Is this woman aware that static analysis is a non-negotiable requirement for filing your 510(k) if you do anything vaguely medical the FDA has to look at? Not that I would willingly choose Oracle for medical device applications, but the cognitive dissonance here is amusing. Pax vobsicum indeed.
They do use static analysis. However, they do not let third parties analyze their source code. Which shows even more hubris, because they're all but saying, "only we're smart enough to analyze our code."