Blog
EMS Cybersecurity Insights & Resources
Supply-Chain Attacks Through Medical-Device Vendors
How the SolarWinds and Kaseya attack model applies to cardiac monitors, defibrillators, and EMR integrations in EMS.
ImageTrend, ESO, and Zoll Online: A Security-Posture Evaluation Framework
A vendor-neutral rubric for evaluating ePCR platform security at renewal time, with specific questions to send ImageTrend, ESO, and Zoll Online.
Working With an IT MSP That Doesn't Understand EMS
The operational realities your generalist MSP is missing, the contract addendum that closes the gap, and the boundary between IT and operations.
12-Lead Transmission and STEMI Notification Security
How your 12-lead ECG reaches the receiving cath lab today, the HIPAA exposure in each path, and the architecture that is both faster and more defensible.
Paging App Security for Fire and EMS — Active911, IamResponding Threat Model
A practical threat model for Active911, IamResponding and similar paging apps covering the data pipeline, location privacy, and vendor renewal questions.
Vendor Risk Management for Small EMS Agencies Without a CISO
How to manage vendor risk for a small EMS agency without a CISO. A lean 80-20 approach focusing on the vendors that handle PHI and keep the trucks running.
Your ePCR Vendor's BAA Probably Isn't Enough
Most ePCR BAAs meet the vendor's minimum, not yours. Here are the clauses and redline questions EMS agencies should send back before signing.