HealthTech, MedTech & AI Diagnostics
HealthTech and MedTech companies build products that process health, genomic and imaging data continuously — a cardiac imaging algorithm, a genomic analysis platform, an epigenetic test, a stroke-detection model. Each product is a data processing activity in its own right, often with the company acting as processor for hospital customers and as controller for its own users, and increasingly as a provider of an AI system under Regulation (EU) 2024/1689.
The compliance stack is layered: GDPR and UK GDPR for personal data, the MDR and IVDR for device software and its technical documentation, the EU AI Act for AI systems classified as high-risk under Annex I or Annex III, NIS2 and ISO 27001 expectations from hospital procurement, and HIPAA when the product is sold in the United States.
iliomad works with product, engineering and regulatory teams to implement one framework across these regimes — a DPO who understands software, an AI Officer for the AI Act, and cybersecurity documentation that survives a hospital security questionnaire.
What a HealthTech company has to get right
Hospital customers, notified bodies and investors ask the same questions in a different order. The obligations below are the ones that decide whether a procurement, a CE marking or a financing round goes through.
A platform sold to hospitals usually processes patient data as a processor under Art. 28 GDPR, while processing its own users' data as a controller. Getting this qualification wrong invalidates the contracts and the privacy notices. iliomad documents the role per product and per customer type and builds the DPA templates your sales team can sign.
An AI system that is a medical device or a safety component of one is high-risk under Annex I of the AI Act; certain other health uses fall under Annex III. Providers must implement a risk management system (Art. 9), data governance (Art. 10), technical documentation (Art. 11), logging, transparency, human oversight and a quality management system (Art. 17). iliomad classifies each system and builds the documentation alongside your MDR/IVDR file — see AI compliance services.
Art. 25 GDPR requires privacy by design and by default; the MDR and IVDR require cybersecurity in the technical documentation; hospital procurement requires evidence of both. This means data flow maps, pseudonymisation strategies, access controls, retention rules and a DPIA per product before launch, not after. See DPIA and cybersecurity for life sciences.
Training and validating models on patient data requires a lawful basis — Art. 9(2)(j) GDPR for scientific research with appropriate safeguards, or consent — and a documented anonymisation or pseudonymisation position. Art. 10(5) of the AI Act allows processing of special-category data for bias detection under strict conditions. iliomad documents the position for each dataset and each model.
Selling to hospitals means answering ISO 27001, NIS2 and national health-data hosting requirements (such as HDS certification in France) in every tender. A DPO and an information security framework that speak the hospital's language shorten the sales cycle. iliomad prepares the compliance pack once and keeps it current.
A product used by US covered entities makes the company a business associate under HIPAA, with a Business Associate Agreement, the Security Rule safeguards and breach notification duties. State laws such as the CCPA/CPRA add consumer-facing obligations. iliomad aligns the GDPR framework with HIPAA and CPRA so that one programme covers both markets.
How iliomad Health Data can help you
iliomad Health Data supports HealthTech, MedTech and AI companies from seed stage to scale-up — cardiac imaging, genomic platforms, epigenetic testing, AI stroke detection, digital therapeutics. Our consultants combine data protection, AI regulation and cybersecurity, and work directly with product and engineering teams. The engagement is structured as a DPO or AI Officer mandate plus scoped deliverables, so that you pay for a framework, not for hourly firefighting.
FAQs
Our frequently questions
