Mark a Data Right Yes Only When the Contract States It
Device Data Rights Checklist
Companion to Medical Device Connectivity · Updated 2026-09-29
Use this with the contract, for any device whose records, logs, or configuration the institution will need later. Procurement, counsel, and the institution’s data or privacy owner complete it; “Hospitals Should Make Connectivity the Default for Institutional Device Purchases” works it on the smart infusion pump.
The US Food and Drug Administration’s (FDA) premarket cybersecurity guidance (current edition dated February 3, 2026; substance finalized June 27, 2025), which is nonbinding, states that “cybersecurity controls should not be intended to prohibit a user from accessing their device data.” Ask every vendor to commit to that in writing. The rest of this checklist is doctrine that the contract must create. Read the draft contract against each row. Mark a right “yes” only when the contract states it.
The Device Data Rights Checklist: each right counts only when the contract states it.
| Right | Pass when | In the contract? |
|---|---|---|
| Scope of the institution’s data | The contract defines it to include device records, event and audit logs, configuration, service data about the institution’s units, and anything derived from them. | |
| Access during the contract | The institution can read its data through a documented interface at any time, without per-query or per-integration fees. | |
| Export | The institution can export all of its data in a complete, documented, machine-readable format, through an authenticated path whose every use is logged. | |
| Manufacturer access | The contract lists what data the manufacturer can reach, by which path (remote service, cloud service, field service tools), and for what purpose. | |
| Manufacturer use | Uses beyond service and support (product improvement, benchmarking, model training, sale) need the institution’s written consent, use by use. | |
| De-identification | Where de-identified use is allowed, the contract names the method and prohibits re-identification. | |
| Privacy terms | The data-use terms are consistent with the institution’s existing privacy and data-handling agreements with the vendor, and neither weakens the other. | |
| Third parties | The vendor discloses every subprocessor, and the institution may give its own data to any third party it chooses. | |
| Integration freedom | The institution may connect the device to other companies’ systems without losing warranty or support. | |
| No lockout by security controls | Security controls don’t block the institution from its own data. | |
| Retention and end of contract | The contract states how long the vendor keeps the data. At the end, the institution receives a final full export, then certified deletion. | |
| Changes to terms | The vendor can’t change data terms through a software update, a click-through screen, or revised online terms. |
A right marked “no” is one the institution doesn’t have. Decide before signing whether the device is still worth buying without it. Once years of your data sit with the vendor, you have little bargaining power to add the right.
