Industry

HIPAA compliance for medical devices & digital health

Device telemetry, companion apps, and cloud backends put you in HIPAA scope alongside FDA obligations.

Administrative safeguards Physical safeguards Technical safeguards Privacy rule Breach notification

Device telemetry, companion apps, and cloud backends put you in HIPAA scope alongside FDA obligations.

What usually goes wrong

  • Device-to-cloud telemetry containing identifiable data
  • Firmware update and access control on constrained hardware
  • FDA cybersecurity expectations running parallel to HIPAA
  • Hospital customers demanding MDS2 plus HIPAA evidence

What SuperHIPAA does about it

  • Device fleet inventory with ePHI classification
  • Firmware and update-path safeguard documentation
  • Combined HIPAA and premarket cybersecurity evidence mapping
  • Hospital procurement response pack

Your obligations in one paragraph

As a both, you must conduct an accurate and thorough risk analysis, implement the required Security Rule specifications (and either implement or document a rationale for each addressable one), maintain policies and procedures, train your workforce, execute business associate agreements with everyone who touches ePHI on your behalf, and be able to detect, assess, and report breaches. All of it must be evidenced. None of it is a one-time project.

Where most medical devices & digital health actually stand

The pattern we see in this vertical: policies exist, training happens sporadically, BAAs are partially in place, and the risk analysis is either missing or several years stale. That last one is the finding that turns an incident into a penalty, because it is the first document OCR requests.

Getting started

  1. Free readiness assessment — scored report, no call required
  2. Gap assessment — if the score shows real exposure
  3. Implementation — we fix it with you, or hand your team the plan
  4. Platform — keeps it true after we leave

Start where you are

Take the free readiness assessment — 24 questions, about eight minutes, no call required. You get a scored report identifying which required specifications you are missing and what to fix first. If it turns out you are further along than you thought, we will tell you that too.

Questions

Are medical devices & digital health covered entities or business associates?

Typically **Both**. It matters because it changes which obligations are yours directly and which flow through a BAA. The readiness assessment determines your scope in the first three questions.

How long does it take to get compliant?

For an organisation starting from near zero, 8–12 weeks to a defensible position: risk analysis complete, required safeguards implemented, policies live, workforce trained. Anyone promising two weeks is selling you a certificate.

What does it cost?

Platform starts at a published monthly price — see pricing. Services are fixed-fee. There is no 'contact us for a quote' wall on this site.

Do you replace our IT provider?

No. We tell your IT provider exactly what to configure and then verify they did it.

Does FDA cybersecurity guidance replace HIPAA for us?

No — they run in parallel. FDA premarket and postmarket cybersecurity covers the device itself; HIPAA covers the PHI you receive, maintain, or transmit. The documentation overlaps substantially, and we reuse it rather than duplicating it.

Is device telemetry actually PHI?

If it is health-related data tied to an identifiable person, yes — and device serial numbers and IP addresses count as identifiers under the §164.514 de-identification standard. Treat telemetry as PHI unless you have genuinely de-identified it.

Hospital customers demand security questionnaires before every pilot. Can you help?

That is standard vendor diligence before PHI flows to you. A current risk analysis, a mapped control set, and a live evidence library turn a 300-question review from a fire drill into an export.

Our device stores data on-device only — do we even need a BAA?

If you never receive, maintain, or transmit PHI on a provider's behalf, you may not be a business associate. But cloud sync, remote support access, or diagnostic logs usually change that answer — map the actual data flow before concluding you are out of scope.

Hospitals keep asking for an MDS2 form. How does that relate to HIPAA?

The MDS2 is the standardised security disclosure hospitals use to slot your device into their own risk analysis — it describes capabilities like audit logging, encryption, and patch paths. It is not a HIPAA artefact itself, but the answers come from the same control documentation, so we keep one source of truth feeding both.

Our field technicians remote into devices on hospital networks. Is that in scope?

Very much — remote servicing that can reach ePHI makes you a business associate to that hospital, and the access path itself needs authentication, logging, and session controls you can evidence. Vendor remote access is a favourite intrusion vector, so expect customer security teams to probe it hardest.

Our companion app also sells direct to consumers. Same rules?

No — data a consumer records for themselves sits outside HIPAA, but the FTC's Health Breach Notification Rule and state privacy laws apply instead, and the same app becomes HIPAA-scoped the moment a provider prescribes or receives data through it. Running one app under two regimes needs the boundary designed, not discovered.

See your compliance program in one place

A 20-minute walkthrough with a practitioner. No slides, no pressure.

Book a demo