MedShield AI reads a mirror of your clinical network — DICOM, HL7 v2 over MLLP, and the industrial protocols in the same building — and decodes what it sees. It has no code path that sends a packet. Not disabled by configuration: absent by construction.
Verify it yourself: block all outbound traffic from the sensor host.
The assessment still completes.
No. Biomedical engineering owns device uptime and validation status, and a routine network probe is documented to push field devices into states that need a power cycle. So the honest answer has to be structural, not a promise.
The sensor reads from a mirror port, a passive tap, or a capture file you hand us. It initiates nothing.
Nothing is deployed onto a modality, workstation, pump or server. No credentials are requested.
Runs on-premise. Models run locally. Block egress at the firewall and the assessment still completes.
Active protocol testing exists as a separate service. It is never part of an assessment by default, and it happens only under its own written scope, outside clinical hours, with Biomed present. We read MDS2 and IEC 80001 as your documents — we do not issue or certify against them.
Generic scanners see an open port. Clinical protocols carry their meaning in the payload, so the sensor decodes them properly and tags each observation with a MITRE ATT&CK for ICS technique at the moment it is parsed.
| Protocol | What is decoded | Technique |
|---|---|---|
| DICOM 104 · 11112 |
All association and data PDU types, called and calling AE titles, and write operations — C-STORE, N-CREATE, N-SET — plus aborted and rejected associations. | T0859 |
| HL7 v2 / MLLP 2575 |
MLLP framing including escaped delimiters, message header fields, eight message types that mutate clinical state, and whether a message carries a patient-identifying segment. | T0882 |
| Modbus TCP · DNP3 EtherNet/IP · BACnet |
The building and plant systems sharing your clinical VLANs — chillers, air handling, medical gas, power. Where a hospital is also an industrial site. | T0831 · T0836 · T0855 |
Most of the HIPAA Security Rule is not observable on a network at all. The administrative safeguards under §164.308 — your risk analysis, workforce training, business associate agreements — are satisfied by documented process, and no capture can evidence them. Your report names them as out of scope rather than quietly counting them as covered.
Clinical networks carry vendor quirks, truncated frames and decades-old implementations. So the parsers are attacked continuously as part of the build — coverage-guided fuzzing plus a fixed battery of malformed payloads across every protocol, asserting that none of them can crash the decoder. A recovery guard sits behind that as a last resort.
A fixed battery run across every protocol decoder on each build, asserting zero crashes.
The fuzzer keeps inventing inputs we did not think of, and the parsers have to survive them.
Clinical and industrial together, because in a hospital they share the same cable.
Which segments, which window, who is present, and what is explicitly excluded. Biomed signs the same document. No target is accepted without it.
We connect to a SPAN port or work from a capture your team produces. Clinical operations are not touched, because nothing is sent.
Every finding cites the exact 45 CFR clause. Every clause the capture could not evidence is named. The document is yours, in a form a successor can act on.
Because the assessment runs on-premise and we take no access to patient records, there is generally no business associate relationship to paper — but that is a determination for your counsel, not for a vendor to assert. We will answer your third-party review honestly, including about our size.
We work on systems where the response can be more dangerous than the attack — hospitals, water, energy. That constraint drives everything: passive by default, on-premise, models that run in your building and send nothing out. MedShield is the healthcare line.
We are two people, pre-revenue and self-funded, and we would rather tell you that than have you discover it. If you build detection, work in clinical engineering, or run security at a hospital and this is the way you think the problem should be approached — we want to hear from you.
We are raising to put engineering behind clinical-protocol coverage and to run our first hospital assessments properly. No traction theatre: we have no customers yet, no revenue, and no committed capital. What exists is working software and a way of building we think is right.