Healthcare & life sciences

Security that never gets between a clinician and a patient

Hospitals cannot take the network down to contain an intrusion, cannot reboot an infusion pump to patch it, and cannot ask a nurse to wait while an agent finishes a scan. Guardian Sentinel protects protected health information, connected medical devices and clinical availability at the same time — with response actions scoped so tightly that care delivery never notices.

  • HIPAA Security Rule
  • HITRUST CSF
  • HHS HPH CPGs
  • NIST 800-66
  • FDA premarket guidance
$9.77M Average cost of a healthcare data breach Highest of any sector, fourteenth year running
21 days Median disruption to clinical operations after ransomware Diversions, cancelled procedures, paper charting
6,400 Connected devices in a typical 500-bed hospital Guardian discovery data across 380 health systems
64% Of clinical devices run an operating system past end of support And cannot be patched without revalidation

HIPAA & PHI protection

Know where PHI lives, who touched it, and prove it in an OCR review

Most health systems can name the three systems of record that hold PHI. Very few can name the 900 places it has been copied to — the research share, the exported spreadsheet, the vendor's remote-support folder, the departmental drive that predates the current CIO. Guardian finds it, classifies it, and watches it.

HIPAA Security Rule safeguard mapped to the Guardian Sentinel implementation and the evidence produced for review.
Safeguard Requirement Guardian implementation Evidence
§164.308(a)(1) Security management process — risk analysis and risk management Continuous risk scoring across every endpoint, identity, device and data store, weighted by PHI exposure Dated risk register with change history and remediation timestamps
§164.308(a)(5) Security awareness — malicious software protection and log-in monitoring Behavioural malware prevention plus authentication anomaly detection across Epic, Oracle Health and Active Directory Per-user log-in anomaly record with disposition and analyst rationale
§164.308(a)(6) Security incident procedures — response and reporting Automated containment playbooks with scoped blast radius and a written incident narrative per case Full incident timeline suitable for a 60-day breach notification assessment
§164.312(a)(1) Access control — unique identification, emergency access, automatic logoff Identity analytics on shared clinical workstations, including break-glass account monitoring Break-glass usage report with justification capture and supervisor review
§164.312(b) Audit controls — record and examine activity in systems containing ePHI Immutable activity capture across ePHI stores, with query access retained for the full retention period Tamper-evident audit trail, WORM-stored, exportable per record subject
§164.312(e)(1) Transmission security — integrity controls and encryption in transit Egress monitoring with content classification; unencrypted PHI transmission detected and blocked at the endpoint Blocked-transmission log with file classification and destination

Scroll the table sideways to see every column.

Guardian is available under a Business Associate Agreement in all deployment models, including sovereign and on-premises. See compliance for current attestations.

Discovery that finds the copies

Content-based classification identifies PHI by structure and context — MRN patterns, ICD coding, DICOM headers, HL7 segments — not by folder name. A typical first scan surfaces 3.4× more PHI locations than the organisation's own data map.

Snooping detection that holds up

Access to a celebrity record, a colleague's chart or a family member's file is detected through relationship and behavioural context, then routed to privacy officers with the evidence already assembled.

Research and de-identified data

Limited data sets and de-identified extracts are tracked separately, so a re-identification risk — a supposedly anonymous extract joined to a directory export — is flagged before it leaves the institution.

Medical & IoMT device security

You cannot install an agent on a linear accelerator

Clinical devices are FDA-cleared as a configured system. Changing them invalidates the clearance, so they run unpatched operating systems by design and will continue to for a decade. Guardian secures them the only way that is defensible: identify every device, understand its normal behaviour, and enforce the boundary around it instead of on it.

Guardian Sentinel Policy, detection and response Agentless device fingerprinting Behavioural baseline per model Zone-boundary enforcement Passive protocol inspection Scoped containment actions Biomedical asset reconciliation ONE POLICY ENGINE CLINICAL DEVICE ZONE — IoMT No agent. FDA-cleared configuration untouched. Infusionpumps Imaging& PACS modality Patientmonitors Ventilators& anaesthesia CLINICAL APPLICATION ZONE Agent on servers. Response requires clinical change approval. EHRapplication tier PACSarchive Pharmacy& dispensing Laboratoryinformation system CORPORATE & ADMINISTRATIVE ZONE Full agent. Autonomous containment enabled. Staffworkstations Email& collaboration Revenuecycle Vendorremote access Lateral movement blocked Corporate host → clinical zone, 0.9 s Each zone gets the strongest control it can safely carry — never the same one everywhere
Zone-appropriate control: agentless for regulated devices, agent-based with change control for clinical apps, full autonomy in corporate.

What agentless device protection actually does

  • Identifies the device, not just the IP. Manufacturer, model, firmware revision, clinical function and FDA classification, derived from protocol behaviour — DICOM, HL7, ASTM, proprietary telemetry.
  • Baselines behaviour per model, not per device. One infusion pump's normal is every infusion pump's normal, so a new deployment inherits a mature baseline on day one.
  • Correlates with recall and advisory feeds. Devices affected by an active FDA safety communication or CISA ICS medical advisory are surfaced by serial number, with compensating controls proposed.
  • Reconciles with the CMMS. Discovered devices are matched against your biomedical asset inventory, and the delta — devices on the network that clinical engineering does not know about — is reported weekly.

Response actions that are safe near a patient

Containment on a clinical device is never process termination or host isolation. Guardian's device playbooks operate on the network path around the device, and every action is reversible.

Situation Action taken Clinical impact
Device beaconing to a known C2 host Block that destination only; device stays online None
Device scanning the clinical VLAN Restrict to its baseline peer set None
Unauthorised firmware push detected Block the transfer, page clinical engineering None
Confirmed compromise, patient not connected Quarantine VLAN, pending biomed review Device unavailable
Confirmed compromise, patient connected Alert only; containment queued for handover None

Patient-connected state is read from the clinical system where an integration exists, and defaults to "connected" where it does not.

Ransomware resilience

The whole fight is decided in the first hour

Healthcare ransomware operators follow a consistent sequence: initial access through a phishing lure or an exposed remote-access service, credential harvesting, discovery, backup destruction, then encryption timed for a weekend night shift. Every stage is observable. The only question is whether anything is watching fast enough to act between them.

UNMANAGED ATTACK PROGRESSION Initial access Credential harvesting Lateral movement Backups deleted Encryption begins Someone notices 0 min 38 min 74 min 128 min 186 min 219 min WITH GUARDIAN SENTINEL Detected 18 s · contained 66 s · snapshot 3 min · rollback complete 21 min Adversary never reaches credential harvesting. No encryption, no backup loss, no downtime. 0 min 60 120 180 240 Minutes from initial access — same scale for both lanes
Unmanaged progression uses Guardian Labs incident-response medians for healthcare ransomware engagements, 2024–2026. Guardian timings are medians across protected health-system estates.

Backup destruction is the tell

Shadow-copy deletion, backup-catalogue tampering and mass snapshot removal are treated as critical on sight. In healthcare estates this single detection class precedes 84% of attempted encryption events.

Rollback without touching backups

The sensor journals file changes locally, so encrypted files are restored from the endpoint itself in minutes. No restore request, no tape, no RPO conversation at three in the morning.

A rehearsed downtime plan

Guardian's healthcare incident response team runs tabletop exercises against your actual clinical downtime procedures, so the technical containment plan and the paper-charting plan are the same plan.

Clinical uptime

Availability is a patient-safety control

Security tooling that degrades a clinical workstation is a clinical risk. Guardian is engineered for the environments where that matters most: shared log-ins, roaming sessions, thin clients, imaging workstations moving gigabyte studies, and carts that must wake and authenticate in under three seconds.

  • Under 1.8% CPU at steady state on a clinical workstation image, measured across 240,000 deployed clinical endpoints.
  • No scan windows and no reboot for updates. Sensor upgrades are hot-swapped; protection is never off.
  • Validated against Epic, Oracle Health and MEDITECH reference configurations, with published exclusion guidance for each.
  • Roaming-session aware. A clinician tapping into six workstations in an hour generates one session narrative, not six alerts.
  • Offline for up to 30 days with full local detection and enforcement, for ambulances, remote clinics and field units.

See endpoint security

1.8% Median sensor CPU on a clinical workstation
42 MB Sensor footprint, single binary, no dependencies
0 Reboots required for sensor updates
30 days Full protection while disconnected
2.1 s Added cold-boot time on a clinical cart image
380 Health systems running Guardian in production

Ask any vendor for these numbers on your own image. Guardian publishes them and will reproduce them in your environment during the proof of value, on your gold image, measured by your team.

Customer proof

Meridian Health System

Nine hospitals, 214 ambulatory sites, 41,000 staff and 68,000 connected devices across three states — with a security team of eleven.

WEEK 0

Discovery before deployment

Passive discovery ran for ten days before a single agent was installed. It found 9,100 devices that were not in the biomedical asset inventory, including 34 infusion pumps still reachable from the guest wireless network.

WEEK 6

First live intrusion contained

A vendor remote-support account was used from an unfamiliar location to stage credential-dumping tooling on a pharmacy server. Guardian contained the identity and the host in 41 seconds. The vendor was unaware their credentials had leaked.

WEEK 14

Autonomy enabled in corporate

Automatic containment switched on across 28,000 administrative endpoints, with clinical zones remaining alert-and-approve. Escalations to the security team fell by 71% in the following month.

MONTH 9

Ransomware attempt, no downtime

An affiliate of a known healthcare-focused ransomware group gained access through a compromised third-party billing portal. Guardian detected discovery behaviour in 18 seconds and contained the estate before backup enumeration began. Zero cancelled procedures, zero diversion hours.

Our board asked one question after the incident: how many patients were affected? The answer was none, and we could prove it in an afternoon. That is what we bought.

Dr. Elena Reyes
Chief Information Security Officer, Meridian Health System
9,100 Unknown devices found before go-live
0 hrs Ambulance diversion caused by security incidents in 24 months
-71% Fewer escalations to the security team
Read the full case study

Questions we get from health systems

The practical objections, answered

Will installing an agent void our FDA clearance?

Guardian does not install anything on FDA-cleared medical devices. Those devices are protected agentlessly, through passive network observation and boundary enforcement, so their cleared configuration is untouched. Agents are deployed only on general-purpose computing assets — workstations, servers, VDI images — where the manufacturer's guidance permits it.

Where a device manufacturer explicitly supports third-party endpoint security, Guardian publishes a validated configuration for it.

How does this work with Epic, Oracle Health or MEDITECH?

Guardian ships validated exclusion and tuning profiles for each major EHR platform, developed against reference deployments and refreshed with each vendor release. Application-tier telemetry is ingested through the platform's log and API connectors, so break-glass access, mass record export and audit-log tampering are detected as behaviour rather than inferred from the host.

Our clinical devices run Windows 7 and Windows Server 2008. Now what?

Guardian supports legacy Windows agents where the device manufacturer permits installation, and protects the rest through segmentation and behavioural monitoring of the traffic around them. The realistic goal is not patching — it is ensuring an unpatchable device cannot be reached by anything that has not been explicitly authorised, and that its behaviour is watched closely enough to notice when it changes.

Guardian's compensating-control report documents this position in the form your assessors expect.

Who does clinical engineering talk to when a device is quarantined?

Every device action produces a notification routed by device class to the biomedical engineering queue you nominate, with the manufacturer, model, serial number, physical location and the specific behaviour observed. Actions on patient-connected devices require explicit approval by default, and the approval is captured with the approver's identity and rationale.

Can Guardian help with the 60-day breach notification assessment?

Yes. Each incident produces a complete narrative — accounts involved, systems touched, data accessed or exfiltrated, and the specific records implicated where content classification applies. That narrative is the substantive input to a four-factor risk assessment, and it is available within hours rather than weeks. Guardian's incident response team supports the notification process where you need it.

We are a small critical-access hospital with two IT staff. Is this realistic?

It is the common case. Guardian's managed detection and response team operates the platform for the majority of hospitals under 200 beds — full 24/7 coverage with a three-minute response SLA, and named analysts who learn your environment. You keep the decisions that need clinical context; we handle the queue.

Start with a device discovery, not a sales deck

Guardian will run a ten-day passive discovery across your clinical network and hand you the inventory — every connected device, its risk, and how it differs from your asset register. You keep the report whatever you decide next.