Correlens

Medical Sector

Patient-connected software, watched like a critical system.

A connected medical device carries the same anatomy as any modern product: an embedded stack, third-party components, radios and a backend. What changes is the stake, and the regulator. Correlens keeps the software inventory, the vulnerabilities and the supplier picture of a device portfolio current, with the records a submission or an audit asks for.

Medical Sector
A portfolio, inventoriedMonitors, pumps, imaging and companion apps tracked as one component inventory, resolved per device family and release.
SBOMs regulators readSubmission-grade bills of materials: validated for completeness, enriched continuously, exportable when the reviewer asks.
Exploit-aware triageKEV, EPSS and exploit evidence rank findings for patient-impact reality, not raw severity noise.
Postmarket evidenceMonitoring, decisions and suppressions recorded continuously, so postmarket surveillance is a record, not a scramble.

The estate you defend

The hospital network is the vehicle bus of this vertical.

Devices ship with long service lives into environments you do not control, speak radio and network protocols to clinical systems, and run third-party components that age faster than the hardware. The exposure logic is familiar; the consequences are clinical.

  • Long-lived fleets. A device generation serves for a decade; its OSS components will not. EOL and patch posture need tracking per release.
  • Connected by default. Wireless, network and interoperability interfaces put device software in reach of whatever shares the network.
  • A regulated supply chain. Third-party and OSS components carry your obligations once they ship in your device.

What applies

The regulator reads your software list now.

Medical-device cybersecurity has moved from guidance to gate: market access increasingly depends on the quality of your software transparency and vulnerability handling.

US FDA Cyber devices file cybersecurity information in premarket submissions, including a software bill of materials, and must maintain postmarket vulnerability processes.
EU MDR The general safety and performance requirements make secure software design, risk management and update planning part of conformity.
IEC 62304 / 81001-5-1 The software lifecycle and health-software security standards auditors expect your engineering records to follow.
EU CRA Devices under MDR and IVDR are excluded from the CRA itself, but companion apps and separately sold components can still fall in its scope.

Talk to us about your device portfolio.

Book a demo