QAreMed
MenuClose

Situation

What does QA readiness mean before a Series A?

Sort the list by what fixes each answer. A HITRUST i1 certification takes six to twelve months on HITRUST's own published figure, and only an approved External Assessor may run the assessment behind it, so it cannot arrive before a close. A written software safety class rationale, a requirements trace and a dated safeguard test can.

What has happened
A term sheet is signed or a lead investor's diligence request has arrived, the round has a date on it, and somebody now has to put a written answer against every regulatory line on the list.
If nothing changes
An unanswered line does not stay neutral. It becomes a closing condition, a holdback or a finding, and the lines you cannot answer in the weeks available are the ones whose answer was settled by a date that has already passed.

Why is a testing question suddenly a financing question?

Because the answers on a diligence list carry dates, and the round carries a date, and only one of those two can be moved. A funding process compresses almost everything it touches. It does not compress an obligation that attached on a day in the past, and it does not compress a report that a body outside your company is the only party permitted to issue.

The useful first move is a sorting exercise, not a remediation plan. Read every regulatory line on the request and put each one in one of three places. Some were settled by a date that has already gone by, and the only honest work left on them is to describe them accurately. Some belong to somebody else's queue, and the queue has a published length. The remainder is prose that a person inside the company can still write this month, dated honestly, and those are the lines your weeks are actually for.

That sort takes an afternoon and it changes where the money and the attention go. Done in the other order, the weeks are spent on the item that was never going to land, and nothing gets filed against the items that would have.

What happens to a line you leave open until the close?

It gets answered by whatever document does exist, and that document may say something you did not intend it to say. Two shapes are worth naming.

The first is a certificate offered where a record was asked for. HITRUST prints the limit inside its own HIPAA Compliance Insights report: the assurance limitations carry the words "not a certification of HIPAA Compliance", and the transmittal letter hands the risk analysis required at 164.308(a)(1)(ii)(a) back to the assessed organisation's own management. The same report is scoped to "a defined boundary" of named facilities and platforms, and it instructs anyone relying on it to weigh that scope against the organisation's HIPAA obligations. Every one of those statements travels with the document you file. What each assessment type covers, and which parts of HIPAA the framework leaves out by design, is set out at HITRUST testing requirements.

The second is a quality manual that still answers to a regulation under its former name. Since 2 February 2026 part 820 of 21 CFR has answered to a new title, the Quality Management System Regulation, and its section 820.7(b) now brings ISO 13485:2016(E) in by reference. The rule behind that, 89 FR 7496, reached the Federal Register two years earlier on 2 February 2024, and a technical amendments rule at 90 FR 55978 of 4 December 2025 carried the renaming through 179 sections across 18 parts of Title 21 on the same effective day. That day passed seven months before this page. A procedure written against the superseded text answers a question nobody is asking now.

Which answers were settled before the round started?

Three, and each of them is already written down in a document you hold.

The first is the twelve-month look-back sitting behind the HIPAA safe harbour. HITRUST's April 2023 paper "HITRUST and HIPAA" sets out the mechanism: HITECH, as amended on 5 January 2021 by H.R. 7898, is satisfied by recognized security practices that were already running through the year preceding the demonstration, which the paper renders as no fewer than the previous twelve months. Count backwards from your close date. A practice adopted during the round sits inside a window that opened a year before it, and the start of that window does not move.

The second is the order of two dates already in your customer file. 45 CFR 164.502(e)(1)(i) requires the satisfactory assurance to be obtained before a covered entity discloses protected health information to a business associate. The written contract is then a required implementation specification of the Security Rule, under 45 CFR 164.308(b)(3). The day the agreement was signed and the day the first record arrived are both recorded somewhere. Neither has to be reconstructed, and their order cannot be edited.

The third is the shelf life of an assurance report you already hold. The HITRUST Assessment Handbook gives an e1 or i1 report a 12 month life and an r2 report a 24 month life, each counted from the report's own date, and then pins that date: it is the day the Management Representation Letter is dated. A certificate's remaining life was fixed at a signature and can be read off this afternoon. Where that life ends inside the investment period under discussion, saying so first costs less than being asked.

Which lines on the list are not gaps at all?

The ones whose obligation has a start date in the future. Pricing those as present deficiencies buys engineering months against a finding that was never valid, and the months come out of the same quarter as the round.

Article 113 of Regulation (EU) 2024/1689 carries the application dates for the EU AI Act, and the text consolidated on 27 July 2026 gives two that reach a medical product. A system that is high risk through Article 6(2) and Annex III comes under Sections 1, 2 and 3 of Chapter III on 2 December 2027. A system that is high risk through Article 6(1) and Annex I, the route a regulated device takes, comes under them on 2 August 2028. Regulation (EU) 2026/1744 of 8 July 2026 pushed that second date out by twelve months from the 2 August 2027 it replaced, and the recital behind it blames standards and guidance that were not ready in time together with national authorities that had not yet been set up. A memo drafted before that July quotes a deadline the Union has since replaced. Which obligations of the Act are live now, and which wait for those two dates, is worked through at EU AI Act validation for medical software.

Certification criteria carry the same shape. 45 CFR 170.315(b)(3)(ii)(A) allows either of two electronic prescribing standards up to and including 31 December 2027, then from 1 January 2028 requires only the one adopted at 45 CFR 170.205(b)(2). A dated cutover with an owner and a release behind it is a roadmap line. It is not a defect in the product as it stands.

Two questions therefore go back to whoever raised the finding: which provision does this come from, and from what date does that provision apply? Both are answerable from the text in an afternoon, and an item that survives both questions is a real one.

What can you actually produce in the weeks you have?

Documents whose only inputs are a decision, a name and today's date. Each item below is prose that someone inside the company is already qualified to write, and each closes a line on the list without waiting for an outside party.

Six things a month can produce

  1. Write the software safety class for each software system, with the reasoning beside it. Under clause 4.3 of IEC 62304 the class follows from the worst case harm the system can contribute to, weighed once any controls outside the software itself are taken into account.
  2. Name the controls that argument rests on. The same clause lets a system that first came out as class B or C take a new classification once further controls outside it are in place.
  3. Build the requirements trace. Every requirement gets a test, or a written reason why some other means verifies it.
  4. List the systems that create, receive, hold or transmit electronic protected health information. This list is the scope statement every later document inherits.
  5. Record each technical safeguard that was exercised. Name the build, the date of the run and the result.
  6. Write down which edition of each standard the document set answers to.

Step 2 gets read as a paperwork move and is not one. A new classification under clause 4.3 arrives after the further controls have been implemented, and revising the architecture the software system sits inside counts as one way to implement them. Where those controls already exist and were simply never written down, the argument can be recorded this month. Where they do not exist, writing the argument anyway produces a claim the first reviewer will go looking for.

Steps 3 and 6 shrink everything that comes after them, and they produce the two documents a later reader asks for by name. What each one has to contain, and the form a reviewer accepts, is set out at the validation documentation an auditor reads. Where nobody has yet counted how many software items carry a class of B or C, you can estimate the validation scope from the same decision points, in a page that computes in your browser and sends nothing anywhere.

How long does each item take, and who holds the clock?

The assurance items carry published durations, and the figures in the table below are the issuer's own. Each row names who controls the date, which is the part a founder cannot change by adding people.

Who controls the date for HITRUST e1, i1 and r2 assessments and 45 CFR 170.315(g)(3) testing, and what the issuer publishes for each.
The itemWho controls the dateWhat the issuer publishes
HITRUST e1An approved External Assessor4 to 6 weeks where readiness allows, in the benefits section; about 30 days on average, in the FAQ of the same page
HITRUST i1An approved External AssessorThe i1 page puts usual completion at somewhere between 6 and 12 months
HITRUST r2An approved External AssessorNo duration is published on any HITRUST page
Assessor fieldwork, any typeThe assessor, inside a HITRUST capA maximum window of 90 days, the same for e1, i1 and r2
Safety-enhanced design testing under 45 CFR 170.315(g)(3)Participant recruitmentA minimum of 10 test participants for each capability tested
The documents in the step list aboveYouWhatever your own week allows

Every row above except the last has its date set outside the company, and the assurance rows are closed to all but one kind of firm: HITRUST states that its approved External Assessors "are the only entities authorized to perform the validated assessments that are submitted to HITRUST for certification", and that a Readiness Licensee is not authorised to perform them at all.

The readiness route is open at any time, and it produces a document with a defined status. HITRUST states that a self-assessment generates a Readiness Assessment Report which "cannot be certified", that it performs no quality assurance review of readiness results, and that such reports "will have a lower level of reliability". As a plan with a date against each gap, that document does useful work in a data room. As evidence that a control operates, it will be read exactly as it describes itself.

Where does a round-week answer go wrong?

  • A certificate is filed where a record was requested, and the certificate states inside itself that it is not that record.
  • A finding is accepted and budgeted against a provision whose application date has not arrived.
  • The quality manual answers to 21 CFR part 820 as it read before 2 February 2026, though section 820.7(b) now carries ISO 13485:2016(E) by reference.
  • A data room claims presumption of conformity through EN 62304, which the MDR list does not support. The harmonised standards are listed by Commission Implementing Decision (EU) 2021/1182, whose Annex in the version consolidated on 7 April 2026 numbers 51 entries, and EN 62304 is in none of them.
  • The class is filed as a letter on its own, and the controls outside the software that made the leftover risk tolerable appear nowhere, though clause 4.3 turns on exactly those controls.
  • Nobody checks the remaining life of an existing certification against the investment period, though the handbook fixes that life at 12 or 24 months counted from a letter somebody already signed.
  • The assessment boundary in an assurance report excludes a system that holds electronic protected health information, and nobody read the scope section before filing it.
  • Work is committed on the strength of a diligence memo without anyone asking which provision each finding comes from.

What can a testing supplier do inside a round?

Produce evidence carrying an honest date, and say plainly which lines that evidence does not reach. No certificate in the table above is one a testing firm can issue: HITRUST holds the validated assessment to the organisations it has approved and issues the certificate itself, and this company is not among them. We test against the requirements in these standards and prepare the artefacts an auditor asks for. Compliance itself is held by the organisation that ships the product.

Inside a round, a short engagement adds the material sitting behind the answers you write. A requirements trace, safeguard results against a named build, a class rationale and a scope statement are all made by exercising the product and writing down what happened, so each of them can carry this month's date truthfully. How that work is staffed alongside a team that is also shipping is set out at outsourcing healthcare QA.

None of that work reaches your production records. We do not need production PHI to test. Environments run on synthetic and de-identified data. That holds for a four-week engagement as firmly as for a year-long one. We sign a Business Associate Agreement before any engagement that touches PHI. Where project data lives and what happens to access when an engagement ends are questions a diligence list puts to your suppliers as well as to you, and how we work with protected health information answers both.

Both neighbouring situations run on clocks of their own, which is why they are separate pages. Where the request is missing an answer because the company has never had a QA function at all, the question stops being what to fix before the close and becomes what to build first and in what order, which is worked through at building QA in a digital health startup. And how a diligence team reads whatever record it is handed, in what sequence and with what weight given to a gap, is a separate matter from which answers your calendar permits: technical due diligence on a healthtech product covers the read itself, for any diligence event and not only a funding round.

Everything credited to HITRUST above came from four documents collected for this site on 2 September 2026: its Assessment Handbook, its e1 and i1 product pages, its HIPAA Compliance Insights sample report, and its April 2023 paper "HITRUST and HIPAA". Title 45 section numbers were read in the eCFR snapshot dated 31 August 2026. The Federal Register citations sit in the collected record for ISO 13485, the application dates in Regulation (EU) 2024/1689 as consolidated on 27 July 2026, and the clause numbers in the Edition 1.1 consolidated text of IEC 62304. Where a statement describes what a statute requires but was read in a private publisher's paper rather than in the statute, the sentence says so.

What do buyers ask about this?

Can we be HITRUST certified before the round closes?
Only the shortest of the three is even arguable. HITRUST puts usual i1 completion between 6 and 12 months and publishes no duration for the r2 anywhere, so neither of those reaches a close set for next month. The e1 is quoted at 4 to 6 weeks in one part of its product page and at about 30 days on average in another. All three run through an approved External Assessor, and that queue is not yours to compress.
Does a HITRUST certificate answer the HIPAA line on the list?
Not by itself, and HITRUST says as much in the report. Its HIPAA Compliance Insights sample report describes itself in the assurance limitations as "not a certification of HIPAA Compliance", and the transmittal letter states that management "is responsible for performing and maintaining a risk analysis which adheres to Sec. 164.308(a)(1)(ii)(a) of the HIPAA Security Rule". That analysis stays a separate document carrying its own date.
Our diligence memo says we are late on the EU AI Act. Are we?
Check which date the memo used. Article 113 of Regulation (EU) 2024/1689, as consolidated on 27 July 2026, brings Sections 1, 2 and 3 of Chapter III into application on 2 December 2027 for Annex III high-risk systems and on 2 August 2028 for Annex I systems, which is the medical device route. Regulation (EU) 2026/1744 of 8 July 2026 moved the Annex I date on from 2 August 2027, so a memo written before that day quotes a superseded deadline.
We have four weeks. What is worth starting?
The items that are prose plus a named decision owner. A written software safety class assignment with its reasoning, a requirements trace, a statement of which systems hold electronic protected health information, and a dated record of which technical safeguards were exercised on which build. Each of those can carry an honest date from this month. None of them needs a third party's queue.
Does a readiness assessment count for anything in a data room?
It answers a planning question and not an assurance one. HITRUST states that a self-assessment generates a Readiness Assessment Report which "cannot be certified", that it performs no quality assurance review of readiness results, and that readiness reports "will have a lower level of reliability". Filed as a plan with dates against each gap it is useful. Filed as evidence of a control it will be read as what it says it is.

Which product types does this apply to?

What does validating your product actually involve?

Answer four questions about your markets, your product type and its integrations. You get the standards that reach you, the artefacts each one asks you to produce, and which of them a test supplier delivers.