H-ISAC
Health-ISAC is a nonprofit, membership-based Information Sharing and Analysis Center founded in 2010 that provides healthcare organizations (hospitals, pharma, and medical device manufacturers) with threat intelligence sharing, secure collaboration tools, and resilience programs across the Americas, Europe, and Asia-Pacific.
- Company typePrivate
- Founded2010
- HeadquartersOrmond Beach, United States
- Headcount1–10
- GTM typeB2B
- OfferingServices
What H-ISAC does
Health-ISAC, Inc. (operating as Health-ISAC or H-ISAC) is a Florida-domiciled nonprofit founded in 2010 that serves as the healthcare and public health sector's Information Sharing and Analysis Center. Its core function is to provide a trusted community for hospitals, health systems, pharmaceutical manufacturers, medical device makers, and research facilities to exchange timely, actionable threat intelligence, with membership spanning organizations whose annual revenues range from under $1M to $250B. Penetration into the top tiers of its target market is material, with 85% of the top 25 global pharmaceutical manufacturers and 66% of the top 51 global medical device manufacturers as members, and 52% of members retained for four or more years.
The organization's technical platform is anchored by the Health-ISAC Threat Intelligence Portal (HTIP) for alerts and intelligence, the Health-ISAC Indicator Threat Sharing Tool (HITS) for indicator exchange, a SecureChat channel for peer-to-peer collaboration, and a TLP (Traffic Light Protocol) classification system governing how shared intelligence is handled. Adjacent offerings include the H-ISAC SBOM Studio for medical device software bill of materials management (delivered in partnership with Cybeats), free third-party risk management services via Censinet, an annual healthcare cybersecurity benchmarking study, a resilience exercise series, medical device security and clinician training programs, whitepapers (including AI risk and IAM for CISOs), and four annual regional summits. The organization maintains three regional offices in Orlando, Florida (Americas HQ), Waterloo, Belgium (Europe), and Singapore (APAC), and works closely with the National Council of ISACs, CISA, HHS, the FBI, and HSCC.
Health-ISAC operates a subscription, membership-funded business model. Revenue is generated primarily through annual membership dues, paid event and summit registrations, and a multi-tier sponsor program (Pathfinder, Champion, Visionary, Ambassador) populated by major technology and security vendors such as Google Cloud, AWS, IBM, Booz Allen Hamilton, Cyware, and RiskRecon/Mastercard. Pricing is not publicly disclosed, and a 60-day no-cost trial membership has been used historically as an acquisition lever. Go-to-market is community-led, relying on thought-leadership content (Hacking Healthcare blog, newsletters, whitepapers, webinars, podcasts), working groups and committees, regional summits, and a board-of-directors governance model that reinforces peer accountability within the membership.
H-ISAC firmographics
Firmographics- Name
- H-ISAC
- Legal name
- Health-ISAC, Inc.
- Website
- https://health-isac.org
- Company type
- Private
- Founded year
- 2010
- Operating status
- Operating
- Headcount range
- 1–10 employees
- Short description
- Health-ISAC is a nonprofit, membership-based Information Sharing and Analysis Center founded in 2010 that provides healthcare organizations (hospitals, pharma, and medical device manufacturers) with threat intelligence sharing, secure collaboration tools, and resilience programs across the Americas, Europe, and Asia-Pacific.
- Ownership category
- akta.pro rank
H-ISAC industry classification
Industry- Product category
- Healthcare Cybersecurity Information Sharing
- NAICS
- Business Associations (813910)
- SIC
- Services-Membership Organizations (8600)
- akta.pro primary industry
- Application & API Security for Digital Health (WAF/RASP/API gateways) (HLACAJAH)
- akta.pro secondary industry
- Phishing, Social Engineering & Business Email Compromise (BEC) Training (EDABAGAB)
Keywords
Where H-ISAC is headquartered
LocationHeadquarters
- HQ city
- Ormond Beach
- HQ country
- United States
- HQ region
- North America
Offices3 records
Markets served
H-ISAC business model
Business model- GTM type
- B2B
- Offering type
- Services
- Cost components
- Personnel, Operations, Technology or R&D, Marketing or Sales, Infrastructure
Revenue model
- Membership Fees: Health-ISAC generates primary revenue through annual membership fees from healthcare organizations including hospitals, pharmaceutical manufacturers, medical device manufacturers, and research facilities. Membership provides access to threat intelligence, working groups, events, and the secure sharing platform.
- Summit and Event Registration: Revenue from registration fees for regional and global summits including CISO Summit, European Summit, Fall Americas Summit, and APAC Summit.
- Sponsorship Programs: Revenue from sponsor programs including Pathfinder, Champion, and Visionary tiers, as well as summit sponsorships and ambassador program sponsorships for technology and security vendors.
Pricing tiers
| Model | Billing | Price |
|---|---|---|
| Subscription | Annual | Standard membership with access to threat intelligence, working groups, and events |
| Freemium | Pay-as-you-go | 60-day no-cost trial membership |
Go-to-market motion1 record
Distribution channels3 records
Marketing channels7 records
H-ISAC product offering
Product offeringCore offering
H-ISAC operates as a trusted, membership-based community that enables healthcare organizations to share real-time cyber threat intelligence and collaborate on collective defense. Members gain access to a secure Threat Intelligence Portal (HTIP), the Indicator Threat Sharing Tool (HITS), SecureChat for peer communication, and the SBOM Studio for medical device software bill of materials management. The organization also provides summits, workshops, working groups, and educational content to strengthen sector-wide cybersecurity resilience.
Product overview
Health-ISAC (Health Information Sharing and Analysis Center) is a non-profit trusted community organization, not a commercial technology product company. It provides a platform for threat intelligence sharing, collaboration, and cybersecurity resources for the global health sector. The core offerings include the Threat Intelligence Portal (HTIP) for accessing alerts and intelligence, the Indicator Threat Sharing Tool (HITS) for sharing indicators, and SecureChat for peer communication. Additional offerings include the SBOM Studio for software bill of materials management (via Cybeats partnership), healthcare cybersecurity benchmarking studies, resilience exercise programs, medical device security guidance, clinician training, whitepaper series, and regular Hacking Healthcare blog content. Members also access regional summits (CISO, European, Americas, APAC) for networking and education.
Differentiator
Problem solved
Functional benefit
Products and services
- Health-ISAC Membership Annual membership program providing healthcare organizations with access to threat intelligence, working groups, events, secure sharing platform, and peer collaboration opportunities.
- Health-ISAC Threat Intelligence Portal (HTIP) Secure portal providing members access to threat intelligence, targeted alerts, and real-time information sharing capabilities for the global health sector.
- Health-ISAC Indicator Threat Sharing Tool (HITS) Tool enabling members to share and receive threat indicators to enhance situational awareness and support timely action against current threats.
- Health-ISAC SecureChat Secure chat channel enabling members to communicate, collaborate, and share best practices with health security peers around the world.
- Health-ISAC SBOM Studio Platform for healthcare organizations to manage and share Software Bill of Materials (SBOM) information, accessible through partnership with Cybeats.
- Health-ISAC Resilience Exercise Series Tabletop exercises and simulation drills designed to strengthen operational resilience and incident response capabilities for healthcare organizations.
- Health-ISAC Summits Regional and topic-specific summits (CISO Summit, European Summit, Fall Americas Summit, APAC Summit) providing networking, education, and threat intelligence sharing opportunities.
- Sponsor Programs Sponsor programs (Pathfinder, Champion, Visionary) for technology and security vendors, plus Ambassador Program and summit sponsorships.
- Medical Device Security Program Resources and guidance focused on medical device cybersecurity, including white papers, best practices, and coordination with manufacturers and healthcare delivery organizations.
Quantifiable outcome
- 85% of Top 25 Global Pharmaceutical Manufacturers are Health-ISAC members
- +2 more outcomes
Companies that use H-ISAC
Customer profileNamed customers5 records
Segments5 records
Ideal customer profiles3 records
H-ISAC technology and API
TechnologyTechnology focussed No
API detail
- Has API
- No
- API docs
- API detail
Core technology
AI maturity
App detail
Feature5 records
H-ISAC partnerships and signals
Strategic signalPartnerships
Eleven partnerships are on record, tiered core and minor.
- Google CloudcoreGoogle Cloud is an Ambassador-level sponsor and strategic partner. The partnership focuses on advancing healthcare cybersecurity through shared vision for building a safe and reliable health ecosystem.
- National Council of ISACs (NCI)coreHealth-ISAC is an active member of the National Council of ISACs, participating in cross-sector information sharing initiatives and monthly webinars during Critical Infrastructure Security and Resilience Month.
- CI-ISACcoreHealth-ISAC and CI-ISAC have signed a Memorandum of Understanding for collaborative threat intelligence sharing across critical infrastructure sectors.
- CHIME/AEHIScorePartnership to provide timely healthcare security alerts and tactics for CHIME/AEHIS membership, combining Health-ISAC threat intelligence with CHIME's healthcare IT leadership network.
- CybeatscorePartnership to provide H-ISAC SBOM Studio, enabling healthcare delivery organizations to access Software Bill of Materials management for medical device security.
- CywarecoreCyware launched a threat intelligence platform specifically designed to defend healthcare organizations from cyber threats, featuring the industry's first automated ISAC-to-ISAC operational collaboration.
- Booz Allen HamiltonminorBooz Allen Hamilton joined the Ambassador Program to support healthcare cybersecurity initiatives and engage with Health-ISAC community members.
- RiskRecon and MastercardcorePartnership focused on third-party risk management for healthcare organizations, combining RiskRecon's security ratings with Mastercard's financial intelligence.
- AWS and IBMcoreHealth-ISAC joined AWS, IBM, and 34 other organizations in the Cyber Resiliency Pledge, a commitment to advancing cybersecurity across critical infrastructure.
- Healthcare and Public Health Sector Coordinating Council (HSCC)coreHSCC works with Health-ISAC on joint guidance including the 3rd-Party AI Risk & Supply Chain Transparency Guide and testimony before the Senate HELP Committee.
- American Hospital Association (AHA)coreJoint Threat Bulletins and collaborative warnings to the healthcare sector on emerging threats including potential terror threats and ransomware groups.
Scale indicators7 records
Recent moves7 records
Expansion highlights6 records
H-ISAC competitors and assessment
Company assessmentDirect peers
- FS-ISAC: Information Sharing and Analysis Center for the financial services sector. Direct ISAC analog — membership-funded nonprofit, similar leadership/governance, TLP-classified threat intel, working groups and global summits, but serves financial institutions rather than healthcare.
- Auto-ISAC: Information Sharing and Analysis Center for the automotive sector. Closely comparable ISAC structure — member-funded, threat intelligence sharing, working groups, OEM/vehicle cybersecurity focus — with analogous challenges around operational technology.
- E-ISAC (Electricity Information Sharing and Analysis Center): ISAC serving the North American electricity subsector. Operates the same information-sharing model with TLP classification, sector-specific threat intel, and a CISA-affiliated mandate — directly comparable operating playbook to Health-ISAC.
- MS-ISAC (Multi-State Information Sharing and Analysis Center): ISAC for U.S. state, local, tribal and territorial governments, operating under CIS. Similar sector ISAC model — fee-based membership, threat intelligence, incident response — though focused on public-sector entities; sits within the same National Council of ISACs umbrella.
- IT-ISAC: Information Sharing and Analysis Center for the information technology sector. Peer ISAC by structure: member-driven, TLP-classified threat intel exchange, working groups, vendor / product-security focus — overlapping membership with Health-ISAC via large tech vendors.
- CHIME / AEHIS: CHIME's AEHIS (Association for Executives in Healthcare Information Security) is a named GTM/marketing partner of Health-ISAC. Comparable because it serves healthcare security leaders and provides threat alerts, networking, and education — partially overlapping with Health-ISAC's value proposition.
Others
- National Council of ISACs (NCI): The umbrella body of which Health-ISAC is a member, coordinating cross-sector information sharing among ISACs. Comparable as an ecosystem coordinator and a relevant counterpart for partnership activity, but not a direct competitor.
Broad incumbents
- CrowdStrike (Falcon Intelligence): Commercial endpoint/incident-response vendor offering subscription threat intelligence. Overlaps with Health-ISAC as an alternative intelligence source for healthcare security teams, but operates as a paid commercial platform for a broad customer base rather than a sector-specific trust community.
- Mandiant (Google Cloud): Threat intelligence and incident response firm (now part of Google Cloud). Google Cloud is itself an H-ISAC Ambassador sponsor; Mandiant competes for the same healthcare security budgets via commercial threat intel subscriptions and IR retainers.
Emerging players
- Anomali: Threat intelligence platform vendor that integrates with ISAC feeds. Partial overlap — Anomali enables consumption and analysis of the threat indicators that Health-ISAC members share via HITS / HTIP — adjacent but not directly comparable.
Market position
Strengths5 records
Weaknesses5 records
Competitive moat6 records
Key risks6 records
Key highlights6 records
Customer concentration
H-ISAC social profiles
Digital presenceH-ISAC financial estimates
Financial estimateRevenue estimate
Valuation estimate
H-ISAC leadership team
Management profileNumber of profiles
Profiles6 records
H-ISAC funding detail
Funding detailFunding overview
Funding rounds
Investors
Funding detail is available on the Subscription and Enterprise plan.Contact sales →
H-ISAC M&A and investment
M&A and investmentM&A
Investments
M&A and investment is available on the Subscription and Enterprise plan.Contact sales →
Frequently asked questions about H-ISAC
What does H-ISAC do?
H-ISAC operates as a trusted, membership-based community that enables healthcare organizations to share real-time cyber threat intelligence and collaborate on collective defense. Members gain access to a secure Threat Intelligence Portal (HTIP), the Indicator Threat Sharing Tool (HITS), SecureChat for peer communication, and the SBOM Studio for medical device software bill of materials management. The organization also provides summits, workshops, working groups, and educational content to strengthen sector-wide cybersecurity resilience.
Is H-ISAC a public or private company?
H-ISAC is a private company. It is classified as nonprofit foundation owned and is currently operating.
When was H-ISAC founded?
H-ISAC was founded in 2010. It employs 1 to 10 people.
Where is H-ISAC based?
H-ISAC is headquartered in Ormond Beach, United States, in the North America region.
How does H-ISAC make money?
Three revenue lines are on record. Membership Fees are the primary driver. The others are summit and Event Registration and sponsorship Programs.
Who are H-ISAC's main competitors?
Direct peers on record are FS-ISAC, Auto-ISAC, E-ISAC (Electricity Information Sharing and Analysis Center), MS-ISAC (Multi-State Information Sharing and Analysis Center), IT-ISAC and CHIME / AEHIS. National Council of ISACs (NCI) is listed as an others. Broad incumbents are CrowdStrike (Falcon Intelligence) and Mandiant (Google Cloud). Anomali is listed as an emerging player.
Does H-ISAC have an API?
No public API is recorded for H-ISAC.
What industry is H-ISAC in?
H-ISAC's product category is Healthcare Cybersecurity Information Sharing. Its primary akta.pro industry code is HLACAJAH, Application & API Security for Digital Health (WAF/RASP/API gateways), with a secondary code of EDABAGAB, Phishing, Social Engineering & Business Email Compromise (BEC) Training. Its NAICS code is 813910 and its SIC code is 8600.