For most product categories, choosing IoT connectivity is an IT decision. For medical devices, it is a clinical infrastructure decision - one that affects patient safety, regulatory exposure, and how quickly a product can scale beyond its first market. This guide sets out the criteria that actually separate strong medical IoT providers from generalist connectivity resellers: coverage, security, compliance readiness, device lifecycle support, and global scalability. Use it to evaluate connected health devices partners with the right questions, not a generic checklist.
What IoT Connectivity for Medical Devices Actually Involves
IoT connectivity for medical devices is the wireless infrastructure that lets connected health hardware transmit patient data securely and continuously to clinical platforms, care teams, and hospital systems. In practice, that spans several layers most buyers only notice when one of them fails:
- SIM and eSIM provisioning that activates a device the moment it reaches a patient or care setting, without manual configuration.
- Multi-carrier cellular coverage with automatic fallback, so a single network outage doesn't mean a monitoring gap.
- Private APN infrastructure that keeps patient data off the public internet entirely.
- Real-time fleet monitoring and alerting across every deployed device, not just the ones a support ticket happens to mention.
- Lifecycle management that keeps devices compliant and connected from first activation through end of life, including migration off sunsetting network technologies.
- Regulatory exposure. Devices operating in Europe fall under MDR and GDPR; in the US, under FDA cybersecurity requirements. The connectivity layer sits inside that compliance surface - it isn't a separate procurement decision from the device itself.
- Security expectations. Patient health data is among the most sensitive personal data that exists. Routing it over shared public networks is not an acceptable trade-off for cost savings.
- Reliability at fleet scale. One device losing signal is manageable. A fleet of thousands experiencing intermittent connectivity gaps becomes a clinical risk and an operational burden that's very hard to manage after the fact.
- Cross-border consistency. Clinical trials, chronic disease programmes, and hospital-at-home initiatives increasingly span multiple countries. Connectivity that works in one market but needs renegotiating for the next slows down patient access to care.
For patients, none of this is visible. For the healthcare device manufacturers building on top of it, all of it determines whether the product actually works in the field.
Why Generic IoT Connectivity Falls Short in Healthcare
Consumer IoT can absorb occasional downtime. A smart thermostat dropping offline for ten minutes is a minor inconvenience. A cardiac monitor missing a transmission window is a clinical risk. That difference changes what "good enough" connectivity means, in four specific ways:
Five Criteria for Evaluating a Medical IoT Provider
1. Coverage and Network Resilience
Medical devices end up in basements, rural homes, ambulances, and care facilities with poor signal - not just clean lab environments. A provider relying on a single carrier leaves devices offline whenever that carrier has an outage or coverage gap in a specific area. Look for multi-network SIMs that switch automatically between carriers based on signal strength, and ask for evidence of real-world performance in the geographies your devices will actually operate in, not just national coverage maps.
2. Security by Design
Private APN configurations that keep data off the public internet should be a default, not a paid add-on. Ask whether encryption is applied end-to-end, whether SIM-level authentication is standard, and whether the provider can produce auditable connectivity logs on request - these are the artifacts your own security and compliance teams will need later, and it's far easier to build them in from day one than to retrofit them after a device is already in the field.
3. Compliance Readiness
This is where medical device connectivity standards diverge sharply from general IoT security compliance. In Europe, that means alignment with GDPR data protection requirements and the connectivity considerations baked into MDR technical documentation. In the US, FDA Section 524B now requires "cyber device" manufacturers to embed cybersecurity into a quality management system aligned with ISO 13485 and the Quality Management System Regulation, backed by a Security Risk Management Report and a machine-readable software bill of materials. A connectivity provider that has never supported a regulated healthcare deployment is unlikely to have the right defaults - private networking, audit trails, incident response processes - already in place. Ask directly about prior healthcare and MedTech experience, not just general enterprise IoT scale.
4. Device Lifecycle Support
A medical device's connectivity needs don't end at shipment. Zero-touch provisioning determines whether a device works the moment a patient or caregiver powers it on, without a support call or IT visit. Over-the-air update capability determines whether security patches and firmware fixes can reach a fleet remotely, which matters even more given FDA's postmarket surveillance expectations. And because devices in the field can run for years, ask how the provider handles technology transitions - such as the ongoing 2G and 3G network shutdowns - so a five-year-old device doesn't become an emergency replacement project.
5. Global Scalability
A successful pilot creates its own problem: how to repeat it in the next country. Traditionally, that has meant new carrier contracts, different SIM SKUs per market, and separate support structures by region - all of which slow expansion and introduce inconsistency exactly when a growing programme needs the opposite. Look for providers that support single-SKU global deployment, where one eSIM profile steers automatically to local networks wherever a device lands, managed through one fleet platform rather than a patchwork of regional vendors.
Evaluation Checklist
A condensed version of the above, framed as questions to put directly to any provider you're evaluating:
Criterion |
Ask the provider |
|
Coverage & resilience |
Do you support multi-network SIMs with automatic fallback? What is your indoor/basement coverage like? |
|
Security by design |
Is a private APN available by default? Is patient data ever routed over the public internet? |
|
Compliance readiness |
Do you have experience supporting GDPR, EU MDR, and FDA Section 524B cyber-device requirements? Are connectivity logs auditable? |
|
Device lifecycle support |
Can devices be provisioned zero-touch and updated over the air? How are end-of-life and network-sunset transitions handled? |
|
Global scalability |
Can one SKU work across markets? Is fleet management unified on a single platform as we expand? |
Proof in Practice: Two Connected Health Deployments
MedThings: MedThings builds smart medication dispensers for Norwegian hospitals and home care settings, certified as a Class I medical device manufacturer with design and production based in Norway. By embedding Com4 eSIMs directly into each unit, devices connect automatically the moment they arrive on site, support remote over-the-air software updates, and integrate in real time with hospital systems - with no manual setup on the patient's side and no IT dependency for the care provider. The solution is now deployed across dozens of Norwegian municipalities, has expanded into Denmark, and is drawing interest from healthcare authorities in China and England.
Dignio's Pilly: Founded by doctors and healthcare professionals, Dignio built Pilly - a smart pillbox addressing medication non-adherence, a problem significant enough that only around half of prescribed medications are typically taken as intended. Pilly uses sound and light cues to prompt patients and automatically notifies designated contacts when a dose is missed. Running on Com4 SIM technology over a private network kept separate from the open mobile network, Pilly's critical communications reach their destination every time - a distinction that matters directly to patient safety when the data in question is whether a cardiac patient took their medication. Pilly is now deployed across more than 50 Norwegian counties and has expanded into Denmark.
Both programmes share the same underlying pattern: connectivity that healthcare device teams didn't have to build, secure, or scale themselves, freeing them to focus on the clinical problem the device was designed to solve.
Making the Decision
Choosing a medical IoT provider isn't about finding the cheapest SIM or the biggest coverage map - it's about finding a partner whose defaults already match what regulated healthcare requires: private networking, multi-carrier resilience, audit-ready compliance support, zero-touch lifecycle management, and a path to scale into new markets without starting over. Providers that can't answer the five criteria above in detail are optimised for a different, less demanding kind of IoT deployment.
Com4 has been building that connectivity layer alongside MedTech companies for years - from eSIM provisioning to fleet management, from private networks to lifecycle compliance support across GDPR, MDR, and evolving FDA cybersecurity expectations. If you're developing a connected health product and want to work through what the right connectivity architecture looks like for your specific use case, our team is glad to help.
.jpg?width=1200&height=628&name=SIMS%20(2).jpg)