IoT in healthcare means connected devices that measure something about a patient, a piece of equipment or a care environment and send that data where it can inform care. It ranges from a glucose sensor on a patient’s arm to tags on hospital wheelchairs, and it is often called the Internet of Medical Things (IoMT).
This guide covers the main applications with real examples, how a healthcare IoT system is put together, how remote monitoring is paid for in the US, the regulation that applies to connected medical devices, and the challenges that decide whether a project helps clinicians or just adds alerts.
Applications of IoT in Healthcare
Healthcare IoT falls into three groups: devices that monitor patients, devices that run the hospital, and devices that support care at home.
| Application | Typical devices | What it changes |
|---|---|---|
| Remote patient monitoring | Blood-pressure cuffs, scales, pulse oximeters, glucometers | Deterioration is spotted between appointments, not at the next visit |
| Continuous glucose monitoring | Skin-worn sensors linked to a phone or insulin pump | Readings every few minutes instead of a few finger-pricks a day |
| Cardiac monitoring | Wearable ECG patches, implantable loop recorders, smartwatches | Irregular rhythms are captured when they happen |
| Medication adherence | Smart inhalers, connected pill dispensers | Clinicians see whether treatment is actually taken |
| Hospital asset tracking | Real-time location tags on pumps, beds and wheelchairs | Less time searching, fewer lost devices, better utilisation |
| Environmental monitoring | Fridge and freezer loggers, air quality and humidity sensors | Vaccines and medicines provably kept in range |
| Patient safety | Bed-exit sensors, fall detection, smart beds | Staff alerted before a fall rather than after |
| Ageing in place | Ambient motion, door and appliance sensors | Changes in routine flagged without cameras or wearables |
Examples of IoT in Healthcare
Many of these build on consumer wearables, whose design challenges we cover in wearable product development. For IoT applications beyond healthcare, see our list of IoT examples.
How a Healthcare IoT System Works
The device
Takes the measurement, often on a small battery, and must be accurate, safe and simple enough for a patient to use at home without training.
The gateway
Usually a phone app over Bluetooth, or a cellular hub for patients without smartphones. Cellular hubs remove the setup step that defeats many older patients.
The platform
Receives, stores and checks the data, applies thresholds and routes alerts. It must store readings that arrive late when a device was offline, a pattern covered in offline-first IoT.
The clinical system
Readings and alerts reach the electronic health record, typically through HL7 FHIR interfaces, so clinicians work in the system they already use rather than another portal.
How Remote Patient Monitoring Is Paid For in the US
In the US, remote patient monitoring is billed with CPT codes that Medicare and many private insurers recognise. The codes are worth knowing because they shape how programmes are designed. From January 2026 two new codes made shorter monitoring periods billable.
| CPT code | What it covers |
|---|---|
| 99453 | Initial setup and patient education on the device |
| 99454 | Device supply and data transmission for 16 or more days in 30 |
| 99445 (new in 2026) | Device supply and data transmission for 2 to 15 days in 30 |
| 99457 | First 20 minutes of clinical management in a month |
| 99458 | Each additional 20 minutes of management |
| 99470 (new in 2026) | First 10 minutes of management in a month |
Before 2026, a patient who sent readings on fewer than 16 days in a month generated no device payment, which pushed programmes towards daily readings whether or not they were clinically needed. The new codes let monitoring follow clinical need more closely. Rates and rules change annually, so check the current physician fee schedule before building a business case on them.
Regulation and Security of Connected Medical Devices
A device that diagnoses, treats or monitors a medical condition is usually a regulated medical device, and connecting it to a network brings additional obligations.
- FDA cybersecurity requirements (US): Section 524B of the Federal Food, Drug, and Cosmetic Act applies to “cyber devices” — devices with software that can connect to the internet. Since March 2023, premarket submissions must include a plan to monitor and address vulnerabilities, evidence of secure development, and a software bill of materials (SBOM). The FDA has refused to accept incomplete submissions since October 2023, and updated its guidance in June 2025.
- EU Medical Device Regulation: connected devices sold in Europe need conformity assessment under the MDR, including cybersecurity across the device’s lifetime.
- Privacy: HIPAA in the US and GDPR in Europe, where health data is a special category with stricter conditions for processing.
- Software as a medical device: an app or algorithm that interprets readings to support clinical decisions may itself be regulated, separately from the hardware.
Security cannot be added at the end of a medical project, because the SBOM and vulnerability plan are part of the submission. The engineering practices behind this are covered in IoT device security and IoT device identity.
Challenges of IoT in Healthcare
Building a Healthcare IoT Product
Frequently Asked Questions
Conclusion
IoT in healthcare works when a reading reliably reaches the right clinician in time to change what happens next. The devices are the visible part; the clinical workflow, the integration with the health record, the regulation and the years of security support are what decide whether a programme succeeds.
Medical-grade connected devices combine embedded engineering, secure connectivity and regulated software. Our embedded IoT solutions team builds connected devices with security and lifetime support designed in from the start.
