HEALTHCARE AI COMPLIANCE · EU AI ACT · 1-4 WEEKS

AI used in diagnosis, triage and patient care. Audited once.

Clinical decision support and triage AI are high-risk in Annex III. Nothing is enforced yet, which is what makes the window worth using.


A reviewer with auburn hair, in a dark green blazer, seated at a dark stone desk by a window in a warm, low-lit office, signing a printed page with further papers and a stoneware cup beside them.
Signed off by someone with no stake in the answer
EU AI Act Annex III FDA SaMD HIPAA / HITECH Sub-group accuracy

Our promise

“One examination. Three regimes answered. Performance by group.”

Every finding is tagged with the regime it answers — and ranked by consequence to patients first. The fee starts at $5,000, and nothing is charged until you approve it.

Request this healthcare AI audit
The case file

Clinical AI, in three chapters

The Stack

Three regimes reach one model. The EU AI Act names clinical decision support and diagnostics as high-risk, FDA expects a change-control plan and real-world monitoring of AI-based devices, and HIPAA reaches the training data - because a healthcare training set is made of patients.

The Gap

The evidence usually stops at one number. A clearance, a published study and an accuracy figure - all real, all describing somebody else’s patients. Nobody has measured the model on this population, by group, and an aggregate number is where a sub-group harm hides.

The Office

We are the independent reviewer all three regimes have in mind. iDharma examines the model once - validation, sub-group performance, ground truth, oversight and monitoring - and reports it against each regime in turn, so you receive one technical file and one ranked gap register, not three.

What we audit

AI systems in scope for healthcare

Every system that shapes a decision about a patient - clinical or not.

The systems in scope № 01
  • Clinical decision support
  • Diagnostic imaging AI
  • Patient-facing chatbots and symptom checkers
  • Administrative and operational AI
Clinical AI · iDharma · Presented for assay
When the duty bites № 02
  • Before first use - validated on your own population
  • On every deployment where a clinician holds the override
  • Whenever the model is retrained, recalibrated or re-cut
  • From 2 December 2027 for the Annex III high-risk limb
Clinical AI · iDharma · Presented for assay
Whose duty is it

The clearance is theirs. The patients are yours.

You

The deploying provider

The EU AI Act reaches you as the deployer, and clinical governance reaches you as the organisation whose patients are the ones affected. Whoever puts the system in front of a clinician owes the oversight, owes the monitoring, and owes the answer on the day a decision is later questioned.

Your vendor

The people who built the model

Carries real duties of its own - as the EU AI Act provider, and as the SaMD manufacturer where the device is cleared. A clearance and a published validation study are both worth having. Neither is a statement about how the model performs on your patients. That measurement is yours to make.

The catch

Aggregate accuracy hides the harm

A model reported at 94% overall can sit at 78% on a sub-group that is a twentieth of your patients, and the headline figure will never show it. Performance is a property of a population - and the population it was validated on was never yours. Only a stratified read will ever make it visible.

What most teams assume

“It is FDA-cleared and 94% accurate, so we’re covered.”

What the evidence says

94% on whose patients? And 94% for which of them?

It is the most common finding we write up.

  • Who it is for
  • Hospitals & health systems
  • Digital health & SaMD
  • Diagnostics & imaging
  • Payers & administrators
  • Clinical safety & governance
Why this sector stands out

Healthcare at a glance

A thick tabbed reference volume standing open on a dark desk under a low lamp, its coloured index tabs running down the fore-edge, with a pen and reading glasses beside it: the governance record a clinical AI is expected to have behind it.
01 No penalty has been issued against clinical AI, and the high-risk regime is not yet in application. That is what makes the window worth using rather than watching.
02

Annex III names healthcare AI directly. Obligations apply from 2 December 2027, and the technical file behind them is a year of work.

03

State law is moving faster than the federal picture. Texas TRAIGA healthcare provisions took effect in January 2026; scope varies.

04

A sub-group finding does not wait for a regulator. It is a patient-safety issue on the day it exists, whoever has asked.

The 60-second check

Three questions. Then you’ll know.

No email. No signup. A starting point, not a determination.

0 of 3

Clinical decisions -

This is the Annex III limb. Clinical decision support, diagnostic tools and anything influencing medical treatment are named high-risk. Administrative systems are judged on what the output does to a decision.

Sub-group, on your population -

An aggregate cannot answer this. A model at 94% overall can sit at 78% on a sub-group that is a twentieth of your patients, and the headline figure will never show it.

Oversight exercised -

Oversight is measured, not documented. An override rate near zero across thousands of decisions usually means the information needed to disagree is not on the screen, or there is no time to use it.

The calendar

Four moments, and only one is a date.

Only the third is fixed by an instrument. The other three are the moments somebody asks — and none of the four can be added to another.

  1. Validate

    Before first use

    Performance measured on your own population before the model sees a patient - not on the vendor's validation set.

  2. Oversee

    Every deployment

    Oversight has to be exercisable by the clinician who has it. A right to override nobody can use is not oversight.

  3. Comply

    2 December 2027

    Annex III high-risk obligations apply from that date. The technical file behind them is a year of work, not a quarter.

  4. Monitor

    Continuously

    Real-world performance drifts as your case mix does. FDA expects it watched; so does the post-market limb of the EU Act.

The trap

Teams read 2 December 2027 as the start date and plan backwards from it. Most of a technical file is evidence that has to be collected while the model is being built - validation design, sub-group results, data provenance, change history. Assembled afterwards from a model already live, it is the same document at several times the cost, and thinner.

Requirement & coverage

What the three ask, what we ship

12 obligations across three regimes, and the artefact that discharges each one. Each row names which is speaking — and where one is guidance rather than law, it says so.

Which regimes reach you Device status, role and market, not sector label
A written determination of which of the three bind which system, so nothing is audited twice and nothing is missed.
Provider or deployer EU AI Act - the roles carry different duties
Your role recorded per system, with the vendor obligations separated from yours in writing.
High-risk classification EU AI Act Annex III - clinical AI is named
Each system classified against Annex III with the reasoning stated, including the ones we conclude are out.
Clinical validation evidence EU AI Act; FDA pre-market expectation
The evidence assembled and assessed against the decision the model is actually being used to make.
Sub-group accuracy Aggregate accuracy is not the measure
Performance by demographic group, reported separately, with the disparities named rather than averaged away.
Ground-truth construction How the labels were made decides everything
The labelling process traced end to end, including where a model is being scored against its own past decisions.
Technical documentation EU AI Act Annex IV; FDA submission content
One package built to satisfy both, rather than a technical file and a submission dossier saying the same thing twice.
Human oversight EU AI Act - effective, not nominal
Override paths tested as clinicians actually use them, with the rate at which a human changes the output measured.
Change control FDA predetermined change-control expectation
What may change without a new submission, what may not, and whether your retraining practice stays inside it.
Real-world monitoring FDA expectation; EU post-market monitoring
The monitoring you have, the monitoring each regime expects, and the thresholds that should trigger a clinician looking.
PHI in training data HIPAA / HITECH - it reaches the training set
Where each training record came from, on what basis you hold it, and whether the de-identification actually holds.
Vendor accuracy claims A clearance is not a performance guarantee
Test data, evaluation method and ground-truth construction requested and checked, rather than a benchmark quoted back.
Our methodology

How an iDharma audit works

One pass over the model. Three regimes answered.

  1. Request and scope

    Which systems, which clinical decisions, which population. Priced and approved before anything is charged.

  2. Test once, map three ways

    One pass over the models, scored against the EU AI Act, FDA SaMD expectations and HIPAA together. One to four weeks.

  3. Sign off and report

    You see the draft first. Then the technical file and one gap register - ranked, dated and signed.

Request a healthcare AI audit
An auditor in a black trouser suit and cream blouse, with dark hair in a low bun, standing against a warm pale wall and pointing into the open space alongside.
We do not accept a vendor report as evidence. That is what you are buying.
Struck in your favour

Why providers choose iDharma to review their clinical AI

Genuinely independent

We build, resell and operate no clinical models, and we take no fee tied to what the audit finds.

Three regimes, one pass

One examination of the model, scored against all three - not three workstreams meeting at the end.

Sub-group by default

Performance is reported by demographic group in the base scope. Aggregates are where the harm hides.

Ranked by patient impact

The gap register is ordered by consequence to patients first, and by regulatory exposure second.

Four marks, struck on every report.

Deliverables

What you get

Concrete artefacts, each with a name and a format - you know what lands before you buy.

Clinical AI audit report

The full review: scope, method, every system examined, and the findings written so a clinical safety lead, a regulatory affairs team and your board can each read the part they need - each finding tagged with the regime it answers, and performance reported by demographic group rather than in aggregate.

Signed by a named independent reviewer with no role in building, selling or operating the models, and no fee tied to the finding. One pass over the estate, scored against all three regimes rather than three times over.

Workbook

Sub-group performance tables

Accuracy, sensitivity and specificity by demographic group in a workbook, so your own team can reproduce every figure without asking us for it.

Memo

Ground-truth review

How the labels behind your model were made, by whom, and where the process scores the model against its own past decisions.

Memo

Oversight assessment

Whether the clinician holding the override can exercise it in practice, measured on real use rather than read off the policy.

Package

Technical documentation

One file built to answer EU AI Act Annex IV and FDA submission content together, rather than two documents restating each other.

Ranked

Gap register

Every gap in one list, ordered by consequence to patients first and regulatory exposure second - not by which fix ships soonest.

Memo

Vendor-evidence assessment

What your vendor's clearance and validation study cover for your population and your use, what they do not, and what must be measured here.

Format & fee

Real numbers, upfront.

Scope
Agreed with you, then fixed
Data
A de-identified decision extract
Re-review
On every material retrain - $3,000 against your known baseline

Three regimes over an estate only you can size, so the fee is quoted rather than listed - and nothing is charged until you have approved it.

Request a healthcare AI audit
Clinical AI · Scoped engagement $5,000 from
  • EU AI Act, FDA SaMD and HIPAA in one pass
  • Sub-group performance on your own population
  • Ground-truth and oversight review
  • One gap register, ranked by patient impact
Show your hand

Four things you have to be able to produce

None of the three is graded on intent, and neither is a patient outcome. Each of these is either in your hand on the day somebody asks, or it is not.

The numbers,
by group

Performance by demographic group rather than in aggregate, on your own population. A single headline accuracy figure cannot answer the question being asked.

The labels,
traced

How ground truth was constructed, by whom, and against what. A model scored against its own historical decisions is circular, and it inflates every figure below it.

The override,
exercisable

Evidence that the clinician who holds the override can actually use it - the information, the time and the standing. A right nobody exercises is a right nobody has.

The file,
complete

One documentation package answering Annex IV and the FDA submission content: purpose, data, limitations, change history and who approved each change, dated.

Four cards, and the population on each one is part of the card.

FAQ

Plain answers

Scope, timing, what we test, the engagement. Answered straight.

Request this audit
Our vendor is FDA-cleared. Are we covered?

Clearance describes the device; it is not a statement about your patients. A published study describes the population it was validated on, and that population was not yours.

Is our system high-risk under the EU AI Act?

Clinical decision support, diagnostic tools and anything influencing medical treatment are named in Annex III. Administrative and patient-facing systems are judged on what the output does to a decision.

Nothing is being enforced yet. Why now?

No EU AI Act penalty has been issued against clinical AI and the high-risk regime is not yet in application. The technical file behind it is a year of work - and a sub-group finding does not wait for a regulator.

What exactly do you test?

Classification against Annex III, clinical validation evidence, sub-group accuracy on your own population, how ground truth was built, human oversight as clinicians actually use it, change control, monitoring, and PHI in the training data.

How long does it take, and what does it cost?

One to four weeks for most engagements. Scope and price are agreed and approved before any work begins, and nothing is charged until you approve what the engagement covers.

Get started

Deploying AI in a clinical or patient-facing context?

Tell us what decides, and we come back with a scope and a price within one business day.

What we need from you

Nothing you do not already have. Mostly your system inventory and a de-identified extract of decisions and outcomes, with every document named in writing first.

  1. Which systems decide, and at which point of care
  2. Whether they are built in-house, bought, or both
  3. A de-identified extract of decisions and outcomes
  4. Any validation already done, and on whose patients
  5. Your target date for a read, if you have one

What happens next

  1. You send the five items we need.
  2. We call to scope it within one business day.
  3. Nothing is charged until you approve it.
Request a healthcare AI audit
Sources & standing

Where this page gets its facts

Where the claims on this page come from, and what they are worth - stated, not assumed.

What it is drawn from

  • Regulation (EU) 2024/1689 - the AI Act
  • FDA AI/ML SaMD guidance; HIPAA / HITECH
Annex III from
2 December 2027
Last read
9 September 2026

What it means

  • General information about what these three regimes ask — one of which is guidance rather than law. Not legal, regulatory or clinical advice, and it determines nothing about your own systems.
  • Where a classification is genuinely arguable, or the three pull in different directions, our reports say so rather than pick the convenient reading.

Scope & limitation

  • Do not rest a binding decision on it; engage qualified counsel.
  • Use it as a starting point for a scoping conversation, not as your final word.
  • We are not a clinical safety authority and issue no clinical sign-off. What we produce is evidence for your own clinical governance to reach its conclusion on.

Something on this page out of date?

Tell us