Ravi Patel, Customer Admin

NP-200 system security design review

NimbusPump NP-200 Program · candidate AREV-0004 vs effective baseline DRB-0007

PRJ-2026-0042-DRV-0001Threat review
Threat workbench

Tampered drug library uploaded from compromised pharmacy workstation

PRJ-2026-0042-TV-000129Treatment plannedHighSafety-linked

  1. Proposed (passed)
  2. Confirmed (passed)
  3. Assessed (passed)
  4. Treatment planned (current)
  5. Mitigation pending (pending)
  6. Verified (pending)
  7. Closed (pending)

An attacker controlling the pharmacy drug-library workstation pushes a modified library over DF-000079. Altered concentration limits or care-area profiles silently change dose validation bounds on every device receiving the library, a fleet-wide safety-relevant integrity failure.

Safety-linkedDeterministic ruleConfidence high

Actor: Attacker with workstation compromise or malicious insider; moderate skill.

Elements
AE-000043Drug library storeAE-000054Pharmacy drug-library workstationAE-000042Infusion dosing command processor
Flows
DF-000079Drug library pushDF-000074Drug library read
Sources
SRC-0001VSDX page 2 connector 55
Function
Dose validation limits (fleet-wide)