Healthcare Cybersecurity
M

MedCrypt

Cybersecurity for MEDICAL DEVICE MANUFACTURERS rather than for hospitals, which makes this the only vendor in the index addressing the upstream half of the connected device problem. Where Claroty, Asimily and Ordr help health systems secure devices already deployed on their networks, MedCrypt helps the companies building those devices meet regulatory security obligations before and after market. The regulatory context is what makes this a real category rather than a niche: FDA cybersecurity expectations moved from guidance to enforceable statutory mandate under Section 524B of the Food, Drug and Cosmetics Act via the PATCH Act, with requirements fully effective from October 2023 and a Refuse to Accept policy meaning inadequate cybersecurity documentation can block a submission outright. Manufacturers must submit a Software Bill of Materials, identify known vulnerabilities including those in CISA's Known Exploited Vulnerabilities Catalog, provide safety and security risk assessments per vulnerability, and maintain postmarket monitoring for the life of the device. The flagship product Helm manages SBOM generation, validation and vulnerability tracking across a device portfolio, and its central function is determining which vulnerabilities are actually RELEVANT to a given device rather than listing every CVE matching a component. It draws exploitability intelligence from EPSS, CISA KEV, ExploitDB, Metasploit, NVD and CWE Top 25, applies AI to detect which technology stacks a vulnerability affects in order to suppress false positives, generates short-term mitigations and upgrade paths, and produces FDA-ready SBOM, VEX and VDR reports. Auto-rescoring tracks changes in exploitability and fixability over time. The wider portfolio covers cryptography and device monitoring supporting FDA Secure Product Development Framework implementation. The company publishes substantial regulatory analysis, including work on 2026 FDA premarket deficiency trends, and states it collaborates with regulatory bodies on standards.

Last VerifiedJuly 21, 2026
Compare MedCrypt with other vendors
Founded
Headquarters
San Diego, California, United States
Categories
healthcare-cybersecurity, healthcare-admin-automation
Assessment

Capability Axes

AI Capability
AI Centrality
C
Vendor Published

Deliberate C, and the honest grade despite prominent AI marketing. The core of Helm is a rules engine plus curated third-party exploitability data: component matching via an alias rules engine, lifecycle rules automating end-of-support tracking, and severity and exploitability drawn from EPSS, CISA KEV, ExploitDB, Metasploit, NVD and CWE Top 25. Those are external feeds and deterministic matching, not models. The genuine AI is narrower than the marketing implies: automated detection of which technology stacks a vulnerability affects, false positive suppression, and machine learning based risk mitigation recommendations. Real, but a layer on top. The actual moat is regulatory expertise and the medical-device-specific framing of general software supply chain tooling, which is why the company competes on being purpose-built for manufacturers rather than on model quality. Same principle applied to Reveleer, the credentialing lane and Censinet.

Autonomy and Oversight Model
B
Vendor Published

Automates assessment and scoring while leaving remediation decisions with the manufacturer's product security and regulatory teams. Auto-rescoring continuously monitors changes in vulnerability exploitability and fixability, with a reported reduction in assessment time of at least 90 percent, and bulk rescoring and bulk remediation import operate across a product portfolio. That bulk operation model is the notable autonomy feature and also the risk worth naming: applying a rescore or remediation decision across many device versions at once is efficient but concentrates the consequence of a wrong judgement. Graded B rather than A because no confidence threshold or human review gate is described for the AI-generated stack detection and recommendations.

Model and Technology Transparency
A
Vendor Published

The strongest transparency position in the cybersecurity lane, earned by naming its data sources precisely rather than describing proprietary intelligence. Helm's exploitability assessment is explicitly built on EPSS, CISA KEV, ExploitDB, Metasploit, NVD and CWE Top 25, all publicly identifiable sources a buyer can evaluate independently, and it supports CVSS 2, CVSS 3.x and EPSS scoring. The rules engine behaviour is documented publicly, including alias rules for component matching and lifecycle rules for end-of-support automation, and the company maintains public product documentation rather than gated materials. Naming your inputs allows a customer to reason about what the tool can and cannot know, which almost no vendor in this lane permits.

Clinical and Operational Evidence
C
Vendor Published

All performance evidence is vendor generated. The company publishes case studies stating Helm outperforms commercial and open source competitors on speed and accuracy, and claims at least 90 percent reduction in assessment time, but no independent benchmark, named customer result or disclosed methodology was located. Competitive case studies authored by the vendor comparing itself to unnamed competitors are the weakest evidence form in this index. That said, the regulatory analysis the company publishes, including work on FDA premarket deficiency trends, is substantive industry contribution even though it is not product evidence.

AI Safety and PHI Stewardship
A
Vendor Published

Structurally the cleanest PHI position of any vendor in this index, and it is worth stating why rather than treating it as absence of risk. MedCrypt's customers are device manufacturers, and the data it processes is software bills of materials, component inventories and vulnerability records. It does not touch patient data, hospital networks or clinical systems at all. There is no PHI surface to steward. Note one genuine security consideration the company itself raises, which is unusually candid: it warns that while the FDA recommends SBOMs be shared with customers for transparency, disclosure creates additional attack surface by revealing component details to threat actors, and states manufacturers must weigh that trade-off. Flagging the downside of a regulator's own recommendation is an admission against the compliance-tooling interest.

Regulatory and Compliance
HIPAA and BAA Posture
Not rated

Not applicable in the usual sense. The company does not process protected health information, since its customers are device manufacturers and its data is software composition and vulnerability information. No BAA would ordinarily be required for this relationship.

Security Certifications and Trust Center
Not rated

No third party attestation such as SOC 2 Type II or ISO 27001 was retrieved at the time of review. As with every other vendor in this lane, a security company without a published security attestation is a notable gap, and it is arguably sharper here since customers are entrusting it with a complete map of the software composition and known weaknesses of their devices, which is a high-value target in itself.

FDA and Regulatory Status
A
Regulatory Filing

Not itself an FDA regulated product, but graded A because regulatory alignment is the entire product proposition and it is executed with unusual precision. The offering maps directly to enforceable obligations: FDA Secure Product Development Framework implementation, SBOM generation and maintenance meeting NTIA minimum elements plus level of support and end-of-support dates per component, per-vulnerability safety and security risk assessments including CISA Known Exploited Vulnerabilities, postmarket monitoring for device lifetime, VEX and VDR reporting, the 12-document requirement for eSTAR submissions, and CISA incident reporting readiness. The company correctly frames the 2025 shift from guidance to enforceable statutory mandate under Section 524B and the Refuse to Accept policy, and publishes analysis of actual FDA premarket deficiency patterns. Few vendors in this index demonstrate this depth of regulatory literacy, and here it is the substance rather than a compliance claim.

AI Governance and Bias Disclosure
Not rated

No governance framework or model evaluation disclosure located. The relevant risk is false negatives rather than demographic bias: if AI-driven technology stack detection incorrectly determines a vulnerability does not affect a device, that vulnerability is suppressed from the manufacturer's view and may reach an FDA submission undisclosed, which the company's own analysis identifies as a leading cause of premarket deficiencies. No published false negative rate or validation of the suppression logic was located.

Integration and Deployment
EHR and Interoperability Depth
B
Vendor Published

EHR integration is irrelevant to this buyer; the meaningful surface is the manufacturer's development toolchain. Helm offers an API and integration options to continuously ingest SBOM updates, supports manual creation and upload, and provides one-click generation of FDA-ready SBOM, VEX and VDR reports, with bulk remediation import across a device portfolio. Graded B rather than A because no named CI/CD, build system or product lifecycle management integrations were located, and continuous SBOM ingestion in a regulated development environment depends heavily on those connections.

Deployment Model and Data Residency
Not rated

Cloud platform by implication with public product documentation available, but no hosting architecture, deployment option or data residency disclosure was located at the time of review.

Commercial
Commercial Transparency
C
Vendor Published

No pricing published and no pricing basis disclosed; the site routes to a demo request. The natural pricing unit would be per device or per product line under management, which matters because a manufacturer with a broad portfolio faces very different economics than one with a single device, and none of that is public.

Setting and Specialty Coverage
B
Vendor Published

Deep within a single well-defined buyer type rather than broad. Serves medical device manufacturers across R&D and engineering, quality and regulatory affairs teams handling 510(k), PMA and De Novo submissions, and product security and risk functions, spanning premarket submission through postmarket lifetime monitoring. The portfolio covers cryptography, SBOM and vulnerability management, and device monitoring. Graded B rather than A because coverage is confined to the manufacturer side with no health system or clinical deployment, and the index grades it on the same scale as vendors serving multiple settings.

Commercial

Pricing

Vendor-published figures are labeled as such. Figures labeled “Estimated” are derived from third-party sources and have not been confirmed by the vendor.

Entry Price Pricing Basis BAA Tier Implementation Source
Not published
Undisclosed. Likely per device or product line; the commercial case is regulatory submission risk rather than labour savings. Vendor Published

No pricing published and no pricing basis disclosed; the site routes to a demo request. The likely unit is per device or per product line under management, which matters a great deal in this buyer segment because a manufacturer with a single connected device faces entirely different economics than one managing a portfolio of dozens across multiple product families and software versions. Buyers should establish whether pricing scales by device, by product family, by SBOM count or by seat, and how versions are counted, since Helm's bulk rescoring and bulk remediation features exist precisely because portfolios contain many versions of the same product. The commercial case here is unusual and worth framing correctly: this is not primarily a cost-saving purchase, it is regulatory risk mitigation. Under Section 524B and the Refuse to Accept policy, inadequate cybersecurity documentation can block a premarket submission outright, so the relevant comparison is against the cost and schedule impact of a rejected or delayed FDA submission rather than against the labour cost of manual vulnerability assessment. The company's reported claim of at least 90 percent reduction in assessment time is the labour argument, but it is vendor-generated without methodology and is the weaker half of the case. Also worth confirming: whether the cryptography and device monitoring products are licensed separately from Helm, since the portfolio spans several distinct capabilities supporting FDA Secure Product Development Framework implementation.

AI Health Index

An independent reference for evaluating AI vendors in healthcare. No vendor pays for inclusion, placement, or rating.

Index Status
Last index update
July 21, 2026
The AI Health Index is an editorial reference, not a regulatory body. Vendor data is verified against published sources and public regulatory filings. Figures labeled “Estimated” have not been confirmed by the vendor. See the Methodology page for evaluation standards and limitations.
© 2026 AI Health Index
3801 N Capital of Texas Hwy, Ste E240 · Austin, TX 78746