Eracent offers healthcare orgs free access to SBOM analytics software

Business News

Because it is getting harder to underestimate “the evil genius of the modern-day cybercriminal,” Eracent, which develops asset management tools for software and IT, says it will offer healthcare organizations a no-cost tool that can automate the scanning of medical devices’ software bills of materials and match listed components to vulnerability data in its product library.

WHY IT MATTERS

Beginning October 1, the U.S. Food and Drug Administration announced that new medical device submissions must contain a detailed cybersecurity plan for how manufacturers will monitor and address vulnerabilities.

Part of the 2022 Omnibus Appropriations Act, the long-awaited measure gives the FDA the authority to require the SBOM with each medical device. 

“An SBOM by itself is impotent and ineffective if it is not constantly scrutinized by an automated, proactive process with instant visibility and vigilance in mitigating and resolving any component-level security weaknesses across the life cycle of the hardware/software device,” said Walt Szablowski, Eracent founder and executive chairman, in the announcement.

The C-SCRM platform recognizes obsolete components that can increase security risks, including open-source software components within applications that standard vulnerability analysis tools do not scan, according to Eracent.

The global enterprise network management company, with its U.S. base in Riegelsville, Pennsylvania, says that it is offering access to its device-analytics platform to get all healthcare sectors affected by new medical device cybersecurity regulations on the road to compliance.

Medical device vulnerabilities, such as ones in insulin pumps, defibrillators, mobile cardiac telemetry, pacemakers and intrathecal pain pumps, can be exploited by skilled hackers seeking to interfere with a medical facility’s operations or compromise protected data.

They can also endanger patient health.

“The healthcare industry needs to appreciate the risks that may exist in the medical device software they use, whether open-source or proprietary. And medical device manufacturers need to acknowledge the potential risks inherent in the products they offer,” Eracent said.

THE LARGER TREND

The PATCH Act initially sought to impose a series of cybersecurity requirements for manufacturers applying for premarket approval through the FDA, but the requirement was dropped in the final bill this past year.

In September, the FBI offered healthcare organizations recommendations for addressing cybersecurity vulnerabilities in active medical devices.

However, risk analysis is “still a very manual and labor-intensive process,” said Kathy Hughes, CISO of Northwell Health, during a panel on third-party cybersecurity at the December 2022 HIMSS Healthcare Cybersecurity Forum.

Automating the discovery of vulnerabilities presented by medical devices can help minimize cybersecurity breaches that can impact operations and affect patient care is an important strategy for healthcare IT this year.

ON THE RECORD

“These new cybersecurity regulations tend to have a cascade effect that may sneak up on some unsuspecting entities in and around the aggregate medical-industrial complex,” said Szablowski in the announcement. “We are now offering medical providers and device manufacturers unprecedented free access to our SBOM supply chain risk end-point discovery and end-point analysis software solutions.”

Andrea Fox is senior editor of Healthcare IT News.
Email: af**@***ss.org

Healthcare IT News is a HIMSS Media publication.

Read More
Michele Haslett

Latest

The Area Where Duke Could Dominate College Basketball Next Season

Basketball The Duke basketball program will enter the 2026-27...

Don’t call us just a WLFI treasury company, says AI Financial

The company says it is building a broader fintech, tokenization and digital infrastructure business, but its latest SEC filing shows WLFI still dominates the balance sheet. May 21, 2026, 5:20 a.m. 2 min read Make preferred on AI Financial, formerly known as Alt5 Sigma, wants the market to know that it's more than just its

The new art of war is just as bloody as the old

For help please visit help.ft.com. We apologise for any inconvenience. The following information can help our support team to resolve this issue. Reason Challenge Request ID 9ff3d58409635031 Status Code 403

Navigate Sole Trader Registration With This Step-By-Step Guide

Steering sole trader registration can seem intimidating, but it doesn’t have to be. You’ll begin by selecting a unique business name and, if needed, filing an Assumed Name Certificate. Next, securing an Employer Identification Number (EIN) is vital for tax purposes. Opening a dedicated business bank account helps maintain financial clarity. Comprehending the necessary licenses

Newsletter

Don't miss

The Area Where Duke Could Dominate College Basketball Next Season

Basketball The Duke basketball program will enter the 2026-27...

Don’t call us just a WLFI treasury company, says AI Financial

The company says it is building a broader fintech, tokenization and digital infrastructure business, but its latest SEC filing shows WLFI still dominates the balance sheet. May 21, 2026, 5:20 a.m. 2 min read Make preferred on AI Financial, formerly known as Alt5 Sigma, wants the market to know that it's more than just its

The new art of war is just as bloody as the old

For help please visit help.ft.com. We apologise for any inconvenience. The following information can help our support team to resolve this issue. Reason Challenge Request ID 9ff3d58409635031 Status Code 403

Navigate Sole Trader Registration With This Step-By-Step Guide

Steering sole trader registration can seem intimidating, but it doesn’t have to be. You’ll begin by selecting a unique business name and, if needed, filing an Assumed Name Certificate. Next, securing an Employer Identification Number (EIN) is vital for tax purposes. Opening a dedicated business bank account helps maintain financial clarity. Comprehending the necessary licenses

What Makes an Effective Accounts Receivable Management Strategy?

An effective accounts receivable management strategy is essential for maintaining healthy cash flow in your business. It starts with clear communication about payment terms and a streamlined invoicing process that reduces errors. Implementing solid credit policies helps assess customer risk, as well as leveraging technology can improve efficiency. By monitoring key performance indicators, you can

Tesla’s Business Has Become Much More Diversified in Just the Past Five Years. Does That Make Its Stock a Better Buy Today?

Key Points Tesla's energy generation and storage segment generated 27% revenue growth last year. The company's non-automotive segments were able to help offset a double-digit decline in auto revenue in 2025. These 10 stocks could mint the next wave of millionaires › Tesla (NASDAQ: TSLA) is known for its electric vehicles (EVs), and while they

WD sees sustainability as key business driver in an ‘AI economy’

Hard drive company WD promoted long-term operations and sustainability executive Jackie Jung to become its first chief sustainability officer in February, as it steps up sales to companies building AI data centers. Her vision: Turn sustainability into a “brand” for WD, a strategy that reduces risk for the $6 billion company (formerly known as Western

5 Business Ideas Worth Starting in 2026

If there is one thing Nigerians understand well, it is how to spot opportunity inside hardship. In 2026, that mindset will matter more than ever. The economy is tough, competition is rising, and many people are looking for smarter ways to earn, build, and survive. But even in a difficult environment, some businesses still stand