FDA’s risk-based framework for standalone medical software, aligned with IMDRF. Note: FDA withdrew the SaMD Clinical Evaluation guidance in January 2026.
Visit →Frameworks that make digital health legible, evaluable, deployable.
Curated regulatory pathways, evaluation frameworks, AI assurance standards, and interoperability references — the documents healthcare innovators, clinicians, and policy professionals actually use to build, evaluate, and deploy.
The rules of market access.
FDA, EU, UK, and global medical-device regulators determine who can ship a digital health product, in what category, and with what evidence. Several of these frameworks were materially updated in early 2026.
FDA’s coordinating hub for digital health policy. Houses the TEMPO pilot launched with CMS in early 2026, Pre-Cert lessons learned, and AI/ML strategy.
Visit →Defines the four-criteria test under the 21st Century Cures Act for distinguishing non-device CDS from regulated SaMD. Updated January 2026.
Visit →Final FDA guidance establishing PCCPs for managing modifications to AI/ML-enabled devices across the total product lifecycle.
Visit →Ten guiding principles for ML medical-device development, originally authored by FDA, Health Canada, and the UK MHRA in 2021, now formalized as a final IMDRF document (January 2025) to drive international harmonization.
Visit →Updated January 2026. Defines what falls outside FDA medical device oversight, with expanded examples covering wearables and non-invasive monitoring.
Visit →Successor to the Medical Device Directive. Governs SaMD, digital therapeutics, and AI-enabled medical devices placed on the EU market. A targeted simplification proposal was tabled in December 2025.
Visit →Risk-tiered AI regulation. Most healthcare AI falls in the high-risk category, requiring conformity assessment, transparency, and human oversight.
Visit →UK regulator’s roadmap and guidance for SaMD and AI as a Medical Device, shaping the post-Brexit UK regulatory regime.
Visit →Risk-based pathway for SaMD aligned with IMDRF. Co-author of the GMLP guiding principles with FDA and MHRA.
Visit →International harmonized definitions, risk categorization, quality management, and clinical evaluation principles for SaMD.
Visit →WHO’s global guidance on regulatory considerations for AI/ML medical devices, intended to support harmonization across member states.
Visit →Does it actually work?
The frameworks the field uses to evaluate whether a digital health product does what it says — from clinical validation, to outcomes measurement, to evidence-based reporting standards.
Foundational framework for digital clinical measures: Verification, Analytical validation, Clinical validation. Extended by V3+ Usability Validation.
Visit →Practitioner playbooks covering Digital Clinical Measures, Digital Healthcare, Pediatric Digital Medicine, and Implementing AI in Healthcare.
Visit →UK reference for the level of evidence needed to demonstrate effectiveness and value across digital health technology risk tiers.
Visit →Standardized outcome measurement across 46 Sets covering roughly 60 percent of the global disease burden, designed to enable global benchmarking of value-based care.
Visit →UK-based digital health assessment platform. Powers app libraries for the NHS and other health systems through standardized review.
Visit →Independent institute publishing evidence-based assessments of digital health solutions across value, clinical impact, and adoption.
Visit →Five-pillar assessment for NHS-bound digital health products: clinical safety, data protection, technical assurance, interoperability, usability. Refreshed Feb 2026 with a 25 percent question reduction.
Visit →Reporting guidelines for clinical trials of AI interventions. Extensions to CONSORT (results) and SPIRIT (protocols).
Visit →Reporting guideline for early-stage clinical evaluation of AI decision support, covering the gap between offline validation and randomized trials.
Visit →Transparent Reporting of multivariable prediction models, AI extension. Covers diagnostic and prognostic AI/ML model reporting.
Visit →Extension of TRIPOD+AI addressing the unique reporting challenges of large language models in biomedical and healthcare applications, with a 19-item checklist covering explainability, transparency, and human oversight.
Visit →Reporting standard for systematic reviews of clinical AI studies, extending PRISMA to address AI-specific methodological considerations.
Visit →U.S. federal R&D agency funding high-risk, high-reward biomedical and digital health programs across diagnostics, AI, and care delivery.
Visit →Who’s watching the AI.
Governance, assurance, and ethics frameworks specific to health AI. The layer between regulatory pathways and operational deployment — what health systems are increasingly required to demonstrate.
CHAI’s primary playbook for ethical and quality-assured deployment of AI in healthcare, paired with the Assurance Standards Guide.
Visit →Following September 2025 joint guidance with CHAI, Joint Commission launched its voluntary RUAIH certification in June 2026, covering governance, data management, bias reduction, monitoring, and transparency. Organizations do not need Joint Commission accreditation to apply.
Visit →Voluntary U.S. framework for governing, mapping, measuring, and managing AI risk. Widely adopted across health AI assurance programs. A Critical Infrastructure Profile was announced in April 2026.
Visit →Companion profile to the AI RMF specifically addressing generative AI risks, including hallucination, content provenance, and prompt injection.
Visit →First international certifiable standard for AI management systems. Specifies requirements for establishing, implementing, and continually improving an AIMS.
Visit →Companion standard to ISO/IEC 42001 providing guidance on assessing how AI systems affect individuals, groups, and society across their lifecycle, and how to integrate that assessment into an AI management system.
Visit →Foundational risk management standard required for SaMD and most medical device regulatory submissions worldwide.
Visit →Software lifecycle processes for medical device software. A major Edition 2 revision — replacing the three safety classes with two process rigor levels and adding AI/ML lifecycle provisions — is in FDIS stage, expected late 2026 or early 2027.
Visit →Six core ethical principles for AI in health, with companion 2024 guidance on large multi-modal models (LMMs).
Visit →Unifying AI Code of Conduct framework with six Code Commitments and ten Code Principles for health, health care, and biomedical science, informing the CHAI and NIST frameworks.
Visit →HTI-1 established decision-support intervention (DSI) transparency requirements for ONC-certified EHRs. ONC has since withdrawn non-finalized HTI-2 provisions and proposed the deregulatory HTI-5 rule (Dec 2025), scaling the certification program toward a FHIR-first approach.
Visit →International principles for trustworthy AI, adopted by 47 adherents and informing healthcare AI policy globally.
Visit →Master library of more than 700 health research reporting guidelines. Hosts CONSORT, STROBE, PRISMA, TRIPOD, SPIRIT, and their AI extensions.
Visit →Common Security Framework harmonizing 70+ regulations and standards including HIPAA, NIST, ISO 27001, and PCI. Now offers dedicated AI Security and AI Risk Management assessment products.
Visit →ARPA-H’s Digital Health Security Initiative — a federal program funding technology to strengthen the nation’s digital health infrastructure against cyberattacks.
Visit →The plumbing.
How digital health systems exchange data, structure information, and connect to the broader healthcare infrastructure. Without these, nothing scales.
Fast Healthcare Interoperability Resources. The dominant modern healthcare data exchange standard, mandated for U.S. EHRs and increasingly globally.
Visit →App platform standard built on FHIR and OAuth 2.0. The standard pathway for third-party clinical apps to plug into EHRs.
Visit →United States Core Data for Interoperability. Standardized data classes that ONC-certified health IT must support, expanded annually.
Visit →Trusted Exchange Framework and Common Agreement. National-scale health information exchange via Qualified Health Information Networks (QHINs) — over 1.5 billion documents shared as of mid-2026.
Visit →Digital Imaging and Communications in Medicine. The universal standard for medical image storage, exchange, and metadata.
Visit →Family of standards for communication between personal health devices, wearables, and remote monitoring systems.
Visit →Comprehensive clinical terminology used across EHRs globally. The most widely-deployed clinical reference terminology in the world.
Visit →Universal coding system for laboratory tests, clinical observations, and survey instruments. Required by USCDI and used by every major lab.
Visit →Observational Medical Outcomes Partnership Common Data Model. Standardized data model used for federated observational health research at scale.
Visit →Frequently asked questions.
Quick answers about which frameworks apply to which products, who needs to comply, and how the layers fit together.
What is Software as a Medical Device (SaMD) and how does the FDA regulate it?
What frameworks govern AI assurance and safety in healthcare?
What is the V3 framework for digital clinical measures?
Which standards make digital health systems interoperable?
What reporting guidelines apply to clinical AI studies?
How do U.S. and EU digital health regulations differ?
What is the NHS DTAC and who needs to comply?
What is the difference between ISO 14971, IEC 62304, and ISO/IEC 42001?
Which frameworks are most important for digital health startups to know?
Get the Digital.Health newsletter.
Curated digital health news, framework updates, and platform releases — delivered to your inbox. Join 30,000+ clinicians, innovators, and health leaders.
Subscribe free →Complete index of digital health frameworks and standards
Digital.Health curates 49 essential frameworks and standards across four categories: Regulatory frameworks & pathways (12), Evaluation & evidence frameworks (13), AI assurance, safety & responsible use (15), and Technical standards & interoperability (9).
Curated by Daniel Kraft, MD, Stanford- and Harvard-trained physician-scientist and Founder of Digital.Health.
Common questions this index answers: What is Software as a Medical Device (SaMD) and how does the FDA regulate it? What frameworks govern AI assurance and safety in healthcare? What is the V3 framework for digital clinical measures? Which standards make digital health systems interoperable? What reporting guidelines apply to clinical AI studies? How do U.S. and EU digital health regulations differ? What is the NHS DTAC and who needs to comply? What is the difference between ISO 14971, IEC 62304, and ISO/IEC 42001? Which frameworks are most important for digital health startups to know?
Topics covered: FDA Software as a Medical Device, EU MDR and AI Act, MHRA AI as a Medical Device, IMDRF harmonization, WHO AI for health, DiMe V3+ framework, NICE Evidence Standards Framework, ICHOM outcome measurement, NHS DTAC, Peterson Health Technology Institute, CONSORT-AI / SPIRIT-AI, DECIDE-AI, TRIPOD+AI, TRIPOD-LLM, PRISMA-AI, ARPA-H, ARPA-H DIGIHEALS, CHAI Responsible AI Guide, Joint Commission RUAIH certification, NIST AI Risk Management Framework, ISO/IEC 42001, ISO/IEC 42005, ISO 14971, IEC 62304, WHO AI ethics, NAM AI Code of Conduct, ONC HTI rules, OECD AI Principles, EQUATOR Network, HITRUST CSF, HL7 FHIR, SMART on FHIR, USCDI, TEFCA, DICOM, IEEE 11073, SNOMED CT, LOINC, OMOP Common Data Model.