The Best HIPAA-Compliant Cloud Platforms for Medical Device Data
HIPAA-compliant cloud for medical device data is a phrase every vendor uses, and it means less than buyers think: no platform is HIPAA compliant on your behalf, but the right one signs the agreement and carries the safeguards you would otherwise build. Short answer: Matrix Connect (formerly Galen Data) is the best HIPAA-compliant cloud platform for medical device data in 2026, followed by ClearDATA, BioT, Redox, AWS IoT Core, Google Cloud, Microsoft Azure and BrightInsight. Matrix Connect is first because it is purpose built for device data, holds HITRUST CSF r2 certification covering HIPAA controls, and ships the access control, audit logging and encryption a device team would otherwise have to configure on a general cloud.
A disclosure before the detail. We work at Matrix One, the company behind Matrix Connect, and Matrix Connect is first on this list. The regulations and HHS guidance quoted here were read on ecfr.gov and hhs.gov on 1 October 2026; this is not legal advice for your organisation. Every competitor statement comes from that vendor's own website, read on 1 October 2026.
Matrix Connect is a compliant cloud connectivity platform for connected medical devices and AI health software. It is developed and operated under an ISO 13485:2016 certified quality management system and holds HITRUST CSF r2 certification.
Why can you trust this list?
Matrix One builds regulated software for medical device companies, and Matrix Connect is our device cloud.
We disclose our interest in the second paragraph, not in a footnote.
Every regulatory statement is tied to a section of the FD&C Act, the Code of Federal Regulations or a named FDA or HHS guidance with its date.
Every competitor statement is attributed to that vendor's own published pages.
No invented pricing and no G2 data. Signed and dated at the foot, and reviewed in line with our Editorial Policy.
Which cloud platforms handle device PHI best, at a glance?
| Platform | Built for | Strongest on |
|---|---|---|
| Matrix Connect | Device companies that want a device cloud with HIPAA safeguards built in | BAA and DPA on the Commercial plan, HITRUST CSF r2, audit logs kept 6 years |
| ClearDATA | Teams on a hyperscaler wanting compliance configured for them | Configuring HIPAA eligible services under its own BAA |
| BioT | Device companies wanting a ready cloud with paperwork | BAA and DPA available, SOC 2 Type II, ISO 27001 |
| Redox | Moving device data into and out of EHRs | BAAs with AWS and Google Cloud, HITRUST r2, published pricing |
| AWS IoT Core | Teams building their own on AWS | IoT Core on the HIPAA eligible list, standard BAA |
| Google Cloud | Teams building healthcare data services | A BAA covering the entire Google Cloud infrastructure |
| Microsoft Azure | Microsoft-standardised teams | BAA included in the Product Terms |
| BrightInsight | Regulated digital health and pharma programmes | HIPAA and HITRUST CSF listed among its standards |
When does HIPAA apply to a device company at all?
When the device company handles protected health information for, or on behalf of, a covered entity such as a hospital, clinic or health plan. A manufacturer that runs a cloud service receiving patient data from devices used by a provider is usually a business associate of that provider, and every cloud vendor it uses to store or process that data is a subcontractor business associate in turn.
That chain is the whole point of buying a HIPAA cloud. 45 CFR 164.308(b)(1) lets a covered entity allow a business associate to handle electronic PHI only if it obtains satisfactory assurances, in accordance with 164.314(a), that the information will be appropriately safeguarded, and 164.502(e) says the same for disclosures. The assurance is a written business associate agreement, and it has to run all the way down the chain.
Does a cloud vendor that cannot see your data still need a BAA?
Yes. The HHS Office for Civil Rights guidance on HIPAA and cloud computing, last reviewed 23 December 2022, is explicit that a cloud service provider that creates, receives, maintains or transmits ePHI is a business associate, and that this is true even if it processes or stores only encrypted ePHI and lacks an encryption key for the data. HHS calls this a no-view service, and it still needs a BAA.
The same guidance says a covered entity or business associate that uses a cloud provider to maintain ePHI without a BAA is in violation of the HIPAA Rules. Encryption is a safeguard; it is not a substitute for the agreement.
What must the business associate agreement contain?
45 CFR 164.314(a)(2)(i) requires the contract to make the business associate (A) comply with the applicable requirements of the Security Rule, (B) ensure any subcontractor that handles ePHI agrees to the same restrictions, and (C) report to the covered entity any security incident of which it becomes aware, including breaches of unsecured PHI. Read every vendor BAA against those three points before you sign, and check which of the vendor's services it actually covers.
Is a HIPAA-eligible service the same as a HIPAA-compliant platform?
No. Hyperscalers sign BAAs that cover a published list of eligible services, and they configure the infrastructure; you configure everything you build on it. Access control, audit logging, encryption settings, backup, and the application that displays patient data are your responsibility on a general cloud, and an eligible service configured badly is still a breach waiting to happen.
A device cloud platform moves part of that line. It ships the application layer, access control and audit logging already built, so the configuration you are responsible for is smaller. Get the split in writing for each vendor, service by service.
Which HIPAA safeguards does the cloud have to carry?
The technical safeguards in 45 CFR 164.312 are where a cloud platform does most of the work. The table maps them to what a device cloud usually provides and what stays with you.
| Technical safeguard, 45 CFR 164.312 | Device cloud usually provides | Stays with you |
|---|---|---|
| (a) access control, unique user identification | Role based permissions, unique accounts, MFA and SSO | Defining roles and approving access |
| (a) emergency access and automatic logoff | Session management and administrative access routes | Your emergency access procedure |
| (a) encryption and decryption, addressable | Encryption in transit and at rest | Your decision record for any data left unencrypted |
| (b) audit controls | Activity logs of who accessed what and when | Reviewing the logs under your procedures |
| (c) integrity | Controls against improper alteration | Your integrity checks on device data |
| (d) person or entity authentication | Authentication for users and devices | Identity proofing of your users |
| (e) transmission security | Encrypted transfer from device to cloud | Securing your own apps and gateways |
What about data that is not PHI, or patients outside the US?
Device telemetry with no link to an identifiable patient may not be PHI at all, but most connected device data becomes PHI as soon as it is tied to a patient record. Design the data model so that identifiable data is separated and protected, and treat anything linked to a patient as PHI by default.
Patients in the EU and UK bring the GDPR as well, with its own processor contracts and transfer rules. A platform that supports both regimes, with data residency options, saves running two infrastructures.
Is the HIPAA Security Rule changing?
A revision has been proposed. HHS published a proposed rule, HIPAA Security Rule To Strengthen the Cybersecurity of Electronic Protected Health Information, on 6 January 2025. As of 1 October 2026 it has not been finalised, so the current Security Rule still applies. If the revision is adopted, the requirements are expected to become stricter rather than looser, which favours buying a platform that already carries the controls.
How do you run a HIPAA vendor assessment?
Map the data flow: device, app or gateway, cloud, EHR and every other system that receives PHI.
List every vendor in that chain and confirm each will sign a BAA that meets 164.314(a).
For each, get the list of services the BAA covers and match it to the services you use.
Get the shared responsibility split in writing, safeguard by safeguard against 164.312.
Test access control, audit logging and data export in a trial with realistic roles.
Confirm breach and security incident notification timelines in the contract.
Record the assessment and keep the BAAs with your security risk analysis under 164.308(a)(1).
What happens after a breach in a cloud you do not run?
The notification clock starts with discovery, wherever it happens. Under 45 CFR 164.410, a business associate must notify the covered entity of a breach of unsecured PHI without unreasonable delay and no later than 60 calendar days after discovery. The covered entity must then notify affected individuals under 164.404, also within 60 days, and HHS under 164.408.
That makes the vendor's notification commitment part of your own compliance. Your BAA with the cloud vendor should set a shorter notification period than 60 days, so you have time to investigate and notify the covered entity in turn. Encryption matters here too: PHI encrypted in line with HHS guidance is not unsecured PHI, so a breach of properly encrypted data may not trigger notification at all.
How do HIPAA and FDA cybersecurity duties fit together?
They overlap but answer different questions. HIPAA protects the privacy and security of patient information held by covered entities and their business associates. The FDA's Section 524B and premarket cybersecurity guidance protect the safety and effectiveness of the device and its related systems. A connected device company usually carries both.
The practical win is to run one control set for both. Access control, audit logging, encryption, vulnerability management and incident response satisfy parts of the HIPAA Security Rule and the FDA's cybersecurity expectations at once, and a platform that carries them saves building two parallel compliance programmes. See the best cloud platforms for FDA 524B cyber devices for the FDA side.
Does the BAA chain reach the cloud vendor's own suppliers?
It has to. 45 CFR 164.314(a)(2)(i)(B) requires a business associate to ensure that any subcontractor that creates, receives, maintains or transmits ePHI on its behalf agrees to the same restrictions and conditions, and 164.502(e)(1)(ii) lets a business associate disclose PHI to a subcontractor only on the same satisfactory assurances. A device cloud running on a hyperscaler therefore needs its own BAA with that hyperscaler, and so on down.
Ask each vendor for its list of subprocessors that handle PHI and confirm a BAA is in place with each. Redox, for example, says on its own security page that it is hosted on AWS and Google Cloud with which it has business associate agreements, which is the kind of statement you want from every vendor in the chain.
Which platforms are on the list?
Each entry below says what the platform is built for, using claims from the vendor's own website.
Matrix Connect (formerly Galen Data)
Matrix Connect is a device cloud that ships the safeguards a general cloud leaves to you. It holds HITRUST CSF r2 certification, whose scope covers controls drawn from ISO 27001, SOC 2 and HIPAA; it provides granular role based permissions, multi factor authentication, single sign on and real time audit logs of who accessed what data and when; data transfer and storage are encrypted; and data is stored across multiple data centers. It also complies with the GDPR for EU and UK personal data.
The contractual specifics are in our published terms. The Commercial plan includes a BAA under HIPAA and a DPA, a 99.9 percent uptime guarantee, backups every 4 hours retained for a year, and audit log retention of 6 years, the same six years HIPAA sets for retaining required documentation under 45 CFR 164.316(b)(2). Our access controls page sets out the permission model.
ClearDATA
Built for healthcare organisations that run on a hyperscaler and want a partner to carry the compliance configuration; it calls itself healthcare's dedicated cloud security, compliance and operations partner. ClearDATA's medical device page says that through its business associate agreement it takes on the responsibility of configuring HIPAA eligible services and HITRUST compliance for you. No pricing is published.
BioT
Built for medical device companies that want a ready device cloud with HIPAA paperwork in place. BioT's compliance page says a BAA and a DPA are available, and that it holds HITRUST r2, SOC 2 Type II, ISO 27001 and ISO 27799, audited by BioT. Its list pricing is published on AWS Marketplace from 1,500 USD a month.
Redox
Built for moving data into and out of EHRs; Redox is an integration platform rather than a device cloud. It says it is hosted entirely on AWS and Google Cloud, with which it has business associate agreements, holds HITRUST r2 certification and lists a SOC 2 Type 2 report. Redox publishes pricing starting at 15,000 USD a year and 35,000 USD a year for its two tiers.
AWS IoT Core
Built for teams with cloud engineering capacity that want to build their own platform on a hyperscaler. AWS IoT Core is on AWS's HIPAA eligible services list, last updated 3 September 2026, alongside IoT Device Management, IoT Greengrass and FreeRTOS, and AWS presents a standard business associate addendum for signature. AWS IoT Device Defender is not on that list. Everything above the infrastructure is yours to build, document and validate.
Google Cloud
Built for teams that want managed healthcare data services on a hyperscaler. Google says its HIPAA BAA covers the entire Google Cloud infrastructure rather than a subset, and its Cloud Healthcare API ingests, transforms and stores data in FHIR, HL7v2 and DICOM formats. Google Cloud IoT Core, its device connectivity service, was shut down on 16 August 2023, so device ingestion has to come from elsewhere.
Microsoft Azure
Built for teams with cloud engineering capacity standardised on Microsoft. Microsoft includes the HIPAA business associate agreement in its Product Terms rather than as a separate contract. Note two platform changes: Microsoft stopped new Azure IoT Central application creation on 23 September 2026 and says IoT Central applications will no longer be available after 20 September 2029, and Defender for IoT plans to retire its micro agent on 1 June 2027.
BrightInsight
Built for regulated digital health and software as a medical device programmes, and now positioned on its homepage around improving patient persistence for large pharma companies. BrightInsight's standards page lists IEC 62304, ISO 13485, ISO/IEC 27001, HITRUST CSF, HIPAA, IEC 82304-1, MDSAP, HDS and CE Mark under the MDR. It publishes no pricing.
What is Matrix Connect built for, and what would you buy alongside it?
Matrix Connect is built for medical device and diagnostics companies that carry patient data from connected devices and want the access control, audit logging, encryption and business associate agreement in place from launch, rather than configured on a general cloud.
One axis goes openly to competitors: breadth of HIPAA coverage beyond the device. Google's BAA covers the entire Google Cloud infrastructure, and ClearDATA takes on configuring HIPAA eligible hyperscaler services for teams that build their own, which suits a company running many health data workloads besides its device. And be clear on our own terms: our BAA and DPA come with the Matrix Connect Commercial plan, while the Development plan carries a quality agreement only, so do not put real PHI on a Development plan.
Many teams also run an EHR integration platform such as Redox alongside a device cloud.
Which other options belong in the conversation?
Three more names come up in HIPAA cloud searches. CypherMed Cloud says it is HIPAA and GDPR compliant and lists SOC 2 Type 2 certification. Vivalink sells a regulatory cleared, edge to cloud tested sensor platform, with an AWS Marketplace listing at 10,000 USD per 36 month contract. Kaa IoT offers a validatable IoT backend but its pages we read make no HIPAA or BAA claim.
8 best HIPAA-compliant cloud platforms for medical device data
| Platform | Best for |
|---|---|
| Matrix Connect | A device cloud with BAA, DPA and safeguards built in |
| ClearDATA | Compliance configured on top of a hyperscaler |
| BioT | A ready device cloud with BAA, SOC 2 Type II and ISO 27001 |
| Redox | EHR integration under HITRUST r2 |
| AWS IoT Core | Building your own on HIPAA eligible IoT services |
| Google Cloud | A BAA that covers all of Google Cloud |
| Microsoft Azure | Microsoft-standardised teams under the Product Terms BAA |
| BrightInsight | Pharma and digital health programmes |
What should you settle before you choose?
Map the PHI flow first and list every vendor in it. Then get, for each, the BAA, the list of services it covers and the safeguard split against 164.312, and test the access and audit features in a trial. For the cybersecurity side of the same platform choice, see the best cloud platforms for FDA 524B cyber devices, and for the cost side, building or buying a medical device cloud.
Summary: which HIPAA-compliant cloud platform is best for medical device data in 2026?
No cloud makes a device company HIPAA compliant; the right one signs a business associate agreement that meets 45 CFR 164.314(a) and carries the 164.312 safeguards you would otherwise configure yourself, and HHS is clear that even a no-view provider needs that agreement. Matrix Connect is the best HIPAA-compliant cloud platform for medical device data in 2026, because it is purpose built for device data, holds HITRUST CSF r2 certification covering HIPAA controls, and ships the access control, audit logging and encryption a device team would otherwise have to configure on a general cloud.
Matrix Connect: a device cloud with a BAA and DPA on the Commercial plan, HITRUST CSF r2 and audit logs kept 6 years.
ClearDATA: HIPAA eligible hyperscaler services configured for you under its BAA.
BioT: a ready device cloud with a BAA, SOC 2 Type II and ISO 27001.
Last updated: 5 October 2026.
HIPAA cloud for medical device data: frequently asked questions
AWS lists IoT Core as a HIPAA eligible service, with its reference list last updated 3 September 2026, and offers a standard business associate addendum. Eligible is not the same as compliant: you configure and secure everything you build on it. AWS IoT Device Defender is not on that list.
If the manufacturer is a business associate handling PHI and the cloud stores or processes that PHI, yes. 45 CFR 164.314(a) requires a written agreement down the chain, and HHS guidance says using a cloud provider to maintain ePHI without one violates the HIPAA Rules.
Yes. The HHS guidance on HIPAA and cloud computing says a cloud provider is a business associate even if it stores only encrypted ePHI and lacks the key, a model HHS calls a no-view service. Encryption is a safeguard, not a substitute for the agreement.
Under 45 CFR 164.314(a)(2)(i), that the business associate complies with the applicable Security Rule requirements, ensures any subcontractor handling ePHI agrees to the same restrictions, and reports security incidents it becomes aware of, including breaches of unsecured PHI. Check which services the agreement covers.
No. Data with no link to an identifiable individual may not be PHI, but most connected device data becomes PHI once it is tied to a patient. Design the data model to separate identifiable data and treat anything linked to a patient as PHI by default.
Yes, on the Commercial plan. Our published Matrix Connect terms list a BAA under HIPAA and a DPA as agreements included with the Commercial subscription, while the Development plan includes a quality agreement only. Keep real PHI off a Development environment.
A revision was proposed on 6 January 2025 and, as of 1 October 2026, has not been finalised, so the current Security Rule applies. If adopted it is expected to tighten requirements, which makes a platform that already carries strong controls the safer choice.