CrowdStrike Falcon® for XIoT is extending its industry-leading protections to medical devices in healthcare environments. This will provide comprehensive security for patient care at a time when healthcare organizations are a key target for threat actors.
As of January 2026, the HHS listed over 750 reported breaches within healthcare environments that were under investigation. The CrowdStrike 2026 Global Threat Report revealed a sustained increase in interactive intrusion campaigns throughout 2025, with 10% of them targeting healthcare.
The proliferation of connected medical devices such as infusion pumps, patient monitors, and imaging tools has expanded the attack surface. Many of these devices obtain sensitive clinical data, are mission-critical to patient safety and healthcare operations, and often are legacy systems operating unsupported or at end-of-life. In addition to connected medical devices, hospitals must also manage connected XIoT devices such as security cameras, lighting and energy systems, and building management systems. If any of these devices are taken off their network, the consequences could be severe.
With hospitals managing a consistently growing number of connected devices, their protection must be a top priority. Falcon for XIoT is introducing support for medical device protocols by providing continuous visibility and protection for connected healthcare environments. The cloud-native Falcon sensor will be able to monitor device behavior and protocol communications, detect anomalies, and block malicious actions before they impact patient care. This capability is now available in beta.
IoT, OT, and IoMT Asset Visibility in the Falcon Platform
The discovery of IoMT, IoT, and OT devices on hospital networks typically requires additional network scanning solutions or manual inventory tracking. Falcon for XIoT will be able to natively obtain asset visibility of internet-connected clinical devices across DICOM (Digital Imaging and Communications in Medicine), HL7 (Health Level 7), and other clinical or IoT devices on the network.
By obtaining an automated inventory collection, Falcon for XIoT will be able to identify legacy devices and unsupported assets, and profile other devices for integration into security processes and controls directly in the Falcon platform.