Three regimes reach one model. The EU AI Act names clinical decision support and diagnostics as high-risk, FDA expects a change-control plan and real-world monitoring of AI-based devices, and HIPAA reaches the training data - because a healthcare training set is made of patients.
AI used in diagnosis, triage and patient care. Audited once.
Clinical decision support and triage AI are high-risk in Annex III. Nothing is enforced yet, which is what makes the window worth using.
Our promise
“One examination. Three regimes answered. Performance by group.”
Every finding is tagged with the regime it answers — and ranked by consequence to patients first. The fee starts at $5,000, and nothing is charged until you approve it.
Request this healthcare AI auditClinical AI, in three chapters
The evidence usually stops at one number. A clearance, a published study and an accuracy figure - all real, all describing somebody else’s patients. Nobody has measured the model on this population, by group, and an aggregate number is where a sub-group harm hides.
We are the independent reviewer all three regimes have in mind. iDharma examines the model once - validation, sub-group performance, ground truth, oversight and monitoring - and reports it against each regime in turn, so you receive one technical file and one ranked gap register, not three.
AI systems in scope for healthcare
Every system that shapes a decision about a patient - clinical or not.
- Clinical decision support
- Diagnostic imaging AI
- Patient-facing chatbots and symptom checkers
- Administrative and operational AI
- Before first use - validated on your own population
- On every deployment where a clinician holds the override
- Whenever the model is retrained, recalibrated or re-cut
- From 2 December 2027 for the Annex III high-risk limb
The clearance is theirs. The patients are yours.
The deploying provider
The EU AI Act reaches you as the deployer, and clinical governance reaches you as the organisation whose patients are the ones affected. Whoever puts the system in front of a clinician owes the oversight, owes the monitoring, and owes the answer on the day a decision is later questioned.
The people who built the model
Carries real duties of its own - as the EU AI Act provider, and as the SaMD manufacturer where the device is cleared. A clearance and a published validation study are both worth having. Neither is a statement about how the model performs on your patients. That measurement is yours to make.
Aggregate accuracy hides the harm
A model reported at 94% overall can sit at 78% on a sub-group that is a twentieth of your patients, and the headline figure will never show it. Performance is a property of a population - and the population it was validated on was never yours. Only a stratified read will ever make it visible.
“It is FDA-cleared and 94% accurate, so we’re covered.”
94% on whose patients? And 94% for which of them?
It is the most common finding we write up.
- Who it is for
- Hospitals & health systems
- Digital health & SaMD
- Diagnostics & imaging
- Payers & administrators
- Clinical safety & governance
Healthcare at a glance
Annex III names healthcare AI directly. Obligations apply from 2 December 2027, and the technical file behind them is a year of work.
State law is moving faster than the federal picture. Texas TRAIGA healthcare provisions took effect in January 2026; scope varies.
A sub-group finding does not wait for a regulator. It is a patient-safety issue on the day it exists, whoever has asked.
Three questions. Then you’ll know.
No email. No signup. A starting point, not a determination.
Your scope check
Four moments, and only one is a date.
Only the third is fixed by an instrument. The other three are the moments somebody asks — and none of the four can be added to another.
-
Validate
Before first usePerformance measured on your own population before the model sees a patient - not on the vendor's validation set.
-
Oversee
Every deploymentOversight has to be exercisable by the clinician who has it. A right to override nobody can use is not oversight.
-
Comply
2 December 2027Annex III high-risk obligations apply from that date. The technical file behind them is a year of work, not a quarter.
-
Monitor
ContinuouslyReal-world performance drifts as your case mix does. FDA expects it watched; so does the post-market limb of the EU Act.
Teams read 2 December 2027 as the start date and plan backwards from it. Most of a technical file is evidence that has to be collected while the model is being built - validation design, sub-group results, data provenance, change history. Assembled afterwards from a model already live, it is the same document at several times the cost, and thinner.
What the three ask, what we ship
12 obligations across three regimes, and the artefact that discharges each one. Each row names which is speaking — and where one is guidance rather than law, it says so.
- Which regimes reach you Device status, role and market, not sector label
- A written determination of which of the three bind which system, so nothing is audited twice and nothing is missed.
- Provider or deployer EU AI Act - the roles carry different duties
- Your role recorded per system, with the vendor obligations separated from yours in writing.
- High-risk classification EU AI Act Annex III - clinical AI is named
- Each system classified against Annex III with the reasoning stated, including the ones we conclude are out.
- Clinical validation evidence EU AI Act; FDA pre-market expectation
- The evidence assembled and assessed against the decision the model is actually being used to make.
- Sub-group accuracy Aggregate accuracy is not the measure
- Performance by demographic group, reported separately, with the disparities named rather than averaged away.
- Ground-truth construction How the labels were made decides everything
- The labelling process traced end to end, including where a model is being scored against its own past decisions.
- Technical documentation EU AI Act Annex IV; FDA submission content
- One package built to satisfy both, rather than a technical file and a submission dossier saying the same thing twice.
- Human oversight EU AI Act - effective, not nominal
- Override paths tested as clinicians actually use them, with the rate at which a human changes the output measured.
- Change control FDA predetermined change-control expectation
- What may change without a new submission, what may not, and whether your retraining practice stays inside it.
- Real-world monitoring FDA expectation; EU post-market monitoring
- The monitoring you have, the monitoring each regime expects, and the thresholds that should trigger a clinician looking.
- PHI in training data HIPAA / HITECH - it reaches the training set
- Where each training record came from, on what basis you hold it, and whether the de-identification actually holds.
- Vendor accuracy claims A clearance is not a performance guarantee
- Test data, evaluation method and ground-truth construction requested and checked, rather than a benchmark quoted back.
How an iDharma audit works
One pass over the model. Three regimes answered.
-
Request and scope
Which systems, which clinical decisions, which population. Priced and approved before anything is charged.
-
Test once, map three ways
One pass over the models, scored against the EU AI Act, FDA SaMD expectations and HIPAA together. One to four weeks.
-
Sign off and report
You see the draft first. Then the technical file and one gap register - ranked, dated and signed.
Why providers choose iDharma to review their clinical AI
Genuinely independent
We build, resell and operate no clinical models, and we take no fee tied to what the audit finds.
Three regimes, one pass
One examination of the model, scored against all three - not three workstreams meeting at the end.
Sub-group by default
Performance is reported by demographic group in the base scope. Aggregates are where the harm hides.
Ranked by patient impact
The gap register is ordered by consequence to patients first, and by regulatory exposure second.
Four marks, struck on every report.
What you get
Concrete artefacts, each with a name and a format - you know what lands before you buy.
Clinical AI audit report
The full review: scope, method, every system examined, and the findings written so a clinical safety lead, a regulatory affairs team and your board can each read the part they need - each finding tagged with the regime it answers, and performance reported by demographic group rather than in aggregate.
Signed by a named independent reviewer with no role in building, selling or operating the models, and no fee tied to the finding. One pass over the estate, scored against all three regimes rather than three times over.
Sub-group performance tables
Accuracy, sensitivity and specificity by demographic group in a workbook, so your own team can reproduce every figure without asking us for it.
Ground-truth review
How the labels behind your model were made, by whom, and where the process scores the model against its own past decisions.
Oversight assessment
Whether the clinician holding the override can exercise it in practice, measured on real use rather than read off the policy.
Technical documentation
One file built to answer EU AI Act Annex IV and FDA submission content together, rather than two documents restating each other.
Gap register
Every gap in one list, ordered by consequence to patients first and regulatory exposure second - not by which fix ships soonest.
Vendor-evidence assessment
What your vendor's clearance and validation study cover for your population and your use, what they do not, and what must be measured here.
Real numbers, upfront.
- Scope
- Agreed with you, then fixed
- Data
- A de-identified decision extract
- Re-review
- On every material retrain - $3,000 against your known baseline
Three regimes over an estate only you can size, so the fee is quoted rather than listed - and nothing is charged until you have approved it.
Request a healthcare AI audit- EU AI Act, FDA SaMD and HIPAA in one pass
- Sub-group performance on your own population
- Ground-truth and oversight review
- One gap register, ranked by patient impact
Four things you have to be able to produce
None of the three is graded on intent, and neither is a patient outcome. Each of these is either in your hand on the day somebody asks, or it is not.
The numbers,
by group
Performance by demographic group rather than in aggregate, on your own population. A single headline accuracy figure cannot answer the question being asked.
The labels,
traced
How ground truth was constructed, by whom, and against what. A model scored against its own historical decisions is circular, and it inflates every figure below it.
The override,
exercisable
Evidence that the clinician who holds the override can actually use it - the information, the time and the standing. A right nobody exercises is a right nobody has.
The file,
complete
One documentation package answering Annex IV and the FDA submission content: purpose, data, limitations, change history and who approved each change, dated.
Four cards, and the population on each one is part of the card.
Plain answers
Scope, timing, what we test, the engagement. Answered straight.
Request this auditOur vendor is FDA-cleared. Are we covered?
Clearance describes the device; it is not a statement about your patients. A published study describes the population it was validated on, and that population was not yours.
Is our system high-risk under the EU AI Act?
Clinical decision support, diagnostic tools and anything influencing medical treatment are named in Annex III. Administrative and patient-facing systems are judged on what the output does to a decision.
Nothing is being enforced yet. Why now?
No EU AI Act penalty has been issued against clinical AI and the high-risk regime is not yet in application. The technical file behind it is a year of work - and a sub-group finding does not wait for a regulator.
What exactly do you test?
Classification against Annex III, clinical validation evidence, sub-group accuracy on your own population, how ground truth was built, human oversight as clinicians actually use it, change control, monitoring, and PHI in the training data.
How long does it take, and what does it cost?
One to four weeks for most engagements. Scope and price are agreed and approved before any work begins, and nothing is charged until you approve what the engagement covers.
Deploying AI in a clinical or patient-facing context?
Tell us what decides, and we come back with a scope and a price within one business day.
What we need from you
Nothing you do not already have. Mostly your system inventory and a de-identified extract of decisions and outcomes, with every document named in writing first.
- Which systems decide, and at which point of care
- Whether they are built in-house, bought, or both
- A de-identified extract of decisions and outcomes
- Any validation already done, and on whose patients
- Your target date for a read, if you have one
What happens next
- You send the five items we need.
- We call to scope it within one business day.
- Nothing is charged until you approve it.
Where this page gets its facts
Where the claims on this page come from, and what they are worth - stated, not assumed.
What it is drawn from
- Regulation (EU) 2024/1689 - the AI Act
- FDA AI/ML SaMD guidance; HIPAA / HITECH
- Annex III from
- 2 December 2027
- Last read
- 9 September 2026
What it means
- General information about what these three regimes ask — one of which is guidance rather than law. Not legal, regulatory or clinical advice, and it determines nothing about your own systems.
- Where a classification is genuinely arguable, or the three pull in different directions, our reports say so rather than pick the convenient reading.
Scope & limitation
- Do not rest a binding decision on it; engage qualified counsel.
- Use it as a starting point for a scoping conversation, not as your final word.
- We are not a clinical safety authority and issue no clinical sign-off. What we produce is evidence for your own clinical governance to reach its conclusion on.
Something on this page out of date?
Tell usFrom Insights
Related reading
How to Prepare for an AI Audit: The Readiness Checklist
Six things to have ready before the engagement starts. Assembling them takes a fortnight off the clock — and tends to find the first two findings before an auditor does.
What Is an AI Audit? Scope, Standards, and What You Get
An independent review of what your AI actually does, measured against a named standard — not a certificate, and not a review of what the documentation says it does.
What an AI Governance Framework Actually Contains
Five working parts, not a policy document. What each one has to do, how to tell whether yours is real, and why a framework is not the same thing as compliance.
AI Compliance for Healthcare Providers: What Actually Applies
Four regimes reach clinical AI, and they ask different questions. What each one wants a provider to be able to show — and the two places health systems are most often caught short.