Skip to content
    Sector · Healthcare

    Healthcare & medical devices

    Medical-device regulation and health-data privacy, grounded article by article.

    Ansvar is a gateway for the AI assistant your team already uses — Claude, Microsoft Copilot, any MCP client. Connect it, and every answer below comes back cited to the provision or marked unresolved.

    MDR · IVDRarticle-level + annexes
    Art. 9special-category health data
    FDA · CMSUS federal health regulation

    MDR, IVDR, the Clinical Trials Regulation and the European Health Data Space are served at article level, alongside GDPR Article 9 for special-category health data and the horizontal cyber regimes. Beyond the EU, US federal health regulation from the FDA and CMS comes verbatim from the eCFR, and device regulation for seven more jurisdictions — Great Britain, Canada, Switzerland, South Korea, Japan, Australia and Colombia — is attributed per provision. The device software, safety-risk and security standards are a clause map on top. Ask the provision; then run the DPIA, gap analysis or device threat model that turns it into evidence.

    what we cover

    The law and standards we ground on

    Regulation

    Medical Device Regulation (Reg (EU) 2017/745)

    article-level, incl. annexes

    Regulation

    In Vitro Diagnostic Regulation (Reg (EU) 2017/746)

    Regulation

    Clinical Trials Regulation (Reg (EU) 536/2014)

    Regulation

    European Health Data Space (Reg (EU) 2025/327)

    Regulation

    GDPR Art. 9 — special-category health data (+ full GDPR)

    Regulation

    US federal health regulation — FDA (21 CFR) and CMS (42 CFR)

    served verbatim from the eCFR

    Regulation

    National medical-device regulation outside the EU — GB, CA, CH, KR, JP, AU, CO

    device-regulation text attributed per provision to the jurisdiction that issued it

    Standard

    Control mapping: medical-device software, safety and security standards

    97 clauses across IEC 62304, IEC 81001-5-1, ANSI/AAMI SW96 and AAMI TIR57, ISO 14971, IEC 60601-1 (incl. clause 14 PEMS), IEC 82304-1 and the surgical- and rehabilitation-robot parts IEC 80601-2-77/-78 — clause map + Ansvar cross-refs, not the standard text

    Regulation

    Horizontal: NIS2 · EU AI Act (software as a medical device) · CRA

    GuidancePremium

    MDCG medical-device guidance

    GuidancePremium

    US FDA guidance documents

    48 final guidances on medical-device, drug and biologics regulation, served verbatim

    GuidancePremium

    Dutch statutory disciplinary-tribunal rulings

    48,205 full-text decisions from 2001 onward — the regional healthcare colleges and the Centraal Tuchtcollege alongside the advocatuur, notariaat, accountancy, veterinary and maritime tribunals

    what you can do

    Workflows that turn it into evidence

    DPIA for special-category health data

    GDPR Art. 35 + Art. 9, with Germany and Sweden variants

    Regulatory gap analysis

    against MDR / IVDR / GDPR / NIS2, with a dedicated NIS2 variant

    Medical-device product-security threat model

    STRIDE over a device data-flow diagram — not a device-conformity verdict

    LINDDUN privacy threat model

    for clinical and patient-data flows

    FRIA — EU AI Act Art. 27

    for AI-based devices and high-risk software-as-a-medical-device AI

    Document review, paragraph-cited

    technical documentation, clinical SOPs and QMS documents

    assembledPremium

    Device software & security standards research as cited answers

    the IEC 62304 / 81001-5-1 / ISO 14971 clause map and the FDA guidance layer, every answer cited to its source

    STRIDE threat-model workflows run on every plan against a system you describe — 1 run a month on Free, 2 on Solo, 5 on Premium, which also adds the LINDDUN and TARA families, the rendered reports, and case law inside the run. Document-grounded workflows run on Team and Company. Every tier runs the same corpora as cited research inside your own AI client.

    Questions buyers ask first

    Does this certify a device as conforming?
    No. The workflows produce a cited gap analysis and a STRIDE threat model against MDR/IVDR and the security obligations — decision-support, not a conformity verdict or a notified-body assessment.
    Is national health law covered?
    The EU regulations (MDR, IVDR, CTR, EHDS) and GDPR are covered at article level. Beyond the EU, US federal health regulation from the FDA (21 CFR) and CMS (42 CFR) is served verbatim, with the FDA final guidances on Premium and above, and dedicated device-regulation text covers Great Britain, Canada, Switzerland, South Korea, Japan, Australia and Colombia. National health statutes are also reachable inside the audited national-law corpora.

    Run it against your own systems

    Connect the AI client you already use and ask your first cited question — Free, Solo, Premium and Team are self-serve.

    Building healthcare compliance? It works today — we take on a few design partners per sector to tune it to your team.