QAreMed
MenuClose

Which standards apply to healthcare software, and where?

Eighteen standards, grouped by the market each one binds in. Every page carries the clause numbers a tester works to, the artefacts an auditor asks for, and a link to the primary source with the date it was last read. A standard binding in several markets appears under each of them.

Which standards apply where you are shipping?

United States

  • 21 CFR Part 11What 21 CFR Part 11 asks of a computerised system, which requirements FDA said in 2003 it would not enforce, and what validation testing has to demonstrate.
  • FDA CSAWhat FDA's computer software assurance guidance recommends, which software it covers, how the testing methods nest, and the record an investigator asks for.
  • FHIR R4Why "we support FHIR" names no testable obligation, which parts of R4 version 4.0.1 are stable enough to build on, and what a conformance test measures.
  • HIPAA Security RuleWhat the HIPAA Security Rule asks of software, which technical safeguards a test can exercise, and which records an OCR investigator asks to see.
  • HITRUSTWhat HITRUST certification is, which of the e1, i1 and r2 assessments applies, what it commits you to every year, and where HITRUST's own documents disagree about HIPAA.
  • HL7 v2Why an HL7 v2 message can conform to the standard and still be rejected at the receiving site, which optionality and usage codes decide it, and what a conformance test measures.
  • ICD-10Which of the three ICD-10 code sets your software stores, the construction rules a validator has to encode, and what the 1 October changeover does to stored diagnosis data.
  • IEC 62304What IEC 62304 asks for from software testing, how the safety class changes the scope, and which records an auditor asks to see.
  • IEC 62366-1What IEC 62366-1 Edition 1.1 asks of usability validation, which records land in the usability engineering file, and why FDA recognises only the consolidated edition.
  • IEC 82304-1Which clauses IEC 82304-1 adds on top of IEC 62304, what its validation and accompanying document clauses are called, and why ISO/TS 82304-2 is a different document.
  • ISO 13485Where ISO 13485 requires software to be validated, which clauses reach software under the FDA QMSR, and what an auditor asks to see for each one.
  • ISO 14971Which ISO 14971 clauses testing produces evidence for, why verifying that a risk control works is separate from verifying it exists, and what an auditor opens in the risk management file.
  • ONC Health IT Certification ProgramWhat the ONC Health IT Certification Program tests against 45 CFR 170.315, which obligations recur annually after certification, and what is under enforcement discretion.
  • WCAG 2.1 Level AAWhich US rule actually makes WCAG 2.1 Level AA binding, what a Level AA claim covers, and why Success Criterion 4.1.1 Parsing is still required after W3C retired it.

European Union

  • EU AI ActWhich medical AI the EU AI Act treats as high risk, what Articles 9 to 17 ask testing to produce, and why the Annex I date is now 2 August 2028.
  • EU MDRHow Annex VIII Rule 11 classifies software under the EU MDR, which Annex I requirements bind it, and what Annex II asks for as software test evidence.
  • IEC 62304What IEC 62304 asks for from software testing, how the safety class changes the scope, and which records an auditor asks to see.
  • IEC 82304-1Which clauses IEC 82304-1 adds on top of IEC 62304, what its validation and accompanying document clauses are called, and why ISO/TS 82304-2 is a different document.
  • ISO 13485Where ISO 13485 requires software to be validated, which clauses reach software under the FDA QMSR, and what an auditor asks to see for each one.
  • ISO 14971Which ISO 14971 clauses testing produces evidence for, why verifying that a risk control works is separate from verifying it exists, and what an auditor opens in the risk management file.
  • IVDRHow Regulation (EU) 2017/746 classifies software without an MDR-style software rule, what Annex XIII asks you to prove about performance, and which records an assessor opens first.

International

  • DICOMWhat DICOM PS3.2 requires of a Conformance Statement, why two conforming systems can still fail to interoperate, and which checks a test plan can build from the Standard.
  • FHIR R4Why "we support FHIR" names no testable obligation, which parts of R4 version 4.0.1 are stable enough to build on, and what a conformance test measures.
  • HITRUSTWhat HITRUST certification is, which of the e1, i1 and r2 assessments applies, what it commits you to every year, and where HITRUST's own documents disagree about HIPAA.
  • HL7 v2Why an HL7 v2 message can conform to the standard and still be rejected at the receiving site, which optionality and usage codes decide it, and what a conformance test measures.
  • ICD-10Which of the three ICD-10 code sets your software stores, the construction rules a validator has to encode, and what the 1 October changeover does to stored diagnosis data.
  • IEC 62304What IEC 62304 asks for from software testing, how the safety class changes the scope, and which records an auditor asks to see.
  • IEC 62366-1What IEC 62366-1 Edition 1.1 asks of usability validation, which records land in the usability engineering file, and why FDA recognises only the consolidated edition.
  • IEC 82304-1Which clauses IEC 82304-1 adds on top of IEC 62304, what its validation and accompanying document clauses are called, and why ISO/TS 82304-2 is a different document.
  • ISO 13485Where ISO 13485 requires software to be validated, which clauses reach software under the FDA QMSR, and what an auditor asks to see for each one.
  • ISO 14971Which ISO 14971 clauses testing produces evidence for, why verifying that a risk control works is separate from verifying it exists, and what an auditor opens in the risk management file.
  • WCAG 2.1 Level AAWhich US rule actually makes WCAG 2.1 Level AA binding, what a Level AA claim covers, and why Success Criterion 4.1.1 Parsing is still required after W3C retired it.

What does validating your product actually involve?

Answer four questions about your markets, your product type and its integrations. You get the standards that reach you, the artefacts each one asks you to produce, and which of them a test supplier delivers.