MedShield AI A Wardhelm product line Talk to us
Clinical network assessment

The sensor cannot transmit.

MedShield AI reads a mirror of your clinical network — DICOM, HL7 v2 over MLLP, and the industrial protocols in the same building — and decodes what it sees. It has no code path that sends a packet. Not disabled by configuration: absent by construction.

Verify it yourself: block all outbound traffic from the sensor host.
The assessment still completes.

Mirror / SPAN portSensor
decode NO RETURN PATH
InboundCopied frames only. Nothing is requested.
OutboundNo dial. No socket write. No inject.
The first question in the room

Will this touch my devices?

No. Biomedical engineering owns device uptime and validation status, and a routine network probe is documented to push field devices into states that need a power cycle. So the honest answer has to be structural, not a promise.

0

Packets sent to clinical endpoints

The sensor reads from a mirror port, a passive tap, or a capture file you hand us. It initiates nothing.

0

Agents installed

Nothing is deployed onto a modality, workstation, pump or server. No credentials are requested.

0

Bytes leaving the building

Runs on-premise. Models run locally. Block egress at the firewall and the assessment still completes.

Active protocol testing exists as a separate service. It is never part of an assessment by default, and it happens only under its own written scope, outside clinical hours, with Biomed present. We read MDS2 and IEC 80001 as your documents — we do not issue or certify against them.

Decoded on the wire

Hospital protocols, not just IT ports.

Generic scanners see an open port. Clinical protocols carry their meaning in the payload, so the sensor decodes them properly and tags each observation with a MITRE ATT&CK for ICS technique at the moment it is parsed.

ProtocolWhat is decodedTechnique
DICOM
104 · 11112
All association and data PDU types, called and calling AE titles, and write operations — C-STORE, N-CREATE, N-SET — plus aborted and rejected associations. T0859
HL7 v2 / MLLP
2575
MLLP framing including escaped delimiters, message header fields, eight message types that mutate clinical state, and whether a message carries a patient-identifying segment. T0882
Modbus TCP · DNP3
EtherNet/IP · BACnet
The building and plant systems sharing your clinical VLANs — chillers, air handling, medical gas, power. Where a hospital is also an industrial site. T0831 · T0836 · T0855
Evidence boundary

What the wire can prove, and what it cannot.

Most of the HIPAA Security Rule is not observable on a network at all. The administrative safeguards under §164.308 — your risk analysis, workforce training, business associate agreements — are satisfied by documented process, and no capture can evidence them. Your report names them as out of scope rather than quietly counting them as covered.

Evidenced from a capture
  • →Unencrypted clinical transport observed in practice — the exchange was readable, which is the finding.
  • →Which systems talk to which, over which clinical protocol, and whether that crosses a segment it should not.
  • →Write and state-changing operations against imaging and clinical messaging, with the CFR clause each implicates.
  • →Building and plant systems on clinical VLANs — usually the finding nobody had inventoried.
Not evidenceable this way — stated in the report
  • ✕Your risk analysis, training or BAA programme. Administrative safeguards under §164.308. Process, not packets.
  • ✕Whether an addressable specification was properly assessed. That determination lives in your documentation.
  • ✕Anything on a segment we were not mirrored onto. Scope is stated as a boundary, not implied as coverage.
  • ✕Compliance itself. No vendor can certify HIPAA. An assessment is one input to your risk analysis.
Why we build it this way

A monitor that dies on a malformed packet blinds the people relying on it.

Clinical networks carry vendor quirks, truncated frames and decades-old implementations. So the parsers are attacked continuously as part of the build — coverage-guided fuzzing plus a fixed battery of malformed payloads across every protocol, asserting that none of them can crash the decoder. A recovery guard sits behind that as a last resort.

684

Malformed-payload parse attempts

A fixed battery run across every protocol decoder on each build, asserting zero crashes.

5

Coverage-guided fuzz targets

The fuzzer keeps inventing inputs we did not think of, and the parsers have to survive them.

7

Protocols in one decode chain

Clinical and industrial together, because in a hospital they share the same cable.

How an engagement runs

Fixed scope. Written authorisation. A report you own.

01

Scope in writing, before anything is connected

Which segments, which window, who is present, and what is explicitly excluded. Biomed signs the same document. No target is accepted without it.

02

Passive capture from a mirror port

We connect to a SPAN port or work from a capture your team produces. Clinical operations are not touched, because nothing is sent.

03

A report that cites its clauses and its limits

Every finding cites the exact 45 CFR clause. Every clause the capture could not evidence is named. The document is yours, in a form a successor can act on.

Because the assessment runs on-premise and we take no access to patient records, there is generally no business associate relationship to paper — but that is a determination for your counsel, not for a vendor to assert. We will answer your third-party review honestly, including about our size.

The company behind it

Wardhelm builds the operator-safe half of cyber-physical security.

We work on systems where the response can be more dangerous than the attack — hospitals, water, energy. That constraint drives everything: passive by default, on-premise, models that run in your building and send nothing out. MedShield is the healthcare line.

MedShield AIClinical networks — DICOM, HL7, PACS, medical IoT
NetSentryOT and industrial detection
RTAIAdversary emulation, contained lab only
OrHaShieldOperations and analyst tooling

We are two people, pre-revenue and self-funded, and we would rather tell you that than have you discover it. If you build detection, work in clinical engineering, or run security at a hospital and this is the way you think the problem should be approached — we want to hear from you.

Back the mission

Pre-seed, open.

We are raising to put engineering behind clinical-protocol coverage and to run our first hospital assessments properly. No traction theatre: we have no customers yet, no revenue, and no committed capital. What exists is working software and a way of building we think is right.

StagePre-seed
Target$250,000
CommittedNone yet
Use of fundsEngineering · protocol coverage
Team2 founders
BasedTel Aviv, Israel