Medcrypt Appoints Bob Lyle as Chief Revenue Officer

Medcrypt has announced the appointment of Bob Lyle as Chief Revenue Officer (CRO). With nearly 30 years of experience in enterprise cybersecurity, multimedia IP licensing, and both the software and hardware sectors, Bob brings a wealth of expertise to Medcrypt’s leadership team.

In his new role, Bob will oversee all sales, revenue generation, and marketing efforts as Medcrypt continues to expand its offerings within the medical device cybersecurity landscape. His deep knowledge of enterprise cybersecurity solutions and proven success in scaling high-growth startups and global enterprises will be invaluable as Medcrypt aims to further solidify its market position.

Bob joins Medcrypt from Finite State, following its recent acquisition of MergeBase, a venture-backed supply chain cybersecurity startup, where he led revenue growth and business development as CRO. In addition, Bob serves as the Deputy Chair of the GSMA’s Device Security Group (DSG), contributing to the advancement of global standards for device security. Previously, Bob served as CRO of Cybeats, where he played a critical role in growing the company from its first customers to a successful IPO on the Canadian Securities Exchange (CSE: CYBT).

“I’m excited to join Medcrypt at such a pivotal time in the industry,” said Bob Lyle. “With the increasing regulatory focus on medical device cybersecurity, Medcrypt is in a unique position to help manufacturers meet these evolving challenges, and I look forward to contributing to our growth.”

Bob’s career is marked by entrepreneurial leadership, including co-founding and serving as CEO of Valona Labs, an enterprise cybersecurity startup that achieved a successful exit within two years through acquisition by HMD Global/Nokia Mobile. His work has helped create substantial revenue streams and drive successful exits for venture-backed companies, as well as grow innovative business units in large global organizations.

“We are excited to welcome Bob to the Medcrypt team,” said Mike Kijewski, CEO of Medcrypt. “His extensive experience, both as a senior leader in startups and large organizations, aligns with our strategic growth plans. Bob will be instrumental in helping Medcrypt scale and meet the increasing demand for secure medical devices.”

Bob’s addition comes as Medcrypt continues to grow and expand its solutions to protect medical devices from emerging cybersecurity threats.

Source: MedCrypt

Medcrypt Announces Partnership with NetRise

Medcrypt, Inc. announces its partnership with NetRise to address critical cybersecurity challenges in the healthcare industry. This partnership will provide MDMs with a Software Bill of Materials (SBOM) lifecycle management solution that will empower device makers to proactively identify and address potential security risks and ensure the safety and integrity of their medical devices.

In 2021, the White House released an executive order on the growing need for improved cybersecurity, which included the use of (SBOMs “as a formal record containing the details and supply chain relationships of various components used in building software” for each product. The two primary use cases of SBOMs are to identify vulnerabilities from component information within the SBOM and to monitor license usage, especially of open-source software. The value SBOMs provide is two-fold: Supporting R&D teams in the premarket phase as well as supporting postmarket management and vigilance, thus informing cybersecurity activities across teams, including research and development, product quality, and legal teams. For medical device manufacturers, the U.S. Food and Drug Administration (FDA) is mandating that all software-based medical devices must create and maintain an SBOM, and will start refusing submissions that fail to include this information on October 1, 2023.

The collaboration between Medcrypt and NetRise aims to revolutionize medical device security by combining Medcrypt’s expertise in vulnerability identification and management with NetRise’s unparalleled capabilities in generating SBOMs for embedded devices and firmware. This partnership provides medical device manufacturers with a comprehensive solution to safeguard their devices against potential cyber risks throughout their entire lifecycle.

“As with everything in tech, the vulnerability management space is constantly evolving. We chose to partner with NetRise because our technologies have a clear synergy. This partnership allows us to build a medical device-specific workflow that aligns seamlessly with the requirements of key stakeholders in the healthcare industry,” said Mike Kijewski, CEO of Medcrypt. “With NetRise’s offerings integrated into our vulnerability management solution, Helm, we can support a broader range of use cases, ensuring our customers have the most robust and compliant cybersecurity measures in place.”

Medcrypt will integrate NetRise’s SBOM generation capabilities into Helm, extending the support for SBOMs throughout the entire lifecycle of medical devices. NetRise will offer medical device manufacturers the ability to generate, ingest, enrich, manage, and monitor SBOMs, providing critical visibility into the underlying vulnerabilities of their embedded devices and firmware.

“This collaboration brings together NetRise’s industry-leading SBOM generation capabilities with Medcrypt’s extensive experience in the medical device manufacturing space,” said Thomas Pace, CEO of NetRise. “This combination offers the best SBOM lifecycle management solution in the industry, empowering manufacturers to identify and mitigate security vulnerabilities effectively.”

Source: Medcrypt

Medcrypt Announces Partnership with Tidelift to Strengthen Medical Device Security

Medcrypt, Inc. has announced its partnership with Tidelift, a provider of solutions for improving the security and resilience of the open-source software powering modern applications. This partnership will strengthen medical device security by leveraging data to offer advanced security solutions to customers, ensuring devices stay safe throughout their entire lifecycle.

For MDMs, the upcoming U.S. Food and Drug Administration’s (FDA) deadline of October 1 is a critical milestone, mandating the adoption of software bill of materials (SBOM) analysis for all regulated devices, according to Section 524B(b)(3) of the Federal Food, Drug, and Cosmetic Act. To address this challenge, Medcrypt and Tidelift are collaborating to offer MDMs a robust vulnerability management solution that meets stakeholder needs and enables enhanced post-market vigilance. The partnership provides access to share granular data verified by Tidelift’s partner network of independent maintainers, which will ultimately make device makers better equipped to triage vulnerabilities.

By leveraging Tidelift’s data, Medcrypt advances its Helm solution; this partnership expands the data provided to customers, making a significant impact on post-market vigilance.

“We understand the urgency facing medical device manufacturers in meeting the FDA deadline,” said Om Mahida, VP of Product at Medcrypt. “Together with Tidelift, we’re excited to present an enhanced vulnerability management solution that enables MDMs to proactively manage vulnerabilities.”

This collaboration arms MDMs with a powerful security framework capable of withstanding ever-evolving threats. By co-creating a set of evidence for upstream open source package secure development practices and continuously updating these certifications, the joint solution empowers manufacturers to not only meet the regulatory deadline but maintain a dynamic vulnerability program that safeguards medical devices in an evolving threat landscape.

Donald Fischer, co-founder, and CEO of Tidelift, shared the significance of the partnership, saying, “At Tidelift, we’re committed to providing the highest-quality data and tools to our customers. Partnering with Medcrypt allows us to expand our reach and impact in the healthcare industry, enhancing medical device security and raising the bar for cybersecurity standards.”

Source: Medcrypt

Medcrypt Launches New FDA Cybersecurity Readiness Services

Medcrypt, Inc. has announced its latest offering “FDA Cybersecurity Readiness Services” empowering medical device manufacturers (MDMs) to confidently navigate the U.S. Food and Drug Administration’s (FDA) Refuse to Accept (RTA) policy as well as the new Section 524B requirements stemming from the Consolidated Appropriations Act, 2023.

The RTA policy evaluates the acceptability of medical device submissions, focusing on crucial elements, including cybersecurity, and may result in refusal if requirements from the amendment of the Food, Drug, and Cosmetic Act (FD&C Act) are not met. Medcrypt’s comprehensive services also prioritize the FDA’s eSTAR, a now mandatory FDA program that guides manufacturers in documenting and describing to the FDA their cybersecurity efforts for all 510(k) submissions, unless exempted. Both initiatives were issued by the FDA with an effective date of October 1, 2023.

Medcrypt’s FDA Cybersecurity Readiness Services streamline MDMs’ FDA journey, catering to those preparing, submitting, or already encountering issues:

  1. FDA Cybersecurity Filing Readiness Survey: This free assessment for MDMs helps gauge submission readiness with survey questions aligned with the FDA guidance, including RTA/eSTAR and provides valuable insights into the risks to acceptance.
  2. FDA Cybersecurity Filing Remediation: For MDMs who do not pass the FDA Filing Readiness Survey or have received an FDA refusal, Medcrypt’s experts can help identify gaps and create a prioritized plan to rectify issues, ensuring the submission becomes acceptable.
  3. FDA Cybersecurity Submission Readiness: Aimed at MDMs with submissions either already under FDA review or planned for the near future, this service offers a comprehensive review using MedCrypt’s unique framework to ensure cybersecurity compliance.
  4. Hold Letter Cybersecurity Response: In the event of an FDA hold letter, Medcrypt provides immediate guidance to navigate the response process effectively.

“We developed the FDA Cybersecurity Readiness Services to address the growing demand from medical device manufacturers seeking guidance through the complex and evolving submission process. Our goal is to equip MDMs with comprehensive insights into cybersecurity gaps, enabling them to prioritize and manage these gaps efficiently,” Naomi Schwartz, senior director of quality and safety at Medcrypt.

Seth Carmody, VP of Regulatory Strategy at Medcrypt, shared, “Our program is led by experts who have previously held cybersecurity roles at the FDA, worked in medical device manufacturing, or comparable industries. This expertise ensures that our services meet the highest standards and help our customers successfully navigate the FDA’s stringent requirements.”

For MDMs, these services streamline the submission process, saving time and fostering confidence in meeting FDA requirements. Regulators also benefit from better-organized submissions, adhering to guidance and providing contextualized cybersecurity design and validation details as expected by the FDA. Medcrypt’s primary objective is to support MDMs facing new submissions under cybersecurity draft guidance and needing to comply with the amendment to the FD&C Act (Section 524B). In addition to assessing the pivotal role of FDA Cybersecurity Readiness Services, Medcrypt’s supporting product portfolio includes additional innovative products that address vulnerability management, network encryption, and cryptography.

Interested in ensuring your medical devices comply with FDA cybersecurity expectations (both requirements per the Act and recommendations per cybersecurity guidance)? Inquire with MedCrypt to learn more about our FDA Cybersecurity Readiness Services, designed to guide medical device manufacturers through the new 510(k) eSTAR submission requirement and the cybersecurity Refuse to Accept (RTA) policy and streamline the path to regulatory approval.

Source: Medcrypt

MedCrypt Announces Partnership with Kansas State University

MedCrypt, Inc. has partnered with Kansas State University by providing a grant to drive advancements in quantifying regulatory and cybersecurity risk in the medical field. This summer, the partnership will aim to enhance medical device cybersecurity research by focusing on validating the tools used to assess client risk, incorporating a holistic approach, and seamlessly integrating technical elements and public and regulatory policy considerations.

The collaboration, led by Dr. Eugene Vasserman (KSU) and Dr. Seth Carmody (MedCrypt’s VP of Regulatory Strategy), aims to address the varied challenges of assessing and quantifying cybersecurity risks associated with interconnected medical devices and their impact on clinical care delivery, patient safety, and business continuity. The MedCrypt and KSU collaboration brings together premier research institutions to tackle challenging problems faced by MDMs. Additionally, it provides the possibility for working together between MedCrypt, KSU, and Tufts University. With the U.S. Food and Drug Administration’s (FDA’s) decision to refuse future device submissions which don’t meet minimal cybersecurity requirements by October 1, there is a call to action for Medical Device Manufacturers (MDMs) to prioritize cybersecurity.

The research will combine a comprehensive qualitative and quantitative approach that considers risks from both business and technical perspectives. I like prior “one size fits all” work, which includes analyzing the manufacturer-specific approach to cybersecurity during product line engineering and product design, product requirement and risk evaluation including compensating controls, verification and validation procedures, and post-market monitoring and support. By integrating broader cybersecurity practices such as threat modeling, vulnerability monitoring, and incident response, MedCrypt and KSU can work towards enhancing the security posture of medical devices and manufacturers. The urgency to comply with the FDA’s requirements by October 1 provides a compelling incentive for MDMs to engage with MedCrypt. Through the partnership, MedCrypt and KSU can leverage academic best practices in medical device cybersecurity while applying real-life constraints that MDMs experience every day. By doing so, they will contribute to the overall safety and integrity of interconnected medical devices, ultimately improving patient care, reducing the risk of cyber threats in healthcare environments, and placing MDM-level cybersecurity risk estimation on a firmer footing.
“Partnering with Kansas State University allows us to focus on a critical research initiative,” said Seth Carmody. “This partnership validates the value of our risk assessment tools and strengthens our capacity to tackle evolving challenges in medical device cybersecurity. By leveraging academic expertise, industry insights, and an understanding of new rules and regulations, we are confident that our joint efforts will lead to significant advancements.”

Dr. Vasserman brings extensive experience in the security of distributed systems, cyber-physical systems, and the socio-technical aspects of security. As the director of the Kansas State University Center for Cybersecurity and Trustworthy Systems (K-CaTS), he has played a pivotal role in advancing cybersecurity education and has been involved in multiple medical device cybersecurity projects, from the MDM side as well as through collaboration with the FDA. Dr. Vasserman has also received several notable recognitions, including the Commissioner’s Special Citation in 2018 as a member of the St. Jude Medical Cybersecurity Response Team, the Outstanding Service Award in 2020 as a member of the Cardiac Monitor Cybersecurity Review Team, and the Group Recognition Award in the same year as a member of the URGENT/11 Response Team.

“I am honored to lead this research and work closely with MedCrypt to address challenges in medical device cybersecurity,” said Dr. Eugene Vasserman. “Our research will not only provide a holistic understanding of cybersecurity risk in the medical field but also contribute to developing standards and policies that will help strengthen the safety and integrity of medical devices. Together, we aim to make lasting improvements to the industry and protect patients from ever-evolving cyber threats.”

The research team will develop a platform that is both customizable and expandable, integrating qualitative and quantitative metrics. This platform will provide actionable and prioritized recommendations for addressing current and future technological, regulatory, and business risks. In terms of advancing science, the project will result in research papers and software artifacts that disseminate new knowledge and provide a foundation for others to build upon. Customers of MedCrypt can anticipate a swift integration of research findings into their products and services. This integration will bring immediate benefits, such as significantly enhanced proactive risk management, specifically tailored to the processes and needs of MDMs, which will include ongoing monitoring, testing, and updating of security controls. These practices not only help meet regulatory requirements but also effectively reduce cybersecurity risks while simultaneously lowering costs by prioritizing the mitigation strategies most likely to be effective and avoiding those that may yield little long-term benefit. Ultimately, customers can have increased confidence in the security of medical devices, which leads to increased trust between healthcare providers, patients, and the technology they rely on.

Source: MedCrypt

MedCrypt Announces Partnership with Stratigos Security

MedCrypt, Inc. has announced its partnership with Stratigos Security. Together, they offer a suite of third-party assessment and advisory services, with specialized penetration tests for medical device makers to assure the safety and effectiveness of their devices.

In March 2023, the Food and Drug Administration (FDA) announced that beginning October 1, 2023, it will “refuse to accept” medical devices that fail to meet cybersecurity requirements, further highlighting the need for developers to design and maintain products that align with the FDA’s pre- and post-market guidance.

Conventional penetration tests are a poor fit for assessing medical device safety and effectiveness risks. The MedCrypt-Stratigos partnership provides specialized penetration testing specifically designed for medical device manufacturers. These specialized tests simulate attack techniques to identify reasonably foreseeable cybersecurity issues, providing a vital source of evidence to inform risk management. The results and reports are clear, practical, and can be submitted for regulation, making it easier to bring the devices to market and reducing post-market problems. Mature organizations build these tests into their product development framework from the outset, continuing through the lifetime of the device.

“We are excited to team up with Stratigos,” stated Mike Kijewski, CEO of MedCrypt. “It is imperative for device makers to have access to world-class testing resources. Through our partnership with Stratigos, device makers can rely on our combined expertise and insights to ensure the security and integrity of their critical medical devices.”

This partnership provides manufacturers with pertinent identification of vulnerabilities and potential risks to patient safety and data privacy, offering independent evidence to regulators and third parties through regulatory-ready pentest reports. MedCrypt’s comprehensive cybersecurity offerings satisfy the FDA’s and global regulators’ secure product development framework requirements, ensuring healthcare organizations comply with regulations and proactively approach medical device cybersecurity.

“Our team of experienced cybersecurity experts, combined with MedCrypt’s deep understanding of medical device security, enables us to deliver comprehensive and effective penetration testing and security assessments that are tailored to the unique requirements of medical devices. We are committed to helping healthcare organizations mitigate cyber risks and safeguard patient safety,” said Beau Woods, the CEO of Stratigos Security.

Key members in this initiative are:

  • Beau Woods, CEO of Stratigos Security and the co-founder of the Biohacking Village: Device Lab at DEF CON (the world’s biggest hacking conference). Additionally, Beau served as an Entrepreneur in Residence with the FDA, Senior Advisor with the US Cybersecurity and Infrastructure Security Agency (CISA), and has published works as an author and co-author.
  • Naomi Schwartz, senior director of quality and safety at MedCrypt. Her background includes working at the FDA to evaluate software and cybersecurity for the world’s first regulated Automated Insulin Delivery (AID) System and developing Class II regulatory pathways for the three major components of AID systems, a game-changer for supporting patients with insulin-dependent diabetes.
  • Seth Carmody, vice president of regulatory strategy at MedCrypt. Prior to MedCrypt, Carmody worked as the Cybersecurity Program Manager in the Office of the Center Director, Emergency Preparedness/Operations and Medical Countermeasures, within the FDA’s CDRH.
  • Paulino Calderon is co-author of Practical IoT Hacking, Paulino has developed open-source hardware and software tools such as Nmap (one of the top security tools), DICOM fuzzing libraries, CatSniffer, and OWASP IoT Goat.
  • Lukas Kuzmiak specializes in complex systems testing, from large networks to wearable devices including hardware and firmware security for embedded systems with an emphasis on communication layer and custom protocol analysis.
  • Michelle Thompson specializes in embedded systems testing, including communications protocol testing, hardware security testing, privilege model analysis, and firmware review.

Source: MedCrypt

MedCrypt Joins Microsoft Azure Marketplace and Launches Guardian

MedCrypt, Inc. announces that it was selected to participate in Microsoft Azure for Startups, a global program dedicated to accelerating the trajectory of startups through access to a network of technology, mentorship, and business support. As part of its participation, MedCrypt has also announced the launch of its product, Guardian, an embedded library that makes it easy to build cryptography, validate integrity, and keep data private, on the Azure Marketplace.

“We’re excited to join the Microsoft Azure Marketplace ecosystem as it is a great avenue for startups to discover technologies and platforms that enable secure innovation,” said Mike Kijewski, CEO of MedCrypt. “The Food and Drug Administration (FDA) requires manufacturers to include security features into their devices and our collaboration with Microsoft is now making Guardian available to its medical device manufacturing customers, bringing cybersecurity closer to these devices.”

As administrators and operators of medical devices, hospitals must comply with certain Health Insurance Portability and Accountability Act (HIPAA) security and privacy requirements. Additionally, FDA guidelines also mandate devices to be secured to ensure safety. Both of these conditions can be met by using encryption. Integrating connected medical devices across healthcare poses cybersecurity risks. In response, the FDA released updates to its premarket cybersecurity guidance and postmarket cybersecurity guidance, which establish expectations related to the design and maintenance of medical devices.

This collaboration announcement will provide medical device manufacturers with a seamless experience in implementing cryptography in support of those requirements while also furthering MedCrypt’s reach to Microsoft’s existing customer base. With streamlined deployment and management, customers can now take advantage of the scalability and security provided by Azure. MedCrypt’s Guardian meets the needs of software-enabled and connected medical devices with an opportunity to adopt improved security tooling and provides device manufacturers a helpful starting point when building with the Azure Marketplace.

“We are thrilled to be added to the Microsoft Azure platform, as it’ll help medical device manufacturers adopt and deploy our services more easily, which directly impacts how secure their devices will be,” said Vidya Murphy, chief operating officer at MedCrypt. “Launching on the Azure Marketplace is the next step in enabling more medical device companies to drastically improve their security programs, which is incredibly important given that 53% of connected medical devices and other internet of things (IoT) devices in hospitals were found to have known critical vulnerabilities.”

“Customers around the globe are using Microsoft Azure and we are glad to see a partner like MedCrypt deliver a Cryptography API tool to help manufacturers optimize security on medical devices,” said Sally Frank, worldwide lead for health and life sciences, Microsoft for Startups. “Medical device manufacturers are switching to Azure for product support and having Guardian, MedCrypt’s Cryptography API tool fits a need for the marketplace.”

MedCrypt currently provides enhanced security products and services for seven of the top 10 medical device manufacturers and startups and mid-sized companies, including the leading manufacturers of surgical robotics technologies and virtual reality applications for minimally invasive surgery.

In early November 2022, MedCrypt announced a $25M Series B funding round, followed by additional investment from Dexcom Ventures in January 2023. The company will use these funds to scale its cryptography, behavior monitoring, and vulnerability management products across various medical devices, such as glucose monitors and other diabetes devices.

Source: MedCrypt

MedCrypt Expands Cybersecurity Partnerships with Leading Diabetes Technology Companies

MedCrypt, Inc., has announced its work with six diabetes care technology providers, including the leading manufacturers of insulin pumps and continuous glucose monitors, to enable the next generation of diabetes technology to get to market faster with security built in by design.

Approximately 37.3 million Americans live with diabetes and of that, it’s estimated that 350,000 use insulin pumps on a daily basis. The Food and Drug Administration (FDA) has tracked the potential cybersecurity risks associated with the use of insulin pumps and glucose monitors, noting that unauthorized users could gain access to these devices while the users are pairing with other system components such as smartphones. Due to the high-benefit nature of these devices, they need to be reliable and trustworthy. Many diabetes devices are connected, increasingly interoperate, and deliver life-saving dosing, meaning it is crucial that they only work with authorized and authenticated parts.

“Diabetes is a constant disruption in the lives of millions of people, and digital tech brings peace and convenience so that people living with diabetes can control their own health,” said Mike Kijewski, CEO of MedCrypt. “But digital innovation requires security innovation, too. The devices themselves need to ‘trust’ each other through the binding of a unique cryptographic certificate to a device. This area of digital technology couldn’t be more closely in line with why MedCrypt exists. We are solving the unique security challenges in digital healthcare – at scale – so that our customers can confidently build the clinical innovations of the future.”

“The need for proactive cybersecurity within diabetes devices is growing; with the benefits of connected devices comes the potential to expose multiple connected devices to cyber threats,” said Naomi Schwartz, Senior Director of Quality and Safety at MedCrypt. Her background includes working at the FDA to evaluate software and cybersecurity for the world’s first regulated Automated Insulin Delivery (AID) System and developing Class II regulatory pathways for the three major components of AID systems, a game-changer for supporting patients with insulin-dependent diabetes. “Data indicates that physicians and pharmacists in hospitals are thinking about security and that they need clearer information about privacy, security & data sharing before prescribing diabetes tech to their patients. But with this in mind, healthcare providers can’t be specialists in the technology itself and the potential privacy issues. They need a specialist to provide security and privacy assurances; MedCrypt is empowering companies to move faster, designing better, more secure, connected devices, allowing practitioners to prescribe devices without concern about the security of connectivity.”

“People living with diabetes are the best experts in their chronic condition. They live with these devices every day; we couldn’t possibly know more about the impact of their devices than they do,” said Shannon Lantzy, MedCrypt’s vice president of consulting. “We understand how important interoperability is. MedCrypt partners with manufacturers to build technology that provides trust, transparency, interoperability, and choices.”

MedCrypt currently provides enhanced security products and services for seven of the top 10 medical device manufacturers and startups and mid-sized companies, including the leading manufacturers of surgical robotics technologies and virtual reality applications for minimally invasive surgery.

In early November 2022, MedCrypt announced a $25M Series B funding round, followed by additional investment from Dexcom Ventures in January 2023. The company will use these funds to scale its cryptography, behavior monitoring, and vulnerability management products across various medical devices, such as glucose monitors and other diabetes devices. For more information about MedCrypt and its suite of security solutions, please visit medcrypt.com.

Source: MedCrypt

MedCrypt Announces Additional Series B Investment from Dexcom Ventures

MedCrypt, Inc. has announced additional funding from Dexcom Ventures, the corporate venture capital arm of Dexcom. This extension follows MedCrypt’s Series B funding round in November 2022 with investments from Intuitive Ventures, Johnson & Johnson Innovation – JJDC, Inc. (JJDC), among others, bringing the company’s funding to date to $36.4 million. 

“Diabetes care management is one of the main categories of healthcare innovation that is highly dependent on connectivity; consequently, it is one of the main categories heavily scrutinized by the FDA,” said Mike Kijewski, CEO of MedCrypt. “The promise of software in a device can only be achieved when the cybersecurity posture of the device is secure and effective in the threat landscape. MedCrypt has built a cybersecurity platform for all medical devices – for things as small as pacemakers and insulin pumps or as large as surgical robots – and we are honored to be backed by Dexcom Ventures as we continue our push for better device security.”

The global wearable medical device market size is currently valued at $21.3 billion and is expected to grow 28% by 2030. Cybersecurity remains one of the biggest hurdles for connected devices across all areas of healthcare, including the diabetes industry. Dexcom Ventures makes investments to ensure security and reliability in the software and connectivity of interoperable medical devices. 

“As a market leader in diabetes care management, Dexcom understands the value of software and connectivity when innovating the patient experience,” said Naomi Schwartz, Senior Director of Quality and Safety at MedCrypt. Her background includes working at the FDA to evaluate software and cybersecurity for the world’s first regulated Automated Insulin Delivery (AID) System and developing Class II regulatory pathways for the three major components of AID systems, a game-changer for supporting patients with insulin-dependent diabetes.

“We are proud and excited to invest in MedCrypt as they are leading the charge in building cybersecurity technologies and infrastructure for life-saving medical devices,” said Steve Pacelli, Executive Vice President, and Managing Director, Dexcom Ventures. “Cybersecurity has always been a priority for Dexcom and we have seen it become a top priority for healthcare technology companies across many care modalities. We’re excited to see MedCrypt introduce a disruptive solution for these markets.”

In 2022, MedCrypt deployed partnerships with 18 new medical device manufacturers that are committed to improving cybersecurity in healthtech. These additional funds will be used to grow MedCrypt’s engineering team to support this growing demand for cybersecurity in devices – across all products – remaining aligned with requirements set by the FDA and the cybersecurity provisions in the latest Consolidated Appropriations Act, 2023.

MedCrypt currently provides enhanced security products and services for seven of the top 10 medical device manufacturers as well as startups and mid-sized companies, including the leading manufacturers of surgical robotics technologies and virtual reality applications for minimally invasive surgery. 

Source: MedCrypt