Services · Tampa Bay, FL

Six disciplines. One focus: keeping healthcare running.

Dark Analytics is a healthcare-only cybersecurity firm. We secure the hospitals, clinics, and connected medical devices that general-purpose IT security quietly misses, every engagement weighed against the one thing that matters most in a clinical environment: keeping care online.

In short

Dark Analytics is a Tampa Bay cybersecurity firm that works exclusively with healthcare organizations. We secure hospitals, clinics, and connected medical devices (IoMT) across six disciplines: Medical Device & IoMT Security, HIPAA Security Rule readiness, penetration testing, incident response and recovery, security risk assessments, and vCISO advisory, all built around clinical uptime, patient safety, and HIPAA compliance.

What Dark Analytics does

We are a cybersecurity firm built for one industry: healthcare. Not healthcare as a side practice or a vertical add-on, exclusively. Every assessment, test, and response we run starts from a premise most security vendors never internalize: an infusion pump is not a laptop, an MRI cannot be patched on a Tuesday, and downtime in a clinical setting is not an inconvenience, it is a patient-safety event.

Our work spans six disciplines, but they share a single spine. The same engineers who run your penetration test understand why a CT scanner is still on an unsupported operating system. The same team that builds your HIPAA risk analysis can tell you which IoMT VLAN an attacker would pivot through first. That continuity is the point, security findings that hold up to an OCR auditor, your board, and your clinical engineering team at the same time.

We serve hospital and clinic IT and security leaders, CISOs, compliance officers, and clinical/biomedical engineering teams across Tampa Bay and beyond.

Medical Device & IoMT Security

Connected medical devices are the largest blind spot in most hospital security programs. Research from Cynerio has found that roughly 53% of connected medical devices carry a known critical vulnerability, and standard endpoint tools often can't patch them, can't run an agent on them, and frequently can't even see them.

We discover, inventory, segment, and monitor connected devices, from infusion pumps to imaging modalities, accounting for the clinical protocols they actually speak (such as DICOM and HL7) rather than the ones enterprise tools expect. The goal is a defensible IoMT estate that respects FDA-cleared firmware and never takes a clinical procedure offline to secure it. Where IoMT exposure surfaces compliance gaps, this work feeds directly into your HIPAA risk assessment; where it surfaces exploitable paths, it informs the scope of your penetration test.

HIPAA Security Rule Readiness

The HIPAA Security Rule may be changing. In a proposed rule published in early 2025, HHS's Office for Civil Rights (OCR) outlined the most significant update to the Security Rule in over two decades, with proposed new expectations around asset inventory, network segmentation, encryption, multi-factor authentication, and vulnerability management. Those are precisely the controls that tend to fail at the medical-device boundary. The rule is not yet final, but the direction is clear.

We map your environment against the Security Rule (codified at 45 CFR Part 164, Subpart C) and relevant NIST guidance (SP 800-66, SP 800-30, and the Cybersecurity Framework), then give you an evidence-backed, prioritized path to compliance, not a checkbox PDF. This discipline connects tightly to our Security Risk Assessment work: the required risk analysis under § 164.308(a)(1)(ii)(A) is only complete when it includes the IoMT estate, which is exactly where our device-security practice earns its keep.

Penetration Testing

Adversary-grade testing of your networks, applications, EHR-adjacent systems, and clinical environment, designed to model how a healthcare-focused threat actor actually moves: in through a VPN or remote-management tool, laterally across un-segmented clinical VLANs, and onto an unprotected imaging or lab device as a foothold.

Where most pen tests stop at corporate IT, ours account for the clinical floor without putting patient care at risk. You get a report your engineers can act on and your board can understand, findings ranked by real exploitability and patient-safety impact, mapped back to the HIPAA Security Rule and NIST so they slot straight into your remediation roadmap and your next risk assessment.

Incident Response & Recovery

Healthcare is consistently among the costliest industries for data breaches, IBM's 2024 Cost of a Data Breach report puts the healthcare average at roughly $9.77 million, and that same report measured an average breach lifecycle of well over 200 days to identify and contain. In a hospital, every hour of that timeline can mean diverted ambulances and downtime procedures.

We offer an incident response retainer that answers fast, contains the threat, and keeps care running through the worst day, preserving forensic evidence, coordinating with your clinical and legal teams, and tracking the breach-notification obligations under HIPAA. After containment, the recovery work and lessons learned feed directly back into hardening, segmentation, and your next risk assessment so the same door doesn't open twice.

Security Risk Assessments

A thorough Security Risk Assessment is a HIPAA requirement, the risk analysis under § 164.308(a)(1)(ii)(A), and it is among the first documents OCR asks for after a breach. Done well, it is also the single most useful planning artifact a healthcare security program has.

We deliver the assessment the way the regulation intends: a real risk analysis aligned to NIST SP 800-30 methodology and OCR expectations, covering corporate IT and the connected-device estate alike. Not a templated checklist, a prioritized, defensible picture of where your ePHI is actually at risk. It pairs naturally with HIPAA Security Rule readiness on the compliance side and penetration testing on the technical side, so the assessment reflects what an attacker could really do, not just what a questionnaire assumes.

vCISO & Advisory

Not every healthcare organization can justify a full-time CISO, but every one needs senior security leadership, a defensible roadmap, and someone who can speak fluently to both the board and the clinical engineering team.

Our virtual CISO (vCISO) and advisory service provides that leadership on demand: security strategy, multi-year roadmaps, vendor and budget guidance, board-level reporting, and program oversight sized for the realities of a hospital or clinic. The vCISO becomes the connective tissue across the other five disciplines, turning point-in-time assessments, tests, and incidents into a coherent, improving security program.

Why a healthcare-only approach matters

Most security firms treat a hospital like an office with more compliance paperwork. That assumption is where they fail. Healthcare security is governed by constraints that don't exist in a normal enterprise, and ignoring any one of them either breaks clinical care or leaves a gap an attacker walks through.

We built our entire practice around those constraints, which is why our six disciplines interlock instead of operating as disconnected line items.

  • Clinical uptime is non-negotiable. A busy radiology suite can't take a 45-minute patch window on demand. Every control we recommend is weighed against the cost of taking care offline.
  • IoMT is the real attack surface. The clinical floor, infusion pumps, telemetry, imaging, surgical robotics, is where general IT tools go blind and where healthcare ransomware often lands.
  • Patient safety is the stakes, not just data. A compromised or downed device is a care event, not just a compliance event. We treat it that way.
  • FDA and biomed realities are respected, not fought. Many devices run FDA-cleared firmware that vendors won't let you modify. We secure around that reality and work with your clinical engineering team, never around them.
  • Evidence you can defend. Every finding is mapped to the HIPAA Security Rule, NIST, and OCR expectations, ready for auditors and your board at the same time.

How the six disciplines work together

These aren't six products you buy off a shelf. They're one practice viewed from different angles, and the value compounds when they connect.

A Security Risk Assessment surfaces where your ePHI is exposed. A penetration test proves which of those exposures an attacker can actually reach. IoMT security closes the clinical-floor gaps a corporate-only effort would miss. HIPAA readiness translates all of it into regulatory standing. Incident response is the insurance for the day something gets through, and the vCISO keeps the whole loop turning year over year. Most organizations start with one engagement (often the free gap assessment or a risk assessment) and let the findings define what comes next.

How it works

  1. 01

    Start with a free gap assessment

    A senior engineer reviews your environment and gives you a prioritized list of what to fix first, no obligation, no sales theater. It's the fastest way to see where you actually stand against the HIPAA Security Rule and on the clinical floor.

  2. 02

    Scope the right discipline(s)

    Findings define the work. Some clients need a single penetration test or risk assessment; others need an IoMT inventory, a HIPAA readiness program, or an IR retainer in place before an incident. We scope to your risk, not a packaged tier.

  3. 03

    Engage senior, healthcare-fluent people

    You work directly with experienced engineers who understand DICOM, HL7, FDA firmware constraints, and OCR enforcement, not a junior analyst running a generic scanner. We coordinate with your IT, security, compliance, and biomedical/clinical engineering teams.

  4. 04

    Deliver defensible, prioritized results

    Every engagement ends in findings mapped to the HIPAA Security Rule, NIST, and OCR expectations, ranked by real exploitability and patient-safety impact, usable by your engineers, your auditors, and your board.

  5. 05

    Build a continuous program

    Point-in-time work feeds an ongoing loop: assessment to test to remediation to advisory, with a vCISO or retainer keeping the program improving year over year instead of resetting each audit cycle.

Frameworks & standards we align to

Every finding maps back to the standards your auditors, board, and cyber-insurer already speak.

HIPAA Security RuleNIST CSF 2.0NIST SP 800-66 / 800-30HITRUST CSFHHS 405(d) HICPFDA premarket cybersecurity

Frequently asked questions

Do you work on a retainer or per project?

Both. Project-based engagements, a penetration test, a Security Risk Assessment, an IoMT inventory, have a defined scope and deliverable. Retainers fit the disciplines that need continuity: incident response, where you need a team that responds fast, and vCISO advisory, where you need ongoing security leadership. Many clients start with a single project and move to a retainer once the findings show where ongoing support pays off.

Is the work remote or onsite?

Most of our work, assessments, HIPAA readiness, network and application testing, vCISO advisory, is delivered remotely. Some engagements genuinely benefit from being onsite, particularly physical IoMT/medical-device discovery, certain incident response scenarios, and biomedical-team coordination. We're based in Tampa Bay, Florida and scope onsite time where it adds real value rather than billing travel for its own sake.

Who on our team do you work with?

Whoever owns the risk. Typically that's IT and security leadership, the CISO or compliance officer, and, critically, your clinical/biomedical engineering team. The biomed relationship is what sets healthcare security apart: securing connected devices without it leads to broken clinical workflows or voided device support. We work alongside biomed, not around them.

Do I have to buy all six services?

No. The disciplines interlock, but you engage only what you need. Most organizations start with the free gap assessment or a Security Risk Assessment, then let the findings determine what comes next, often an IoMT inventory, a penetration test, HIPAA readiness work, or an incident response retainer. There's no bundled tier you're pushed into.

What size healthcare organizations do you serve?

We work with hospitals, clinics, and healthcare organizations of varying sizes, from independent practices and specialty clinics to larger facilities and their connected-device estates. The common thread is healthcare and ePHI, not headcount. If you're a covered entity or business associate with patient data and connected devices to protect, the approach applies.

How does the HIPAA Security Rule apply to medical devices?

The Security Rule requires covered entities and business associates to protect electronic protected health information (ePHI) through administrative, physical, and technical safeguards, beginning with a risk analysis under 45 CFR § 164.308(a)(1)(ii)(A). Connected medical devices that create, receive, store, or transmit ePHI fall within that scope, yet they're often excluded from the analysis because standard tools can't see them. A defensible risk analysis has to include the IoMT estate, which is where most healthcare programs have their largest gap.

Further reading

Field notes from our research that go deeper on this work.

Find your gaps before attackers do.

A free, no-obligation HIPAA Security Rule gap assessment, a senior engineer, your environment, and a prioritized list of what to fix first. The fastest way to see where you stand across all six disciplines.

Book the free gap assessment → →