Compliance
BioT holds HITRUST r2, SOC 2 Type II, ISO 27001, ISO 27799 and ISO 13485 certification. Every deployment ships with the evidence a submission and a security review ask for: an IEC 62304 Design History File, cybersecurity documentation mapped to the FDA eSTAR structure, an SBOM per release, and certified infrastructure controls you can cite for the platform layer. BioT customers have achieved FDA clearance and CE marking on the platform.
Stays with you
BioT provides
Stays with you
You configure your tenant, your users and your access rules.
BioT provides
HITRUST r2, SOC 2 Type II, ISO 27001 and ISO 27799, held and audited by BioT.
Stays with you
The same evidence for your own device software, with the platform recorded as a component.
BioT provides
Held for the platform, and available for you to reference in your own file.
Stays with you
Your threat model, risk assessment, vulnerability management plan and security testing.
BioT provides
Documentation you can cite for the infrastructure layer of the system.
Stays with you
Your policies, workforce training, lawful basis, and agreements with your own customers.
BioT provides
Plus a published subprocessor list and hosting in the US, EU or Asia.
Stays with you
The submission, and the clearance. This stays yours.
BioT provides
BioT customers have achieved FDA clearance and CE marking on the platform.
The standard
What it means for you
The most demanding security certification in US healthcare. Hundreds of prescriptive controls, independently assessed and re-certified on a fixed cycle. BioT holds the full r2 certification.
Large hospital networks, IDNs and payers treat HITRUST r2 as the bar for vendors handling patient data. Without it, security reviews stall for months of questionnaires. With it, they move.
The audit standard enterprise buyers know best. An independent auditor verifies that security controls operated effectively over months of observation, not a single snapshot. BioT holds a current Type II attestation.
Type II covers a sustained period of operation, not a point in time. It answers the first question every procurement and vendor risk team asks, before they ask it.
The international standard for information security management. A certified ISMS spanning people, process and technology, audited by an accredited certification body.
Recognised in EU and US procurement alike. One certificate that answers security questions on both sides of the Atlantic.
The health-informatics extension of ISO 27001. Security management written specifically for personal health information, not adapted from generic corporate IT.
Written for health data specifically. It signals infrastructure designed around PHI, with controls a general ISO 27001 certificate does not reach.
The quality management standard of the medical device industry itself. The same standard notified bodies and the FDA expect from manufacturers, certified for the platform.
Your device still needs its own QMS. This gives it a certified supplier to reference, with an IEC 62304 Design History File behind it.
An excerpt of the FDA eSTAR v7.0 mapping, from the platform documentation.
Certificates and audit dates are available on request.
01
Section 524B applies to any device with sponsor-controlled software that can connect to the internet. It sets three requirements for a premarket submission. For EU MDR, the same IEC 62304 documentation set supports the software lifecycle evidence in your technical file.
A postmarket vulnerability management plan, with intake, triage and patch commitments.
Section 524B requires a reasonable assurance of cybersecurity, evidenced through secure development practices. BioT's platform layer is HITRUST r2 certified and SOC 2 Type II attested, with an SBOM per release. Evidence you can cite directly.
A machine-readable SBOM, maintained across the product lifecycle.
The full platform package is mapped to the FDA eSTAR structure: requirements, architecture design, test reports, cybersecurity management plan, risk assessment, threat model and SBOM.
See the submission documentation02
BioT runs in one of two models. Which one you choose determines where your data sits, and both give you a dedicated production environment.
Installed into your own AWS account, so the deployment and its data stay in your account.
Hosted on a BioT-managed account, with a dedicated environment for production.
Hosted on AWS, with availability in the US, EU and Asia.
A BAA and a DPA are available under both models.
03
From BioT client engagement data, the direct certification bill for a do-it-yourself medical device cloud is $945,000 over three years, before headcount.
SOC 2 Type 2 and HITRUST r2 also need 18 to 24 months of documented operating history before certification is granted.
HITRUST r2 $341K, SOC 2 Type 2 $201K, DHF documentation $132K, vulnerability scanning $78K.
ISO 27001 $55K, SBOM $51K, ISO 13485 $45K, penetration testing $42K.
The cost compounds: roughly $189K in year one, $312K in year two and $444K in year three.
BioT publishes the third-party subprocessors used to host and process customer data, with their location and the service each one performs. A BAA and a DPA are available under both deployment models.
See the subprocessor listBioT holds HITRUST r2 certification, SOC 2 Type II attestation, and ISO 27001, ISO 27799 and ISO 13485 certification. Software development follows IEC 62304, with a Design History File and an SBOM per release. The full documentation set is published at docs.biot-med.com.
No. Compliance is assessed for your device, and the clearance is yours to obtain. BioT provides certified infrastructure and documentation you can reference in your submission. BioT customers have achieved FDA clearance and CE marking on the platform.
The device-level work stays yours: your threat model, risk assessment, vulnerability management plan and security testing. BioT provides the platform layer mapped to the FDA eSTAR structure: cybersecurity management plan, risk assessment, threat model, architecture views and SBOM, documented at docs.biot-med.com.
On AWS, with availability in the US, EU and Asia. In the customer-account model the deployment sits in your own AWS account. In the managed model it runs on a BioT-managed account with a dedicated environment per customer.
Yes. Both ship in the compliance pack, along with current certificates. Request the pack and the team will send everything.