Trimedx adds agentic AI to TMX Protect to cut device cyber remediation
Trimedx has launched agentic AI capabilities within its TMX Protect platform, the Indianapolis-based clinical asset company announced on 26 August 2026. The update is positioned by the company as a significant step forward in helping health systems identify, prioritise, and address cybersecurity vulnerabilities across connected medical devices, with Trimedx reporting an average 75% reduction in remediation time for cybersecurity projects.
The new functionality allows clinical cybersecurity teams to query the platform using natural-language prompts, surfacing device risk data and generating reports without requiring specialist technical queries. Trimedx says TMX Protect achieves up to 95% identification and matching accuracy across connected medical device inventories, drawing on the company's proprietary dataset covering more than 7.4 million devices.
The platform and the problem it addresses
The release points to a difficult operating environment for hospital cybersecurity teams. According to Trimedx's own figures, more than 50% of connectable medical devices carry known critical vulnerabilities, and 99% of hospitals manage at least one connected device with a known, exploited vulnerability. Those statistics are consistent with findings from healthcare cybersecurity researchers and independent bodies, though Trimedx does not cite an external source for the specific figures in this release.
TMX Protect combines device inventory data, vulnerability intelligence, and workflow tooling in a single platform. The agentic AI layer sits on top of that data estate, enabling users to identify high-risk assets, generate risk assessments, track remediation progress, and surface mitigation strategies for vulnerabilities that lack a manufacturer-approved patch. The last point is notable: a substantial proportion of legacy medical device vulnerabilities have no vendor fix available, so the ability to identify and document compensating controls has practical value for compliance and clinical risk teams.
Srilekha Akula, Chief Data and AI Officer at Trimedx, said the new capabilities are designed to "turn large volumes of device and vulnerability data into actionable insights, enabling teams to prioritise what matters most and take steps that strengthen security while supporting patient care."
Market context and competitive landscape
Connected medical device security has become a dedicated sub-sector within healthcare cybersecurity, drawing both specialist vendors and broader security platforms seeking healthcare verticals. Companies including Claroty, Medigate (now part of Claroty), Armis, and Ordr have built or acquired capabilities targeting the same hospital biomedical and IoT device challenge. The market has attracted heightened regulatory attention: the US Food and Drug Administration's 2023 guidance on cybersecurity in medical devices now requires manufacturers to submit a software bill of materials and a vulnerability disclosure plan with new device submissions, increasing the volume of structured vulnerability data available to platforms such as TMX Protect.
For health systems, the commercial case for dedicated medical device security platforms rests on the difficulty of applying standard IT security tooling to clinical environments, where device downtime carries direct patient-safety implications and patching schedules are constrained by clinical operations. Trimedx's emphasis on combining cybersecurity prioritisation with clinical context addresses that operational reality, though independent validation of the 75% remediation time reduction has not been provided in the announcement.
The company says TMX Protect is already in use across health system clients, though customer names and scale of deployment are not disclosed in this release. Near-term attention will focus on whether Trimedx publishes peer-reviewed or independently audited performance data to substantiate its headline efficiency claim.