Withings is a French connected-health company whose IEEE footprint is two MA-L (24-bit OUI) blocks, 00:24:E4 and A4:7E:FA, both registered to "Withings" at 2 rue Maurice Hartmann, Issy-les-Moulineaux, France. The two blocks together cover roughly 33.5 million addresses, and consolidating them into one vendor entry is far more useful than two near-identical per-prefix pages because both resolve to the same maker of consumer health hardware: smart scales (Body Scan, Body Comp), hybrid smartwatches (ScanWatch 2), blood-pressure monitors (BPM family), sleep analyzers, thermometers, the U-Scan urine reader, and the BeamO multi-vital handheld. These devices join home and clinical networks as Wi-Fi or Bluetooth-bridged endpoints reporting to the Health Mate companion app on iOS and Android, so either prefix on a local network is consistent with a Withings health device. Company history adds useful context: founded June 2008 by Éric Carreel, Cédric Hutchings, and Fred Potter, acquired by Nokia in 2016 and rebranded Nokia Health, then reacquired by Carreel in May 2018 and restored to the Withings name — which is why older inventory may still surface under the Nokia Health label. From a security standpoint Withings is a legitimate vendor with documented practices (ISO 27001:2022 / ISO 27701:2019, French HDS health-data hosting, TLS 1.2+ in transit, AES-256 at rest, a YesWeHack public bug-bounty program); no CVEs surfaced in this pass. The dominant risk is health-data sensitivity (GDPR/HIPAA scope), not network attack surface, so standard IoT hygiene applies — segment onto an IoT VLAN and keep firmware current. The critical data-quality caveat: IEEE publishes no registration dates, so third-party "date registered" values (e.g. 2009-01-19 for 00:24:E4, 2022-03-15 for A4:7E:FA on maclookup.app) are database artifacts, not IEEE facts, and must not be surfaced as IEEE registration dates.
- IEEE assignment
- 2 prefixes → Withings, registered Issy-les-Moulineaux, FR [Confirmed] — IEEE MA-L (enrichment/registries/oui.csv); https://regauth.standards.ieee.org/standards-ra-web/pub/view.html#registries
- Registry / block size
- both MA-L (24-bit OUI); 00:24:E4 and A4:7E:FA (~16.7M addresses each, ~33.5M total) [Confirmed] — IEEE MA-L; https://www.netify.ai/resources/macs/brands/withings, https://maclookup.app/vendors/withings. NOTE: IEEE's public OUI data publishes NO assignment/registration date (oui.csv columns are only Registry, Assignment, Organization Name, Organization Address); any "date registered" on third-party tools is a database artifact, not an IEEE fact.
- HQ / country
- 2 rue Maurice Hartmann, Issy-les-Moulineaux, FR 92130 (registry address; additional offices in Boston, USA and Hong Kong) [Confirmed] — IEEE MA-L; https://en.wikipedia.org/wiki/Withings
- Company status
- active [Confirmed] — https://www.withings.com/eu/en/data-security, https://en.wikipedia.org/wiki/Withings
- Device types
- smart scales (Body Scan, Body Comp), hybrid smartwatches (ScanWatch 2), blood-pressure monitors (BPM Pro 2, BPM Vision), sleep analyzers, thermometers, U-Scan urine reader, BeamO multi-vital handheld [Confirmed] — https://en.wikipedia.org/wiki/Withings, https://www.withings.com/us/en/landing/ces-2025, https://sequans.com/withings-is-modernizing-healthcare-with-cellular-iot-connected-health-devices/
- Notable products
- ScanWatch 2, Body Scan, BPM family, Sleep, U-Scan, BeamO; devices pair with the Health Mate app (iOS/Android) over Wi-Fi and Bluetooth
- Verified prefixes (both MA-L, Withings)
- 00:24:E4, A4:7E:FA [Confirmed] — IEEE MA-L; https://www.netify.ai/resources/macs/brands/withings, https://maclookup.app/vendors/withings
- No MA-M / MA-S assignments found in the cached registries [Confirmed] — IEEE registry (enrichment/registries/oui.csv)
- Corporate history
- founded June 2008 (Éric Carreel, Cédric Hutchings, Fred Potter); acquired by Nokia 2016 → Nokia Health; reacquired by Carreel May 2018 → Withings; acquired Impeto Medical and the 8fit app in 2022 [Confirmed] — https://en.wikipedia.org/wiki/Withings
- Security posture
- ISO 27001:2022 + ISO 27701:2019, French HDS (Health Data Hosting) certification; TLS 1.2+ in transit, AES-256 at rest; YesWeHack public bug-bounty program; third-party pen testing; EU health data in French data centers, US B2B data on GCP; GDPR/HIPAA compliant; no public CVEs or security incidents found in this pass [Confirmed] — https://www.withings.com/eu/en/data-security, https://yeswehack.com/programs/withings-public-program
- Privacy posture
- devices collect sensitive personal health data (weight, heart rate, blood pressure, sleep, ECG, urine biomarkers per product); Withings is a health-data processor under GDPR/HIPAA; EU data stays in French-hosted data centers; staff confidentiality agreements and annual security training [Confirmed] — https://www.withings.com/eu/en/data-security
- Registration-date caveat
- third-party tools cite 2009-01-19 (00:24:E4) and 2022-03-15 (A4:7E:FA); these are database artifacts only — IEEE publishes none. The 00:24:E4 era (~2009) aligns with the original Wi-Fi scale; A4:7E:FA (~2022) likely tracks newer product generations [Likely] — https://maclookup.app/vendors/withings
- Special note
- Withings devices appear on home and clinical networks as Wi-Fi or Bluetooth-bridged endpoints reporting to Health Mate; users can request geographic data regionalization [Confirmed] — https://www.withings.com/eu/en/data-security, https://en.wikipedia.org/wiki/Withings
- Analyst note
- a Withings OUI (00:24:E4 or A4:7E:FA) on a globally-administered address reliably identifies genuine Withings health hardware. Risk profile is low-to-moderate and dominated by health-data sensitivity (GDPR/HIPAA), not network attack surface — no known CVEs in this pass; apply standard IoT hygiene (segmented VLAN, current firmware) [Likely] — https://www.withings.com/eu/en/data-security, https://yeswehack.com/programs/withings-public-program