Software, Cybersecurity and AI
IEC 82304-1: Safety of Health Software Products
IEC 82304-1 covers the safety and security of health software products: software placed on the market on its own and run on general computing platforms such as phones, computers or cloud infrastructure. Where IEC 62304 governs how the software is developed, IEC 82304-1 looks at the finished product, including its requirements, validation, accompanying documents and post-market activities.
At a Glance
- Standard
- IEC 82304-1
- Subject
- Safety of Health Software Products
- Group
- Software, Cybersecurity and AI
- Industries
- 1 industry guides reference it
A plain-language summary of scope, not the standard itself. Buy the current edition from the publisher and check which edition your auditor or market expects.
What It Covers
The standard asks for product requirements derived from the intended use, including the platforms the software is meant to run on, and for validation of the finished product against that intended use. It relies on IEC 62304 for the software lifecycle processes, so the two are normally used together for software-only products.
It also sets expectations for accompanying documents, such as the minimum platform requirements, installation and use instructions and a technical description, and for activities after release, including maintaining the product, distributing updates and telling users about changes and known issues.
Health software is a wider category than medical device software. IEC 82304-1 can apply to software that isn't regulated as a device in a given market, which is why some clinical workflow and wellness developers use it as a quality baseline. For regulated Software as a Medical Device, it covers the product-level questions that the 62304 process doesn't.
Who It Applies To
- Software as a Medical Device sold without dedicated hardware
- Mobile health apps and cloud-hosted clinical software
- Health software developers outside device regulation who want an established product-safety baseline
- Device firms adding standalone software products to a hardware portfolio
What Auditors Check
Product Requirements
Health software product requirements covering intended use, platform requirements, security and data handling.
Product Validation
Validation of the finished product against its intended use, kept distinct from software verification.
Platform Assumptions
Documented minimum platform requirements and a process to assess operating system and browser updates as they arrive.
Accompanying Documents
Instructions and a technical description stating platform requirements, installation steps and known limitations.
Post-Market Process
A process to evaluate feedback, release updates and communicate with users about changes and issues.
Related Services
Software Validation and Device Software (CSV, IEC 62304)
Validate software used in production and the QMS, and build device software on an IEC 62304 lifecycle.
Submission Readiness (510(k), De Novo, PMA, Pre-Sub, 513(g))
The design, risk and V&V evidence behind a 510(k), De Novo or PMA, organized and gap-checked.
AI-Assisted QMS Gap Assessment
An AI-assisted first pass over the QMS documents you already have, with every result reviewed by an advisor.
Industry Guides That Reference IEC 82304-1
IEC 82304-1
Check Your Quality System Against IEC 82304-1
An AI-assisted first pass maps your existing documents against the requirements in scope, and an advisor reviews every result. Please don't send confidential documents yet: secure upload is set up after onboarding.


