Start from a neutral baseline and add what matters to you. Criteria are labeled by source — the platform baseline is architecture-neutral; buyer-contributed criteria are shown separately.
This evaluation is stored in your browser only. We cannot see it, and it is not tied to any account. Save it to a link or create an account to keep it across devices — you can export it at any time either way.
Signing up adds sharing with your team, sending this as an RFP to vendors, and private document sharing. Nothing above is taken away, and nothing here is sent anywhere until you choose to.
Passive, non-intrusive discovery is essential in this category since agents often can't be installed on regulated medical devices without re-certification; ask specifically how device identification works without touching the device itself.
Medical-device-specific vulnerability intelligence (FDA safety communications, manufacturer-specific advisories) is materially more relevant than generic CVE feeds alone; ask for a concrete example of a medical-device-specific advisory the platform surfaced.
Patient-safety-aware risk scoring, distinct from generic IT severity, is a category-defining requirement; the vendor should also address realistic compensating controls (network segmentation) for devices that genuinely can't be patched quickly.
Since many medical devices can't be patched on a normal IT timeline, segmentation is often the primary practical control; automated, device-specific segmentation policy generation is more useful than generic manual VLAN planning.
No buyer-contributed criteria yet
Verified buyers can suggest criteria (anonymized before pooling).
Pre-built, healthcare-specific compliance reporting saves real audit effort; ask for a specific named framework the platform maps to rather than a generic 'healthcare-ready' claim.
Unlike generic IT scanning, disruption risk in this category has direct patient-safety consequences; insist on a clear answer about passive-only monitoring and any real-world incident history, not just a general safety assurance.
Look for transparent, predictable per-facility scaling economics; medical-device deployments often span many distributed facilities with real budget-risk implications if pricing isn't clear upfront.
A compromised medical device carries direct patient-safety risk that a generic IT IR team may not be equipped to handle safely — ask specifically about clinical-safety-aware response expertise and a real engagement track record.
Direct manufacturer coordination is a materially more scalable remediation path than the customer independently chasing every device maker for every finding — ask for evidence of real, established relationships.
Trend-over-time reporting is a distinct capability from a real-time device dashboard — confirm this exists as a maintained, exportable report, particularly relevant given healthcare's regulatory reporting burden.
Look for genuine integration into a unified asset view; a standalone medical-device dashboard disconnected from the broader asset-inventory picture creates real reconciliation burden.
A vendor should give an honest answer about whether smaller/remote facilities get materially weaker coverage — a common real gap for large multi-facility health systems.
The cost asymmetry of false positives is far higher for medical devices (a false alarm can disrupt patient care) than in IT — a vendor should have a clinical-context-aware answer, not a generic IT-derived accuracy figure.
A complete medical-device vulnerability map is an especially high-stakes target given direct patient-safety implications — role-based access control over this specific asset is an often-overlooked consideration.