Mark a Data Right Yes Only When the Contract States It

Device Data Rights Checklist

Companion to Medical Device Connectivity · Updated 2026-09-29

Use this with the contract, for any device whose records, logs, or configuration the institution will need later. Procurement, counsel, and the institution’s data or privacy owner complete it; “Hospitals Should Make Connectivity the Default for Institutional Device Purchases” works it on the smart infusion pump.

The US Food and Drug Administration’s (FDA) premarket cybersecurity guidance (current edition dated February 3, 2026; substance finalized June 27, 2025), which is nonbinding, states that “cybersecurity controls should not be intended to prohibit a user from accessing their device data.” Ask every vendor to commit to that in writing. The rest of this checklist is doctrine that the contract must create. Read the draft contract against each row. Mark a right “yes” only when the contract states it.

The Device Data Rights Checklist: each right counts only when the contract states it.

RightPass whenIn the contract?
Scope of the institution’s dataThe contract defines it to include device records, event and audit logs, configuration, service data about the institution’s units, and anything derived from them.
Access during the contractThe institution can read its data through a documented interface at any time, without per-query or per-integration fees.
ExportThe institution can export all of its data in a complete, documented, machine-readable format, through an authenticated path whose every use is logged.
Manufacturer accessThe contract lists what data the manufacturer can reach, by which path (remote service, cloud service, field service tools), and for what purpose.
Manufacturer useUses beyond service and support (product improvement, benchmarking, model training, sale) need the institution’s written consent, use by use.
De-identificationWhere de-identified use is allowed, the contract names the method and prohibits re-identification.
Privacy termsThe data-use terms are consistent with the institution’s existing privacy and data-handling agreements with the vendor, and neither weakens the other.
Third partiesThe vendor discloses every subprocessor, and the institution may give its own data to any third party it chooses.
Integration freedomThe institution may connect the device to other companies’ systems without losing warranty or support.
No lockout by security controlsSecurity controls don’t block the institution from its own data.
Retention and end of contractThe contract states how long the vendor keeps the data. At the end, the institution receives a final full export, then certified deletion.
Changes to termsThe vendor can’t change data terms through a software update, a click-through screen, or revised online terms.

A right marked “no” is one the institution doesn’t have. Decide before signing whether the device is still worth buying without it. Once years of your data sit with the vendor, you have little bargaining power to add the right.