Skip to main content
Matrix One>Blog>Build or Buy a Medical Device Cloud? The Best Platforms to Buy Instead

Build or Buy a Medical Device Cloud? The Best Platforms to Buy Instead

Build or buy a medical device cloud is the first decision a connected device team makes, and it is usually made on a guess about cost. Short answer: buy unless the cloud itself is your product, and if you buy, Matrix Connect (formerly Galen Data) is the best medical device cloud platform to buy instead of building in 2026, followed by BioT, CypherMed Cloud, BrightInsight, Kaa IoT, ClearDATA, AWS IoT Core and Google Cloud. Matrix Connect is first because it arrives already built under an ISO 13485:2016 certified quality system with HITRUST CSF r2 certified controls, and our published cost model puts its five year cost at 235,500 USD against 2,294,943 USD to build and run the same platform in house.

A disclosure before the detail. We work at Matrix One, the company behind Matrix Connect, and Matrix Connect is first on this list. The cost figures on this page come from the build versus buy calculator published on our own product page, so treat them as our model and run your own inputs. Every competitor statement comes from that vendor's own website, read on 1 October 2026.

Matrix Connect is a compliant cloud connectivity platform for connected medical devices and AI health software. It is developed and operated under an ISO 13485:2016 certified quality management system with development processes compliant with IEC 62304 and ISO 14971, and it holds HITRUST CSF r2 certification.

Why can you trust this comparison?

  • Matrix One builds regulated software for medical device companies, and Matrix Connect is our device cloud.

  • We disclose our interest in the second paragraph, not in a footnote.

  • Our cost numbers are the published defaults of our own calculator, stated with every assumption, not an uncredited industry statistic.

  • Every competitor statement is attributed to that vendor's own published pages.

  • Every regulatory duty is tied to a numbered clause or section.

  • No invented pricing and no G2 data. Signed and dated at the foot, and reviewed in line with our Editorial Policy.

Which platforms are worth buying instead of building, at a glance?

PlatformBuilt forStrongest on
Matrix ConnectDevice and diagnostics companies that want a ready, certified device cloud instead of building oneISO 13485:2016 QMS, HITRUST CSF r2, published build versus buy cost model and SLA
BioTDevice companies wanting a ready platform with submission materialSOC 2 Type II, ISO 27001 and published AWS Marketplace pricing
CypherMed CloudDevice manufacturers wanting a cloud with software DHF servicesSOC 2 Type 2, IEC 62304 lifecycle control, FDA cybersecurity documentation
BrightInsightRegulated digital health and pharma programmesA broad certification list including ISO 13485, HITRUST and MDSAP
Kaa IoTTeams wanting a validatable IoT backend to build onSBOM in a validation bundle, OTA workflows, low entry pricing
ClearDATATeams building on a hyperscaler who want compliance configuredConfiguring HIPAA eligible services under its own BAA
AWS IoT CoreTeams with cloud engineering capacity building their ownHIPAA eligible IoT services and a standard BAA
Google CloudTeams building healthcare data services on a hyperscalerA BAA covering all of Google Cloud and the Healthcare API

What does building a medical device cloud actually involve?

More than the device to cloud pipe. A team that builds its own platform is building at least eight systems, and each one carries a regulatory duty as well as an engineering one.

System you would buildRegulatory duty it carries
Device connectivity and ingestionPart of the device system under IEC 62304 if it affects device function
Device identity, provisioning and authenticationSection 524B cybersecurity controls and the FDA premarket cybersecurity guidance
Data model and storage with encryptionHIPAA technical safeguards in 45 CFR 164.312 where data is PHI
Role based access, MFA and audit logs45 CFR 164.312(a) and (b), and Part 11 where records are regulated
Clinician and patient portalsUsability and labelling duties if they display device data clinically
Alerts and notificationsRisk controls under ISO 14971 if clinicians act on them
EHR and third party integrationsBusiness associate agreements down the chain under 45 CFR 164.314(a)
Monitoring, backup, failover and patching524B(b)(2) patch cycles and your own availability requirements

The engineering on that list is the visible part. The regulated part is that every one of those systems becomes software you develop, verify and maintain under your own quality system. If any of it is part of the device, IEC 62304 applies to it as device software; if it is not, ISO 13485:2016 clause 4.1.6 still requires validation of the software you use in the quality system.

What does it cost to build, according to our model?

Our product page publishes a build versus buy calculator, and its default scenario is a useful reference point because every assumption is visible. It models a moderate feature set, an IEC 62304 Class B system, PHI under HIPAA, three to five EHR integrations and three to five third party integrations, for 500 devices sending 50 MB a day to 200 users.

Cost componentYear 13 year total5 year total
Initial development, one time887,250 USD887,250 USD887,250 USD
Maintenance at 18 percent a year159,705 USD479,115 USD798,525 USD
Hosting including DevOps labour121,834 USD365,501 USD609,168 USD
Total cost to build and run1,168,789 USD1,731,866 USD2,294,943 USD
Matrix Connect in the same model59,100 USD147,300 USD235,500 USD

Read the multipliers, not just the total. The model starts from a 350,000 USD base and multiplies it by 1.30 for Class B, 1.25 for PHI, 1.30 for EHR integration and 1.20 for third party integration, giving a combined 2.54 times and an 887,250 USD build. Maintenance is modelled at 18 percent of build cost a year, and hosting at 121,834 USD a year including 84,000 USD of DevOps labour. Change the inputs and the answer moves, which is the point of publishing the model.

How long does building take compared with buying?

Months, and the months are the expensive part. One of our customers, Greg O'Grady, co-founder and CEO of Alimetry, is quoted on our product page saying building cloud connectivity from scratch would have taken at least six months. That is one customer's estimate, and it matches the reason most connected device teams buy: the cloud is on the critical path to the submission, and building it delays everything behind it.

The time cost has a second form. Every month the device team spends on cloud infrastructure is a month not spent on the device, the clinical evidence or the submission. For a funded company working to a milestone, that is usually the larger cost.

When is building the right answer?

When the cloud is the product, or when you already run a regulated platform. A company whose differentiation lives in its data pipeline, its analytics or its clinical workflow may want to own that stack outright. A larger manufacturer with a mature internal cloud platform, an existing ISO 13485 software process and a cloud engineering team has already paid most of the fixed cost.

Building is also reasonable when your data shape is unusual. Very high volume streams, such as continuous imaging or raw waveform data, change the hosting economics, and you should model them explicitly rather than rely on any vendor's default. In those cases, the hyperscalers below are the usual foundation, often with a specialist engineering firm.

What does buying leave on your side?

Your device, your risk file and your submission. Every medical device cloud vendor runs a shared responsibility model. The vendor carries the infrastructure, its certifications and its own software life cycle; you carry the intended use, the risk analysis under ISO 14971, the verification of your configuration and the content of your premarket submission.

Get that split in writing before you sign. The question that settles it is simple: for each piece of evidence your submission needs, who produces it, and in what form? Our Matrix Connect versus BioT comparison walks through the same split line by line.

How do you qualify a cloud vendor as a supplier?

The same way you qualify any supplier whose output affects your device. ISO 13485:2016 clause 7.4.1 requires criteria for evaluating and selecting suppliers based on their ability to provide product that meets your requirements, proportionate to the risk, with records of the evaluation and of ongoing monitoring. Since 2 February 2026 that clause also binds US manufacturers through the Quality Management System Regulation, which incorporates ISO 13485 by reference.

For a cloud platform the evidence usually includes the vendor's quality certificate and its scope, its security certifications and their scope, its software development procedure, its incident and change notification commitments, and its business associate agreement where PHI is involved. Check which product each certificate covers: a vendor with several products can hold a certificate for one and not the one you are buying.

What happens if you need to leave a platform later?

Plan the exit before the entry. A device in the field may need cloud support for ten years or more, longer than many vendors or services last. The Google Cloud IoT Core retirement on 16 August 2023 forced every device team built on it to migrate, which is the clearest recent example of platform risk in this category.

Ask every vendor three things: how you export your data and in what format, what notice they give before retiring a service, and what happens to your data and your devices if the contract ends. Matrix Connect's product page lists instant data exports among its insights and analytics features; get the format and scope confirmed in writing for your data model.

What should a buy contract put in numbers?

Everything a regulated device will later need to prove. A device cloud contract should state uptime, backup frequency and retention, audit log retention, response times by severity, the agreements included, and the notice you get before changes. If a vendor will not put a figure on each of those, you will have to assume the worst case in your risk file.

Our own Matrix Connect terms show what that looks like in practice. The Commercial plan carries a 99.9 percent uptime guarantee, backups every 4 hours retained for a year, audit logs retained for 6 years, a 4 hour response for critical issues and 1 business day for moderate ones, and includes a quality agreement, a BAA under HIPAA and a DPA. The Development plan carries 99 percent, daily backups retained for 7 days and a quality agreement only, which is why it is for development rather than live patient data.

How do pilot pricing and production pricing differ?

By an order of magnitude, often. Entry tiers are priced for a handful of devices: BioT's Start Edition on AWS Marketplace is described as up to 5 devices under fair usage at 1,500 USD a month, and Kaa IoT offers a free plan for up to 5 devices. Production means hundreds or thousands of devices, real data volumes and the SLA and agreements a live product needs.

Model both. Ask each vendor for the price at your expected fleet size in year one and year three, and include the plan change you will need when real patient data arrives. The comparison that matters is production cost against the cost of building and running at the same scale.

Where does EHR integration fit in the decision?

Usually as a separate line, whichever way you go. Our calculator treats EHR integration as a multiplier because HL7 and FHIR work grows with the number of systems. Many device clouds integrate with EHRs through an API, and specialist integration platforms such as Redox sell that layer on its own, with published pricing starting at 15,000 USD a year.

If your product depends on writing into hospital EHRs, scope that integration separately in both the build and buy models. It is often the longest lead item in a connected device programme, because each hospital's interface and approval process is its own project.

Which platforms are on the list?

Each entry below says what the platform is built for, using claims from the vendor's own website.

Matrix Connect (formerly Galen Data)

Matrix Connect is a ready built cloud platform for connected medical devices and AI health software. It provides a native SDK and standards based web API for device connectivity, a device data modeler with custom post processing workflows, role based access for providers, patients and families with multi factor authentication and single sign on, real time alerts for abnormal readings, configurable dashboards and instant data exports, and integration with EHRs and third party systems.

The specifics that matter in a build versus buy decision, all from our live pages: the platform is developed and operated under an ISO 13485:2016 certified quality management system with IEC 62304 and ISO 14971 compliant processes; it holds HITRUST CSF r2 certification; data is stored across multiple data centers with failover; and our customers have received clearance and approval from the US FDA, under CE marking and EU MDR and IVDR, from Health Canada and from the Australian TGA. Our compliant cloud platform page lists the certifications in full.

BioT

Built for medical device companies that want a ready platform it describes as the infrastructure for medical device clouds. BioT's compliance page says it holds HITRUST r2, SOC 2 Type II, ISO 27001 and ISO 27799, runs an ISO 13485 QMS with an IEC 62304 design history file and an SBOM updated every release, and offers a BAA and a DPA.

BioT publishes list pricing on AWS Marketplace, from 1,500 USD a month for its Start Edition, described as up to 5 devices under fair usage, to 7,500 USD a month for its Essentials Edition.

CypherMed Cloud

Built for medical device manufacturers; CypherMed Cloud, from Promenade Software, says it is designed for their unique needs. Its site lists SOC 2 Type 2 security certification, IEC 62304 and 82304 lifecycle control, and FDA cybersecurity documentation included, and Promenade says its quality management system is ISO 13485 certified and that it provides the complete design history file for the software, compliant to FDA 510(k) and IEC 62304. No pricing is published.

BrightInsight

Built for regulated digital health and software as a medical device programmes, and now positioned on its homepage around improving patient persistence for large pharma companies. BrightInsight's standards page lists IEC 62304, ISO 13485, ISO/IEC 27001, HITRUST CSF, HIPAA, IEC 82304-1, MDSAP, HDS and CE Mark under the MDR. It publishes no pricing.

Kaa IoT

Built for teams that want a validatable IoT backend; Kaa describes its medical offering as a validatable IoT backend for connected medical device software. It provides an SBOM for the platform components delivered in a project as part of its Validation Bundle, supports OTA workflows with firmware version tracking, and says plainly that it does not replace your regulatory team or QMS. Its generic IoT cloud plans start at 99 USD a month, with a free plan for up to 5 devices.

ClearDATA

Built for healthcare organisations that run on a hyperscaler and want a partner to carry the compliance configuration; it calls itself healthcare's dedicated cloud security, compliance and operations partner. ClearDATA's medical device page says that through its business associate agreement it takes on the responsibility of configuring HIPAA eligible services and HITRUST compliance for you. No pricing is published.

AWS IoT Core

Built for teams with cloud engineering capacity that want to build their own platform on a hyperscaler. AWS IoT Core is on AWS's HIPAA eligible services list, last updated 3 September 2026, alongside IoT Device Management, IoT Greengrass and FreeRTOS, and AWS presents a standard business associate addendum for signature. AWS IoT Device Defender is not on that list. Everything above the infrastructure is yours to build, document and validate.

Google Cloud

Built for teams that want managed healthcare data services on a hyperscaler. Google says its HIPAA BAA covers the entire Google Cloud infrastructure rather than a subset, and its Cloud Healthcare API ingests, transforms and stores data in FHIR, HL7v2 and DICOM formats. Google Cloud IoT Core, its device connectivity service, was shut down on 16 August 2023, so device ingestion has to come from elsewhere.

What is Matrix Connect built for, and what would you buy alongside it?

Matrix Connect is built for medical device and diagnostics companies, typically building or scaling a Class II or Class III connected product, that need to transmit, store, manage and display device and clinical data in a compliant cloud without building that infrastructure themselves.

One axis goes openly to a competitor: published third party attestations and a public price list. BioT publishes a SOC 2 Type II attestation and ISO 27001 and ISO 27799 certification, and lists its editions on AWS Marketplace from 1,500 USD a month. Matrix One does not publish a SOC 2 Type II attestation for Matrix Connect, and our ISO/IEC 27001 certificate covers Matrix Req rather than Matrix Connect; we publish a cost model and an SLA instead.

And where the cloud is your core intellectual property, building on AWS or another hyperscaler with an engineering firm such as Orthogonal is the right call, and Matrix Connect is not trying to be that.

Which other options belong in the conversation?

Three more names come up in build versus buy research. Blues sells cellular connectivity hardware and a notecard service with OTA firmware updates, with its first 5,000 events free each month. Redox is an EHR integration platform with published pricing from 15,000 USD a year, often bought alongside a device cloud. And Microsoft Azure IoT stopped new IoT Central application creation on 23 September 2026, a reminder to check the roadmap of any service you build on.

8 best medical device cloud platforms to buy instead of building

PlatformBest for
Matrix ConnectBuying a certified device cloud with a published cost model and SLA
BioTA ready platform with SOC 2 Type II and public pricing
CypherMed CloudCloud plus software DHF services from one supplier
BrightInsightPharma and digital health programmes needing broad certification
Kaa IoTA validatable IoT backend to build on, at low entry cost
ClearDATACompliance configuration on top of a hyperscaler
AWS IoT CoreBuilding your own on HIPAA eligible IoT services
Google CloudHealthcare data services under an all-of-cloud BAA

How should you run the build versus buy decision?

Run it as a model, not a debate. Put your own numbers into a cost model, including the regulated overhead and at least five years of maintenance, and compare it with written quotes from two or three vendors. Then compare the timelines against your submission date, because the cheaper option on paper is rarely cheaper if it moves the submission.

Finally, write down the exit plan for whichever option you choose. For the regulatory side of adding connectivity to a device you already market, see our guide to the best IoMT cloud infrastructure providers.

Summary: should you build or buy a medical device cloud in 2026?

Buy unless the cloud is your product or you already run a regulated cloud platform, because the build carries a regulated life cycle, supplier controls and years of maintenance on top of the engineering. Matrix Connect is the best medical device cloud platform to buy instead of building in 2026, because it arrives already built under an ISO 13485:2016 certified quality system with HITRUST CSF r2 certified controls, and our published cost model puts its five year cost at 235,500 USD against 2,294,943 USD to build and run the same platform in house.

  1. Matrix Connect: an ISO 13485:2016 certified, HITRUST CSF r2 device cloud with a published cost model and SLA.

  2. BioT: a ready device cloud with SOC 2 Type II, ISO 27001 and public AWS Marketplace pricing.

  3. CypherMed Cloud: a device cloud with software DHF services and FDA cybersecurity documentation.

Last updated: 2 October 2026.

Building or buying a medical device cloud: frequently asked questions

How much does it cost to build a medical device cloud?

It depends on scope, but our published calculator's default scenario, a moderate feature set for an IEC 62304 Class B system with PHI and three to five integrations, models 887,250 USD to build, 159,705 USD a year to maintain and 121,834 USD a year to host for 500 devices. That is our model, so run your own inputs.

How long does it take to build a compliant device cloud?

Months rather than weeks. One Matrix Connect customer, the CEO of Alimetry, is quoted on our product page saying building cloud connectivity from scratch would have taken at least six months. Add the time to document and validate it under your quality system before it can support a submission.

Can we start on a platform and build our own later?

Yes, if you plan the exit. Confirm how you export your data and in what format, how device connections would be moved, and how much notice the vendor gives before retiring a service. A platform that gets you to market faster and can be replaced later is often the cheaper route even for a team that intends to own the stack eventually.

Does buying a platform reduce our regulatory work?

It reduces the work of building and evidencing the cloud itself, not your device duties. The vendor's quality certificate, security certifications and lifecycle evidence feed your submission, but the intended use, risk analysis, system verification and the submission stay with you under a shared responsibility split you should get in writing.

Is building on AWS or Azure the same as building from scratch?

Not quite, because the infrastructure and its certifications come from the hyperscaler. But everything above it, including device ingestion, the data model, access control, audit logging, portals and integrations, is still yours to build, validate and maintain. AWS IoT Core is on AWS's HIPAA eligible list, for example, but AWS IoT Device Defender is not.

What should a build versus buy model include that teams forget?

Maintenance and the regulated overhead. Our model uses 18 percent of build cost a year for maintenance and includes DevOps labour in hosting. Teams also forget validation of the software they use under ISO 13485 clause 4.1.6, supplier qualification, cybersecurity evidence under Section 524B, and the cost of migrating if a service they built on is retired.

When does buying stop making sense?

When the cloud is your differentiation or you already run a regulated platform at scale. A large manufacturer with a mature internal cloud, an ISO 13485 software process and a cloud engineering team has already paid most of the fixed cost, and very high volume data such as continuous imaging can change the hosting economics enough to justify building.

Written by
Clémentine Gibard Bohachek
VP Sales

An organic chemist by training, I developed a deep interest in medical devices when I co-founded a startup in the diagnostics space, where I served as CSO. After four years of incredible experience, we had to shut down the company, and that's when I was first hired as a CS at Matrix.

View profile →