Compliance

Compliance for a Medical Device Cloud

BioT holds HITRUST r2, SOC 2 Type II, ISO 27001, ISO 27799 and ISO 13485 certification. Every deployment ships with the evidence a submission and a security review ask for: an IEC 62304 Design History File, cybersecurity documentation mapped to the FDA eSTAR structure, an SBOM per release, and certified infrastructure controls you can cite for the platform layer. BioT customers have achieved FDA clearance and CE marking on the platform.

What You Inherit and What Stays Yours

Stays with you

BioT provides

Stays with you

Infrastructure security and certification

You configure your tenant, your users and your access rules.

BioT provides

Certified, audited controls on AWS

HITRUST r2, SOC 2 Type II, ISO 27001 and ISO 27799, held and audited by BioT.

Stays with you

Quality management and software lifecycle

The same evidence for your own device software, with the platform recorded as a component.

BioT provides

ISO 13485 QMS, IEC 62304 DHF and an SBOM per release

Held for the platform, and available for you to reference in your own file.

Stays with you

Cybersecurity documentation for an FDA submission

Your threat model, risk assessment, vulnerability management plan and security testing.

BioT provides

Platform controls, architecture and SBOM

Documentation you can cite for the infrastructure layer of the system.

Stays with you

Data protection under HIPAA and GDPR

Your policies, workforce training, lawful basis, and agreements with your own customers.

BioT provides

BAA, DPA, encryption, access control and audit logging

Plus a published subprocessor list and hosting in the US, EU or Asia.

Stays with you

Regulatory clearance and CE marking

The submission, and the clearance. This stays yours.

BioT provides

Documentation that supports your submission

BioT customers have achieved FDA clearance and CE marking on the platform.

Certifications BioT Holds

The standard

What it means for you

HITRUST r2

The most demanding security certification in US healthcare. Hundreds of prescriptive controls, independently assessed and re-certified on a fixed cycle. BioT holds the full r2 certification.

Hospital security reviews frequently stop here

Large hospital networks, IDNs and payers treat HITRUST r2 as the bar for vendors handling patient data. Without it, security reviews stall for months of questionnaires. With it, they move.

SOC 2 Type II

The audit standard enterprise buyers know best. An independent auditor verifies that security controls operated effectively over months of observation, not a single snapshot. BioT holds a current Type II attestation.

The baseline an enterprise security review expects

Type II covers a sustained period of operation, not a point in time. It answers the first question every procurement and vendor risk team asks, before they ask it.

ISO 27001

The international standard for information security management. A certified ISMS spanning people, process and technology, audited by an accredited certification body.

The international security baseline

Recognised in EU and US procurement alike. One certificate that answers security questions on both sides of the Atlantic.

ISO 27799

The health-informatics extension of ISO 27001. Security management written specifically for personal health information, not adapted from generic corporate IT.

Health data controls a general ISO 27001 does not cover

Written for health data specifically. It signals infrastructure designed around PHI, with controls a general ISO 27001 certificate does not reach.

ISO 13485

The quality management standard of the medical device industry itself. The same standard notified bodies and the FDA expect from manufacturers, certified for the platform.

A platform QMS your own QMS can reference

Your device still needs its own QMS. This gives it a certified supplier to reference, with an IEC 62304 Design History File behind it.

eSTAR v7.0 submission item              BioT document
---------------------------------------------------------
Software Bill of Materials (SBOM)       SBOM.zip, per release
Vulnerability assessment                Snyk_issues-detail
Off-the-shelf software documentation    OTS-001

An excerpt of the FDA eSTAR v7.0 mapping, from the platform documentation.

Certificates and audit dates are available on request.

Where BioT Fits, and What It Costs to Build Instead

01

Where BioT Fits in Your FDA and MDR Submission

Section 524B applies to any device with sponsor-controlled software that can connect to the internet. It sets three requirements for a premarket submission. For EU MDR, the same IEC 62304 documentation set supports the software lifecycle evidence in your technical file.

  • A postmarket vulnerability management plan, with intake, triage and patch commitments.

  • Section 524B requires a reasonable assurance of cybersecurity, evidenced through secure development practices. BioT's platform layer is HITRUST r2 certified and SOC 2 Type II attested, with an SBOM per release. Evidence you can cite directly.

  • A machine-readable SBOM, maintained across the product lifecycle.

The full platform package is mapped to the FDA eSTAR structure: requirements, architecture design, test reports, cybersecurity management plan, risk assessment, threat model and SBOM.

See the submission documentation

02

Deployment Models and Data Location

BioT runs in one of two models. Which one you choose determines where your data sits, and both give you a dedicated production environment.

  • Installed into your own AWS account, so the deployment and its data stay in your account.

  • Hosted on a BioT-managed account, with a dedicated environment for production.

  • Hosted on AWS, with availability in the US, EU and Asia.

  • A BAA and a DPA are available under both models.

03

Certification Cost If You Build Instead

From BioT client engagement data, the direct certification bill for a do-it-yourself medical device cloud is $945,000 over three years, before headcount.

  • SOC 2 Type 2 and HITRUST r2 also need 18 to 24 months of documented operating history before certification is granted.

  • HITRUST r2 $341K, SOC 2 Type 2 $201K, DHF documentation $132K, vulnerability scanning $78K.

  • ISO 27001 $55K, SBOM $51K, ISO 13485 $45K, penetration testing $42K.

  • The cost compounds: roughly $189K in year one, $312K in year two and $444K in year three.

Subprocessors, Agreements and Common Questions

BioT publishes the third-party subprocessors used to host and process customer data, with their location and the service each one performs. A BAA and a DPA are available under both deployment models.

See the subprocessor list

What certifications does BioT hold?

BioT holds HITRUST r2 certification, SOC 2 Type II attestation, and ISO 27001, ISO 27799 and ISO 13485 certification. Software development follows IEC 62304, with a Design History File and an SBOM per release. The full documentation set is published at docs.biot-med.com.

Does using BioT make my device compliant?

No. Compliance is assessed for your device, and the clearance is yours to obtain. BioT provides certified infrastructure and documentation you can reference in your submission. BioT customers have achieved FDA clearance and CE marking on the platform.

What do I still have to do for a 524B submission?

The device-level work stays yours: your threat model, risk assessment, vulnerability management plan and security testing. BioT provides the platform layer mapped to the FDA eSTAR structure: cybersecurity management plan, risk assessment, threat model, architecture views and SBOM, documented at docs.biot-med.com.

Where is customer data hosted?

On AWS, with availability in the US, EU and Asia. In the customer-account model the deployment sits in your own AWS account. In the managed model it runs on a BioT-managed account with a dedicated environment per customer.

Can I get the BAA and the DPA?

Yes. Both ship in the compliance pack, along with current certificates. Request the pack and the team will send everything.

Bring us your compliance requirements

Request the compliance pack