Skip to content
← All compliance guides·Industry Guides
🏥Critical Risk

AI Compliance for Healthcare

The most regulated AI sector: EU AI Act high-risk, FDA SaMD, HIPAA

Healthcare AI faces the highest compliance burden of any sector. Clinical decision support and diagnostic AI is classified as high-risk under the EU AI Act via Article 6(1) + Annex I (the MDR/IVDR product-safety route), may require FDA clearance as Software as a Medical Device, and must comply with HIPAA if it processes protected health information. Getting it right requires coordinating three regulatory frameworks simultaneously.

Applicable regulations

EU AI Act — High-Risk (Art. 6(1) + Annex I, MDR/IVDR route)

Critical Risk

Scope: AI embedded in an EU MDR/IVDR-regulated medical device used in clinical settings; separately, Annex III §5(a) covers non-device AI used for access/triage/resource-allocation decisions

Conformity assessment (folded into the MDR/IVDR notified-body procedure under Article 43(3)), technical documentation, human oversight design, logging, bias testing, EU AI database registration

Deadline: December 2, 2027 (deferred from August 2026)

US FDA — Software as a Medical Device (SaMD)

Critical Risk

Scope: AI clinical decision support tools in the US

Class I/II/III classification, 510(k) clearance or PMA, predicate device identification, clinical validation

Deadline: Before deployment

HIPAA Security and Privacy Rules

High Risk

Scope: Any AI processing protected health information

Business Associate Agreement with all AI vendors, minimum necessary standard, encryption, audit logging, breach notification

Deadline: Ongoing

EU Medical Device Regulation (MDR)

High Risk

Scope: AI-powered medical devices marketed in EU

MDR conformity assessment (coordinates with EU AI Act), CE marking, notified body review for Class IIb/III devices

Deadline: Before EU deployment

GDPR — Special Category Data

High Risk

Scope: Processing health data of EU residents

Explicit consent or Article 9(2)(h) exemption for health data, DPIA required, data minimization, retention limits

Deadline: Ongoing

What to do first

1

Determine FDA classification before building — engage FDA via Pre-Submission meeting for novel AI

2

Start EU AI Act technical documentation now — it takes 3–6 months minimum for clinical AI

3

Sign Business Associate Agreements with all AI vendors before any PHI is processed

4

Design human oversight into clinical UX — AI should present confidence levels, not certainties

5

Implement comprehensive inference logging from day one — retrofitting is painful

6

Ensure training data is demographically diverse — document this explicitly

Estimated compliance cost

$80,000–$250,000 initial + $20,000–$50,000/year ongoing

Proactive compliance typically costs 3–5× less than post-enforcement remediation.

Generate your healthcare AI compliance plan

Aegis Firma maps your specific AI systems against all applicable regulations for healthcare — and generates prioritized documentation across 169 jurisdictions.

Get Healthcare compliance plan

Further reading

Other industry guides