QMSAdvisor

Software, Cybersecurity and AI

IEC 82304-1: Safety of Health Software Products

IEC 82304-1 covers the safety and security of health software products: software placed on the market on its own and run on general computing platforms such as phones, computers or cloud infrastructure. Where IEC 62304 governs how the software is developed, IEC 82304-1 looks at the finished product, including its requirements, validation, accompanying documents and post-market activities.

At a Glance

Standard
IEC 82304-1
Subject
Safety of Health Software Products
Group
Software, Cybersecurity and AI
Industries
1 industry guides reference it

A plain-language summary of scope, not the standard itself. Buy the current edition from the publisher and check which edition your auditor or market expects.

What It Covers

The standard asks for product requirements derived from the intended use, including the platforms the software is meant to run on, and for validation of the finished product against that intended use. It relies on IEC 62304 for the software lifecycle processes, so the two are normally used together for software-only products.

It also sets expectations for accompanying documents, such as the minimum platform requirements, installation and use instructions and a technical description, and for activities after release, including maintaining the product, distributing updates and telling users about changes and known issues.

Health software is a wider category than medical device software. IEC 82304-1 can apply to software that isn't regulated as a device in a given market, which is why some clinical workflow and wellness developers use it as a quality baseline. For regulated Software as a Medical Device, it covers the product-level questions that the 62304 process doesn't.

Who It Applies To

  • Software as a Medical Device sold without dedicated hardware
  • Mobile health apps and cloud-hosted clinical software
  • Health software developers outside device regulation who want an established product-safety baseline
  • Device firms adding standalone software products to a hardware portfolio

What Auditors Check

  • Product Requirements

    Health software product requirements covering intended use, platform requirements, security and data handling.

  • Product Validation

    Validation of the finished product against its intended use, kept distinct from software verification.

  • Platform Assumptions

    Documented minimum platform requirements and a process to assess operating system and browser updates as they arrive.

  • Accompanying Documents

    Instructions and a technical description stating platform requirements, installation steps and known limitations.

  • Post-Market Process

    A process to evaluate feedback, release updates and communicate with users about changes and issues.

Related Services

IEC 82304-1

Check Your Quality System Against IEC 82304-1

An AI-assisted first pass maps your existing documents against the requirements in scope, and an advisor reviews every result. Please don't send confidential documents yet: secure upload is set up after onboarding.