Humanize Health

REGULATORY

Our regulatory foundations

The standards, regulations, and frameworks the advisory work is built on — each summarised in plain language: what it covers, and why it matters for software that reaches patients.

ISO 13485Medical Device Quality Management

The internationally recognized standard for quality management systems in the medical device industry. It defines how a company designs, develops, manufactures, and maintains medical devices in a controlled, documented, and auditable way — covering everything from design controls to corrective actions.

ISO 13485 in detail →

ISO 14971Risk Management for Medical Devices

The standard that governs how medical device manufacturers identify, evaluate, and control risks throughout a product's life — from initial design through post-market use. It ensures that every known hazard has been assessed and that residual risks are acceptable relative to the product's benefits.

ISO 14971 in detail →

IEC 62304Medical Device Software Lifecycle

A software-specific standard that defines the processes required to safely develop and maintain medical device software — including planning, requirements, architecture, testing, and ongoing maintenance. It also governs how third-party and open-source software components are managed within a regulated product.

IEC 62304 in detail →

IEC 81001-5-1Health Software Cybersecurity

A newer standard focused specifically on integrating cybersecurity into the software development lifecycle for health software. It addresses how security risks are identified and mitigated alongside safety risks, reflecting the growing importance of protecting connected health technologies.

IEC 81001-5-1 in detail →

IEC 62366-1Usability Engineering

The standard governing how medical devices and software are designed to be safe and effective for their intended users. It requires structured evaluation of how real users interact with a product, to minimize the risk of use errors that could affect patient safety.

IEC 62366-1 in detail →

ISO 27001Information Security Management

A globally recognized standard for information security management systems (ISMS). It provides a framework for protecting sensitive data — including how organizations assess security risks, implement controls, and continuously improve their security posture.

ISO 27001 in detail →

GDPREU Data Protection

The European Union's comprehensive data protection law. It governs how personal data — including health data — is collected, processed, stored, and shared, and grants individuals specific rights over their own data.

GDPR in detail →

HIPAAUS Health Data Privacy

US federal legislation that sets standards for protecting sensitive patient health information. It governs how healthcare-related data is handled by covered entities and their business associates in the United States.

HIPAA in detail →

EU MDREU Medical Device Regulation

The regulatory framework governing the safety, performance, and market approval of medical devices sold in the European Union, including software-based devices (SaMD). It defines classification rules, clinical evidence requirements, and conformity assessment procedures.

EU MDR in detail →

IMDRF SaMD Framework

Guidance developed by the International Medical Device Regulators Forum specifically for Software as a Medical Device (SaMD). It provides a shared international framework for classifying SaMD risk and defining the clinical evidence expected to support its safety and effectiveness.

IMDRF SaMD Framework in detail →

Working out which of these apply to what you are building is usually the first conversation.

Get in touch →