The average hospital now operates more than 10,000 connected medical devices — infusion pumps, patient monitors, ventilators, imaging systems, and bedside diagnostic units — each with a network address, a firmware version, an owner, a location, and a PM schedule that may or may not be documented anywhere. As the Internet of Medical Things (IoMT) footprint expands faster than biomedical and IT teams can track it, the gap between devices in operation and devices with documented ownership, maintenance status, and cybersecurity baseline grows into a significant patient safety and regulatory compliance exposure. OxMaint gives hospital biomedical, clinical engineering, and IT security teams a live, unified asset inventory for every connected medical device — tracking ownership, location, PM status, firmware version, network segment, and risk priority so nothing falls through the gap between who manages what.
FDA GUIDANCE
The FDA's 2023 cybersecurity guidance for medical devices requires manufacturers and health systems to maintain a software bill of materials (SBOM) and asset inventory with documented vulnerability management processes for all connected devices.
IOMT ASSET MANAGEMENT
One Inventory. Every Connected Device. Live Status.
OxMaint maintains a real-time asset record for every networked medical device — PM status, ownership, location, risk tier, and maintenance history — all in one searchable dashboard.
Why Undocumented IoMT Devices Are a Growing Risk
62%
of healthcare organizations cannot fully inventory their connected medical devices
Ponemon Institute, Healthcare IoT Security Report
53%
of connected medical devices have at least one known critical vulnerability unpatched
Claroty Healthcare Device Security Report, 2023
88%
of healthcare data breaches involve a device or endpoint with undocumented access credentials
Verizon Data Breach Investigations Report
What an OxMaint Asset Record Captures for Each Connected Device
DEVICE IDENTITY
Device name, manufacturer, model, serial number
Firmware version and last update date
MAC address and IP network segment
Operating system and end-of-support date
OWNERSHIP & LOCATION
Responsible department and clinical owner
Physical location: building, floor, room
Lease vs. owned status and contract expiry
Vendor service agreement and contact
MAINTENANCE & RISK
PM schedule and last completed inspection
Open corrective work orders
Risk tier: critical, high, standard
Known vulnerability flags and patch status
Connected Medical Device Risk Tiers — OxMaint Priority Classification
| Device Category |
Risk Tier |
PM Frequency |
Cybersecurity Review |
OxMaint Action on Overdue |
| Ventilators, infusion pumps |
Critical |
Every 90 days |
Quarterly |
Escalate to biomed director |
| Patient monitors, telemetry |
High |
Every 6 months |
Semi-annual |
Supervisor notification + WO |
| Imaging systems (MRI, CT) |
Critical |
Per OEM schedule |
Annual + patch event |
Escalate immediately |
| Bedside diagnostics |
Standard |
Annually |
Annual |
Queue for next maintenance cycle |
| Nurse call & intercom |
Standard |
Annually |
Annual |
Batch with department PM round |
EXPERT REVIEW
Dr. Anil Mehta, MS, CBET
Certified Biomedical Equipment Technician & Clinical Engineering Director — 17 Years Academic Medical Center
The IoMT inventory problem is deceptively simple-sounding and operationally brutal. Every month a hospital acquires new devices through purchasing, patient transfers, vendor demos, and department-level procurement that bypasses biomedical review. Without an active inventory system, you are always working from a list that is weeks behind reality. The clinical risk is real: when IT security needs to patch a vulnerability in a device category, they need to know every instance, where it is, and who is responsible. A CMMS like OxMaint that enforces asset registration at the point of acquisition is the only way to maintain an inventory that is actually current.
Build a Live, Audit-Ready Inventory of Every Connected Medical Device
OxMaint tracks PM status, ownership, location, and risk tier across your entire IoMT estate — ready for Joint Commission, FDA audit, or cyber incident response.
Frequently Asked Questions
How does OxMaint handle newly acquired or transferred medical devices that aren't in the inventory yet?
OxMaint provides a mobile device intake workflow where biomed technicians scan a barcode or QR code at the point of receipt and immediately create the asset record — capturing manufacturer data, serial number, location, and clinical owner before the device ever reaches a patient floor. Devices in an "unregistered" state trigger an alert to the biomed team for intake processing. This enforces registration as part of the receiving workflow rather than relying on retrospective audits.
Sign up free to configure the intake process.
Can OxMaint integrate with HTM platforms like Nuvolo, ServiceMax, or existing hospital CMMS systems?
OxMaint connects to existing clinical engineering platforms and hospital systems via REST API — either as a primary CMMS or as an integration layer that syncs asset records, PM status, and work order data between systems. For hospitals already using an HTM or biomedical platform, OxMaint can serve as the enterprise-wide facilities layer while passing IoMT device data between systems.
Book a demo to discuss your current system architecture.
How does OxMaint support cybersecurity incident response for connected medical devices?
During a cybersecurity incident affecting a connected device type — such as an FDA advisory requiring isolation of specific infusion pump models — OxMaint allows your IT and biomed teams to instantly query all affected device instances by model, firmware version, network segment, or location. The system can bulk-create work orders to inspect or isolate affected devices, assign them to the right teams, and track remediation progress to completion. This replaces the manual spreadsheet search that typically takes days during an active incident response.
What does OxMaint produce for FDA cybersecurity compliance documentation for connected devices?
OxMaint generates asset inventory reports that include device identity, firmware version, network details, PM history, and open vulnerability status — aligned with the documentation requirements in FDA guidance on cybersecurity for networked medical devices. Reports can be exported by device category, risk tier, or department and are formatted for both internal risk management review and external regulatory submission. The system maintains a dated history of all changes to device records for audit trail purposes.