Who We Serve: Medical Equipment
Diagnostic Imaging
An imaging system is part capital equipment, part software platform and, for x-ray and CT, part radiation-emitting product. Each part brings its own records and its own audit questions. We help imaging manufacturers see where those records fall out of step.
Standards and Regulations to Know
- IEC 60601-1Basic Safety and Essential Performance of Medical Electrical Equipment
- IEC 60601-1-2Electromagnetic Compatibility of Medical Electrical Equipment
- IEC 62304Medical Device Software Lifecycle Processes
- IEC 81001-5-1Security Activities in the Health Software Lifecycle
- IEC 62366-1Usability Engineering for Medical Devices
- ISO 14971Risk Management for Medical Devices
- 21 CFR Part 820 (QMSR)Quality Management System Regulation
- 21 CFR Part 806Reports of Corrections and Removals
Typical Regulatory Exposure
Imaging hardware falls under the IEC 60601-1 family, including particular standards for specific modalities, and the software that acquires, reconstructs or analyzes images falls under IEC 62304. X-ray, CT and other systems that emit radiation also carry FDA electronic product radiation control requirements, which sit alongside the device quality system and have their own reports and records.
Much of an imaging company's risk lives in the installed base. Systems stay in service for years, receive software updates and upgrades in the field, connect to hospital networks and image archives, and may be serviced by a mix of the manufacturer's engineers and others. Knowing which version runs where, and what each update changed, is a quality system question, not only a service one.
Image analysis software, including AI-enabled detection and triage tools, adds the software lifecycle, cybersecurity and data management expectations of software devices, applied to outputs clinicians rely on for diagnosis. IEC 81001-5-1 covers security across the health software lifecycle, which matters for systems that sit on hospital networks for years.
Where Audits Find Gaps
- 01
Software Versions Untracked in the Field
Upgrades and patches are deployed site by site, but no controlled record shows which version each installed system runs, so a correction cannot be scoped quickly.
- 02
Image Quality Not Verified After Updates
Updates that touch acquisition or reconstruction are released after functional testing, with no documented check of image quality against the original verification.
- 03
Security Patching Outside Change Control
Operating system and security patches reach installed systems through IT channels, with no device-level assessment or record in the QMS.
- 04
Radiation Product Records Lagging
Model changes and new configurations were made without checking whether radiation product reports or the related records needed updating.
- 05
Interface Problems Not Fed Back
Connections to hospital archives and viewing systems were verified against one configuration, and problems reported from other sites are fixed locally without reaching complaint handling or design.
Relevant Standards and Regulations
- IEC 60601-1Basic Safety and Essential Performance of Medical Electrical Equipment
- IEC 60601-1-2Electromagnetic Compatibility of Medical Electrical Equipment
- IEC 62304Medical Device Software Lifecycle Processes
- IEC 81001-5-1Security Activities in the Health Software Lifecycle
- IEC 62366-1Usability Engineering for Medical Devices
- ISO 14971Risk Management for Medical Devices
- 21 CFR Part 820 (QMSR)Quality Management System Regulation
- 21 CFR Part 806Reports of Corrections and Removals
Relevant Services
Software Validation and Device Software (CSV, IEC 62304)
Validate software used in production and the QMS, and build device software on an IEC 62304 lifecycle.
AI-Assisted QMS Gap Assessment
An AI-assisted first pass over the QMS documents you already have, with every result reviewed by an advisor.
FDA Inspection Readiness (CP 7382.850)
FDA device inspection preparation built around Compliance Program 7382.850 and its risk-based approach.
CAPA System Remediation
Fixing a CAPA system auditors keep citing: the procedure, the records, root cause, effectiveness and backlog.
Audits and Inspections You May Face
FDA Baseline Surveillance Inspection
FDA's comprehensive surveillance inspection of your quality system under Compliance Program 7382.850.
MDSAP Audit
One audit by a recognized auditing organization that covers several participating regulators, including FDA.
ISO 13485 Surveillance Audit
The periodic audits, at least annually, that support continued ISO 13485 certification between renewals.
Questions
Are radiation control requirements part of a QMS inspection?
They are a separate set of FDA requirements with their own reports and records, and they are not one of the QMS areas in Compliance Program 7382.850. We still look at them in a readiness review, because a radiation report that lags behind the product usually means change control is lagging too.
How do we handle AI-enabled image analysis in a hardware-focused QMS?
Treat it as a software device with its own lifecycle: data management, verification on independent data, performance monitoring and controlled updates. Hardware-focused quality systems usually need new procedures for those activities rather than adapted versions of existing ones.
Can you assess our installed base records?
Yes. Upload service, installation and upgrade records along with your configuration documentation. The first pass looks for systems with unknown or inconsistent versions and for updates without change records, and an advisor reviews what it finds.
Diagnostic Imaging
Get an Advisor's View of Your Quality System
Tell us about your devices and the audit or inspection ahead, and an advisor will scope an assessment for your kind of product. Please don't send confidential documents yet: secure upload is set up after onboarding.


