Examples of IoT in Healthcare: 10 Connected Medical Devices

The Internet of Medical Things (IoMT) market is projected to reach $260 billion by 2027, with over 7 million IoMT devices deployed in smart hospitals by 2026. Connected medical devices are changing how patients are monitored, how medications are delivered, how surgeries are performed, and how hospitals operate. They also create cybersecurity obligations that healthcare organizations must manage. The ten examples of IoT in healthcare below show how connected technology is changing clinical care and what each device type means for hospital cybersecurity.


On this page:

  • Examples of IoT in Healthcare at a Glance
  • What Is IoT in Healthcare
  • 10 Examples of IoT in Healthcare
  • Other Examples of IoT in Healthcare
  • The Security Challenge Across All Healthcare IoT
  • How Asimily Helps Secure Healthcare IoT
  • Frequently Asked Questions

Examples of IoT in Healthcare at a Glance
Device Clinical use Primary security concern
Continuous glucose monitors Real-time glucose readings and closed-loop insulin dosing Wireless links to insulin pumps and ePHI sent over BLE
Remote patient monitoring Vital-sign tracking after discharge Devices on home networks outside hospital control
Smart infusion pumps Networked medication delivery with drug libraries Firmware and configuration tampering
Connected imaging systems MRI, CT, and ultrasound connected to PACS End-of-life operating systems and unencrypted DICOM traffic
Wearable health monitors Clinical-grade ECG, blood oxygen, and temperature monitoring Data aggregation platforms that hold thousands of patient records
Automated medication dispensing Point-of-care storage and controlled substance tracking Credential weaknesses and a path into the EHR and Active Directory
Surgical robotics Robotic-assisted minimally invasive procedures Network availability during procedures and vendor remote access
Smart building systems HVAC, pressure, and environmental control for clinical spaces BACnet traffic on infrastructure shared with clinical systems
RTLS and asset tracking Locating equipment, staff, and patients Location data privacy and a campus-wide wireless footprint
AI clinical decision support Early warning and sepsis prediction from device data Integrity of the data pipeline feeding the model
What Is IoT in Healthcare?

The Internet of Things (IoT) in healthcare is the network of connected medical devices, sensors, and clinical systems that collect, transmit, and analyze patient data over hospital networks and the internet. Common examples of IoT in healthcare range from wearable monitors and implantable sensors to imaging systems, medication dispensing cabinets, and robotic surgical platforms.

When these devices are used in clinical settings, the category is commonly called the Internet of Medical Things (IoMT). IoMT devices are distinct from general enterprise IoT (printers, VoIP phones, building systems) because they interact with patients, process protected health information (PHI), and often directly affect clinical outcomes. A compromised smart thermostat is an inconvenience. A compromised infusion pump is a patient safety event.

A single hospital runs thousands of these devices alongside building systems and standard IT, and they rarely share an owner. Clinical engineering manages pumps and monitors, facilities manages HVAC and access control, IT manages the network, and the security team is accountable for all of it. Much of the risk in healthcare IoT sits in that split: devices that no single team fully inventories, patches, or segments.

Each example below covers the clinical use case and the security considerations that come with it.

10 Examples of IoT in Healthcare

1. Continuous Glucose Monitors (CGMs)

More than 40 million people in the US have diabetes, according to the CDC’s National Diabetes Statistics Report. Effective glucose management is critical for avoiding both short-term emergencies and long-term complications. Traditional monitoring relied on manual finger-prick tests that captured a single moment and missed dangerous fluctuations between measurements.

IoT-connected continuous glucose monitors use a small sensor inserted under the skin to measure glucose levels every few minutes. They transmit readings wirelessly to a smartphone app, a clinical dashboard, or a connected insulin delivery system. Modern CGMs from manufacturers like Abbott (FreeStyle Libre) and Dexcom (G7) provide real-time trend data, predictive alerts for dangerous highs and lows, and integration with insulin pumps for closed-loop automated dosing. Clinicians can review continuous trend data between visits instead of relying on a patient’s handwritten log.

Security considerations: CGMs transmit patient health data over Bluetooth Low Energy (BLE), which has documented weaknesses, including eavesdropping and replay attacks. The data is classified as ePHI under HIPAA. When CGMs feed data to connected insulin pumps in closed-loop systems, a compromise could affect medication delivery. That risk has precedent. In 2019, the FDA warned that certain Medtronic MiniMed insulin pumps could be accessed wirelessly by an unauthorized person nearby, and the affected models were recalled. Segmentation policies should isolate the systems that receive CGM data from general hospital traffic.

2. Remote Patient Monitoring (RPM) Systems

Hospital readmissions are one of the most expensive problems in healthcare. Remote patient monitoring continues data collection after a patient leaves the hospital. Connected devices measure vital signs (heart rate, blood pressure, oxygen saturation, weight, and temperature) and transmit readings to clinical teams for ongoing oversight.

RPM programs have shown measurable clinical impact. At Harrington Hospital, part of UMass Memorial Health, a remote monitoring program for heart failure patients cut all-cause 30-day readmissions by 50%. Patients used a connected scale and blood pressure cuff at home, and nurses reviewed the readings daily. Medicare reimburses RPM under dedicated billing codes, which has supported adoption across health systems. RPM is now used for chronic disease management (heart failure, COPD, diabetes, and hypertension), post-surgical recovery, prenatal and maternal health, and behavioral health check-ins.

Security considerations: RPM devices operate outside the hospital’s physical network perimeter, often on patients’ home Wi-Fi networks. Data transmission security depends on the manufacturer’s implementation of encryption and authentication. Healthcare organizations should evaluate how RPM vendors protect data in transit and at rest, and confirm that the clinical dashboards receiving RPM data are segmented from other hospital systems. A misconfigured cloud backend exposes every enrolled patient at once, so vendor security review belongs in the procurement process.

Related: IoT Security: The Complete Guide to Protecting Connected Devices

3. Smart Infusion Pumps

Infusion pumps deliver medications, fluids, and nutrients directly into a patient’s bloodstream at precise rates. IoT-enabled infusion pumps add network connectivity for several functions:

  • Drug library updates
  • Remote dose adjustments
  • Integration with electronic health records
  • Real-time monitoring of infusion status, fluid volumes, and alarm conditions

Smart pumps include dose-error reduction systems that check programmed doses against drug libraries to catch potential medication errors. Clinical staff can monitor multiple patients’ infusions at once from a central dashboard. Predictive analytics can flag pumps approaching end-of-fluid or detect occlusions before they trigger alarms.

Security considerations: Infusion pumps appear regularly in CISA’s ICS medical advisories. In 2023, CISA published an advisory covering eight vulnerabilities in the BD Alaris system that could allow an attacker to modify firmware or change system configurations. Because infusion pumps directly control medication delivery, a compromise could result in an overdose or underdose. A critical control is network segmentation that restricts pump communication to the EHR, the drug library server, and the management console.

Related: Medical Device Vulnerability Management: A Practical Guide

4. Connected Imaging Systems (MRI, CT, and Ultrasound)

IoT-connected imaging systems integrate with hospital PACS (Picture Archiving and Communication Systems), transmit diagnostic images to clinicians in real time, and enable remote radiologist access. AI-assisted imaging analysis can flag potential findings for radiologist review. That speeds diagnosis for conditions like stroke, where minutes affect outcomes.

Cloud connectivity enables vendor remote support, firmware updates, and predictive maintenance that reduces unplanned downtime. IoT sensors on imaging equipment monitor performance metrics (helium levels on MRI, tube usage on CT) and alert biomedical engineering teams before failures occur.

Security considerations: Imaging systems are large, expensive, and have lifecycles of 10 to 20 years. Many run end-of-life operating systems such as Windows 7 or Windows XP that no longer receive security patches. They communicate using DICOM, a protocol with limited built-in security that often sends patient data and images across the network without encryption. Vendor remote support adds a standing external connection into the imaging environment. For imaging systems that cannot be updated, compensating controls such as network segmentation and virtual patching are often the only viable security measures.

Related: Lumexa Imaging Breach: When a Vendor Connection Becomes the Attack Path

5. Wearable Health Monitors

Wearable health technology has moved from consumer fitness tracking into clinically validated medical monitoring. Examples include the Apple Watch, with its FDA-cleared ECG app and irregular rhythm notifications, and dedicated medical wearables such as the BioIntelliSense BioButton and Masimo W1. These devices continuously measure heart rate, heart rhythm, blood oxygen, skin temperature, and activity levels.

Clinical applications include:

  • Post-operative cardiac monitoring, with wearable ECG patches replacing bulky Holter monitors
  • Fall detection and emergency alerting for elderly patients
  • Sleep apnea screening
  • Atrial fibrillation detection in at-risk populations

The data these devices generate feeds clinical decision support systems with longitudinal health data that periodic office visits cannot match.

Security considerations: Wearable devices transmit health data over BLE, Wi-Fi, and cellular connections. Data aggregation platforms collect information from thousands of patients at once, which makes them high-value targets for data theft. Wearables that connect to hospital networks for clinical integration must be inventoried, assessed for known vulnerabilities, and included in the organization’s segmentation policies. Before clinical adoption, a pre-purchase security assessment should evaluate the manufacturer’s data handling, encryption implementation, and patch support commitments. For IoMT purchases, Asimily’s ProSecure assesses a device model’s security risk before spend is committed.

Related: CISO’s Security Risk Assessment Guide for Medical Device Procurement

6. Automated Medication Dispensing Systems

Automated dispensing cabinets (ADCs) like BD Pyxis and Omnicell systems store, dispense, and track medications at the point of care. These IoT-connected systems integrate with EHR and pharmacy systems so the right medication reaches the right patient at the right dose. They maintain controlled substance logs, automate restocking workflows, and provide real-time inventory visibility across the hospital.

ADCs reduce medication errors, cut the time nurses spend locating and verifying medications, and provide audit trails for regulatory compliance. Some systems now include biometric authentication and barcode verification at the point of dispensing.

Security considerations: ADCs connect to EHR systems, pharmacy databases, and often the hospital’s Active Directory for user authentication. A compromised cabinet could give an attacker access to patient medication records and controlled substance logs, along with a lateral movement path into the EHR environment. Dispensing systems have their own advisory history. CISA has published advisories on hard-coded credentials in BD Pyxis products that could expose ePHI. It has also flagged a session fixation flaw that could let a previous user’s Active Directory credentials be reused to access the device. These systems belong on segmented networks with strict access controls and behavioral monitoring.

7. Connected Surgical Robotics

Robotic-assisted surgery platforms like Intuitive Surgical’s da Vinci and Medtronic’s Hugo RAS use network connectivity for several functions:

  • Real-time data transmission
  • Remote surgeon consultation
  • Intraoperative imaging integration
  • Post-procedure analytics

These systems allow surgeons to perform minimally invasive procedures with greater precision than manual techniques, reducing incision size, blood loss, and recovery time.

Emerging applications include AI-assisted surgical planning based on patient imaging data and telesurgery that lets specialist surgeons guide procedures remotely. Digital twin technology is also emerging, creating virtual replicas of patient anatomy for pre-surgical simulation.

Security considerations: Surgical robotics systems require very high network reliability and low latency, and network disruption during a procedure is a direct patient safety risk. These systems also connect to imaging databases, patient records, and vendor cloud services for software updates and performance analytics. Segmentation must guarantee network performance for surgical systems while isolating them from general hospital traffic. Vendor remote access for maintenance and updates should be time-limited, logged, and authenticated.

8. Smart Building and Environmental Systems

Hospital building systems, including HVAC, fire suppression, elevator controls, lighting, and access control, increasingly rely on IoT sensors and controllers to maintain clinical environments. Their clinical roles include:

  • Keeping operating room temperature and humidity within the ranges required for surgical safety
  • Precise temperature monitoring in pharmacy and laboratory storage to protect medication and sample integrity
  • Running negative-pressure isolation rooms, which depend on building automation to contain airborne pathogens

IoT-connected environmental monitoring provides:

  • Continuous data logging for Joint Commission and regulatory compliance
  • Automated alerting when conditions drift outside specified ranges
  • Energy management across large hospital campuses
  • Integration with clinical systems, such as operating room schedules that trigger HVAC adjustments

Security considerations: Building automation systems communicate over BACnet, LonWorks, and other industrial protocols designed for reliability, with little security built in. Facilities teams often manage these systems rather than IT, which creates ownership gaps where neither team has full visibility. A building automation controller that shares a network segment with clinical systems gives an attacker a path from a lightly monitored device to a sensitive one. Asimily inventories building automation devices alongside clinical IoMT, so both appear in one view with the same risk prioritization.

Related: How Segmentation Contains a Hospital OT Ransomware Attack

9. Real-Time Location Systems (RTLS) and Asset Tracking

Hospital staff lose time searching for infusion pumps, wheelchairs, and other mobile equipment. RTLS attaches IoT tags (BLE beacons, UWB, RFID, or Wi-Fi) to equipment and staff badges to provide real-time location visibility.

Beyond equipment tracking, RTLS supports:

  • Patient flow optimization, including wait times, room turnover, and department throughput
  • Staff safety through duress alerting
  • Hand hygiene compliance monitoring
  • Contact tracing during infectious disease outbreaks

Asset utilization data from RTLS helps biomedical engineering and supply chain teams make evidence-based purchasing decisions. This avoids capital spending on equipment the hospital already owns but cannot find.

Security considerations: RTLS infrastructure covers the entire hospital campus and generates location data for equipment, staff, and sometimes patients. This data reveals movement patterns, staffing levels, and patient locations, so it carries both privacy and physical security implications. RTLS tags communicate constantly over wireless protocols, and the backend servers that process location data should be segmented and access-controlled. Asimily’s medical device utilization capability tracks how devices are used and adds device-level security and operational context to RTLS data.

Related: Automated IoT Visibility and Deep Categorization

10. AI-Powered Clinical Decision Support

AI-powered clinical decision support systems use IoT device data (vital signs, lab results, imaging, and medication records) to identify patterns that predict adverse events before they occur. Early warning systems monitor indicators of patient deterioration and alert clinical teams before a code event. Sepsis prediction algorithms analyze vital sign trends from bedside monitors to flag at-risk patients hours before clinical presentation.

These systems draw on several devices at once. A patient’s bedside monitor, infusion pump, ventilator, and lab analyzer can all feed the same model. The value depends on the quality, completeness, and timeliness of that data pipeline. Emergency departments are also deploying AI-assisted triage that uses IoT sensor data to prioritize patients by acuity.

Security considerations: Clinical decision support systems ingest data from the most sensitive IoT devices in the hospital, and their recommendations directly influence clinical decisions. The pipeline from device to model must be protected against tampering, since manipulated input data could produce incorrect clinical recommendations. These systems also process and store large volumes of ePHI, which makes them high-value targets for data exfiltration. Security teams should confirm that data feeds from IoT devices to clinical decision support platforms are authenticated, encrypted, and monitored for anomalies.

Other Examples of IoT in Healthcare

The ten examples above cover the devices most hospital security teams manage day-to-day. Several other connected devices extend IoT deeper into patient care, and a few already have documented security histories.

Implantable Cardiac Devices

Pacemakers and implantable cardioverter defibrillators (ICDs) transmit device and rhythm data to clinicians, often through a bedside home monitor. In 2017, the FDA approved a firmware update for about 465,000 Abbott (formerly St. Jude Medical) pacemakers in the US. The update addressed vulnerabilities that could allow unauthorized access using commercially available equipment, and each patient needed an in-person clinic visit to receive it.

Networked Bedside Patient Monitors

Bedside monitors track ECG, heart rate, blood oxygen, and blood pressure, and send readings to central nursing stations. In January 2025, CISA and the FDA warned that the Contec CMS8000 patient monitor contained a hidden backdoor that could leak patient data to an external address and allow remote code execution.

Connected Inhalers

Smart inhalers for asthma and COPD record when and how often a patient uses their medication. Some also log environmental data that helps clinicians identify triggers. They typically pair with a smartphone app over BLE.

Ingestible Sensors

Ingestible sensors collect data from inside the digestive tract, such as pH levels or signs of internal bleeding, without an invasive procedure. They transmit readings wirelessly to an external receiver before passing through the body.

Smart Hospital Beds

Connected beds monitor patient movement, weight, and bed-exit events, and send fall-risk alerts to nursing staff. Because they connect to the nurse call system and often the EHR, they belong in the same inventory and segmentation policies as other clinical devices.

The Security Challenge Across All Healthcare IoT

The examples above share security characteristics that healthcare delivery organizations must address.

Most of these devices cannot run security agents. Traditional endpoint security tools do not work on infusion pumps, CGMs, imaging systems, or building automation controllers. Security has to be applied at the network layer, around the device rather than on it.

Clinical protocols lack built-in security. DICOM, HL7, and BACnet were designed for functionality, with security added later or not at all. They often send data without encryption or authentication, and standard IT monitoring tools do not parse them.

Device lifecycles exceed IT refresh cycles. MRI machines, surgical robots, and building automation systems operate for 10 to 20 years. Many will run end-of-life operating systems for most of their working life. Compensating controls such as segmentation and virtual patching carry most of the security load for these devices.

Scale makes manual management impossible. A health system with 50,000 connected devices cannot manually inventory, assess, segment, and monitor each one. Every stage requires automation.

Regulatory requirements apply to all of them. HIPAA already requires covered entities to protect the ePHI these devices handle, and the FDA’s premarket cybersecurity requirements apply to device manufacturers. New York’s 10 NYCRR 405.46, fully enforceable since October 2025, requires general hospitals to maintain asset inventories and network monitoring. A proposed update to the HIPAA Security Rule would make a technology asset inventory and network map mandatory. As of September 2026, that rule has not been finalized.

Related: Healthcare Cyberattacks: Why Hospitals Are the Top Target

Related: Network Segmentation Security Best Practices

How Asimily Helps Secure Healthcare IoT

Each example in this guide adds a device that clinical teams depend on and that security teams cannot install an agent on. Most health systems already have a NAC deployed. Far fewer have turned it into working segmentation for clinical devices. Writing, testing, and maintaining those policies by hand cannot keep pace with a network where pumps move between floors and imaging systems receive new firmware.

Asimily builds a complete, agentless inventory of every IoT, OT, IoMT, and IT device on the network, without touching clinical equipment or interrupting care. Deep packet inspection that understands DICOM, HL7, and BACnet supplies the detail behind each device record. ATT&CK Analysis then determines whether a vulnerability is exploitable on a specific device in its actual network position. Teams start with the small set of devices driving most of the risk.

Asimily’s Segmentation Orchestration turns that prioritization into enforced policy on the NAC the hospital already runs, including Cisco ISE, Aruba ClearPass, and Arista. Policy Auto-Recommendation proposes where to start. Policy Creation writes each policy in the NAC’s native format. Policy Simulation tests it against real, observed traffic, so clinical engineering can see which connections would change before anything is applied. Continuous Segmentation keeps policy aligned as devices are added, moved, or retired.

For medical devices specifically, ProSecure evaluates the security risk of a device model before purchase. When an incident does occur, native packet capture supports forensic investigation.

Asimily is ranked #1 by KLAS in Healthcare IoT Security. See how Asimily protects connected medical devices or request a demo.

Frequently Asked Questions
What Are Examples of IoT in Healthcare

Common examples of IoT in healthcare include:

  • Continuous glucose monitors
  • Remote patient monitoring systems
  • Smart infusion pumps
  • Connected imaging systems
  • Wearable health monitors
  • Automated medication dispensing cabinets
  • Surgical robotics
  • Smart building systems
  • Real-time location systems
  • AI-powered clinical decision support

Implantable cardiac devices, bedside patient monitors, connected inhalers, ingestible sensors, and smart hospital beds are also widely used.

What Is the Difference Between IoT and IoMT

IoT refers to any connected device that collects or exchanges data over a network, including printers, cameras, and building controls. IoMT (the Internet of Medical Things) is the subset used for clinical care. These devices interact with patients, process protected health information, and can directly affect patient safety.

What Is the Most Common Use of IoT in Healthcare

Remote patient monitoring is one of the most widely adopted uses. Connected devices track vital signs such as heart rate, blood pressure, and weight after a patient leaves the hospital, and transmit readings to clinical teams. Inside the hospital, networked infusion pumps, patient monitors, and imaging systems are among the most common connected devices.

Why Are IoT Medical Devices Difficult to Secure

Most medical devices cannot run security agents, and many run end-of-life operating systems for years after vendor support ends. They also communicate over clinical protocols like DICOM and HL7 that often lack encryption. Patching often requires vendor involvement and clinical downtime, so security teams rely on network-level controls.

How Do Hospitals Protect IoT and IoMT Devices They Cannot Patch

Hospitals protect unpatchable devices with compensating controls. Network segmentation restricts each device to the systems it needs to reach. Behavioral monitoring detects abnormal traffic, and virtual patching blocks known exploit paths. Testing segmentation policies against real network traffic before enforcement helps confirm that clinical workflows keep running.


Asimily is the Proactive Cyber Asset Defense Platform across your entire cyber asset attack surface: IoT, OT, IoMT, and IT. It empowers teams to reduce risk efficiently by identifying the riskiest devices, prioritizing what matters, and continuously orchestrating the segmentation and mitigation actions that close exposures without disrupting operations. Ranked 11th on the 2024 Deloitte Technology Fast 500 and #1 by KLAS in Healthcare IoT Security 2026. Learn moreHome.

Secure Every IoT Device.
Automatically.

Cyber threats move fast — so should you. Asimily gives instant inventory and smart, prioritized risk mitigation insights for every IoT, OT, and IoMT device — so you can take action before threats strike.