Our Specialty
What Do We Offer?
Software now sits at the heart of modern healthcare, and that raises real questions about how privacy and security are protected. Strong security and privacy controls are essential to keep personal (health) information confidential and patients safe. But because both fields are horizontal, cutting across many laws rather than being centralised within medical device regulation, it is often difficult to identify which regulations, standards, and guidance documents actually apply to a given organisation or product.
The picture differs not only between the European Union and the United States, but from one (member) state to another. Compliance is rarely straightforward and calls for expert understanding of how the legislative approaches diverge. Privacy, for example, is governed in the EU by the GDPR 2016/679 and in the US by HIPAA/HITECH, while medical devices are regulated in the EU under the MDR 2017/745 and IVDR 2017/746.
Crucially, complying with privacy law and medical device regulation does not automatically mean you comply with cybersecurity legislation. In the EU, cybersecurity obligations increasingly come from horizontal frameworks such as the Cyber Resilience Act and the NIS2 Directive, and from national rules that vary by country: Spain has implemented Royal Decree 311/2022 (the National Security Framework), the Netherlands applies NEN 7510-1 for information security management in healthcare, and France requires HDS certification for hosting health data.
In the US, cybersecurity is increasingly holding up FDA product registrations, and the requirements keep growing. Manufacturers are now expected to perform threat modelling (using a data flow diagram to define security requirements and mitigations), evaluate threats with STRIDE and score them with CVSS, maintain and review a Software Bill of Materials (SBOM), and carry out verification and validation testing — including a penetration test to demonstrate the product is secure. Comparable expectations apply in the EU through the IEC 81001-5-1 standard, which is used to demonstrate a securely developed health software product.
MedQAIR helps manufacturers navigate this landscape end to end — from privacy and data protection assessments (DPIAs) and data processing agreements, through threat modelling, secure development, and IEC 81001-5-1 implementation, to FDA cybersecurity documentation, vulnerability management, and full cybersecurity lifecycle planning.