IP Library Granted Patent US 12,443,721
Granted Patent B2
US 12,443,721 · App. 17/924,743 · Granted Oct 14, 2025

Medical device cybersecurity platform

Inventors: Manish Jadhav (McMurray, PA); Kenneth Zalevsky (Pittsburgh, PA)
Assignee: Vigilant Ops, Inc.
G06F21/577G06F8/65G16H40/40G06F2221/034
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,443,721
App. No.
17/924,743
Granted
Oct 14, 2025
Kind
B2
Abstract

Systems and methods for the management of cybersecurity risks for medical devices are disclosed. A system may streamline and automate the process of generating a cybersecurity bill of materials and evaluate it against the National Vulnerability Database or a similar source. Furthermore, the system may provide a secure platform for data to be transferred between medical device manufacturers and healthcare delivery organizations allowing for the notification of security vulnerabilities and the transferal of security updates.

Claims (44)

1. A system for the management of cybersecurity risks for medical devices, the system comprising:

a processor; and

a non-transitory, processor-readable storage medium, wherein the non-transitory, processor-readable storage medium comprises one or more programming instructions that, when executed, cause the processor to:

receive data associated with a medical device;

evaluate, based on the data, an identity of the medical device;

generate, based on the identification, a cybersecurity bill of materials associated with the medical device, wherein the cybersecurity bill of materials comprises a software bill of materials detailing a software component of the medical device, wherein the software bill of materials comprises a build status comprising a build environment of the software component and a current status comprising applied updates to the software component;

standardize the cybersecurity bill of materials based on a common platform enumeration database;

evaluate, using a vulnerability database, the cybersecurity bill of materials to identify one or more potential vulnerabilities;

provide notification of the one or more potential vulnerabilities to at least one user;

determine, using a manufacturer's database, whether the medical device is up-to-date; and

responsive to determining that the device is not up-to-date, receive a patch from the manufacturer's database to update the medical device.

2. The system of claim 1 , wherein the received data associated with the medical device comprises at least one of a device manufacturer, a device name, a device model, a device version, an IP address, a device domain, a device administrator, or a device password.

3. The system of claim 1 , wherein the one or more programming instructions that, when executed, cause the processor to receive data associated with the medical device further comprise one or more programming instructions that, when executed, cause the processor to interrogate the medical device directly for data.

4. The system of claim 1 , wherein the data associated with the medical device is received directly from the medical device.

5. The system of claim 1 , wherein the data associated with the medical device is received directly from the build environment of the software.

6. The system of claim 1 , wherein the at least one user comprises at least one of a medical device manufacturer user, a healthcare delivery organization user, or a platform maintenance user.

7. The system of claim 1 , wherein the one or more programming instructions that, when executed, cause the processor to evaluate, using a vulnerability database, the cybersecurity bill of materials to identify one or more potential vulnerabilities are performed recursively and in real-time.

8. The system of claim 1 , wherein the one or more programming instructions that, when executed, cause the processor to provide notification of the one or more potential vulnerabilities further comprise one or more programming instructions that, when executed, cause the processor to flag the one or more potential vulnerabilities on a graphical user interface.

9. The system of claim 1 , wherein the one or more programming instructions that, when executed, cause the processor to provide notification of the one or more potential vulnerabilities further comprise one or more programming instructions that, when executed, cause the processor to message at least one user using an automated email, text, call, messaging application, or service ticket system.

10. The system claim 1 , wherein the one or more programming instructions that, when executed, cause the processor to evaluate the identity of the medical device further comprise one or more programming instructions that, when executed, cause the processor to map the identity of the device to a standard naming convention of a known device.

11. The system of claim 1 , further comprising one or more programming instructions that, when executed, cause the processor to automatically deploy the received patch.

12. The system of claim 1 , further comprising one or more programming instructions that, when executed, cause the processor to:

transmit a notification associated with the received patch to at least one user;

receive deployment instructions to deploy the received patch from the at least one user; and

deploy the received patch in response to receiving the deployment instructions.

13. The system of claim 11 , wherein the one or more programming instructions that, when executed, cause the processor to deploy the received patch further comprise one or more programming instructions that, when executed, cause the processor to deploy the received patch at a pre-determined time.

14. A method for the management of cybersecurity risks for medical devices, the method comprising:

receiving data associated with a medical device;

evaluating, based on the data, an identity of the medical device;

generating, based on the identification, a cybersecurity bill of materials associated with the medical device, wherein the cybersecurity bill of materials comprises a software bill of materials detailing a software component of the medical device, wherein the software bill of materials comprises a build status comprising a build environment of the software component and a current status comprising applied updates to the software component;

standardizing the cybersecurity bill of materials based on a common platform enumeration database;

evaluating, using a vulnerability database, the cybersecurity bill of materials to identify one or more potential vulnerabilities;

providing notification of the one or more potential vulnerabilities to at least one user;

determine, using a manufacturer's database, whether the medical device is up-to-date; and

responsive to determining that the device is not up-to-date, receiving a patch from the manufacturer's database to update the medical device.

15. The method of claim 14 , wherein receiving data associated with the medical device further comprises interrogating the medical device directly for data.

16. The method of claim 14 , wherein providing notification of the one or more potential vulnerabilities further comprises flagging the one or more potential vulnerabilities on a graphical user interface.

17. The method of claim 14 , wherein providing notification of the one or more potential vulnerabilities further comprises messaging at least one user using an automated email, text, call, messaging application, or service ticket system.

18. The method of claim 14 , wherein evaluating the identity of the medical device further comprises mapping the identity of the device to a standard naming convention of a known device.

19. The method of claim 14 , further comprising automatically deploying the received patch.

20. The method of claim 14 , further comprising:

transmitting a notification associated with the received patch to at least one user;

receiving deployment instructions to deploy the received patch from the at least one user; and

deploying the received patch in response to receiving the deployment instructions.

Assignments (3)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 19, 2025
From: VIGILANT OPS, INC.
To: C2A-SEC, LTD.
Reel/Frame 073588/0768 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 10, 2023
From: JADHAV, MANISH
To: VIGILANT OPS, INC.
Reel/Frame 064552/0031 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 10, 2023
From: ZALEVSKY, KENNETH
To: VIGILANT OPS, INC.
Reel/Frame 064552/0091 →
Continuity (2)
Provisional Application 63022938 · May 11, 2020
Related Publication 20230244791A1 · Aug 3, 2023
References Cited (11)
US 8051414B2 · Stender · 2011 [cited by examiner]
US 9749349B1 · Czarny · 2017 [cited by examiner]
US 10089473B2 · Mahrous · 2018 [cited by examiner]
US 11636198B1 · Kulkarni · 2023 [cited by examiner]
US 11783062B2 · Lounsberry · 2023 [cited by examiner]
US 20070203547A1 · Costello · 2007 [cited by examiner]
US 20170169229A1 · Brucker et al. · 2017 [cited by applicant]
US 20180351987A1 · Patel · 2018 [cited by examiner]
US 20190114435A1 · Bhalla · 2019 [cited by examiner]
US 20200201620A1 · Beard · 2020 [cited by examiner]
Stockhausen et al. “Continuous security patch delivery and risk management for medical devices” Mar. 16, 2020, 2020 IEEE International Conference on Software Architecture Companion (ICSA-C), IEEE, 204-209 (6 pages). [cited by applicant]