AirStrip® Product Security & Cybersecurity

Security vigilant

AirStrip ONE® Mobile and Web — security information, coordinated vulnerability disclosure, and security bulletins for customers and researchers.

Our commitment to product security

Medical device software is a potential target of cyberattack. AirStrip actively monitors the security of the AirStrip ONE platform across its lifecycle and takes action to address vulnerabilities.

  • Prevent

    Secure Product Development Framework (SPDF) applied across the whole lifecycle — threat modeling, security risk management, and security testing before every release.

  • Detect

    Continuous post-market monitoring of vulnerabilities and exploits informed by field data, security research, and threat intelligence.

  • Respond

    Incident response and coordinated vulnerability disclosure is formed with risk-driven corrective action to address timely responses.

Security is a shared responsibility

Product cybersecurity is shared among manufacturers, healthcare facilities, providers, and patients. These practices keep the AirStrip ONE environment secure.

For clinicians and users

  • Log out when finished, and lock shared or unattended devices
  • Use a device passcode or biometric lock; keep lock-screen notifications private
  • Access AirStrip only via the official app or your site’s approved web address — beware of look-alike login pages
  • Prefer trusted networks (hospital network, cellular, or site-approved VPN) over public Wi-Fi
  • Never store or transmit patient data through insecure channels (photos, personal email, SMS)
  • Use the Hide-PHI option in shared or public areas

For hospital IT & administrators

  • Keep devices, operating systems, and browsers within supported versions and promptly updated
  • Enforce MDM lock policies on shared ward devices; configure the site session timeout
  • Provision individual accounts; revoke access and device registrations at staff departure or decommissioning
  • Apply AirStrip software updates per site policy and the agreed maintenance window
  • Report suspected security incidents to your site IT/security contact and AirStrip Support (24×7)

Grounded in recognized standards

Information security management

  • ISO/IEC 27001Information Security Management System
  • NIST SP 800-53Security and privacy controls
  • HIPAA45 CFR Part 164 Security and Privacy rules; AirStrip operates as a Business Associate of the healthcare institution
  • EU GDPR 2016/679protection of personal data

AirStrip regularly evaluates and continually improves its cybersecurity controls to protect the confidentiality, integrity, and availability of information entrusted to it.

Product cybersecurity process

  • ANSI/AAMI TIR57principles for medical device security risk management
  • ANSI/AAMI TIR97post-market security risk management
  • ANSI/AAMI SW96security risk management for device manufacturers
  • IEC 81001-5-1security activities in the health software lifecycle
  • ISO 14971risk management for medical devices
  • MDCG 2019-16cybersecurity for medical devices (EU)
  • MDCG 2025-4safe availability of MDSW apps on online platforms
  • FDApremarket and postmarket cybersecurity guidance
  • Regulation (EU) 2017/745 (MDR)
  • NIST SP 800-30conducting risk assessments

Secure Product Development Framework (SPDF)

The SPDF protects the safety and effectiveness of AirStrip ONE across the total product lifecycle and is integrated with product development, risk management, and the quality system.

  1. Design
  2. Development
  3. Release
  4. Support
  5. Decommission

Cybersecurity risk management

Assets, threats, and vulnerabilities identified and assessed for impact on device functionality, users, and patients; risk levels and mitigations determined; residual risk assessed.

Architecture & threat modeling

End-to-end security architecture with trust boundaries, plus threat modeling (STRIDE) across all system elements — including supply chain, installation, deployment, maintenance, and decommissioning risks.

Cybersecurity testing

Verification confirms design outputs meet security design inputs; validation confirms controls are effective in the environment of use.

Cybersecurity transparency

Labeling, the Cybersecurity Risk Management Plan and the Coordinated Vulnerability Disclosure process keep users informed of secure configuration, updates, and known risks.

Post-market monitoring & incident response

Continuous post-market surveillance

Cybersecurity risks evolve after release, so premarket controls alone are not enough. For marketed products, AirStrip monitors, identifies, and addresses vulnerabilities and exploits:

  • Monitoring of vulnerability sources and field signals
  • Design-change evaluation so no new threats or vulnerabilities are introduced
  • Installation-phase controls that avoid introducing security risks at customer sites
  • Corrective and preventive action where required

Incident response framework

  1. Identify & triage — intake from monitoring, customers, or researchers; assess impact on confidentiality, integrity, availability, and patient safety
  2. Assess risk — security risk evaluation against acceptability criteria; controlled vs uncontrolled risk of patient harm
  3. Mitigate & correct — remediation, patch/update planning, CAPA where required; effectiveness verified before closure
  4. Communicate — coordinated vulnerability disclosure and, when needed, security bulletins with recommended customer actions
  5. Review — management review of the process at planned intervals to confirm continuing effectiveness

Coordinated Vulnerability Disclosure — report a concern

We value the contributions of the security research community. If you believe you have identified a potential security vulnerability in an AirStrip product or service, we want to know so we can investigate.

Who to contact

Security researchers and users

Emailsecurity@airstrip.com

Customers (technical)

AirStrip Technical Support, 24×7

North America+1 (877) 258-5869

UK+011 44 800-088-5520

Canada+1 (210) 805-0444 opt. 2

Emailcases@airstrip.com

Users

Contact your healthcare facility first.

What to include

  • Your contact information (used only to follow up; never shared)
  • Technical description: method of discovery (when, where, how)
  • Impacted products and software versions
  • Testing environment and tools used
  • Whether anyone else has been notified (agencies, vendors, coordinators)

Please do not include any protected health information (PHI) or personally identifiable information in your report.

What happens after you report

  1. Acknowledgementwe confirm receipt of your submission and assign a point of contact.
  2. Investigationour security engineers review your report and may follow up to confirm technical details or better understand the finding.
  3. Risk assessmentwe evaluate potential impact across AirStrip products, including effects on confidentiality, integrity, availability, and patient safety, against our documented risk acceptability criteria.
  4. Action & updatewe determine appropriate action (mitigation, update, disclosure) and provide you with a summary of actions taken once analysis is complete.
  5. Recognitionwith your consent, we may publicly acknowledge your contribution to improving the security of our products and services in the relevant security bulletin.

Security bulletins

When a confirmed vulnerability affects an AirStrip product, we publish a security bulletin here with a plain-language summary, affected products, and recommended actions.

Current status: no active security bulletins for AirStrip ONE Mobile and Web. (As of 22 September 2026)

Every bulletin contains

  1. Summary — what the vulnerability is and what it could affect
  2. Products impacted — models and software versions
  3. Mitigations & recommended actions — what customers and users should do
  4. References — CVE identifiers and external advisories (e.g., CISA) where applicable
  5. Acknowledgements — with reporter consent

Stay informed

Customers are notified of security-relevant updates through their AirStrip service representative and site administrator channels.

Questions about a bulletin: security@airstrip.com or AirStrip Technical Support 24×7.

How AirStrip ONE® protects patient data

Explicit registration & approval

Every device is registered with AirStrip Global Services and explicitly approved by the site administrator before any patient data is accessible.

Encrypted transport only

All registration, authentication, and data requests occur over HTTPS with TLS; data flows through explicit firewall rules on identified ports.

Session control

Self-expiring session tokens verified on every request; inactivity timeout ends the session (site-configurable; default 15 minutes).

No PHI stored on device

Patient data is view-only, held in encrypted in-memory state, never stored physically on the device; a Hide-PHI toggle is available for shared settings.

Biometric & MDM support

Touch ID / Face ID device authentication on mobile; MDM enrollment option for shared hospital devices; per-device registration codes.

Customer-hosted data

Patient data remains on customer-hosted servers inside the hospital environment; only outbound TLS traffic is required to AirStrip services.

Contact & routing

I am…TopicContact
Security researcherSuspected vulnerability in an AirStrip productsecurity@airstrip.com — see Coordinated Vulnerability Disclosure
Customer / clinicianTechnical or security question about daily useAirStrip Technical Support 24×7 · NA +1 (877) 258-5869 · cases@airstrip.com
Customer / clinicianSuspected security incident (lost device, account misuse)Your site IT/security contact AND AirStrip Technical Support 24×7
GeneralProduct informationinfo@airstrip.com · +1 (210) 805-0444

AirStrip Technologies, Inc.
2915 W. Bitters Rd. Suite 215, San Antonio, TX 78248, USA

MedEnvoy Global B.V.
Prinses Margrietplantsoen 33 – Suite 123, 2595 AM The Hague, The Netherlands

We are sure we can help you

Get in touch with us to schedule a demo today.