Use Instructions

Page |
48
15. DATA SECURITY AND PATIENT PRIVACY
All communication between the CTE implant and the Base Station units employs a unique
communication protocol, with each CTE having a unique radio that is assigned to it in
manufacturing. Base stations can communicate with only one CTE at a time using this radio ID.
NOTE: A patient could potentially have two CTE implants (one in each knee) but would only need
one Base Station in that scenario.
The communication between base stations and CTE is also encrypted (both the data payload and
messaging) with the unique encryption key assignment during the manufacture of the CTE. In
addition, communication integrity as well as data integrity checks are applied on the data
received at both ends.
The Canary Medical Cloud Platform is designed for assuring HIPAA-compliance. When a Home
Base Station is set up by the patient, a secure connection is established between the Base Station
and the Canary Cloud and is in effect for all communication thereafter. The Home Base Station
unit decrypts messages and data from the implant, adds the serial number of the CTE, packages
and encrypts the unprocessed data before transmitting the encrypted unprocessed data to the
Cloud using standard TLS (Transport Layer Security) protocol. The communication and data are
checked for integrity by the Cloud application before it is processed to output the CMGP.
Patients who wish to receive the CTE with CHIRP System must consent to the CTE implant data
collection, storage, analysis, and sharing of their implant and basic personal and health data with
HCP(s) they designate to provide their healthcare. As such, data will be identifiable to their
healthcare providers and authorized administrators of the Canary Medical CTE with CHIRP
System. The patient will have the right to be forgotten and will have the ability to turn off the
kinematic data collection of the device after a minimum required time for data generation. If
the patient does not wish to consent, they can receive a standard of care, non-reporting tibial
extension.
Each HCP and patient user are assigned a unique username and will be prompted to enter a
password at initial login. The unique username and password is needed for logging into their
account thereafter and accessing the physician and patient dashboards, respectively.
16. COMPONENT MAINTENANCE
16.1. CTE
The CTE is an implant that remains in the body indefinitely and therefore cannot be maintained.
Physician Instructions for Use
DRAFT