Security that never gets between a clinician and a patient
Hospitals cannot take the network down to contain an intrusion, cannot
reboot an infusion pump to patch it, and cannot ask a nurse to wait while an agent
finishes a scan. Guardian Sentinel protects protected health information, connected
medical devices and clinical availability at the same time — with response actions
scoped so tightly that care delivery never notices.
$9.77MAverage cost of a healthcare data breachHighest of any sector, fourteenth year running
21 daysMedian disruption to clinical operations after ransomwareDiversions, cancelled procedures, paper charting
6,400Connected devices in a typical 500-bed hospitalGuardian discovery data across 380 health systems
64%Of clinical devices run an operating system past end of supportAnd cannot be patched without revalidation
HIPAA & PHI protection
Know where PHI lives, who touched it, and prove it in an OCR review
Most health systems can name the three systems of record that hold PHI.
Very few can name the 900 places it has been copied to — the research share, the
exported spreadsheet, the vendor's remote-support folder, the departmental drive that
predates the current CIO. Guardian finds it, classifies it, and watches it.
HIPAA Security Rule safeguard mapped to the Guardian Sentinel implementation and the evidence produced for review.
Safeguard
Requirement
Guardian implementation
Evidence
§164.308(a)(1)
Security management process — risk analysis and risk management
Continuous risk scoring across every endpoint, identity, device and data store, weighted by PHI exposure
Dated risk register with change history and remediation timestamps
§164.308(a)(5)
Security awareness — malicious software protection and log-in monitoring
Behavioural malware prevention plus authentication anomaly detection across Epic, Oracle Health and Active Directory
Per-user log-in anomaly record with disposition and analyst rationale
§164.308(a)(6)
Security incident procedures — response and reporting
Automated containment playbooks with scoped blast radius and a written incident narrative per case
Full incident timeline suitable for a 60-day breach notification assessment
§164.312(a)(1)
Access control — unique identification, emergency access, automatic logoff
Identity analytics on shared clinical workstations, including break-glass account monitoring
Break-glass usage report with justification capture and supervisor review
§164.312(b)
Audit controls — record and examine activity in systems containing ePHI
Immutable activity capture across ePHI stores, with query access retained for the full retention period
Tamper-evident audit trail, WORM-stored, exportable per record subject
§164.312(e)(1)
Transmission security — integrity controls and encryption in transit
Egress monitoring with content classification; unencrypted PHI transmission detected and blocked at the endpoint
Blocked-transmission log with file classification and destination
Scroll the table sideways to see every column.
Guardian is available under a Business Associate Agreement in all
deployment models, including sovereign and on-premises. See
compliance for current attestations.
Discovery that finds the copies
Content-based classification identifies PHI by structure and context — MRN patterns,
ICD coding, DICOM headers, HL7 segments — not by folder name. A typical first scan
surfaces 3.4× more PHI locations than the organisation's own data map.
Snooping detection that holds up
Access to a celebrity record, a colleague's chart or a family member's file is
detected through relationship and behavioural context, then routed to privacy
officers with the evidence already assembled.
Research and de-identified data
Limited data sets and de-identified extracts are tracked separately, so a
re-identification risk — a supposedly anonymous extract joined to a directory export —
is flagged before it leaves the institution.
Medical & IoMT device security
You cannot install an agent on a linear accelerator
Clinical devices are FDA-cleared as a configured system. Changing them
invalidates the clearance, so they run unpatched operating systems by design and will
continue to for a decade. Guardian secures them the only way that is defensible:
identify every device, understand its normal behaviour, and enforce the boundary around
it instead of on it.
sentinel://clinical-zones
Zone-appropriate control: agentless for regulated devices, agent-based with change control for clinical apps, full autonomy in corporate.
What agentless device protection actually does
Identifies the device, not just the IP. Manufacturer, model,
firmware revision, clinical function and FDA classification, derived from protocol
behaviour — DICOM, HL7, ASTM, proprietary telemetry.
Baselines behaviour per model, not per device. One infusion
pump's normal is every infusion pump's normal, so a new deployment inherits a
mature baseline on day one.
Correlates with recall and advisory feeds. Devices affected
by an active FDA safety communication or CISA ICS medical advisory are surfaced
by serial number, with compensating controls proposed.
Reconciles with the CMMS. Discovered devices are matched
against your biomedical asset inventory, and the delta — devices on the network
that clinical engineering does not know about — is reported weekly.
Response actions that are safe near a patient
Containment on a clinical device is never process termination or
host isolation. Guardian's device playbooks operate on the network path around the
device, and every action is reversible.
Situation
Action taken
Clinical impact
Device beaconing to a known C2 host
Block that destination only; device stays online
None
Device scanning the clinical VLAN
Restrict to its baseline peer set
None
Unauthorised firmware push detected
Block the transfer, page clinical engineering
None
Confirmed compromise, patient not connected
Quarantine VLAN, pending biomed review
Device unavailable
Confirmed compromise, patient connected
Alert only; containment queued for handover
None
Patient-connected state is read from the clinical system where an
integration exists, and defaults to "connected" where it does not.
Ransomware resilience
The whole fight is decided in the first hour
Healthcare ransomware operators follow a consistent sequence: initial
access through a phishing lure or an exposed remote-access service, credential
harvesting, discovery, backup destruction, then encryption timed for a weekend night
shift. Every stage is observable. The only question is whether anything is watching
fast enough to act between them.
Unmanaged progression uses Guardian Labs incident-response medians for healthcare ransomware
engagements, 2024–2026. Guardian timings are medians across protected health-system estates.
Backup destruction is the tell
Shadow-copy deletion, backup-catalogue tampering and mass snapshot removal are
treated as critical on sight. In healthcare estates this single detection class
precedes 84% of attempted encryption events.
Rollback without touching backups
The sensor journals file changes locally, so encrypted files are restored from the
endpoint itself in minutes. No restore request, no tape, no RPO conversation at
three in the morning.
A rehearsed downtime plan
Guardian's healthcare incident response team runs tabletop exercises against your
actual clinical downtime procedures, so the technical containment plan and the
paper-charting plan are the same plan.
Clinical uptime
Availability is a patient-safety control
Security tooling that degrades a clinical workstation is a clinical
risk. Guardian is engineered for the environments where that matters most: shared
log-ins, roaming sessions, thin clients, imaging workstations moving gigabyte
studies, and carts that must wake and authenticate in under three seconds.
Under 1.8% CPU at steady state on a clinical workstation
image, measured across 240,000 deployed clinical endpoints.
No scan windows and no reboot for updates. Sensor upgrades
are hot-swapped; protection is never off.
Validated against Epic, Oracle Health and MEDITECH reference
configurations, with published exclusion guidance for each.
Roaming-session aware. A clinician tapping into six
workstations in an hour generates one session narrative, not six alerts.
Offline for up to 30 days with full local detection and
enforcement, for ambulances, remote clinics and field units.
42 MBSensor footprint, single binary, no dependencies
0Reboots required for sensor updates
30 daysFull protection while disconnected
2.1 sAdded cold-boot time on a clinical cart image
380Health systems running Guardian in production
Ask any vendor for these numbers on your own image. Guardian
publishes them and will reproduce them in your environment during the proof of
value, on your gold image, measured by your team.
Customer proof
Meridian Health System
Nine hospitals, 214 ambulatory sites, 41,000 staff and 68,000 connected
devices across three states — with a security team of eleven.
WEEK 0
Discovery before deployment
Passive discovery ran for ten days before a single agent was installed. It found
9,100 devices that were not in the biomedical asset inventory, including 34
infusion pumps still reachable from the guest wireless network.
WEEK 6
First live intrusion contained
A vendor remote-support account was used from an unfamiliar location to stage
credential-dumping tooling on a pharmacy server. Guardian contained the identity
and the host in 41 seconds. The vendor was unaware their credentials had leaked.
WEEK 14
Autonomy enabled in corporate
Automatic containment switched on across 28,000 administrative endpoints, with
clinical zones remaining alert-and-approve. Escalations to the security team fell
by 71% in the following month.
MONTH 9
Ransomware attempt, no downtime
An affiliate of a known healthcare-focused ransomware group gained access through
a compromised third-party billing portal. Guardian detected discovery behaviour in
18 seconds and contained the estate before backup enumeration began. Zero
cancelled procedures, zero diversion hours.
Our board asked one question after the incident: how
many patients were affected? The answer was none, and we could prove it in an
afternoon. That is what we bought.
DR
Dr. Elena Reyes
Chief Information Security Officer, Meridian Health System
9,100Unknown devices found before go-live
0 hrsAmbulance diversion caused by security incidents in 24 months
Guardian does not install anything on FDA-cleared medical devices. Those devices
are protected agentlessly, through passive network observation and boundary
enforcement, so their cleared configuration is untouched. Agents are deployed only
on general-purpose computing assets — workstations, servers, VDI images — where the
manufacturer's guidance permits it.
Where a device manufacturer explicitly supports third-party endpoint security,
Guardian publishes a validated configuration for it.
How does this work with Epic, Oracle Health or MEDITECH?
Guardian ships validated exclusion and tuning profiles for each major EHR platform,
developed against reference deployments and refreshed with each vendor release.
Application-tier telemetry is ingested through the platform's log and API connectors,
so break-glass access, mass record export and audit-log tampering are detected as
behaviour rather than inferred from the host.
Our clinical devices run Windows 7 and Windows Server 2008. Now what?
Guardian supports legacy Windows agents where the device manufacturer permits
installation, and protects the rest through segmentation and behavioural monitoring
of the traffic around them. The realistic goal is not patching — it is ensuring an
unpatchable device cannot be reached by anything that has not been explicitly
authorised, and that its behaviour is watched closely enough to notice when it
changes.
Guardian's compensating-control report documents this position in the form your
assessors expect.
Who does clinical engineering talk to when a device is quarantined?
Every device action produces a notification routed by device class to the biomedical
engineering queue you nominate, with the manufacturer, model, serial number, physical
location and the specific behaviour observed. Actions on patient-connected devices
require explicit approval by default, and the approval is captured with the
approver's identity and rationale.
Can Guardian help with the 60-day breach notification assessment?
Yes. Each incident produces a complete narrative — accounts involved, systems
touched, data accessed or exfiltrated, and the specific records implicated where
content classification applies. That narrative is the substantive input to a
four-factor risk assessment, and it is available within hours rather than weeks.
Guardian's incident response team
supports the notification process where you need it.
We are a small critical-access hospital with two IT staff. Is this realistic?
It is the common case. Guardian's managed detection
and response team operates the platform for the majority of hospitals under
200 beds — full 24/7 coverage with a three-minute response SLA, and named analysts
who learn your environment. You keep the decisions that need clinical context; we
handle the queue.
Guardian will run a ten-day passive discovery across your clinical network and hand
you the inventory — every connected device, its risk, and how it differs from your
asset register. You keep the report whatever you decide next.