Skip to main content

New: AI Privacy Impact Assessments for teams shipping AI features. Learn about AI-PIAs

HIPAA · Digital health & life sciences

HIPAA Readiness for Medical Device Makers

HIPAA readiness prepares a Canadian device maker for the moment a US hospital or health system asks you to sign a Business Associate Agreement, whether because your RPM cloud stores US patient telemetry or because your field-service technicians remotely access stored images or logs during support calls. Business associate status attaches the day PHI enters your systems, even if your device simply services a machine already owned by the hospital. We run the gap analysis and build the evidence package before that BAA is signed.

Reviewed by the Privacy Horizon team · Last reviewed

What you're protecting

What becomes a HIPAA obligation for a connected device maker

The trigger here is not always the primary data model, it is often a support path nobody flagged as PHI-bearing.

RPM cloud telemetry from US patients

Physiological readings and monitoring data stored or processed for a US covered entity, the most obvious business-associate trigger for a remote-monitoring platform.

Remote-maintenance access to stored images or logs

DICOM images, service logs and diagnostic data your field-service or support team can access remotely while servicing a device already owned by a US hospital.

Companion-app accounts tied to US patients

Account and health data collected through a patient- or clinician-facing app connected to your device, wherever it is hosted.

The subcontractor chain behind your cloud

Your own cloud host, analytics vendor or support tooling touching the same PHI, each needing its own BAA back to you before it can be part of the service you provide.

Regulatory map

How business associate status reaches a hardware company

HIPAA is not Canadian law, and it does not require you to sell software to be reached by it.

Business associate status even for service-only access

A device maker that creates, receives, maintains or transmits PHI for a US covered entity, including through remote service access to a device the hospital already owns, is a business associate directly liable under the Security Rule.

Primary source →

The required security risk analysis

An organization-wide risk analysis of the systems holding electronic PHI is a mandatory Security Rule safeguard, covering your RPM cloud and remote-maintenance tooling specifically.

Primary source →

The 60-day business associate breach notice

A breach of unsecured PHI has to be reported to the covered entity inside the window your BAA sets, mechanics defined by the Breach Notification Rule.

Primary source →

PHIPA and PIPEDA running in parallel

If the same RPM platform also serves Canadian hospitals, you may hold business associate, electronic service provider and PIPEDA-covered organization status simultaneously across the same architecture.

Read our guide →

What goes wrong

What HIPAA readiness catches before a US deal closes

The gaps a readiness review finds tend to sit exactly where support and hosting infrastructure meet.

  • Remote-maintenance credentials without adequate controls

    Service-account access built for legitimate device support, without the access logging and minimum-necessary discipline a covered entity's own security team will expect to see evidence of.

  • A cloud subcontractor without its own BAA

    An analytics or hosting vendor touching RPM telemetry without a signed BAA back to you breaks the accountability chain HIPAA requires, one of the fastest gaps a readiness review surfaces.

  • A missing or stale risk analysis covering device-service systems

    An outdated risk analysis that never accounted for remote-maintenance tooling or a newer RPM cloud environment leaves exactly the systems most likely to be tested unassessed.

Our hipaa for medical device makers

What our HIPAA readiness covers for a device maker

A gap analysis against your current PIPEDA or PHIPA posture, the required risk analysis, and BAA readiness for both directions of your service relationship.

3d render of tomography imaging room
  1. HIPAA gap analysis

    A comparison of your current Canadian privacy posture against HIPAA's three rules, scoped specifically to the RPM cloud and remote-service access paths that touch US patient data.

  2. Security risk analysis

    The Security Rule's mandatory risk analysis, mapped to your actual cloud infrastructure and the remote-maintenance tooling field-service teams use.

  3. BAA and subcontractor readiness

    Review of the BAA your US hospital customer will send, and the subcontractor agreements you need with your own cloud host and support vendors.

  4. Policy development for a Canadian operating context

    HIPAA-aligned policies written for how your Canadian engineering, field-service and support teams actually work.

  5. Staff training and ongoing support

    Role-based training for field-service technicians and support staff who touch PHI, followed by ongoing support to re-run the risk analysis as your architecture changes.

How the engagement runs

How HIPAA readiness proceeds before a BAA is signed

We scope first, since PHI in a device company often flows through fewer, more specific paths than in a typical software product.

  1. Step 1

    Scope where US PHI enters

    We map RPM telemetry, remote-maintenance access and companion-app data to identify every point where US patient information is created, accessed or stored.

  2. Step 2

    Run the gap and risk analyses

    The mandatory security risk analysis and a gap review against the three HIPAA rules are completed together against your device-service architecture.

  3. Step 3

    Remediate in priority order

    Access controls on remote-maintenance tooling, subcontractor BAAs, policies and training close in order of risk.

  4. Step 4

    Assemble the evidence package

    A current, organized set of documents, risk analysis, policies, training records and signed BAAs, ready for the covered entity's own diligence review.

What it costs

What determines HIPAA readiness cost for a device maker

Cost depends on how much of your architecture touches PHI, the RPM cloud, the companion app, remote-service tooling, or all three, how many subcontractors need their own BAAs, and how close your existing PIPEDA or PHIPA program already sits to HIPAA's requirements.

A device maker whose PHI exposure is confined to remote-maintenance access alone costs less to bring into scope than one running a full RPM cloud platform for US patients. We scope pricing after mapping where US patient data actually flows through your product and support processes.

Medical Device Makers: HIPAA questions, answered

Yes, if that service touches PHI, such as remotely accessing stored images or diagnostic logs during a support call. Business associate status turns on whether you create, receive, maintain or transmit PHI on the covered entity's behalf, not on whether you also run a broader cloud platform.

It should specify exactly what access your technicians have, the minimum-necessary scope of that access, logging and audit requirements, and the breach-notification window that applies if that access path is ever compromised. Vague language about general support access is not sufficient for a covered entity's own compliance needs.

HIPAA applies wherever PHI is created, received, maintained or transmitted, which is typically the cloud and any remote-service access path rather than the hardware itself. The physical device usually does not directly trigger HIPAA unless it independently stores identifiable data that leaves your control.

They run in parallel across the same architecture if you serve both markets. PHIPA governs your relationship with Ontario custodians, HIPAA governs your relationship with US covered entities, and a single RPM platform can carry both sets of obligations simultaneously depending on which hospital's data is in question.

Yes, if their work involves remote access to systems holding PHI. Training should cover minimum-necessary access, what to do if PHI is incidentally captured during a service call, and how to recognize when an access pattern needs to be logged or reported.

What's Protecting Your Business from the Next Threat?

Don't wait for a breach to expose your vulnerabilities. Let Privacy Horizon secure your data, ensure compliance, and build lasting trust.

(647) 622-2644

Free, no obligation

Get a quote

Tell us what you need and we'll come back within one business day with a tailored quote.

We only use your details to respond to this request.