MedSec LLC
- Company typePrivate
- Founded2016
- HeadquartersMiami, United States
- Headcount11–50
- GTM typeB2B
- OfferingServices
What MedSec LLC does
MedSec LLC, founded in 2016 and headquartered in Fort Lauderdale, Florida, is a boutique cybersecurity firm that operates exclusively in the medical device and healthcare delivery vertical. The company delivers professional services to two primary customer segments: medical device manufacturers (penetration testing, threat modeling, architecture and design reviews, incident response, regulatory submission support covering FDA premarket reviews, EU MDR, IEC 81001-5-1 audits, and FDA mock submissions) and hospitals and healthcare delivery organizations (cybersecurity program development, policy templates, fleet risk reduction, vulnerability management, and MDS2 completion support). Its product surface comprises three layers: a consulting practice sold via enterprise sales motion, MedSec Academy training (Fundamental and Core course series plus free webinars used for lead generation), and the BRIDGE communication platform launched in March 2026, which connects medical device manufacturers (paying a nominal annual membership) with hospitals (joining free) to deliver vulnerability advisories, MDS2 forms, and end-of-support notifications through a unified dashboard.
BRIDGE, which is a registered trademark, is the company's product-led growth vehicle and creates a two-sided marketplace whose value scales with the number of manufacturers and hospitals on the platform; the firm has referenced engagement with 40+ healthcare systems during prototyping and frames its broader ecosystem as spanning 300+ organizations. Revenue mechanics mix recurring subscription (BRIDGE manufacturer fees), professional services (consulting and paid Academy courses), and freemium (hospital access, free webinars). The firm has no disclosed external funding, operates with 11-50 employees, and monetizes through direct enterprise sales for advisory work and self-serve onboarding for BRIDGE.
MedSec's defensibility rests on its regulatory standing: CEO Michelle Jump serves as convener of ISO/TC 215 WG4, project lead for ISO 81001-5-2, a member of JWG7, and (as of April 2026) Chair of the U.S. Technical Advisory Group for ISO/TC 215 and U.S. Head of Delegation. The team draws senior practitioners from Medtronic, Stryker, Smith & Nephew, and the U.S. Navy, supported by a Technical Advisory Board that includes senior security leaders from Mozilla, Northeastern University, ANALYGENCE Labs, and CareFirst. The firm maintains affiliations with AAMI, CISA, Health-ISAC, APAC Med, MDIC, and the Healthcare and Public Health Sector Coordinating Council, and generates demand through HIMSS, AAMI eXchange, and International MedTech conferences.
MedSec LLC firmographics
Firmographics- Name
- MedSec LLC
- Legal name
- MedSec, LLC
- Website
- https://medsec.com
- Company type
- Private
- Founded year
- 2016
- Operating status
- Operating
- Headcount range
- 11–50 employees
- Ownership category
- akta.pro rank
MedSec LLC industry classification
Industry- Product category
- Medical Device Cybersecurity Services
- NAICS
- Other Scientific and Technical Consulting Services (541690), Computer Systems Design and Related Services (54151)
- SIC
- Services-Health Services (8000), Services-Computer Programming, Data Processing, Etc. (7370)
- akta.pro primary industry
- Governance, Risk & Compliance (GRC) + HIPAA/HITRUST/ISO Readiness (HLACAJAJ)
Keywords
Where MedSec LLC is headquartered
LocationHeadquarters
- HQ city
- Miami
- HQ country
- United States
- HQ region
- North America
Offices1 record
Markets served
MedSec LLC business model
Business model- GTM type
- B2B
- Offering type
- Services
- Cost components
- Personnel, Technology or R&D, Marketing or Sales, Operations, Infrastructure
Revenue model
- BRIDGE Platform Membership: Medical device manufacturers pay a nominal membership fee to use the BRIDGE platform for communicating security information to hospitals. Hospital customers join for free, creating a two-sided marketplace model.
- Cybersecurity Consulting Services: Advisory and consulting services including penetration testing, threat modeling, architecture reviews, security compliance, and incident response for medical device manufacturers and hospitals.
- Training Courses: MedSec Academy offers fee-based training courses for medical device manufacturers covering regulatory compliance, technical security, and global standards. Courses include Fundamental Series (beginner) and Core Series (advanced) with different difficulty levels.
- Free Webinars: Free educational webinars on regulatory, standards, and technical aspects of medical device cybersecurity serve as lead generation for paid consulting and training services.
Pricing tiers
| Model | Billing | Price |
|---|---|---|
| Subscription | Annual | BRIDGE Platform - Manufacturer Membership |
| Freemium | Monthly | BRIDGE Platform - Hospital Access |
| Other | Multi-year contract | Training Courses |
| Freemium | Monthly | Webinars |
Go-to-market motion4 records
Distribution channels5 records
Marketing channels9 records
MedSec LLC product offering
Product offeringCore offering
MedSec LLC provides cybersecurity services and solutions to medical device manufacturers and hospitals, including penetration testing, threat modeling, architecture reviews, incident response, and regulatory submission support. The company also operates BRIDGE™, a centralized communication platform that connects manufacturers with healthcare delivery organizations for sharing vulnerability advisories, MDS2 forms, and end-of-support notifications.
Product overview
MedSec LLC operates as a global leader in medical device and hospital cybersecurity services, offering a portfolio of professional services and a proprietary communication platform. The core offerings include BRIDGE™, a centralized platform that connects medical device manufacturers with healthcare delivery organizations for security information sharing, and MedSec Academy, which provides structured training through Fundamental and Core course series. Technical services include penetration testing, threat modeling, and architecture reviews. Compliance services encompass regulatory submission support, incident response, and IEC 81001-5-1 audits. Additional programs include the Partner Program (ongoing strategic support), Accelerator Program (security risk management and threat modeling), and MedSec Community (bi-monthly intelligence sessions). The company also offers hospital-specific advisory services for building cybersecurity programs.
Differentiator
Problem solved
Functional benefit
Brands
- BRIDGE: A communication platform designed to connect medical device manufacturers (MDMs) and healthcare delivery organizations (HDOs) for more effective sharing of critical device security information. Delivers vulnerability advisories, MDS2 forms, and End of Support notifications through a single trusted platform.
Products and services
- BRIDGE™ Platform A centralized communication platform that connects medical device manufacturers with healthcare delivery organizations, delivering vulnerability advisories, MDS2 forms, and End-of-Support notifications through a single dashboard. Manufacturers pay a nominal membership fee; hospitals join for free.
- MedSec Academy Industry education platform offering specialized training through Fundamental and Core course series covering FDA submissions, international regulations, cybersecurity standards, and architecture views for medical device cybersecurity professionals.
- Technical Services Technical cybersecurity services including penetration testing (web, network, mobile, embedded, mainframe), threat modeling, and architecture and design reviews for medical device manufacturers.
- Security Compliance Services Compliance services including incident response, regulatory submission support (early review, FDA mock submission, deficiency support), and IEC 81001-5-1 audits for medical device manufacturers.
- Hospital Cybersecurity Advisory Services Advisory services for hospitals including cybersecurity program basics, policy and procedure templates, progressive risk reduction planning, medical device security programs, vulnerability management, and network segmentation approaches.
- MedSec Partner Program Ongoing strategic support program providing continuous partnership benefits and discounted training for medical device manufacturers.
- Accelerator Program Focused program for security risk management and threat modeling to accelerate manufacturer cybersecurity capabilities.
Quantifiable outcome
- 40+ healthcare systems provided feedback supporting BRIDGE platform concept at AAMI eXchange prototype demonstration
- +1 more outcomes
Companies that use MedSec LLC
Customer profileSegments3 records
Ideal customer profiles3 records
MedSec LLC technology and API
TechnologyTechnology focussed Yes
API detail
- Has API
- No
- API docs
- API detail
Core technology
AI maturity
App detail
Feature5 records
MedSec LLC partnerships and signals
Strategic signalPartnerships
Eight partnerships are on record, tiered affiliation and core.
- AAMIaffiliationMedSec shows AAMI logo as part of industry involvement section on website, indicating participation in AAMI eXchange conferences and alignment with AAMI standards and guidelines for medical device cybersecurity.
- Cybersecurity & Infrastructure Security Agency (CISA)affiliationMedSec shows CISA logo indicating alignment with federal cybersecurity guidance and participation in national cybersecurity initiatives for healthcare infrastructure.
- Health-ISACaffiliationHealth-ISAC membership shown on website indicating participation in healthcare cybersecurity information sharing and industry collaboration.
- APAC MedaffiliationMedSec shows APAC Med logo indicating focus on Asia-Pacific medical device market and regional industry involvement.
- ISO (International Organization for Standardization)coreMedSec CEO Michelle Jump serves as convener of ISO Technical Committee for Health Informatics WG4 (Security, Safety and Privacy), project lead for ISO 81001-5-2, and member of JWG7, providing deep involvement in international standards development.
- Healthcare and Public Health Sector Coordinating CouncilaffiliationMedSec shows Healthcare and Public Health logo indicating collaboration with sector coordinating bodies for healthcare cybersecurity.
- Medical Device Innovation Consortium (MDIC)affiliationMedSec shows MDIC logo indicating collaboration with the medical device innovation consortium focused on regulatory science and patient safety.
- Technical Advisory Board MemberscoreMedSec partners with a Technical Advisory Board including Stephanie Domas (VP of Security, Mozilla), Kevin Fu (Professor, Northeastern University), Art Manion (Deputy Director, ANALYGENCE Labs), and Rob Suarez (VP & CISO, CareFirst) providing technical guidance and strategic counsel.
Scale indicators3 records
Recent moves6 records
Expansion highlights6 records
MedSec LLC competitors and assessment
Company assessmentDirect peers
- Cynerio: Healthcare cybersecurity platform focused on medical device security for hospitals. Direct competitor to MedSec's hospital-side offering and BRIDGE platform, with overlapping customer base and similar vulnerability-management value proposition.
- Claroty: Industrial and medical IoT cybersecurity vendor with deep healthcare segment focus. Competes with MedSec on medical device visibility, vulnerability management, and hospital-side security programs.
- Asimily: Medical device cybersecurity platform serving hospitals and HDOs with device inventory, risk scoring, and vulnerability prioritization. Closely overlaps MedSec's BRIDGE and hospital advisory offerings across the same buyer profile.
- NCC Group: Global cybersecurity consulting firm with established medical device security testing practice. Competes with MedSec's penetration testing, threat modeling, and regulatory submission support services.
- Finite State: Medical device security platform purpose-built for manufacturers, offering firmware analysis, SBOM management, and vulnerability disclosure. Direct overlap with MedSec's manufacturer-side services and BRIDGE.
Broad incumbents
- Mandiant (Google Cloud): Incident response and cybersecurity consulting firm (now part of Google Cloud) with healthcare vertical services. Overlaps with MedSec's incident response and regulatory advisory practices at enterprise scale.
- CrowdStrike: Large endpoint and cloud security vendor with expanding healthcare and medical device security practice. Represents a well-capitalized incumbent that could move further into MedSec's niche with broader portfolio leverage.
- Palo Alto Networks (Unit 42): Major cybersecurity platform with Unit 42 consulting arm covering healthcare and IoT/OT security. Represents a broad incumbent that competes for the same enterprise medical-device manufacturer and hospital security budget.
- Schellman: Cybersecurity compliance and audit firm covering HIPAA, HITRUST, SOC 2, and ISO standards. Adjacent competitor to MedSec's regulatory compliance and standards advisory offerings.
Emerging players
- TRM Labs: Blockchain and digital asset risk management firm. Tangentially adjacent in the broader healthcare cybersecurity ecosystem but not a direct competitor; included only as an emerging player in adjacent security domains MedSec could expand into.
Market position
Strengths5 records
Weaknesses5 records
Competitive moat5 records
Key risks7 records
Key highlights7 records
Customer concentration
MedSec LLC social profiles
Digital presenceMedSec LLC financial estimates
Financial estimateRevenue estimate
Valuation estimate
MedSec LLC leadership team
Management profileNumber of profiles
Profiles12 records
MedSec LLC funding detail
Funding detailFunding overview
Funding rounds
Investors
Funding detail is available on the Subscription and Enterprise plan.Contact sales →
MedSec LLC M&A and investment
M&A and investmentM&A
Investments
M&A and investment is available on the Subscription and Enterprise plan.Contact sales →
Frequently asked questions about MedSec LLC
What does MedSec LLC do?
MedSec LLC provides cybersecurity services and solutions to medical device manufacturers and hospitals, including penetration testing, threat modeling, architecture reviews, incident response, and regulatory submission support. The company also operates BRIDGE™, a centralized communication platform that connects manufacturers with healthcare delivery organizations for sharing vulnerability advisories, MDS2 forms, and end-of-support notifications.
Is MedSec LLC a public or private company?
MedSec LLC is a private company. It is classified as founder individual operated bootstrapped and is currently operating.
When was MedSec LLC founded?
MedSec LLC was founded in 2016. It employs 11 to 50 people.
Where is MedSec LLC based?
MedSec LLC is headquartered in Miami, United States, in the North America region.
How does MedSec LLC make money?
Four revenue lines are on record. BRIDGE Platform Membership is the primary driver. The others are cybersecurity Consulting Services, training Courses and free Webinars.
Who are MedSec LLC's main competitors?
Direct peers on record are Cynerio, Claroty, Asimily, NCC Group and Finite State. Broad incumbents are Mandiant (Google Cloud), CrowdStrike, Palo Alto Networks (Unit 42) and Schellman. TRM Labs is listed as an emerging player.
Does MedSec LLC have an API?
No public API is recorded for MedSec LLC.
What industry is MedSec LLC in?
MedSec LLC's product category is Medical Device Cybersecurity Services. Its primary akta.pro industry code is HLACAJAJ, Governance, Risk & Compliance (GRC) + HIPAA/HITRUST/ISO Readiness. Its NAICS code is 541690 and its SIC code is 8000.