Back to the directory

Healthcare IT · Medical device cybersecurity

Medcrypt

A San Diego company that sells device makers the cryptography, vulnerability tracking and regulatory paperwork the FDA now demands before a connected device reaches the market. It has never made a device of its own. That is the design.

Founded2016 · San Diego and Solana Beach, CA
BatchY Combinator, Winter 2019
Sells toDevice manufacturers, not hospitals
ProductsHelm, Guardian, Canary, Ghost
FDA recordsNo 510(k) or PMA in its own name
On file with the SEC$39.69M sold, four Form D filings
CEOMike Kijewski, co-founder

Username: admin

Ask Mike Kijewski what is wrong with the software inside hospital equipment and he does not reach for a nation state. He reaches for a login.

“Medical device manufacturers (MDMs) have historically hard-coded usernames and passwords into devices, like username: admin; password: p@ssword,” he told a device industry magazine in June 2025. Most manufacturers have learned this is unacceptable, he added. Then the line that matters: “There are even some devices being sold today in which these user authentication issues have never been addressed.”

By his count, about four fifths of the security flaws medical device companies disclose trace to three things: weak authentication, operating systems nobody updated, and encryption implemented badly by teams too small to employ a cryptographer. Medcrypt builds the parts device companies keep getting wrong, then sells the evidence that they got them right.

What the law actually requires

The market Medcrypt spent seven years predicting arrived as statute. Section 3305 of the Consolidated Appropriations Act, 2023, signed December 29, 2022, added section 524B to the Federal Food, Drug, and Cosmetic Act, effective March 29, 2023.

For a cyber device, the sponsor of a premarket submission must do three things: submit a plan to monitor, identify and address postmarket vulnerabilities and exploits in a reasonable time, including coordinated disclosure; maintain processes giving reasonable assurance the device and related systems are cybersecure, and make patches available on a reasonably justified regular cycle and out of cycle as soon as possible for critical vulnerabilities; and provide a software bill of materials covering commercial, open source and off the shelf components. Final FDA guidance addressing 524B issued June 27, 2025.

What the law does not do is name a vendor. A manufacturer with enough security engineers can satisfy every clause in house. Medcrypt is a bet that most will not want to. Its 2026 analysis of FDA deficiency letters, written by a former FDA cybersecurity program manager now on its payroll, argues the agency has stopped accepting documents as proof: “The FDA is no longer satisfied with the mere presence of a report.”

Three founders and the professor who wrote the check

Kijewski taught high school physics before he taught himself business. He took a master’s in medical physics at the University of Pennsylvania, moved into Wharton’s healthcare management track, and co-founded Gamma Basics, a radiation oncology software company Varian Medical Systems bought in 2013. He and Eric Pancoast began laying groundwork for Medcrypt in 2014. The September 2016 seed release named a third founder, Brett Hemenway, a cryptographer and research professor at Penn, as chief scientific officer. That round was $750,000, led by Safeguard Scientifics, whose managing director Gary Kurtzman had been Kijewski’s Wharton professor and became chairman of the board. Kurtzman is the only director appearing on both the 2019 and 2025 SEC filings.

Nine years of waiting for the regulator

The company hired ahead of the rules. In March 2020 Seth Carmody, eight years the FDA’s cybersecurity program manager at its device center, became vice president of regulatory strategy. That August, Medcrypt bought MedISAO, then one of three information sharing organizations created to meet an FDA postmarket recommendation. In 2022 it added Naomi Schwartz, a former FDA premarket reviewer. The money tracked the same curve: a $5.3 million Series A led by Section 32 in May 2019 alongside the Y Combinator winter batch, then a $25 million Series B in November 2022 led by Intuitive Ventures and Johnson & Johnson Innovation, extended by Dexcom Ventures to a stated $36.4 million. Three months later, 524B took effect.

What is proven, and what is still claimed

Operations track. Medcrypt supplies regulated manufacturers rather than being one, so the usual healthcare evidence trail does not apply. There is no clearance to read and no trial to enrol in. What exists is filings, published vulnerability analysis, named hires out of the FDA, and partner announcements.
EvidenceWhat the record showsSource type
FDA device recordsNo 510(k) and no PMA under the company name as of September 22, 2026, consistent with a supplier rather than a device sponsor.Public record
Trials and grantsNo registered trial, no NIH award, no NSF award found. Medcrypt funds outside work instead: a 2023 grant to Kansas State University under Dr. Eugene Vasserman, and a Tufts fellowship on threat modeling.Not found
Peer-reviewed paperBuilding resilient medical technology supply chains with a software bill of materials, npj Digital Medicine, February 23, 2021, PMID 33623135. Its disclosure statement identifies Seth Carmody as MedCrypt’s VP of regulatory strategy.Public record
Vulnerability researchA decade of ICS-CERT medical device advisories analysed, 2013 to 2024, published April 2, 2025: advisory rate up 386% since 2016; 59.8% of vulnerabilities from authentication and code defects; 200 of 433 from four vendors, Baxter, BD, Medtronic and Philips; patch references down 22% in 2024.Company research
Regulatory talentCarmody joined March 2020 after eight years at FDA CDRH. Naomi Schwartz, who reviewed the first regulated automated insulin delivery system at the FDA, joined in 2022.Independent
Standards workAn October 2025 partner release states several Medcrypt experts are contributing authors of the Health Sector Coordinating Council Joint Security Plan, and that the company participates in IEEE 2621.Partner-stated
Named customersNone. In May 2025 the company said 8 of the top 10 global manufacturers used it, with 250 or more projects in 12 months. Its home page on September 11, 2026 says 13 of the top 50 and 200 or more projects.Company-stated
Submission successA claimed 100% FDA approval rate, with a guarantee. The FDA publishes no per-consultant acceptance data, so no public record can confirm or contradict it.Company-stated
Capital raisedBoilerplate said “more than $36 million” as late as May 29, 2025. A Form D filed February 19, 2025 records $8,301,480 of debt sold to 18 investors, first sale February 4, 2025.Claim differs from filings

Read plainly: the evidence is regulatory, not clinical. Medcrypt has the filings, the ex-regulators and the published analysis a compliance vendor should have. What it has never produced is a named customer, a revenue figure, or outside verification of its approval rate. Those are the three numbers a buyer would most want, and all three are still the company describing itself.

What to watch

  • Whether any device maker goes on the record. Nine years in, the customer roster is a ratio and never a name.
  • Whether the “more than $36 million” figure is updated. The SEC record has been ahead of it since February 2025.
  • The next equity Form D. The last one was November 2022; the most recent filing was debt.
  • Enforcement under 524B. The company’s own analysis found patch references falling 22% in the first year the requirement had legal force.
  • The EU Cyber Resilience Act, whose vulnerability reporting the company dates to September 11, 2026.

In their words

“Historically, healthcare companies would assume that, well, if my device is running inside a hospital, we can trust the people inside the hospital, and if a bad guy gets into the hospital, then that’s not our problem.”

Mike Kijewski, founder and CEO, TechCrunch, 2022 · Independent

“Approximately 80% of cybersecurity vulnerability disclosures by medical device companies are caused by either poor user authentication, outdated operating systems, or weak encryption implementations.”

Mike Kijewski, Medical Device and Diagnostic Industry, 2025 · Interview

“While it’s distressing to think about a hacker remotely disabling a medical device, it’s far more unnerving to consider a hacker silently taking over a device and sending it malicious instructions, resulting in a patient’s injury or worse, death.”

Mike Kijewski, seed round announcement, 2016 · Company release

“While cybersecurity attacks to a device such as a pacemaker seem more dangerous, delays to patient care due to cyberattacks are much more real and likely.”

Vidya Murthy, then VP of operations, Series A announcement, 2019 · Company release

“Security has no panacea. Some vendors will choose to gamble that the FDA and their customers won’t notice an inattention to security, yet they’ll lose.”

Seth Carmody, former FDA cybersecurity program manager, 24x7 Magazine, 2020 · Interview

“I think there’s an opportunity for there to be a very large, publicly traded healthcare-specific cybersecurity company.”

Mike Kijewski, TechCrunch, 2022 · Independent
Medcrypt funding profile on HVCFHealthcare Venture Capital Fund

Related companies

Sources

  1. Public recordCybersecurity, on section 3305 and section 524BFDA · Jun 7, 2026
  2. Public recordForm D, MedCrypt Inc., CIK 0001681688SEC · 2016, 2019, 2022, 2025
  3. Public recordSoftware bill of materials paper, PMID 33623135npj Digital Medicine · Feb 23, 2021
  4. IndependentMedCrypt lands $25M injection to secure vulnerable medical devicesTechCrunch · Nov 1, 2022
  5. IndependentMedCrypt nets $25M to enhance cybersecurity on medical devicesSan Diego Union-Tribune · Nov 1, 2022
  6. IndependentMedCrypt raises $5.3 million Series A roundMedCity News · May 12, 2019
  7. InterviewMedCrypt Introduces SaaS Platform for Security Risk AssessmentMD+DI · Jun 11, 2025
  8. InterviewFormer FDA Leader Talks Cybersecurity24x7 Magazine · Apr 28, 2020
  9. InterviewInterview with Mike KijewskiSafetyDetectives · Aug 8, 2023
  10. IndependentMedCrypt financials, listing an $8.3M debt roundCB Insights · Sep 22, 2026
  11. CompanyMedCrypt Raises $750,000 Seed RoundPR Newswire · Sep 13, 2016
  12. CompanyMedCrypt Joined by Former FDA Leader Seth CarmodyPR Newswire · Mar 4, 2020
  13. CompanyMedCrypt Acquires MedISAOPR Newswire · Aug 13, 2020
  14. CompanyMedCrypt Partners With Kansas State UniversityPR Newswire · Jul 11, 2023
  15. CompanyMedcrypt Expands Platform CapabilitiesPR Newswire · May 29, 2025
  16. PartnerThirdwayv and Medcrypt Forge PartnershipPR Newswire · Oct 28, 2025
  17. Company researchICS-CERT 2024 Report on a decade of disclosuresMedcrypt · Apr 2, 2025
  18. Company researchNavigating the 2026 FDA Cybersecurity LandscapeMedcrypt, Seth Carmody · Mar 4, 2026
  19. CompanyMedcrypt home page, about page and Helm documentationMedcrypt · Sep 22, 2026

Profile researched and written by Healthcare Discovery. Last updated September 29, 2026.