HEALTHCARE CYBERSECURITY EXPERTS
Secure in use.
Secure in your audit.
We give MDR manufacturers the audit-ready cybersecurity evidence their Notified Body demands under IEC 81001-5-1 — from pentests and secure code reviews to the compliance documentation that makes them count. Hospitals turn to us for §17 MPBetreibV assessments; healthcare cloud operators for C5 readiness.
WHO WE SERVE
Three audiences. One specialty.
You build a medical device
Your Notified Body demands cybersecurity evidence under IEC 81001-5-1. We deliver it — pentests, secure code reviews, and the compliance documentation that makes them count.
MDR cybersecurityYou run IT in a hospital or clinic
§17 MPBetreibV requires independent security assessments for medical device software in clinical operation. We handle them and deliver reports for your device logbook.
§17 MPBetreibV testingYou process patient data in the cloud
§393 SGB V makes a C5 Type 2 attestation mandatory. We prepare you end-to-end — from control mapping to audit-ready evidence.
C5 readinessOur Team
Meet our qualified experts who combine academic research with years of practical cybersecurity experience, specializing in medical device security and compliance.

Dr. rer. nat. Simon Weber
Senior Penetration Tester & Security Researcher
PhD security researcher who found critical vulnerabilities in hospital systems and contributed to the B3S hospital security standard (BAK MV). Simon turns academic rigor into audit-ready results that protect real patients.

Dipl.-Inf. Volker Schönefeld
Senior Penetration Tester & Application Security Expert
20+ years as CTO. 50+ million app downloads. Teams up to 35 experts. IoT fleets with thousands of devices. Volker brings deep security expertise and makes complex compliance simple.
PROOF, NOT PROMISES
Critical vulnerabilities in healthcare,
responsibly disclosed.
We don't just test: we find critical vulnerabilities in healthcare systems and coordinate their disclosure with vendors and authorities. Our public track record across gematik, Orthanc, DCMTK, and the Robert Koch Institute is how our clients know our pentests find what matters.
What Our Clients Say
Hear from teams we've worked with

“We have been working with Machine Spirits for several years and value their technical expertise and straightforward collaboration. Their actionable recommendations have been instrumental in sustainably strengthening the protection of the patient data entrusted to us.”
“As a security partner for our DiGA, Machine Spirits impressed us with their in-depth pentests. Their competent TR-03161 consulting and clear recommendations were crucial in meeting the demanding BSI requirements quickly and securely.”

“Machine Spirits helped uncover vulnerabilities in our platform early with a structured and in-depth pentest before we went through MDR certification. The clear reports and pragmatic communication helped us quickly close security gaps and efficiently update our documentation.”
Our Expertise
We specialize in cybersecurity for healthcare: medical devices, hospital infrastructure, and cloud compliance.
MDR Penetration Testing
Audit-ready security testing for MDR Class I, IIa & IIb medical devices and SaMD. We deliver the technical evidence Notified Bodies require for IEC 81001-5-1 compliance.
Learn moreDICOM & PACS Security
The DICOM standard was built for connectivity, not security. We test PACS systems and medical imaging infrastructure against both protocol-level threats and MDR compliance requirements.
Learn moreSecure Code Review
Source code analysis by experienced developers. We find security flaws and provide fixes that fit your architecture and accelerate secure releases.
Learn moreHospital IT Security
Independent IT security assessments for medical device software per §17 MPBetreibV. Standards-compliant testing that stands up in your medical device logbook and before regulatory authorities.
Learn moreC5 Cloud Compliance
Your cloud provider's C5 attestation covers their infrastructure, not your application. We help healthcare organizations achieve their own C5 Type 2 attestation under §393 SGB V.
Learn moreAI & LLM Security
Security assessments for AI-powered medical devices navigating the intersection of MDR and EU AI Act compliance. From prompt injection to model manipulation and data extraction.
Learn moreContact Us
Get in touch to discuss your security requirements.
Phone
+49 221 65031192Response Time
We typically respond to all inquiries within 24 hours during business days.
Average response time: 6-12 hours

