Noxturnal Security Statement
Nox Medical treats cybersecurity as part of the medical device lifecycle for Noxturnal and Noxturnal US. Noxturnal is desktop Software as a Medical Device used by trained healthcare professionals to configure Nox devices, collect or download sleep study recordings, review and analyze physiological signals, and prepare reports. Our current security risk management file concludes that Noxturnal's individual and overall residual security risks are acceptable, and that no vulnerabilities affecting cybersecurity or product safety have been identified that require reporting to end users.
Security Compliance Basis
Noxturnal is managed under a formal security risk management process aligned with current medical device cybersecurity expectations, including IEC 81001-5-1:2021, ANSI/AAMI SW96:2023, IEC 82304-1:2016, ISO/IEC 29147:2018, FDA medical device cybersecurity guidance, IMDRF cybersecurity and SBOM principles, and AAMI TIR57. Security analysis is maintained through the product lifecycle and is documented in the Noxturnal Security Risk Management Plan, Security Threat Evaluation, Security Risk Management Report, Cybersecurity Activities record, and Software Bill of Materials.
How Security Is Addressed
- Threat modeling uses STRIDE and DREAD to identify assets, trust boundaries, data flows, threat actors, vulnerabilities, potential patient or operator impact, and countermeasures.
- The assessment covers Noxturnal's Windows desktop installation, local and network recording libraries, configuration databases, Nox devices, Nox C1 access points, third-party device interfaces, HL7 and GDT integrations, and supported server/cloud connections.
- All evaluated residual security risks are categorized as Minor after controls, meaning the residual risk is considered acceptable under the product's security risk acceptance criteria.
- Implemented controls are reviewed from both security and safety perspectives, including whether controls introduce new hazards or conflicting requirements.
Product and Deployment Controls
| Area | Customer relevant summary |
| Installation integrity | Noxturnal is installed through a signed installer, and installed assemblies are signed with a digital certificate bearing the Nox Medical ehf. name. Installation or update requires administrator privileges. |
| Customer environment | Noxturnal runs on customer-managed Windows PCs and, where used, customer-managed LANs, storage, databases, and endpoint controls. Nox Medical does not have access to the customer's production PC environment. |
| Access and data handling | Local settings, recording indexes, recording libraries, HL7/GDT sources, and network storage rely on Windows, database, and site-controlled account permissions. Global settings require Admin-level access. |
| Connected services | Supported recording server or cloud-related connections use OIDC authorization and encrypted HTTPS where applicable. Discovery of networked medical devices is limited to approved Nox devices; Nox C1 access points can be password protected. |
Vulnerability Management
- The codebase is scanned regularly using Snyk, with the current configuration set to daily scanning; documented scan-result reviews are maintained through the Cybersecurity Activities record.
- The SBOM is maintained through the product lifecycle and at least for each new released version, covering SOUP, COTS, OTS, commercial, open-source, and other off-the-shelf software used in the product.
- Potential vulnerabilities are assessed using the product threat evaluation process and CVSS-informed criteria. Critical, High, Medium, and Low findings have defined response expectations, with customer notification through the customer relationship process when applicable.
- Field issues, post-market surveillance input, feature changes, and identified security vulnerabilities can trigger a formal change request and product update process.
Comments