Healthcare AI Compliance

Clinical AI, diagnostic tools, and patient-facing systems — independently audited against the EU AI Act, FDA SaMD guidance, and HIPAA

Clinical decision support, diagnostic AI, and triage systems are classified high-risk under the EU AI Act Annex III. US regulators are signalling enforcement is next. The pre-enforcement window is open — and will not stay open indefinitely.

Healthcare at a glance iDharma
Annex III EU AI Act classification
Healthcare AI systems are directly named as high-risk — obligations apply from August 2026
$45M 2026 enforcement precedent
EU AI hiring platform fine for human-oversight failures — directly transferable to clinical AI precedent
Jan 2026 State-level obligation
Texas TRAIGA healthcare-AI provisions effective — verify current scope before relying on this date
Measured against NIST AI RMF ISO/IEC 42001 EU AI Act HIPAA SOC 2 India DPDP

What we audit

AI systems in scope for Healthcare

Every system below is covered in a standard iDharma engagement. Complex or multi-system deployments are scoped on request.

Clinical decision support (CDS)

AI recommending diagnosis, treatment, or triage decisions — EU AI Act Annex III classification, FDA SaMD pathway, and clinical validation evidence.

Diagnostic imaging AI

Radiology, pathology, and ophthalmology AI — performance benchmarking by demographic, ground truth construction, and sub-group accuracy disparities.

Patient-facing AI

Chatbots, symptom checkers, and mental-health tools — transparency obligations, safeguarding requirements, and accuracy in high-stakes contexts.

Administrative and operational AI

Prior authorisation automation, billing AI, and staffing models — fair treatment, auditability, and data governance.

Regulatory frameworks

What we audit against

Every iDharma Healthcare engagement maps simultaneously against the frameworks below — producing one gap register, not three separate reports.

EU AI Act — Annex III

Clinical decision support, diagnostic tools, and any AI influencing medical treatment is high-risk. Conformity assessment, technical documentation, and ongoing monitoring are mandatory.

FDA Software as a Medical Device (SaMD)

AI/ML-based SaMD requires a predetermined change-control plan and real-world performance monitoring. FDA has issued guidance on transparency and bias expectations.

HIPAA / HITECH

Training data for healthcare AI almost always includes PHI. Data governance, de-identification, and access control requirements apply to the full AI development lifecycle.

Our methodology

How an iDharma audit works

We do not accept vendor documentation as evidence, and we do not produce checkbox compliance reports. Every audit gives you a named auditor, a cited methodology, and a straight answer on where your AI stands.

01

We evaluate clinical AI against both the EU AI Act technical file requirements and FDA SaMD pre-market expectations — in a single engagement.

02

We independently assess sub-group accuracy across demographic groups — aggregate accuracy that masks disparate performance is a patient harm and a regulatory liability.

03

We review the ground truth construction process for diagnostic AI — models evaluated against their own historical decisions have circularity problems that inflate apparent accuracy.

04

We verify that human oversight mechanisms are effective in practice, not just documented — regulators have penalised firms where oversight existed on paper but personnel lacked the capability to intervene.

Get started

Deploying AI in a clinical or patient-facing context?

Start with the free Risk Snapshot to understand your EU AI Act and FDA exposure before the compliance window closes.

Your situation

“AI is already making healthcare decisions — with no independent proof it holds up.”

In 1–4 weeks

One prioritised gap register mapped to the frameworks you answer to — signed by a named auditor.

Scoped before you pay — nothing is charged until you approve what the engagement covers.