosure dashboard maintained by the company's threat research team, partnerships with medical device manufacturers that supply confirmed vulnerability data, and documented alignment with Australian critical infrastructure legislation.

What is missing is the frame a US health system buys against. Nothing published addresses how the platform supports a customer's obligations under federal medical device cybersecurity requirements, health sector cybersecurity performance goals, or recognised health industry practices. Worth asking how the product maps to those specifically.

CC on AI Governance and Bias DisclosureResponsible artificial intelligence is committed to in policy language with no evaluation behind it. Most of the index sits here.
Vendor Published

The gap here is conspicuous because everything around it is so thorough. A trust center carrying eight compliance programmes contains no AI governance content at all, while the company markets an agentic AI security product. The product page raises the training question itself, under a heading stating that what AI is trained on matters, and answers it with scale drawn from the installed base: a model trained on more than a decade of accumulated data across tens of thousands of deployed sites.

That is presented as a competitive advantage rather than as a disclosure, and nothing addresses tenant isolation, whether customer environments can be excluded from model training, or what consent applies. There is also no published evaluation, error rate or false positive characterisation for the agent, and no AI specific governance certification. Human oversight is asserted at the level of positioning. Worth asking whether a customer's environment data trains the shared model and whether opting out is possible.

CC on AI Liability and RecourseMechanisms exist that let someone challenge an output, such as audit trails, source traceability or review before commit, with nothing standing behind the output and no route for the harmed party.
Vendor Published

One provenance choice does real work here and it is worth distinguishing from the usual claims. Device intelligence is credited in part to direct partnerships with medical device manufacturers, who supply confirmed vulnerability information and guidance on exploitability rather than the platform inferring both from network observation.

For a product whose output drives segmentation and patching decisions, intelligence confirmed by the party that built the device is materially better than intelligence deduced about it, and it is the sort of sourcing a buyer can verify by asking which manufacturers participate. That is the basis for the grade. Nothing measures the result.

No accuracy or false positive figures were located for detection or for the agent, no evaluation methodology is published, and superlative framing about the model stands unsupported. The consequence pattern this index recorded for a peer applies here too: a device classified wrongly produces a wrong risk rating and then a wrong network policy, and a policy that isolates a clinical device that needed connectivity is a patient safety event arising from a security control.

No warranty, indemnity or remediation commitment was located. Ask which manufacturers supply confirmed intelligence and what proportion of the catalogue that covers, for classification accuracy, and for the false positive rate at the recommended configuration.

Integration and Deployment
AA on EHR and Interoperability DepthNamed bidirectional integrations with major record systems, verifiable in marketplace listings or integration documentation, with evidence the connection runs in production.
Vendor Published

Broad, named and correctly targeted at the systems that matter in this category, which are not EHRs. Integration spans SIEM through Splunk and Microsoft Sentinel, IT service management through ServiceNow, biomedical inventory and maintenance management through TRIMEDX and Accruent, and enforcement at the firewall and network access control layer.

The biomedical inventory link is the most specific documented in this lane: more than sixty device attributes are passed, including identification, location, operating system, application and firmware versions, serial number, network status, security posture and utilisation. That is the record a biomedical engineering team actually works from, and passing that depth connects the security team's risk view to the people who physically maintain the devices.

There is no EHR integration and none is claimed, which is the right scope here rather than a shortfall. Integrations are named partner connectors rather than standards based interfaces, so a buyer running a platform outside that list should confirm coverage.

BB on Deployment Model and Data ResidencyOptions and residency are stated with isolation or the processing path left open.
Vendor Published

Modular, SaaS based platform that integrates with existing hospital IT and security infrastructure. Deployment model clearly described; specific data residency and tenancy isolation commitments not retrieved this pass.

Commercial
CC on Commercial TransparencyNo price is published and the posture is discoverable: a buyer can establish how the product is sold and what drives the cost before contacting the vendor. Most of the index sits here.
Vendor Published

No pricing, rate card or cost structure is published. The product is described as modular and delivered as software as a service, with cost reduction framed against consolidating multiple point products, but nothing quantifies licensing, whether pricing scales by device count, site or bandwidth, or what a multi site health system would pay. Third party recognition is used in place of commercial detail, including analyst placement and repeated category awards.

That is the norm rather than the exception in this category, where every comparable vendor is equally opaque, so the grade reflects a category wide practice rather than an outlier. Worth requesting the pricing metric early, since device count based licensing behaves very differently from site based licensing across a multi facility system.

AA on Setting and Specialty CoverageWhere the product is validated to operate is named and supported, settings and specialties both, whether the coverage is broad or deliberately narrow.
Vendor Published

Precisely scoped: connected device security for healthcare delivery organizations, spanning IoMT (from IV pumps to ultrasound machines), IoT, and building management systems. Clear, specific coverage.

Comparisons

Compared With

Each comparison carries a written verdict, the buyer conditions that favor each vendor, and a graded side by side. Pairs that cross a category boundary are grouped separately, and their verdicts state where the boundary sits rather than manufacturing a head to head.

Public Record

Announced Deployments

Publicly announced health system deployments and partnerships. This is a record of announcements, not an assessment of deployment success or scale.

Siemens Healthineers (technology partner)
Medigate software underpins Siemens Healthineers ActSafe cybersecurity solution
Commercial

Pricing

Vendor-published figures are labeled as such. Figures labeled “Estimated” are derived from third-party sources and have not been confirmed by the vendor.

Entry Price Pricing Basis BAA Tier Implementation Source
Contact the vendor
Enterprise subscription; per bed or per license models reported Third Party Estimated

Third party coverage indicates an enterprise subscription with some reports of per bed or per license structures. No published rate card; pricing is quote based.