A large hospital runs between 10,000 and 25,000 connected medical devices, and those devices can account for 30–40% of all networked endpoints in clinical environments. Healthcare is consistently among the most targeted sectors, and here a breach isn't only a data problem: ransomware that reaches connected devices threatens patient safety directly.
This guide compares Claroty, Armis, Asimily, Cynerio, Ordr, Forescout, Palo Alto Networks, and TerraZone - through a lens most vendor roundups miss. Medical device security operates in two distinct layers, and confusing them is the most common mistake in vendor selection.
The two layers
Visibility and discovery answers: what devices do we have, and what is their risk? These vendors passively discover and fingerprint every connected device, classify it, identify vulnerabilities, score risk in clinical context, and recommend segmentation policy. This is genuinely hard - thousands of heterogeneous devices speaking hundreds of proprietary protocols, discovered without disrupting clinical operations.
Protection and containment answers a different question: now that we know a device is vulnerable and cannot be patched, how do we stop a threat from reaching it or spreading from it? This layer is about enforcement - isolating devices so a compromise in one place cannot propagate, regardless of whether the device can run security software.
The distinction matters because most visibility vendors recommend segmentation policy, but the actual enforcement usually depends on separate infrastructure - NAC systems, switch-level controls, or firewalls. Knowing an infusion pump is vulnerable does not protect the pump. Enforcing isolation that contains a threat does.
A complete program needs both. Visibility without enforcement leaves devices identified but unprotected; enforcement without visibility lacks the intelligence to set the right policies.
How to evaluate
Device discovery and classification. Passive fingerprinting across hundreds of protocols, without active scanning that could disrupt sensitive clinical equipment.
Agentless operation. Most medical devices cannot run agents - unpatchable legacy operating systems, locked-down firmware, and FDA-regulated software that cannot be modified without recertification. Anything requiring an agent is a non-starter for the bulk of the fleet.
Enforcement, not recommendation. Whether the vendor actually enforces isolation or recommends policies that depend on separate infrastructure to implement.
Ransomware containment. Architecturally preventing spread device-to-device and from IT into the device fleet. In healthcare, containment is a patient-safety control.
Clinical non-disruption and no network redesign. Both layers must operate without impeding patient care or requiring the hospital network to be re-architected.
HIPAA and FDA alignment. Support for the HIPAA Security Rule, FDA cybersecurity guidance, and audit reporting.
What the comparison shows
The vendors fall into three groups.
Visibility leaders - Claroty, Armis, Asimily, Cynerio, Ordr - dominate the discovery layer. All are agentless, all classify devices deeply, and all generate segmentation policy. Their enforcement is delivered through recommendation and integration: the isolation itself is implemented by the network infrastructure underneath.
Visibility plus infrastructure enforcement - Forescout, Palo Alto - bridge the layers by pairing discovery with their own NAC or firewall enforcement. The trade-off is deployment complexity and, in Palo Alto's case, healthcare classification depth that is generally less mature than the dedicated specialists.
Enforcement-first - TerraZone - sits in the protection layer rather than the visibility layer, enforcing identity-based isolation directly and integrating with the visibility platforms that identify the devices.
Vendor profiles
Claroty (xDome / Medigate). One of the most established healthcare device platforms, having acquired Medigate in 2022 to combine OT security expertise with clinical device intelligence. Deep protocol analysis across hundreds of medical device protocols, risk scoring in clinical context rather than raw CVSS, and segmentation recommendations from observed device communication. Strong KLAS 2026 score and a leader in the 2026 Gartner Magic Quadrant for CPS Protection Platforms.
Best fit for: hospitals prioritizing comprehensive visibility and clinical-context risk scoring across IT/OT/IoMT.
Armis. Broad asset intelligence extending well beyond healthcare, with agentless discovery and a large device behavior knowledge base. ServiceNow announced its acquisition of Armis for $7.75 billion in December 2025, expected to close in the second half of 2026.
Best fit for: organizations needing visibility across healthcare and non-healthcare connected assets.
Asimily. Purpose-built IoMT exposure management for healthcare delivery organizations, and a leader in the 2026 Gartner Magic Quadrant for CPS Protection Platforms. Passive discovery profiles devices without network scans; risk scoring prioritizes remediation by clinical impact, with HIPAA reporting built in.
Best fit for: healthcare delivery organizations prioritizing exposure management and clinical-impact prioritization.
Cynerio (Axonius). Healthcare-focused IoT and device security, now part of Axonius. Strong threat detection, deep ePHI visibility, and clinical workflow integration, positioned within a broader asset management platform.
Best fit for: hospitals prioritizing ePHI-aware visibility, particularly those evaluating the Axonius ecosystem.
Ordr. Connected device visibility with strong healthcare deployment maturity, generating segmentation policy with enforcement through NAC integration.
Best fit for: hospitals seeking device visibility paired with NAC-based enforcement.
Forescout (CyberMDX). Combines visibility with network access control, strengthened for healthcare by the CyberMDX acquisition - bridging both layers more than pure visibility vendors. NAC enforcement carries deployment complexity through VLAN dependencies and rollout time, and IoMT classification depth may not match the dedicated specialists.
Best fit for: organizations wanting visibility and NAC enforcement in one platform.
Palo Alto Networks (Medical IoT Security). Device visibility paired with firewall-based enforcement inside the wider Palo Alto ecosystem. Healthcare-specific classification depth is generally less mature than the specialists, and enforcement depends on the firewall infrastructure.
Best fit for: hospitals standardized on Palo Alto seeking integrated IoT enforcement.
TerraZone (truePass). Occupies the protection layer. Agentless identity-based microsegmentation treats each device or device group as its own protected segment, enforcing isolation that does not depend on the device's own security posture - which matters because medical devices overwhelmingly cannot be patched or hardened. Each device communicates only with what it is explicitly authorized to reach. Deployment requires no network redesign, and TerraZone integrates with visibility platforms rather than replacing them: the visibility vendor identifies the devices, TerraZone enforces the policy.
Best fit for: hospitals with device visibility that need enforcement containing threats around unpatchable devices - typically paired with a visibility leader.
Why enforcement determines ransomware outcomes
Healthcare ransomware incidents share a pattern. An initial compromise establishes a foothold, then the ransomware moves laterally through a flat network until it reaches valuable or vulnerable targets - including connected devices that cannot defend themselves. The damage is determined not by whether the organization knew those devices were vulnerable, but by whether the architecture allowed lateral movement to reach them.
A hospital can have a complete inventory with every vulnerability scored and still suffer catastrophic spread if nothing architecturally prevents the movement. The device fleet is uniquely dependent on enforcement because the devices cannot be hardened - they run unpatchable systems by design and clinical necessity. Microsegmentation contains a compromise to its initial foothold: the unpatchable infusion pump, the legacy imaging system, the locked-down monitor are protected not by their own security capability but by the architecture around them.
How to choose
Start with visibility. A hospital cannot protect what it cannot see. Choose on healthcare specialization depth, clinical-context risk scoring, and integration with existing systems.
Then check enforcement. Evaluate whether your visibility vendor's enforcement - often NAC- or firewall-dependent - actually contains threats, or whether a dedicated enforcement architecture is needed.
Match deployment to your environment. Flat networks need enforcement urgently. Large unpatchable legacy fleets need agentless protection. Concern about clinical disruption points to solutions that deploy without network redesign.
Expect a combination. The strongest programmes pair a visibility leader for device intelligence with an enforcement architecture for containment. Visibility sets the right policies; enforcement makes them real.
Frequently asked questions
Can medical device security vendors stop ransomware?
It depends on the layer. Visibility vendors identify vulnerable devices and recommend segmentation, but containment depends on enforcement. Ransomware spreads through lateral movement across flat networks; stopping it requires architecturally preventing that movement, regardless of whether individual devices can be patched.
Why can't medical devices just run security software?
They run unpatchable legacy operating systems, locked-down firmware, and FDA-regulated software that cannot be modified without recertification. Many run end-of-life systems that no longer receive updates, and clinical necessity means they often cannot be taken offline. Protection has to come from the architecture around the device.
Do hospitals need both a visibility vendor and an enforcement solution?
For most, yes. Some visibility vendors include NAC or firewall enforcement, but enforcement quality varies. Hospitals prioritizing containment around unpatchable devices often pair a visibility leader with dedicated microsegmentation.
How do these vendors support HIPAA compliance?
Visibility vendors provide device inventory, vulnerability reporting, and HIPAA-aligned documentation. Enforcement supports the Security Rule's access, audit, and integrity requirements by demonstrating segmentation and attributing every device communication to an authenticated identity.
Conclusion
These vendors each bring genuine capability, but they operate in two layers that solve different problems. The specialists lead decisively at finding, classifying, and assessing connected devices - the foundation any programme requires. Enforcement is where incident outcomes are decided.
The most common selection mistake is treating the layers as interchangeable, assuming a strong visibility platform automatically protects devices. Visibility informs; enforcement protects. Map your needs across both layers and choose accordingly.
