Healthcare / Hospital Intranet · Remote O&M for Medical Device Workstations (Data Stays On-Premise)
For equipment-vendor remote-assistance scenarios inside the hospital intranet, a non-intrusive gateway deployed on the intranet lets device vendors troubleshoot medical-device workstations remotely — without leaving the hospital and without touching the public network.
Core solution for this scenario

I. Industry Pain Points
Typical challenges for Healthcare / Hospital Intranet / Medical Devices in equipment O&M and data acquisition.
- Failures of medical devices (imaging workstations, lab instruments, therapy consoles) often need the OEM engineer's remote assistance, but connecting the device directly to the public network carries patient-data-leak and compliance risk.
- Under the Data Security Law, the Personal Information Protection Law and industry requirements, medical data is strictly forbidden from leaving the hospital boundary, so traditional public-cloud remote tools are unusable.
- In-hospital clinical engineers are limited; device issues at night or on holidays cannot be responded to in time, affecting diagnostic continuity and downtime.
- Multi-campus, multi-brand device workstations have varied interfaces and lack a unified, compliant remote-assistance entry point.
II. Solution
Build a "screen layer + protocol layer" dual-source data closed loop with the AIXOT non-intrusive gateway combination.
- APM-G220 Non-intrusive Smart Tuning Gateway is deployed on the hospital intranet, physically taking over the medical-device workstation's video and USB keyboard / mouse; the controlled side needs zero installation and zero networking, and the OEM engineer assists remotely inside the intranet boundary after approval.
- Data stays on-premise: the remote link is confined to the hospital intranet / private network, and screen content is never transmitted over the public network, satisfying medical-data localisation requirements.
- Vendor remote operations are standardised through keyboard / mouse scripts, with OCR verifying on-screen feedback, and the whole session is screen-recorded for the hospital's audit and accountability.
- Device workstations across campuses are unified under one management plane, forming a compliant, hospital-wide remote-assistance channel that replaces scattered public-network remote tools.
III. Deployment Steps
An executable path from interface inventory to a standardised closed loop.
- Map the video / USB interfaces and network zones of in-hospital device workstations; plan G220 intranet deployment points
- Record the vendor's high-frequency assistance actions (log export, parameter review, software configuration) as standard scripts
- Configure intranet / private-network backhaul and an approval gateway; vendor remote access requires hospital work-order approval
- Establish a “data stays on-premise” remote-assistance SOP: request → approval → intranet access → script execution → recording archived
- Unify management and a permission matrix for multi-campus devices, and audit remote sessions periodically
IV. System Integration & Data Connectivity
Standardised connection points with MES / SCADA / PLC / quality systems.
- Connect to the hospital O&M approval / work-order system: vendor access requires hospital approval
- Connect to the device-asset system: device–gateway topology synced for quick locating
- Connect to intranet security audit: remote recordings and operation logs retained for compliance
- Connect to the vendor service desk: only the intranet channel is opened, eliminating public-network exposure
V. Value & Quantified Metrics
Measurable benefits from the non-intrusive solution.
VI. Deployment Boundaries & Compliance Red Lines
Compliance & applicable boundaries
Medical data is strictly forbidden from leaving the hospital boundary; 4G must not connect to a public cloud, and the remote link must be confined to the intranet / private network. The G220 applies only to device workstations with video output and USB input; pure embedded devices without a display need separate evaluation.
VII. FAQ
High-frequency questions for the Healthcare / Hospital Intranet / Medical Devices scenario.
Can the device vendor connect directly over the public network?
No, and it is not allowed. The G220 confines remote assistance within the hospital intranet / private-network boundary; screen data never traverses the public network, satisfying the “data stays on-premise” requirement.
Does the controlled medical device need a client installed?
No. The G220 takes over video and keyboard / mouse non-intrusively; the controlled device needs zero installation and zero networking.
How is compliance auditing ensured?
Every vendor remote-assistance session is fully screen-recorded; actions and on-screen changes are retained and can be replayed for audit, meeting medical-data compliance requirements.
How are multiple campuses managed uniformly?
Multiple G220 units are managed through the private platform, forming a cross-campus unified view and permission matrix — suited to group hospitals.