Health & life sciences

Medical devices & diagnostics. Software is a medical device too.

Every claim, update and screen has to match what was approved.

Device, diagnostics and imaging makers, connected-device and software-as-a-medical-device companies, where every claim must match the licence and every update can change the risk. We design clinician and patient interfaces, regulated product sites and the documentation, data and AI governance that keep a device approvable in India, the EU and the US.

The number we move
Time from design change to approved release
Where we work in medical devices & diagnostics
  • Diagnostics & imaging
  • Connected & wearable devices
  • Surgical & hospital equipment
  • Software as a medical device
  • In-vitro diagnostics
  • Consumables & implants
Rules mapped
8 rules · 5 areas
Disciplines that lead
TechnologyProduct
Frameworks we build to
ISO/IEC 27001:2022 — Information security management systemsDPDP Act 2023 — Digital Personal Data Protection Act, 2023EU AI Act — Artificial Intelligence Act (EU) 2024/1689NIST AI RMF 1.0 — AI Risk Management FrameworkOWASP Top 10 for LLM Applications — LLM and generative AI security risksHIPAA Security Rule — Safeguards for electronic protected health information
A surgeon in a cap, glasses and mask works under a single bright light in a dark operating room
Medical devices & diagnosticsEvery device ends up in a clinician’s hands.

Where the rules biteMap of all forty-one industries

  • Claims Advertising & claims: Shapes most of the work
  • Regulator Sector regulator: Shapes most of the work
  • Payments Payments: Sometimes shapes the work
  • Data Personal data: Shapes most of the work
  • Security Security & incidents: Shapes most of the work
  • Access Accessibility: Often shapes the work
  • AI AI governance: Shapes most of the work

What is shifting

Every device is licensed now, and software answers to the same rules.

India finished bringing all devices under licence, its regulator drafted guidance for device software, and AI in devices gained dated duties in the EU. Each shift names what it demands, with a fact you can check.

A chest X-ray showing the ribs, the lungs and the outline of the heart
Software now reads the image first; a clinician still decides.
  1. Every medical device in India now needs a licence.

    It demandsLabels, instructions, product sites and promotion that match the licensed intended use exactly.

    SignalUnder the Medical Devices Rules, 2017, class A and B devices came under licensing from 1 October 2022, and class C and D devices from 1 October 2023.

  2. Software became a device in its own right.

    It demandsRisk classification, design controls and change plans for software from the first sprint.

    SignalCDSCO published draft guidance on medical device software on 21 October 2025, covering software that is a device and software within one.

  3. AI inside devices got a dated rulebook in the EU.

    It demandsDocumentation, data governance and human oversight for AI features, planned before market entry.

    SignalThe EU’s 2026 Digital Omnibus set 2 August 2028 for AI Act high-risk duties on AI that is part of products such as medical devices.

  4. Device promotion now runs to its own code.

    It demandsClaims, events and samples designed to the code, with a complaints route published.

    SignalThe Department of Pharmaceuticals introduced the Uniform Code for Marketing Practices in Medical Devices on 6 September 2024.

The rulebook

Licensed, labelled and promoted only as approved.

India’s Medical Devices Rules and marketing code, the EU device and AI rules and US guidance on AI-enabled software, read for a typical programme. Your regulatory and quality teams keep sign-off.

Frameworks we build to

  • ISO/IEC 27001:2022 — Information security management systems
  • DPDP Act 2023 — Digital Personal Data Protection Act, 2023
  • EU AI Act — Artificial Intelligence Act (EU) 2024/1689
  • NIST AI RMF 1.0 — AI Risk Management Framework
  • OWASP Top 10 for LLM Applications — LLM and generative AI security risks
  • HIPAA Security Rule — Safeguards for electronic protected health information

Frameworks we design and build to — not a claim of certification.

Advertising & claims

Shapes most of the work

  1. Department of Pharmaceuticals

    Uniform Code for Marketing Practices in Medical Devices, 2024

    No promotion before approval, and claims must match the approved product information; gifts and hospitality for healthcare professionals are barred.

    We designEvery page, brochure and talk draws on a claims library mapped to the licensed intended use.

    Department of Pharmaceuticals · UCMPMD, introduced 6 September 2024

Sector regulator

Shapes most of the work

  1. CDSCO, Ministry of Health

    Medical Devices Rules, 2017

    Devices are classed A to D by risk and every class now needs a licence; software intended for diagnosis, monitoring or treatment is regulated as a device.

    We designInterfaces, labels and instructions are designed to the intended use the licence records.

    Medical Devices Rules, 2017 · licensing for class A and B from 1 October 2022, class C and D from 1 October 2023

  2. CDSCO, Ministry of Health

    CDSCO guidance on medical device software (draft)

    Draft guidance sets out how software that is a device, or part of one, is classified by risk and licensed, including how AI models may change after approval.

    We designSoftware is specified with its risk class, evidence and change plan before the first release.

    CDSCO · draft guidance document on Medical Device Software, 21 October 2025

  3. European Union

    EU Medical Device Regulation

    Devices for the EU need conformity assessment under the MDR; certificates under the old directives can remain valid until 31 December 2027 or 31 December 2028, depending on class, under the 2023 extension.

    We designTechnical documentation and labelling are structured once and versioned per market.

    Regulation (EU) 2017/745, as amended by Regulation (EU) 2023/607 Official text: EU Medical Device Regulation

Personal data

Shapes most of the work

  1. Ministry of Electronics and IT

    DPDP Act, 2023 and DPDP Rules, 2025

    Readings, images and device data collected per purpose with consent, withdrawal as easy as consent, and breach reporting to the Data Protection Board.

    We designDevice apps collect only what the clinical purpose needs, with consent logged per purpose.

    DPDP Act, 2023 · DPDP Rules, 2025 (core obligations from 13 May 2027) Official text: DPDP Act, 2023 and DPDP Rules, 2025

Security & incidents

Shapes most of the work

  1. Indian Computer Emergency Response Team

    CERT-In Directions, 2022

    Cyber incidents reported to CERT-In within six hours of being noticed, and ICT logs kept for 180 days.

    We designConnected devices and portals ship with logging, monitoring and an incident runbook.

    CERT-In · Directions under section 70B(6), 28 April 2022 Official text: CERT-In Directions, 2022

AI governance

Shapes most of the work

  1. European Union

    EU AI Act — AI in medical devices

    AI that is a safety component of a device needing notified-body assessment is high-risk; under the 2026 Digital Omnibus those duties apply from 2 August 2028.

    We designAI features get documentation, data governance, logging and human oversight from the first design.

    Regulation (EU) 2024/1689 · Article 6(1), as amended by Regulation (EU) 2026/1744 Official text: EU AI Act — AI in medical devices

  2. US Food and Drug Administration

    US FDA guidance on change control plans for AI

    Makers can describe planned modifications to AI-enabled device software, with the methods and assessments behind them, in the original marketing submission.

    We designEvery AI feature ships with a written plan for how it may change and how each change is tested.

    FDA · final guidance on Predetermined Change Control Plans for AI-Enabled Device Software Functions, 4 December 2024 Official text: US FDA guidance on change control plans for AI

Compiled 3 October 2026. Our reading of typical programmes, not legal advice. Rules change; your counsel confirms how each one applies to you.

Challenges

What gets in the way in medical devices & diagnostics.

The problems that surface in nearly every medical devices & diagnostics programme: the ones customers feel, and the ones teams carry.

Your customers

  1. Clinicians short of time

    Interfaces that surface the right reading and alarm without adding clicks to a shift.

  2. Patients using devices at home

    Set-up, readings and alerts that make sense without a nurse in the room.

  3. Trust in what the software says

    Clear limits on what an algorithm does, and when to call a clinician.

A bedside patient monitor showing a green waveform and vital-sign readings
Connected devices are judged on alarms, uptime and security.

Your operation

  1. Every change is a regulatory event

    Software updates, new claims and new markets can each need fresh evidence or approval.

  2. Several regulators, one product

    India, the EU and the US ask for different files about the same device.

  3. Security for critical devices

    Connected devices need patching, monitoring and disclosure for years after launch.

What we build

What we build for medical devices & diagnostics, discipline by discipline.

A typical programme here draws on each discipline in this mix. Every line names what it builds for the industry and links to the capability that does the work.

Leads Core Supports Share of a typical programme, by role · illustrative
  1. Device apps, data platforms and secure cloud services built with design controls and audit trails.

  2. Clinician and patient interfaces designed to the intended use, with usability testing built in.

  3. Product launches and clinician education kept inside the approved claims.

  4. 04

    AI Design

    Core

    AI features with evaluation sets, change plans and clinician oversight designed in.

  5. 05

    Brand Design

    Supports

    Portfolio brands and labelling systems that hold every regulated mark and instruction.

  6. 06

    Marketing Technology

    Supports

    Clinician engagement and service journeys on one consented record.

Programmes

Design to the intended use first, then build the evidence around it.

The way in reads your claims, labelling, interface and software change process against the device rules, and ranks the fixes by approval risk. Lengths are typical, never promised.

The way in

Intended-use and interface review

We read your claims, labelling, interface and software change process against the device rules in each market, and rank the fixes by approval risk.

Package
Sprint · Fixed fee
Typical length
2–3 weeks
It sets
Time from design change to approved release, as a baseline
  • Product experience audit
  • Compliance readiness

What it hands over

  • A claims-to-intended-use gap register
  • A usability risk list for the next design iteration
  • A software change and documentation plan for each market
Start here
  1. 02Milestone · 4–9 months

    Device app and clinician dashboard

    A patient app and clinician dashboard designed and built under design controls, with usability evidence and traceable requirements.

    MovesUse errors found in summative usability testing

    Services: End-to-end UX & UI design · Web or mobile app · Custom CRM or operations platform

    Enquire about Device app and clinician dashboard
  2. 03Project · 8–12 weeks

    AI feature with an evaluation set and change plan

    An AI feature specified with its evaluation set, performance limits, human oversight and a plan for how it may change after approval.

    MovesPerformance on the agreed evaluation set

    Services: Brand fidelity evaluation · AI feature design & build

    Enquire about AI feature with an evaluation set and change plan
  3. 04Project · 6–10 weeks

    Regulated product site and claims library

    A product site and claims library that keep every page, brochure and talk inside the approved intended use, market by market.

    MovesShare of promotional claims mapped to the approved intended use

    Services: Website · Content model & headless CMS · Brand check

    Enquire about Regulated product site and claims library

How success is measured

The number we moveTime from design change to approved release

  • Time from design change to approved release
  • Use errors found in summative usability testing
  • Support contacts per 1,000 devices in use
  • Share of promotional claims mapped to the approved intended use

AI, under the rules

AI flags and summarises, a clinician makes every call.

Each use case has an owner, an evaluation set, a change plan and a log; nothing a model produces reaches a patient without a clinician.

Use case 01

Image triage support

Measured bySensitivity and specificity on the agreed evaluation set

Tested forOWASP LLM06 · Excessive agency

agent / image-triage-support Guarded
  1. TaskFlags studies that may need urgent review and drafts a structured summary for the reporting clinician.
  2. GuardrailFlags and summaries only; it never issues a diagnosis or a report, and its performance is checked against an agreed evaluation set.
  3. HumanA qualified clinician reads every study and signs every report.
  4. LogStudy, model version, flag, summary and the clinician’s decision.

Ships only with its evaluation set, its guardrail and an owner

Use case 02

Complaint and vigilance intake

Measured byReports routed within the agreed time

Tested forOWASP LLM02 · Sensitive information disclosure

agent / complaint-and-vigilance-intake Guarded
  1. TaskReads service calls and complaints for possible adverse events and malfunctions, and routes them to vigilance.
  2. GuardrailIt only flags and routes; it never closes a complaint or assesses causality.
  3. HumanThe vigilance team assesses every flagged report.
  4. LogMessage, flag reason, routing time and outcome.

Ships only with its evaluation set, its guardrail and an owner

Use case 03

Technical documentation drafts

Measured byReview cycles per document

Tested forOWASP LLM09 · Misinformation

agent / technical-documentation-drafts Guarded
  1. TaskDrafts sections of technical files and change notes from approved design records.
  2. GuardrailCites the design record behind every statement and never invents a test result.
  3. HumanRegulatory affairs reviews and signs every document.
  4. LogDraft, records cited and reviewer.

Ships only with its evaluation set, its guardrail and an owner

Work and insights

Published work follows client approval.

We publish medical devices & diagnostics projects only once a client signs off the write-up. Meanwhile, here is the reading that applies.

A typical programme · composite

A diagnostics company rebuilt its device app and clinician dashboard around the licensed intended use, with a change plan for its algorithm and a claims library that keeps every brochure, page and talk inside the approval.

Anonymised and illustrative: the shape a programme takes, never a named client.

Questions

What regulatory, product and quality leads ask us first.

Something else on your mind? Ask us directly

Q.01Is our app a medical device?

If its intended use is to diagnose, monitor, treat or prevent a disease, it may be — in India, the EU and the US alike. We help you write the intended use precisely and design within it; the classification decision and any licence application stay with your regulatory team.

Q.02Do you work inside our design controls and risk management?

Yes. We work inside your quality system: requirements traced to designs and tests, usability testing that feeds your risk file, and documentation in the form your auditors expect.

Q.03How do you handle AI that keeps learning?

We design AI features with a fixed, evaluated version in use and a written plan for how it may change — what, how it is tested and when it needs approval — in line with the US FDA’s guidance on change control plans and the EU AI Act. Nothing changes in the field without that plan.

Q.04Do you work with hospitals as well as device makers?

Yes: we also design clinician-facing tools and portals for providers. Our page on hospitals and care providers covers that work.

Let’s build what happens next.

Tell us what you’re building. We’ll answer straight.

Book a discovery call

Three ways to start

  1. 01About 2 minutes

    A quick question

    You get A reply from a lead, not a sales queue

  2. 02About 8 minutesMost useful

    A project brief

    You get Options and a first scope after one call

  3. 03About 15 minutes

    A formal RFQ or RFP

    You get Receipt confirmed and a named bid lead

Every engagement starts with a written scope and a quote agreed before work begins. How each package is priced