generated: '2026-08-26' method: searched source: https://www.qtmedical.com/en/privacy note: >- QT Medical publishes no machine-readable API contract, so nothing here is derived from a spec. Every entry below is read from a page QT Medical itself serves. The regulatory clearances are device clearances (medical-device market authorisation), not API or information-security certifications, and are recorded as such — a 510(k) says nothing about how the QTM Dashboard is secured. No SOC 2, ISO 27001 or HITRUST attestation and no trust center was found on any QT Medical host. standards: - id: hipaa name: Health Insurance Portability and Accountability Act (US) conforms: true evidence: >- Privacy Policy: "We acknowledge that in certain cases, we may be a Business Associate under HIPAA and will not use or disclose PHI collected through your use of the Services for any purpose that, where applicable, would violate HIPAA." The same policy states the company follows the Section 164.514(b)(2)(i) safe-harbor de-identification standard (removal of 18 identifiers) and describes HIPAA Security Rule safeguards (Security Management Process, Security Official, Security Incident, Contingency Plans). source: https://www.qtmedical.com/en/privacy - id: hitech name: HITECH Act (US) conforms: true evidence: >- Privacy Policy: "We use appropriate and reasonable security measures as required by relevant laws, including but not limited to HIPAA, CCPA, HITECH and Standard of Privacy of Individually Identifiable Health Information." source: https://www.qtmedical.com/en/privacy - id: ccpa name: California Consumer Privacy Act conforms: true evidence: 'Named in the Privacy Policy alongside HIPAA and HITECH as a law the company''s security measures are held to.' source: https://www.qtmedical.com/en/privacy - id: gdpr name: EU General Data Protection Regulation conforms: true evidence: >- The Privacy Policy carries a dedicated "GDPR Policy" section defining Data Subject, Service Provider/Data Processor, the legal bases for processing, data-subject rights for users "within the EU", and how to exercise access, rectification, cancellation and opposition. The PCA 500 product page describes the cloud as "HIPAA & GDPR" compliant. source: https://www.qtmedical.com/en/privacy - id: fda-510k name: US FDA 510(k) clearance (device authorisation, not an API standard) conforms: true evidence: >- PCA 500 cleared in 2018 for professional and personal use by adults in non-acute settings; cleared 2022 (K220795) for infants, children and adolescents; cleared February 2024 for acute-care use. A "User Manual_System_USFDA" PDF is published on the downloads page. source: https://www.qtmedical.com/en/downloads - id: ce-mark name: EU CE marking (medical device) conforms: true evidence: 'A separate "User Manual_System_CE" PDF is published on the QT Medical downloads page, and the company states CE Mark approval for PCA 500.' source: https://www.qtmedical.com/en/downloads - id: pmda-japan name: Japan PMDA approval (medical device) conforms: true evidence: 'Listed by QT Medical among PCA 500 regulatory approvals (FDA, CE, PMDA, TGA, Health Canada).' source: https://www.qtmedical.com/en/products/PCA-500 - id: tga-australia name: Australia TGA approval (medical device) conforms: true evidence: 'Listed by QT Medical among PCA 500 regulatory approvals.' source: https://www.qtmedical.com/en/products/PCA-500 - id: health-canada-mdl name: Health Canada Medical Device Licence conforms: true evidence: 'QT Medical news release: "QT Medical''s PCA 500 Receives Health Canada''s MDL Registration, Expanding into the Canadian Market."' source: https://www.qtmedical.com/en/news/qt-medicals-pac-500-receives-health-canadas-mdl-registration-expanding-into-the-canadian-market - id: oauth2 name: OAuth 2.0 conforms: false evidence: >- /.well-known/oauth-authorization-server returned 404 on both www.qtmedical.com and dashboard.qtmedical.com; no OAuth documentation is published. source: well-known/qt-medical-well-known.yml - id: oidc name: OpenID Connect conforms: false evidence: '/.well-known/openid-configuration returned 404 on both hosts.' source: well-known/qt-medical-well-known.yml - id: rfc9457 name: RFC 9457 Problem Details for HTTP APIs conforms: false evidence: 'No API contract or error reference is published, so the error envelope cannot be observed.' source: 'no published contract' domain_standards: - id: hl7v2 name: HL7 v2 messaging declared: false evidence: >- NOT FOUND. Cardiology device data would normally reach an EMR as HL7 v2 ORU^R01 or as HL7 aECG/FHIR Observation, and the regulated-health regime shortlist makes these the first standards worth probing. QT Medical advertises "API available for EMR integration" on its own PCA 500 page but names no standard, publishes no contract, and describes the default EMR path as manual PDF upload ("Completed ECG report available in PDF for EMR"). Recorded as an honest miss — reward-only, so no penalty is implied. source: https://qtmedical.com/en-gb/PCA_500 - id: fhir name: HL7 FHIR declared: false evidence: 'No FHIR base URL, CapabilityStatement or /metadata endpoint was found on any QT Medical host; the term does not appear anywhere on the public site.' source: https://www.qtmedical.com/en - id: hl7-aecg name: HL7 annotated ECG (aECG) / SCP-ECG / DICOM Waveform declared: false evidence: 'No waveform-interchange format is named in any public QT Medical material; ECGs are offered to third parties as PDF.' source: https://qtmedical.com/en-gb/PCA_500