Software as a medical device and digital health

Software becomes a medical device on the strength of its intended purpose, and the claim in a marketing brochure can decide a classification the engineering team never planned for. From that point the MDR expects clinical evidence built for algorithms, post-market surveillance that keeps pace with software that changes after release, and cybersecurity obligations that reach past the device into the hospital network. The commercial layer is moving as fast as the regulatory one: Germany reimburses digital therapeutics through the DiGA directory on outcome-based prices, and Switzerland offers a regulatory sandbox for digital health built on guidance rather than statute. The analyses below follow a US digital-health product from classification through evidence, vigilance, security and reimbursement, with the AI Act's second layer where the software learns.

8 insights · latest May 2026

Insights on Software as a medical device and digital health

No. 07 Critical Compliance

Software as a Medical Device (SaMD): Classification Pitfalls

SaMD classification under EU MDR creates regulatory exposure developers discover post-launch. Marketing claims often inadvertently determine regulatory status.

No. 11 Critical Compliance

Clinical Evidence for SaMD: Regulatory Expectations

SaMD clinical evidence under EU MDR requires analytical validation, clinical validation, and real-world evidence (burdens many software developers underestimate).

No. 12 Critical Compliance

Post-Market Surveillance for SaMD: When Software Keeps Changing

SaMD post-market surveillance extends beyond incident reporting. Algorithm monitoring, vigilance, and PSUR requirements create ongoing compliance burdens.

No. 14 Emerging Issue

AI-Enabled Medical Devices: The Regulatory Convergence Problem

Machine learning algorithms that evolve post-market challenge traditional regulatory frameworks built for static devices. What happens when your device learns after approval?

No. 18 High Stakes

Cybersecurity for SaMD: Meeting MDR and Beyond

SaMD cybersecurity under the EU MDR, IEC 81001-5-1 and the Swiss ISG: vulnerability management, incident reporting and security updates beyond standard IT.

No. 51 Critical Compliance

The EU AI Act Meets the MDR: What the August 2026 Cliff Really Means for US Medical AI

AI-enabled medical software reaches high-risk status through the AI Act's Annex I product route rather than Annex III, so obligations attach in 2027 and are assessed as a second layer inside MDR conformity assessment.

No. 10 Emerging Issue

Regulatory Sandbox for Digital Health in Switzerland

Switzerland's regulatory sandbox for digital health offers flexibility through guidance rather than statute. What this means for market entry strategy and timing.

No. 50 Emerging Issue

Germany's DiGA Reform: Outcome-Based Pricing and Class IIb for US Digital Therapeutics

Germany's Digital-Gesetz rewrote § 134 SGB V so that from 2026 at least 20 percent of a DiGA's negotiated price turns on measured outcomes, and the BfArM directory now admits Class IIb software on stricter evidence terms.

Counsel on this topic: Digital health compliance counsel.

Good questions deserve specific answers.

Get in Touch