Frameworks that make digital health legible, evaluable, deployable.

Curated regulatory pathways, evaluation frameworks, AI assurance standards, and interoperability references — the documents healthcare innovators, clinicians, and policy professionals actually use to build, evaluate, and deploy.

49Frameworks & standards
4Editorial categories
17Updated in 2025—26
Aug 2026Last updated
01 · Regulatory frameworks & pathways

The rules of market access.

FDA, EU, UK, and global medical-device regulators determine who can ship a digital health product, in what category, and with what evidence. Several of these frameworks were materially updated in early 2026.

U.S. FDA USA Active
FoundationalUpdated 2026

FDA’s risk-based framework for standalone medical software, aligned with IMDRF. Note: FDA withdrew the SaMD Clinical Evaluation guidance in January 2026.

Visit →
FDA · Health Canada · MHRA · IMDRF Tri-regulator Active
AI/MLUpdated 2025

Ten guiding principles for ML medical-device development, originally authored by FDA, Health Canada, and the UK MHRA in 2021, now formalized as a final IMDRF document (January 2025) to drive international harmonization.

Visit →
European Commission EU Active
EURegulation

Successor to the Medical Device Directive. Governs SaMD, digital therapeutics, and AI-enabled medical devices placed on the EU market. A targeted simplification proposal was tabled in December 2025.

Visit →
European Union EU Phased rollout
EUAI Regulation

Risk-tiered AI regulation. Most healthcare AI falls in the high-risk category, requiring conformity assessment, transparency, and human oversight.

Visit →
02 · Evaluation & evidence frameworks

Does it actually work?

The frameworks the field uses to evaluate whether a digital health product does what it says — from clinical validation, to outcomes measurement, to evidence-based reporting standards.

Digital Medicine Society Global Free
FoundationalValidation

Foundational framework for digital clinical measures: Verification, Analytical validation, Clinical validation. Extended by V3+ Usability Validation.

Visit →
Digital Medicine Society Global Free
PractitionerImplementation

Practitioner playbooks covering Digital Clinical Measures, Digital Healthcare, Pediatric Digital Medicine, and Implementing AI in Healthcare.

Visit →
ICHOM Global Free
OutcomesValue-based

Standardized outcome measurement across 46 Sets covering roughly 60 percent of the global disease burden, designed to enable global benchmarking of value-based care.

Visit →
ORCHA UK Active
UKApp Assessment

UK-based digital health assessment platform. Powers app libraries for the NHS and other health systems through standardized review.

Visit →
NHS England UK Refreshed Feb 2026
UKUpdated 2026

Five-pillar assessment for NHS-bound digital health products: clinical safety, data protection, technical assurance, interoperability, usability. Refreshed Feb 2026 with a 25 percent question reduction.

Visit →
EQUATOR Network Global Free
ReportingTrials

Reporting guidelines for clinical trials of AI interventions. Extensions to CONSORT (results) and SPIRIT (protocols).

Visit →
DECIDE-AI Steering Group Global Free
ReportingDecision Support

Reporting guideline for early-stage clinical evaluation of AI decision support, covering the gap between offline validation and randomized trials.

Visit →
TRIPOD Group Global Free
ReportingPrediction Models

Transparent Reporting of multivariable prediction models, AI extension. Covers diagnostic and prognostic AI/ML model reporting.

Visit →
TRIPOD Group Global Free
NewLLM Reporting

Extension of TRIPOD+AI addressing the unique reporting challenges of large language models in biomedical and healthcare applications, with a 19-item checklist covering explainability, transparency, and human oversight.

Visit →
EQUATOR Network Global Free
ReportingSystematic Reviews

Reporting standard for systematic reviews of clinical AI studies, extending PRISMA to address AI-specific methodological considerations.

Visit →
ARPA-H USA Active funding
USAR&D

U.S. federal R&D agency funding high-risk, high-reward biomedical and digital health programs across diagnostics, AI, and care delivery.

Visit →
03 · AI assurance, safety & responsible use

Who’s watching the AI.

Governance, assurance, and ethics frameworks specific to health AI. The layer between regulatory pathways and operational deployment — what health systems are increasingly required to demonstrate.

Coalition for Health AI USA Free
USAHealth AI

CHAI’s primary playbook for ethical and quality-assured deployment of AI in healthcare, paired with the Assurance Standards Guide.

Visit →
Joint Commission · CHAI USA Live since June 2026
Certification liveUSA

Following September 2025 joint guidance with CHAI, Joint Commission launched its voluntary RUAIH certification in June 2026, covering governance, data management, bias reduction, monitoring, and transparency. Organizations do not need Joint Commission accreditation to apply.

Visit →
NIST USA Voluntary
USAFoundational

Voluntary U.S. framework for governing, mapping, measuring, and managing AI risk. Widely adopted across health AI assurance programs. A Critical Infrastructure Profile was announced in April 2026.

Visit →
NIST USA Active
USAGenAI

Companion profile to the AI RMF specifically addressing generative AI risks, including hallucination, content provenance, and prompt injection.

Visit →
ISO Global Certifiable
GlobalCertifiable

First international certifiable standard for AI management systems. Specifies requirements for establishing, implementing, and continually improving an AIMS.

Visit →
ISO Global Published May 2025
NewImpact Assessment

Companion standard to ISO/IEC 42001 providing guidance on assessing how AI systems affect individuals, groups, and society across their lifecycle, and how to integrate that assessment into an AI management system.

Visit →
IEC Global Edition 2 pending
GlobalSoftware Lifecycle

Software lifecycle processes for medical device software. A major Edition 2 revision — replacing the three safety classes with two process rigor levels and adding AI/ML lifecycle provisions — is in FDIS stage, expected late 2026 or early 2027.

Visit →
National Academy of Medicine USA Published May 2025
USACode of Conduct

Unifying AI Code of Conduct framework with six Code Commitments and ten Code Principles for health, health care, and biomedical science, informing the CHAI and NIST frameworks.

Visit →
ONC USA Under revision
USAUpdated 2026

HTI-1 established decision-support intervention (DSI) transparency requirements for ONC-certified EHRs. ONC has since withdrawn non-finalized HTI-2 provisions and proposed the deregulatory HTI-5 rule (Dec 2025), scaling the certification program toward a FHIR-first approach.

Visit →
OECD Global Free
GlobalPrinciples

International principles for trustworthy AI, adopted by 47 adherents and informing healthcare AI policy globally.

Visit →
EQUATOR Network Global Free
GlobalLibrary

Master library of more than 700 health research reporting guidelines. Hosts CONSORT, STROBE, PRISMA, TRIPOD, SPIRIT, and their AI extensions.

Visit →
HITRUST Alliance USA Certifiable
USASecurity

Common Security Framework harmonizing 70+ regulations and standards including HIPAA, NIST, ISO 27001, and PCI. Now offers dedicated AI Security and AI Risk Management assessment products.

Visit →
ARPA-H USA Active funding
NewCybersecurity

ARPA-H’s Digital Health Security Initiative — a federal program funding technology to strengthen the nation’s digital health infrastructure against cyberattacks.

Visit →
04 · Technical standards & interoperability

The plumbing.

How digital health systems exchange data, structure information, and connect to the broader healthcare infrastructure. Without these, nothing scales.

Health Level Seven International Global Free
FoundationalInterop

Fast Healthcare Interoperability Resources. The dominant modern healthcare data exchange standard, mandated for U.S. EHRs and increasingly globally.

Visit →
SMART Health IT Global Free
AppsEHR

App platform standard built on FHIR and OAuth 2.0. The standard pathway for third-party clinical apps to plug into EHRs.

Visit →
ONC USA Annual updates
USAData Classes

United States Core Data for Interoperability. Standardized data classes that ONC-certified health IT must support, expanded annually.

Visit →
Sequoia Project USA 1.5B+ docs shared
USAHIE

Trusted Exchange Framework and Common Agreement. National-scale health information exchange via Qualified Health Information Networks (QHINs) — over 1.5 billion documents shared as of mid-2026.

Visit →
NEMA / MITA Global Free
GlobalImaging

Digital Imaging and Communications in Medicine. The universal standard for medical image storage, exchange, and metadata.

Visit →
SNOMED International Global Licensed
GlobalTerminology

Comprehensive clinical terminology used across EHRs globally. The most widely-deployed clinical reference terminology in the world.

Visit →
Regenstrief Institute Global Free
GlobalLab Codes

Universal coding system for laboratory tests, clinical observations, and survey instruments. Required by USCDI and used by every major lab.

Visit →
OHDSI Global Free
GlobalResearch

Observational Medical Outcomes Partnership Common Data Model. Standardized data model used for federated observational health research at scale.

Visit →
Common questions

Frequently asked questions.

Quick answers about which frameworks apply to which products, who needs to comply, and how the layers fit together.

What is Software as a Medical Device (SaMD) and how does the FDA regulate it?
Software as a Medical Device (SaMD) is software intended for medical purposes that performs those purposes without being part of a hardware medical device. The FDA regulates SaMD using a risk-based approach aligned with the International Medical Device Regulators Forum (IMDRF) framework. Key FDA guidance includes the 510(k) pathway, De Novo classification, Predetermined Change Control Plans (PCCPs) for AI/ML, Good Machine Learning Practice (GMLP), and the Clinical Decision Support Software guidance updated in January 2026. The FDA had authorized over 1,350 AI-enabled medical devices by early 2026.
What frameworks govern AI assurance and safety in healthcare?
The leading AI assurance frameworks for healthcare include the CHAI Responsible AI Guide (RAIG) and Assurance Standards Guide from the Coalition for Health AI; the Joint Commission Responsible Use of AI in Healthcare (RUAIH) Certification, launched June 2026 following the September 2025 joint guidance with CHAI; the NIST AI Risk Management Framework with its Generative AI Profile; ISO/IEC 42001 for AI management systems and its companion ISO/IEC 42005 for AI system impact assessment; the National Academy of Medicine AI Code of Conduct; and the WHO Ethics and Governance of AI for Health. Together these frameworks shape how U.S. health systems govern, evaluate, and deploy clinical AI. See the full AI assurance & safety section.
What is the V3 framework for digital clinical measures?
The V3 framework, developed by the Digital Medicine Society (DiMe), evaluates digital clinical measures across three layers: Verification (do the sensors capture what they claim to capture), Analytical validation (does the algorithm convert sensor data accurately), and Clinical validation (does the measure correspond to the clinical concept of interest in the target population). DiMe has since published V3+ Usability Validation as an extension. The V3 framework has been accessed over 30,000 times and adopted by NIH, FDA, and the European Medicines Agency. See also the DiMe Playbooks.
Which standards make digital health systems interoperable?
The core interoperability standards are HL7 FHIR (Fast Healthcare Interoperability Resources, the dominant modern data exchange standard), SMART on FHIR (the app platform standard for plugging third-party apps into EHRs), USCDI (United States Core Data for Interoperability), and TEFCA (national-scale health information exchange via QHINs, past 1.5 billion documents shared as of mid-2026). Additional standards include DICOM for imaging, SNOMED CT for clinical terminology, LOINC for lab observations, and the OMOP Common Data Model for observational research. See the full technical & interoperability section.
What reporting guidelines apply to clinical AI studies?
The leading reporting guidelines for clinical AI studies are CONSORT-AI / SPIRIT-AI (clinical trial results and protocols), DECIDE-AI (early-stage clinical evaluation of AI decision support), TRIPOD+AI (transparent reporting of AI prediction models), TRIPOD-LLM (a newer extension for large language models), and PRISMA-AI (systematic reviews of clinical AI). All are hosted by the EQUATOR Network, which maintains the master library of over 700 health research reporting guidelines.
How do U.S. and EU digital health regulations differ?
The U.S. regulates digital health primarily through the FDA’s risk-based SaMD framework, with the 21st Century Cures Act exempting certain Clinical Decision Support software. The EU regulates through the Medical Device Regulation (MDR 2017/745), which classifies software based on risk and requires CE marking through Notified Bodies. The EU AI Act adds an additional layer specifically for AI systems, classifying most healthcare AI as high-risk and requiring conformity assessment, transparency, and human oversight. The UK MHRA operates a parallel post-Brexit regime, while Health Canada and the IMDRF help harmonize across regulators.
What is the NHS DTAC and who needs to comply?
The NHS Digital Technology Assessment Criteria (DTAC) is the national baseline assessment framework for digital health technologies entering the NHS in England. It covers five areas: clinical safety, data protection, technical assurance, interoperability, and usability and accessibility. Any supplier or developer wishing to make a digital health product available to NHS organizations must complete a DTAC assessment. NHS England refreshed the DTAC in February 2026 with a 25 percent reduction in questions and clearer scope alignment with NICE.
What is the difference between ISO 14971, IEC 62304, and ISO/IEC 42001?
ISO 14971 is the foundational risk management standard for medical devices, required for nearly every regulatory submission worldwide. IEC 62304 specifies the software lifecycle processes for medical device software, including SaMD; a major Edition 2 revision is in FDIS stage, expected late 2026 or early 2027. ISO/IEC 42001 is the first international certifiable standard for AI management systems, specifying how organizations should govern, design, deploy, and continually improve AI products, complemented by ISO/IEC 42005 for AI system impact assessment. Together they form the standards backbone for compliant SaMD and AI-enabled medical device development.
Which frameworks are most important for digital health startups to know?
Digital health startups should prioritize understanding the FDA SaMD framework (or the EU MDR for European markets), HL7 FHIR for interoperability, ISO 14971 for risk management, IEC 62304 for software lifecycle, the DiMe V3+ framework for evidence generation, the NIST AI Risk Management Framework or ISO/IEC 42001 for AI products, and HITRUST CSF for security. For U.S. health system buyers, the CHAI Responsible AI Guide and the Joint Commission’s RUAIH certification are increasingly required. UK-bound products must additionally satisfy the NHS DTAC and the NICE Evidence Standards Framework.
Stay ahead

Get the Digital.Health newsletter.

Curated digital health news, framework updates, and platform releases — delivered to your inbox. Join 30,000+ clinicians, innovators, and health leaders.

Subscribe free →

Complete index of digital health frameworks and standards

Digital.Health curates 49 essential frameworks and standards across four categories: Regulatory frameworks & pathways (12), Evaluation & evidence frameworks (13), AI assurance, safety & responsible use (15), and Technical standards & interoperability (9).

Curated by Daniel Kraft, MD, Stanford- and Harvard-trained physician-scientist and Founder of Digital.Health.

Common questions this index answers: What is Software as a Medical Device (SaMD) and how does the FDA regulate it? What frameworks govern AI assurance and safety in healthcare? What is the V3 framework for digital clinical measures? Which standards make digital health systems interoperable? What reporting guidelines apply to clinical AI studies? How do U.S. and EU digital health regulations differ? What is the NHS DTAC and who needs to comply? What is the difference between ISO 14971, IEC 62304, and ISO/IEC 42001? Which frameworks are most important for digital health startups to know?

Topics covered: FDA Software as a Medical Device, EU MDR and AI Act, MHRA AI as a Medical Device, IMDRF harmonization, WHO AI for health, DiMe V3+ framework, NICE Evidence Standards Framework, ICHOM outcome measurement, NHS DTAC, Peterson Health Technology Institute, CONSORT-AI / SPIRIT-AI, DECIDE-AI, TRIPOD+AI, TRIPOD-LLM, PRISMA-AI, ARPA-H, ARPA-H DIGIHEALS, CHAI Responsible AI Guide, Joint Commission RUAIH certification, NIST AI Risk Management Framework, ISO/IEC 42001, ISO/IEC 42005, ISO 14971, IEC 62304, WHO AI ethics, NAM AI Code of Conduct, ONC HTI rules, OECD AI Principles, EQUATOR Network, HITRUST CSF, HL7 FHIR, SMART on FHIR, USCDI, TEFCA, DICOM, IEEE 11073, SNOMED CT, LOINC, OMOP Common Data Model.