← Back to Knowledge Base
MedTech2026-09-303 min read

How We Protect MedTech Client Data: Cyber Essentials & Beyond

ULAM LABS is Cyber Essentials certified. See how we protect client data in medical device and digital health software, what the certificate covers, and how to verify it.

ULAM LABS is now Cyber Essentials certified. It isn't the most complex certificate in security, but it answers a question every MedTech and digital health company asks before bringing in a software partner: can we trust you with our systems and our data? Until now, the honest answer was "yes, and here's how we work." Now it's "yes, and here's the independent proof."

Below we cover: what Cyber Essentials covers, why it matters in healthcare, and how we protect client data beyond the certificate.

What Cyber Essentials is

Cyber Essentials is a UK government-backed scheme, designed by the National Cyber Security Centre (NCSC) and delivered by IASME. It sets a baseline of technical controls that protect an organisation against the most common cyber attacks. It covers five areas:

  1. Firewalls: only the network traffic that should get in, gets in.
  2. Secure configuration: no default passwords, no unnecessary software, no open doors left by accident.
  3. User access control: people only have access to what their role needs, and admin rights are limited.
  4. Malware protection: every device is protected against malicious software.
  5. Security update management: systems and software are patched promptly, before known vulnerabilities can be exploited. Our answers were reviewed by an independent certification body, and the certificate is renewed every year. It's not a one-off exercise.

Why the basics matter in healthcare software

Most security incidents don't start with a sophisticated attack. They start with an unpatched server, a shared admin account or a laptop nobody remembered to update. In healthcare, the consequences are bigger. The software we build handles patient data, connects to EHR and NHS systems, and supports quality and regulatory processes that medical device companies are audited on.

That makes every supplier part of the client's risk. A company can have excellent internal controls and still be exposed through a partner with weaker ones. Suppliers are often the easiest way in, which is why procurement teams increasingly ask for proof, not promises.

What it means for our clients

  • Faster supplier due diligence - Cyber Essentials is a recognised answer to the security section of most UK supplier questionnaires. Fewer follow-up calls, fewer email loops.

  • Proof you can check - You don't have to take our word for it. The certificate is listed publicly and can be verified in minutes.

  • Fewer surprises in audits - If your QA or RA team is asked how you assess software suppliers, you have a clear, documented answer.

  • A partner who takes the basics seriously - Access is limited to the people working on your project, devices are managed and patched, and we don't cut corners on the unglamorous work.

How we protect client data

Cyber Essentials covers the technical baseline. Around it, we run our processes in alignment with ISO 27001. In practice, that means:

  • Access control - Only the people working on your project can access your systems and data. Access is removed as soon as someone leaves the project.

  • Data handling - We don't keep client data longer than the project needs it, and we never share it with third parties without your consent.

  • Incident response - We have a defined process for handling security incidents, including how and when we notify you.

  • Supplier management - Third-party tools and subcontractors are assessed for security risk before we rely on them.

  • Risk management - We identify and document security risks on every project, and we act on known vulnerabilities.

  • Document control - Sensitive project documentation lives in secured, managed systems, never in personal email or unsecured drives.

Verify it yourself

You can check our certificate in the public IASME certificate search: HERE. Search for "Ulam Labs" to see the certificate number and validity date. Security questions? Ask us directly

Have a question?

Talk to us
About author

Anna Buczak

Marketing Strategist


Anna is a Marketing Strategist at ULAM LABS, where she translates complex healthcare tech (EHR integrations, HIPAA and GDPR compliance, interoperability) into content people actually want to read.

About us
Portrait of Anna Buczak

MedTech insights delivered

Real case learnings, product decisions, and technical insights from building healthcare software. No marketing fluff.

Mobile app screen — Annual exam for ECG machine
Featured case study

Five years. One team. From 1 hospital to 200.

Hospital staff were reporting issues on paper, by phone, or not at all. No single platform, no visibility, no way to track resolution. We built one and we're still running it five years later.

200+

Hospitals internationally

10,000

Active users

99.9%

Uptime

Additional learning

Explore related topics in our
Knowledge Base

Browse all articles
  • MedTech
    2026-09-045 min read
    NHS DTAC Explained: What It Is, What It Is Not, and When It Enters Your Roadmap

    DTAC, DSPT, DCB0129: four different NHS requirements that get confused for each other. What each one covers, who completes it, whether it is mandatory, and when it should enter your product roadmap.

    Anna Buczak
    Author:Anna Buczak
    Read more
  • MedTech
    2026-09-045 min read
    Where UK Patient Data Can Live, and Who Can Reach It

    Choosing a cloud region for patient data looks like a hosting decision. It propagates into backups, monitoring, CI and support access, and the harder question is not where the disk sits but who can reach it.

    Rafał Nowicki
    Author:Rafał Nowicki
    Read more

Let's see if we're a good fit

No lengthy onboarding, no big commitment upfront. Book a call and we'll tell you within a week if we're the right fit.