Hospital & Medical-Device Security Tracker

BitSense · multi-state (MA · NH · RI · IL · MN) · device fleet, CVE exposure & incidents · saved in this browser
Hospitals → devices
Devices → hospitals
Vulnerabilities
Incidents
Summary
Device chips are color-coded by confidence.
confirmed-fleet (cited, in clinical use) confirmed-research (cited, in a study) inferred (market share / system standard) inferred, low confidence
Inferred chips are hypotheses to confirm on a call; EHR is mostly confirmed, monitors/ventilators/pumps are market-leader inference. Citations (NCT / go-live dates) are in each hospital’s Notes; sources on the Method tab.
Vendor / product Hospitals Which hospitals (click a chip to jump)
This view inverts the hospital data: every vendor/product you tag on any hospital appears here with the list of hospitals that use it. Tag devices on the Hospitals tab and they populate here automatically.
Device → CVE reference from CISA ICS Medical Advisories / NVD. The CVE exposure column on the Hospitals tab cross-references each hospital’s device tags against this table and inherits the device’s confidence (inferred device → inferred exposure). Whether a specific hospital has patched is unknown — treat exposure as potential, to verify.
💬 Ask a question about a device or vulnerability
Try "what mitigates GE MDhex if unpatched", "which pump CVE is worst", "is BD Alaris still an active risk".
Documented public security incidents from the HHS OCR breach portal and reputable news, with cause and source. Absence of an entry means none was found in this pass — not proof of none. A full per-hospital sweep of the HHS OCR portal is the systematic next step.

Hospitals by state

Hospitals by system

Outreach status

Most-tracked vendors

BitSense assistant
agentic · grounded in the tracker