Medical Sector
Patient-connected software, watched like a critical system.
A connected medical device carries the same anatomy as any modern product: an embedded stack, third-party components, radios and a backend. What changes is the stake, and the regulator. Correlens keeps the software inventory, the vulnerabilities and the supplier picture of a device portfolio current, with the records a submission or an audit asks for.
The estate you defend
The hospital network is the vehicle bus of this vertical.
Devices ship with long service lives into environments you do not control, speak radio and network protocols to clinical systems, and run third-party components that age faster than the hardware. The exposure logic is familiar; the consequences are clinical.
- Long-lived fleets. A device generation serves for a decade; its OSS components will not. EOL and patch posture need tracking per release.
- Connected by default. Wireless, network and interoperability interfaces put device software in reach of whatever shares the network.
- A regulated supply chain. Third-party and OSS components carry your obligations once they ship in your device.
What applies
The regulator reads your software list now.
Medical-device cybersecurity has moved from guidance to gate: market access increasingly depends on the quality of your software transparency and vulnerability handling.