The Internet of Things (IoT) is simply the practice of putting sensors and a network connection into ordinary objects so they can report what they measure. In healthcare that object might be a blood pressure cuff, an infusion pump, a hospital bed or a glucose sensor worn on the arm. Once those devices send readings on their own, care no longer depends on the patient being in the room.
The healthcare version of this idea has its own name: the Internet of Medical Things (IoMT), meaning the connected medical devices, wearables and hospital equipment that feed data into clinical systems. This guide explains what IoMT actually delivers in 2026, what it costs, what the security record looks like, and which rules now apply to anyone buying or building these systems.
Key Takeaways
- IoT in healthcare means medical devices that send readings automatically, without a clinic visit.
- Remote patient monitoring is the clearest use case, and Medicare expanded what it pays for in 2026.
- Grand View Research puts the IoT in healthcare market at USD 65.1 billion in 2025, growing at 21.5% a year through 2033.
- Security is the weak point: most hospitals run connected devices with known, exploitable flaws.
- The FDA now requires a software bill of materials and a patching plan before a connected device can be sold in the US.
What Connected Healthcare Devices Actually Do
Strip away the marketing and a connected medical device does three things. It measures something (heart rhythm, glucose, weight, oxygen saturation, pump status). It transmits that measurement over Wi-Fi, cellular or Bluetooth. And it lands in a system where a clinician, or software acting for one, can look at it.
That sounds modest. The change it produces is not. A cardiologist who used to see a heart failure patient every three months now sees a daily weight reading, and a two kilogram gain over three days is an early warning of fluid retention. The measurement itself is old. Getting it without an appointment is what is new.
The same logic applies inside hospitals. Infusion pumps report their own status, ventilators log their settings, and asset tags show where the portable ultrasound went. This is the healthcare branch of a much wider shift covered in our guide to how IoT is changing business operations.
Where the Market Stands in 2026
Market forecasts in this field vary widely, so treat any single number with care. Grand View Research values the IoT in healthcare market at USD 65.1 billion in 2025 and projects USD 308.5 billion by 2033, a compound annual growth rate of 21.5% from 2026 onward. Other research houses publish different totals because they count different things: some include hospital IT infrastructure, others only the devices.
What the numbers agree on is direction. Spending is growing quickly, and it is growing fastest in remote monitoring rather than in hospital hardware. That fits the broader pattern described in our overview of digital transformation in healthcare and the business opportunities mapped out in HealthTech trends.
Remote Patient Monitoring: The Use Case That Pays
Remote patient monitoring (RPM) means a patient uses a connected device at home, the readings go to their care team automatically, and someone reviews them. It is the most established IoMT application because it has a billing code behind it, which matters more than any technology advantage.
What Medicare Pays For in 2026
Until recently, US providers could only bill Medicare for remote monitoring if a device transmitted data on at least 16 days in a 30 day period, and if a clinician spent at least 20 minutes on the case. Short episodes of care did not qualify.
The CY 2026 Medicare Physician Fee Schedule changed that. CMS added CPT 99445 for device supply covering 2 to 15 days of transmitted data, and CPT 99470 for 10 to 19 minutes of treatment management. Remote therapeutic monitoring gained a parallel set of codes (98979, 98980, 98981) plus short-duration device supply codes 98984 to 98986.
The practical effect is that a two week monitoring episode after surgery, or a short medication titration, can now be billed. Programmes that were financially marginal became viable. Separately, Medicare telehealth flexibilities for non-behavioural care in the patient’s home run through 31 December 2027, while behavioural and mental health telehealth at home is now permanent.
Wearables and Home Devices
Consumer wearables and clinical devices are converging, but they are not the same thing. A fitness tracker estimates. A continuous glucose monitor or an FDA-cleared ECG patch measures to a clinical standard and carries regulatory approval. Both feed the same trend of wearable technology reshaping workplaces and homes, yet only one belongs in a treatment decision.
Employers exploring wearables for staff wellbeing face a separate question about who owns the resulting data, which we cover in our guide to wearable tech policy.
Where Connected Devices Save Time and Money
The financial case for IoMT rests on two mechanisms: catching problems earlier and removing journeys that add no clinical value.
Better Management of Chronic Conditions
The CDC reports that 6 in 10 US adults live with a chronic disease and 4 in 10 have two or more. Chronic conditions are exactly the case where continuous data beats a snapshot, because the useful signal is a trend rather than a single reading.
A patient with COPD whose oxygen saturation drifts down over a week can be called in before an emergency admission. That is the mechanism. It only works if someone actually reviews the readings, which is why staffing, not sensors, is usually the limiting factor.
Fewer Trips, Fewer Admissions
Removing a monthly clinic visit saves the patient a half day and the system a slot. For rural patients, or anyone without a car, it can be the difference between attending and not attending.
Be careful with the savings claims that circulate in this market. Vendor case studies often report large reductions in readmissions, but they usually cover selected patient groups in single institutions. The honest position is that remote monitoring has shown benefit in specific conditions, particularly heart failure and diabetes, and that results outside those settings vary. Treat any sweeping figure without a named study behind it as marketing.

Inside a Connected Hospital
Hospitals were early adopters, mostly for unglamorous reasons. Real time location tags on infusion pumps and wheelchairs cut the time nurses spend hunting for equipment. Connected fridges log vaccine temperatures without anyone writing on a clipboard. Smart beds report when a fall-risk patient sits up.
Feeding all of this into one view is what people mean by a smart hospital, and it depends on the same discipline as any other real time data programme: clean inputs, clear thresholds and someone responsible for acting on an alert.
Two technical shifts made this more practical. Faster mobile networks, described in our guide to how 5G impacts business operations, allow reliable connections in buildings where Wi-Fi is patchy. And processing data close to the device instead of in a distant data centre, the approach explained in edge computing for business data, keeps latency low and reduces how much patient data travels. Running the analysis on the device itself, an approach known as edge AI, takes that a step further.
Video consultations sit alongside this hardware rather than replacing it, and immersive tools such as virtual reality in professional settings are still mostly used for training rather than routine care.
The Security Problem Nobody Has Solved
This is the part vendors skip. A connected medical device is a computer that cannot easily be rebooted, patched or taken offline, because a patient may be attached to it.
Why Medical Devices Are Hard to Secure
Security firm Ordr’s 2026 medical device report, based on more than 2.25 million devices across 351 healthcare organisations, found that 99% of hospitals operate at least one IoMT device with a known exploited vulnerability. Devices averaged 6.2 vulnerabilities each, and roughly 60% were past end of life with no patches available.
The reasons are structural. Medical devices have 10 to 15 year service lives, far longer than the operating systems inside them. Many cannot run antivirus software. And a device cleared by a regulator often cannot be modified without revalidation, which discourages updates.
Practical mitigation is less about the devices and more about the network around them. Segmenting medical devices onto their own network, verifying every connection rather than trusting anything inside the perimeter, is the approach we describe in zero-trust cybersecurity. Broader defensive priorities are covered in our overview of cybersecurity trends for businesses.
What the FDA Now Requires
Since Section 524B was added to the US Food, Drug, and Cosmetic Act, manufacturers submitting a “cyber device” for approval must include three things: a plan to monitor and address vulnerabilities after launch, evidence that the device can receive security updates and patches, and a software bill of materials listing every commercial, open source and off-the-shelf software component inside it.
That last item matters for buyers. A software bill of materials tells you, when the next widely exploited library flaw appears, whether your infusion pumps contain it. Ask for one before you sign.
Data Rules and Interoperability
Two devices that cannot exchange data produce two silos rather than one record. Interoperability, meaning the ability of different systems to read each other’s data without custom work, is the difference between a connected hospital and an expensive collection of gadgets. Standards exist, but adoption is uneven, and integration cost is routinely underestimated in business cases.
The legal picture is tightening. In Europe, the European Health Data Space Regulation (EU 2025/327) entered into force in March 2025. Its main provisions for exchanging patient summaries and prescriptions across member states apply from March 2029, with medical images, lab results and discharge reports following in March 2031. Manufacturers of electronic health record systems have interoperability duties under it.
Anyone handling this data should also read across to general obligations in data privacy trends and, where AI is involved in a clinical decision, EU AI Act compliance.
Where AI Fits
A monitoring programme generates far more readings than any clinician can review. Software has to triage them, deciding which ones a human should see. That is the honest description of most AI in this field: alarm filtering and pattern detection, not diagnosis.
It works in the same way as predictive analytics in business decisions, and it fails the same way, through poor data quality and alerts that staff learn to ignore.
Two cautions are specific to healthcare. Clinicians need to know why a system flagged a patient, which is the argument for explainable AI. And where an AI system influences care, it is likely to be treated as high risk under emerging AI regulation. General adoption patterns are covered in our guide to AI in business operations.
What to Check Before You Buy
If you are evaluating a connected health device programme, five questions separate a working deployment from a stalled one.
Who reviews the data, and is that time funded? Which billing codes apply, and do your episodes meet the thresholds? Does the vendor supply a software bill of materials and a patch commitment? How does the device data reach your existing records, and who pays for that integration? And what happens when a patient stops using the device, which is the most common failure mode in home monitoring.
The pattern here mirrors industrial deployments. As with predictive maintenance, the sensors are rarely the hard part. The workflow around them is.
Where This Goes Next
The near-term direction is incremental rather than dramatic: more devices cleared for home use, wider reimbursement, more processing done on the device, and slowly improving data exchange between systems. Ingestible sensors and closed-loop insulin delivery already exist in limited use and will spread.
The same connectivity that supports patients at home also supports staff working away from the building, a shift we examine in how IoT makes remote work more efficient. The organisations that get value from IoMT are not the ones with the most devices. They are the ones that decided in advance what they would do with a reading before they started collecting it.
Found this useful?
Make SmartKeys a preferred source on Google, and our articles will surface more often in your Top Stories, AI Overviews, and AI Mode.
Add as Preferred Source







