Hello @Ming Cheung ,
Thank you for your update.
So are the healthcare IoT devices in the domain or not?
Are the healthcare IoT device with Windows OS or not?
If both are not, please consider the sub role "Network Device Enrollment Service (NDES)" in AD CS.
For more information, we can refer to link below.
Active Directory Certificate Services (AD CS): Network Device Enrollment Service (NDES)
https://social.technet.microsoft.com/wiki/contents/articles/9063.active-directory-certificate-services-ad-cs-network-device-enrollment-service-ndes.aspx
Hope the information above is helpful.
Should you have any question or concern, please feel free to let us know.
Best Regards,
Daisy Zhou
============================================
If the Answer is helpful, please click "Accept Answer" and upvote it.