Security vigilant
AirStrip ONE® Mobile and Web — security information, coordinated vulnerability disclosure, and security bulletins for customers and researchers.
Medical device software is a potential target of cyberattack. AirStrip actively monitors the security of the AirStrip ONE platform across its lifecycle and takes action to address vulnerabilities.
Secure Product Development Framework (SPDF) applied across the whole lifecycle — threat modeling, security risk management, and security testing before every release.
Continuous post-market monitoring of vulnerabilities and exploits informed by field data, security research, and threat intelligence.
Incident response and coordinated vulnerability disclosure is formed with risk-driven corrective action to address timely responses.
Product cybersecurity is shared among manufacturers, healthcare facilities, providers, and patients. These practices keep the AirStrip ONE environment secure.
AirStrip regularly evaluates and continually improves its cybersecurity controls to protect the confidentiality, integrity, and availability of information entrusted to it.
The SPDF protects the safety and effectiveness of AirStrip ONE across the total product lifecycle and is integrated with product development, risk management, and the quality system.
Assets, threats, and vulnerabilities identified and assessed for impact on device functionality, users, and patients; risk levels and mitigations determined; residual risk assessed.
End-to-end security architecture with trust boundaries, plus threat modeling (STRIDE) across all system elements — including supply chain, installation, deployment, maintenance, and decommissioning risks.
Verification confirms design outputs meet security design inputs; validation confirms controls are effective in the environment of use.
Labeling, the Cybersecurity Risk Management Plan and the Coordinated Vulnerability Disclosure process keep users informed of secure configuration, updates, and known risks.
Cybersecurity risks evolve after release, so premarket controls alone are not enough. For marketed products, AirStrip monitors, identifies, and addresses vulnerabilities and exploits:
We value the contributions of the security research community. If you believe you have identified a potential security vulnerability in an AirStrip product or service, we want to know so we can investigate.
AirStrip Technical Support, 24×7
North America+1 (877) 258-5869
Canada+1 (210) 805-0444 opt. 2
Emailcases@airstrip.com
Contact your healthcare facility first.
Please do not include any protected health information (PHI) or personally identifiable information in your report.
When a confirmed vulnerability affects an AirStrip product, we publish a security bulletin here with a plain-language summary, affected products, and recommended actions.
Current status: no active security bulletins for AirStrip ONE Mobile and Web. (As of 22 September 2026)
Customers are notified of security-relevant updates through their AirStrip service representative and site administrator channels.
Questions about a bulletin: security@airstrip.com or AirStrip Technical Support 24×7.
Every device is registered with AirStrip Global Services and explicitly approved by the site administrator before any patient data is accessible.
All registration, authentication, and data requests occur over HTTPS with TLS; data flows through explicit firewall rules on identified ports.
Self-expiring session tokens verified on every request; inactivity timeout ends the session (site-configurable; default 15 minutes).
Patient data is view-only, held in encrypted in-memory state, never stored physically on the device; a Hide-PHI toggle is available for shared settings.
Touch ID / Face ID device authentication on mobile; MDM enrollment option for shared hospital devices; per-device registration codes.
Patient data remains on customer-hosted servers inside the hospital environment; only outbound TLS traffic is required to AirStrip services.
| I am… | Topic | Contact |
|---|---|---|
| Security researcher | Suspected vulnerability in an AirStrip product | security@airstrip.com — see Coordinated Vulnerability Disclosure |
| Customer / clinician | Technical or security question about daily use | AirStrip Technical Support 24×7 · NA +1 (877) 258-5869 · cases@airstrip.com |
| Customer / clinician | Suspected security incident (lost device, account misuse) | Your site IT/security contact AND AirStrip Technical Support 24×7 |
| General | Product information | info@airstrip.com · +1 (210) 805-0444 |
AirStrip Technologies, Inc.
2915 W. Bitters Rd. Suite 215, San Antonio, TX 78248, USA
MedEnvoy Global B.V.
Prinses Margrietplantsoen 33 – Suite 123, 2595 AM The Hague, The Netherlands