Healthcare IT · Medical device cybersecurity
Medcrypt
A San Diego company that sells device makers the cryptography, vulnerability tracking and regulatory paperwork the FDA now demands before a connected device reaches the market. It has never made a device of its own. That is the design.
Username: admin
Ask Mike Kijewski what is wrong with the software inside hospital equipment and he does not reach for a nation state. He reaches for a login.
“Medical device manufacturers (MDMs) have historically hard-coded usernames and passwords into devices, like username: admin; password: p@ssword,” he told a device industry magazine in June 2025. Most manufacturers have learned this is unacceptable, he added. Then the line that matters: “There are even some devices being sold today in which these user authentication issues have never been addressed.”
By his count, about four fifths of the security flaws medical device companies disclose trace to three things: weak authentication, operating systems nobody updated, and encryption implemented badly by teams too small to employ a cryptographer. Medcrypt builds the parts device companies keep getting wrong, then sells the evidence that they got them right.
What the law actually requires
The market Medcrypt spent seven years predicting arrived as statute. Section 3305 of the Consolidated Appropriations Act, 2023, signed December 29, 2022, added section 524B to the Federal Food, Drug, and Cosmetic Act, effective March 29, 2023.
For a cyber device, the sponsor of a premarket submission must do three things: submit a plan to monitor, identify and address postmarket vulnerabilities and exploits in a reasonable time, including coordinated disclosure; maintain processes giving reasonable assurance the device and related systems are cybersecure, and make patches available on a reasonably justified regular cycle and out of cycle as soon as possible for critical vulnerabilities; and provide a software bill of materials covering commercial, open source and off the shelf components. Final FDA guidance addressing 524B issued June 27, 2025.
What the law does not do is name a vendor. A manufacturer with enough security engineers can satisfy every clause in house. Medcrypt is a bet that most will not want to. Its 2026 analysis of FDA deficiency letters, written by a former FDA cybersecurity program manager now on its payroll, argues the agency has stopped accepting documents as proof: “The FDA is no longer satisfied with the mere presence of a report.”
Three founders and the professor who wrote the check
Kijewski taught high school physics before he taught himself business. He took a master’s in medical physics at the University of Pennsylvania, moved into Wharton’s healthcare management track, and co-founded Gamma Basics, a radiation oncology software company Varian Medical Systems bought in 2013. He and Eric Pancoast began laying groundwork for Medcrypt in 2014. The September 2016 seed release named a third founder, Brett Hemenway, a cryptographer and research professor at Penn, as chief scientific officer. That round was $750,000, led by Safeguard Scientifics, whose managing director Gary Kurtzman had been Kijewski’s Wharton professor and became chairman of the board. Kurtzman is the only director appearing on both the 2019 and 2025 SEC filings.
Nine years of waiting for the regulator
The company hired ahead of the rules. In March 2020 Seth Carmody, eight years the FDA’s cybersecurity program manager at its device center, became vice president of regulatory strategy. That August, Medcrypt bought MedISAO, then one of three information sharing organizations created to meet an FDA postmarket recommendation. In 2022 it added Naomi Schwartz, a former FDA premarket reviewer. The money tracked the same curve: a $5.3 million Series A led by Section 32 in May 2019 alongside the Y Combinator winter batch, then a $25 million Series B in November 2022 led by Intuitive Ventures and Johnson & Johnson Innovation, extended by Dexcom Ventures to a stated $36.4 million. Three months later, 524B took effect.
What is proven, and what is still claimed
| Evidence | What the record shows | Source type |
|---|---|---|
| FDA device records | No 510(k) and no PMA under the company name as of September 22, 2026, consistent with a supplier rather than a device sponsor. | Public record |
| Trials and grants | No registered trial, no NIH award, no NSF award found. Medcrypt funds outside work instead: a 2023 grant to Kansas State University under Dr. Eugene Vasserman, and a Tufts fellowship on threat modeling. | Not found |
| Peer-reviewed paper | Building resilient medical technology supply chains with a software bill of materials, npj Digital Medicine, February 23, 2021, PMID 33623135. Its disclosure statement identifies Seth Carmody as MedCrypt’s VP of regulatory strategy. | Public record |
| Vulnerability research | A decade of ICS-CERT medical device advisories analysed, 2013 to 2024, published April 2, 2025: advisory rate up 386% since 2016; 59.8% of vulnerabilities from authentication and code defects; 200 of 433 from four vendors, Baxter, BD, Medtronic and Philips; patch references down 22% in 2024. | Company research |
| Regulatory talent | Carmody joined March 2020 after eight years at FDA CDRH. Naomi Schwartz, who reviewed the first regulated automated insulin delivery system at the FDA, joined in 2022. | Independent |
| Standards work | An October 2025 partner release states several Medcrypt experts are contributing authors of the Health Sector Coordinating Council Joint Security Plan, and that the company participates in IEEE 2621. | Partner-stated |
| Named customers | None. In May 2025 the company said 8 of the top 10 global manufacturers used it, with 250 or more projects in 12 months. Its home page on September 11, 2026 says 13 of the top 50 and 200 or more projects. | Company-stated |
| Submission success | A claimed 100% FDA approval rate, with a guarantee. The FDA publishes no per-consultant acceptance data, so no public record can confirm or contradict it. | Company-stated |
| Capital raised | Boilerplate said “more than $36 million” as late as May 29, 2025. A Form D filed February 19, 2025 records $8,301,480 of debt sold to 18 investors, first sale February 4, 2025. | Claim differs from filings |
Read plainly: the evidence is regulatory, not clinical. Medcrypt has the filings, the ex-regulators and the published analysis a compliance vendor should have. What it has never produced is a named customer, a revenue figure, or outside verification of its approval rate. Those are the three numbers a buyer would most want, and all three are still the company describing itself.
What to watch
- Whether any device maker goes on the record. Nine years in, the customer roster is a ratio and never a name.
- Whether the “more than $36 million” figure is updated. The SEC record has been ahead of it since February 2025.
- The next equity Form D. The last one was November 2022; the most recent filing was debt.
- Enforcement under 524B. The company’s own analysis found patch references falling 22% in the first year the requirement had legal force.
- The EU Cyber Resilience Act, whose vulnerability reporting the company dates to September 11, 2026.
In their words
“Historically, healthcare companies would assume that, well, if my device is running inside a hospital, we can trust the people inside the hospital, and if a bad guy gets into the hospital, then that’s not our problem.”
Mike Kijewski, founder and CEO, TechCrunch, 2022 · Independent
“Approximately 80% of cybersecurity vulnerability disclosures by medical device companies are caused by either poor user authentication, outdated operating systems, or weak encryption implementations.”
Mike Kijewski, Medical Device and Diagnostic Industry, 2025 · Interview
“While it’s distressing to think about a hacker remotely disabling a medical device, it’s far more unnerving to consider a hacker silently taking over a device and sending it malicious instructions, resulting in a patient’s injury or worse, death.”
Mike Kijewski, seed round announcement, 2016 · Company release
“While cybersecurity attacks to a device such as a pacemaker seem more dangerous, delays to patient care due to cyberattacks are much more real and likely.”
Vidya Murthy, then VP of operations, Series A announcement, 2019 · Company release
“Security has no panacea. Some vendors will choose to gamble that the FDA and their customers won’t notice an inattention to security, yet they’ll lose.”
Seth Carmody, former FDA cybersecurity program manager, 24x7 Magazine, 2020 · Interview
“I think there’s an opportunity for there to be a very large, publicly traded healthcare-specific cybersecurity company.”
Mike Kijewski, TechCrunch, 2022 · Independent
Related companies
Sources
- Public recordCybersecurity, on section 3305 and section 524B
- Public recordForm D, MedCrypt Inc., CIK 0001681688
- Public recordSoftware bill of materials paper, PMID 33623135
- IndependentMedCrypt lands $25M injection to secure vulnerable medical devices
- IndependentMedCrypt nets $25M to enhance cybersecurity on medical devices
- IndependentMedCrypt raises $5.3 million Series A round
- InterviewMedCrypt Introduces SaaS Platform for Security Risk Assessment
- InterviewFormer FDA Leader Talks Cybersecurity
- InterviewInterview with Mike Kijewski
- IndependentMedCrypt financials, listing an $8.3M debt round
- CompanyMedCrypt Raises $750,000 Seed Round
- CompanyMedCrypt Joined by Former FDA Leader Seth Carmody
- CompanyMedCrypt Acquires MedISAO
- CompanyMedCrypt Partners With Kansas State University
- CompanyMedcrypt Expands Platform Capabilities
- PartnerThirdwayv and Medcrypt Forge Partnership
- Company researchICS-CERT 2024 Report on a decade of disclosures
- Company researchNavigating the 2026 FDA Cybersecurity Landscape
- CompanyMedcrypt home page, about page and Helm documentation
Profile researched and written by Healthcare Discovery. Last updated September 29, 2026.
