UK: Digital Health In The UK: The New Regulatory Environment Under The Medical Device Regulation

Investment in artificial intelligence (AI) and digital health technologies has increased exponentially over the last few years. In the United Kingdom, the excitement and interest in this space has been supported by NHS policies, including proposals in the NHS Long Term Plan, which set out ambitious aims for the acceleration and adoption of digital health and AI, particularly in primary care, outpatients and wearable devices.

Although these developments are encouraging to developers, there is still no clear framework for reimbursement or tariffs for digital health tools and AI.

At the same time, the plethora of new technologies has led to increased calls for regulation and oversight, particularly around data quality and evaluation. Many of these concerns may be addressed by the new Medical Device Regulation (MDR) and other regulatory developments. In fact, there is some risk that while regulatory landscape is moving quickly, the pricing environment is still a way behind.

In May 2020, the new MDR will change the law and process of certification for medical software. The new law includes significant changes for digital health technologies which are medical devices. In March 2019, the National Institute for Health and Care Excellence (NICE) also published a new evidence standards framework for digital health technologies. The Care Quality Commission (CQC) already regulates online provision of health care, and there are calls for wider and greater regulation. The government has also published a code on the use of data in AI.

Digital Health Technologies and the MDR

The new MDR will mean a significant change to the regulatory framework for medical devices in the European Union.

As with the previous law, the MDR regulates devices through a classification system.

The new regime introduces new rules for medical software that falls within the definition of device. This will mean significant changes for companies that develop or offer medical software solutions, especially if their current certification has been "up-classed" under the MDR.

Key Takeaways for Investors in Digital Health Tools

Companies and investors in digital health should:

  • Check whether their digital health tool is a medical device and caught by the MDR.
  • Review whether their proposed or current certification has changed under the new MDR.
  • Assess the new requirements on certification and general safety in the MDR as those apply to digital health tools.
  • Ensure that development programmes have taken into account the likely time period for certification, which may be lengthy due to shortages in Notified Bodies.
  • Build in the cost of any increased certification requirements and costs of compliance.
  • Take into account the CQC guidance for digital and online health care, and check whether the health tool and service will require CQC registration.
  • If the digital health tool is to be marketed and sold to NHS organisations, understand and take into account the NICE evidence standards framework for digital health technologies. Whilst these are stated to be complementary to the new MDR, the framework has different assessments and evidence requirements.
  • Have a clear strategy about access to market and reimbursement of technologies.
  • Consider the government's Code of Conduct for data driven health and care technology.
  • Understand the implications of a "no deal" Brexit, especially if the technology is marketed across Europe.

Medical Devices Regulation 2017: FAQ

When is software a medical device?

The MDR sets out clear rules on this, which are broadly similar to the previous position but provide helpful clarification.

The key test relates to the purpose of the software. The MDR states:

  • Software in its own right, when specifically intended by the manufacturer to be used for one or more medical purposes, is a medical device.

Example: software used for diagnosis, or predicting disease

  • Software for a general purpose, even if used in a health care setting, is not a medical device.

Example: medical records software used as a storage or retrieval system

  • Software for lifestyle or well-being purposes is not a medical device.

Example: apps which monitor fitness levels, diet and wellbeing

Many companies offering medical software will be familiar with the existing rules, but it is important to know that whilst the MDR principles are broadly similar to the old rules, the MDR introduces new requirements on classification of devices. These new classification requirements will affect many companies offering online health care tools, diagnosis and prediction tools, and software and AI.

What are the new classification rules?

The MDR sets out some specific criteria around the classification of medical software, which is likely to mean that many devices which currently qualify as class I under the existing regime (MDD) may move up a class under the MDR.

The new rules are as follows:

  • Software intended to provide information used to take decisions with diagnosis or therapeutic purposes are Class IIa.
  • Software where these decisions have an impact that may cause a serious deterioration of a person's state of health or a surgical intervention are Class IIb.
  • Software where these decisions have an impact that may cause death or an irreversible deterioration in a person's health are Class III.
  • All other software is Class I.

Whilst some software may remain as Class I, many devices are likely to move up a class level.

This will mean more onerous responsibilities and increased rigour (and time) in relation to the certification of the device.

When do the new rules come into force for medical software?

The MDR came into force on 25 May 2017 but does not apply fully until May 2020.

The MDR includes transition provisions for existing devices. The general principle is that certificates issued by Notified Bodies under the MDD will remain valid, but for varying periods depending on the certification.

Many digital health tools are currently self-certified as Class I devices. If medical software continues to be a Class I device under the MDR, there is likely to be little practical difference for manufacturers, although manufacturers will need to comply with the increased obligations under the MDR.

However, for current Class I devices which are "up-classed" under the MDR, the position is a little less clear. There are no express provisions in the MDR which deal with up-classing, and the express transitional provisions protect certificates "issues by Notified Bodies" rather than to self-certified devices.

The prudent interpretation is that self-certification does not survive an up-class. This means that manufacturers of up-classed medical software will need to comply with the MDR and obtain certification from the MDR from May 2020.

What is the position of Notified Bodies and the timing of certification?

Notified Bodies are the organisations responsible for the issue of certificates for medical devices under both the MDD and the MDR.

There are currently serious concerns about the workloads of Notified Bodies and the impact this may have on the timing of certification. Some estimates suggest that the workload of Notified Bodies has increased seven-fold as a result of MDR changes.

This issue is exacerbated because certain Notified Bodies have also announced their intention not to pursue designation under the MDR, and no new organisations have applied to be Notified Bodies under the MDR.

What are the new data, safety and evaluation requirements under MDR?

Manufacturers must, of course, be mindful of data protection laws that apply to the development, trialling and use of medical devices.

The MDR sets out greater rigour about the evaluation of software and the datasets used to verify and validate medical devices. Manufacturers will need to be able to show how their device has been tested to demonstrate conformity, in particular with regards to safety. For software, this includes detailed information about test design, study protocols, methods of data analysis in addition to data summaries and test conclusions, in particular about software verification and validation (describing the software design and development process and evidence of the validation of the software, as used in the finished device).

For clinical evaluations, the manufacturer also must ensure that the data is evaluated and relevant to the risks and purpose of the device in question.

In addition to the general safety requirements that apply to all medical devices, the MDR sets out some specific requirements for medical software. These new requirements include instructions for use of the software, which must contain minimum requirements for hardware and IT security measures and protections against unauthorised access.

When does software qualify as an accessory?

In some cases, software may also be an accessory (and therefore must comply with the certification rules for accessories). To qualify as an accessory, the software would have either (i) to enable the medical device to function, or (ii) to specifically and directly assist the medical functionality of the device.

This consideration is especially relevant to the interoperability of software used as components or in conjunction with medical devices. There is no guidance on how these new rules in the MDR will work in practice, and it may sometimes be difficult to assess whether software is a device itself or an accessory.

It is also possible that where different medical devices are offered on the market as a single system, multiple certifications may be required.

How will a "no-deal" Brexit affect digital health regulation?

Under the terms of the current proposed withdrawal agreement, the European Union and the United Kingdom will continue to operate under the existing recognition of certifications across Member States.

However, if there is no deal, those transitional mutual recognition provisions will not apply. This is relevant to UK digital health providers that rely on their UK certification across Europe. From the date of Brexit, a UK manufacturer of a medical device will need to ensure that its device is certified by an EU Notified Body before it is placed on the EU market.

Digital Health In The UK: The New Regulatory Environment Under The Medical Device Regulation

The content of this article is intended to provide a general guide to the subject matter. Specialist advice should be sought about your specific circumstances.

To print this article, all you need is to be registered on

Click to Login as an existing user or Register so you can print this article.

Similar Articles
Relevancy Powered by MondaqAI
CMS Cameron McKenna Nabarro Olswang LLP
In association with
Related Topics
Similar Articles
Relevancy Powered by MondaqAI
CMS Cameron McKenna Nabarro Olswang LLP
Related Articles
Related Video
Up-coming Events Search
Font Size:
Mondaq on Twitter
Mondaq Free Registration
Gain access to Mondaq global archive of over 375,000 articles covering 200 countries with a personalised News Alert and automatic login on this device.
Mondaq News Alert (some suggested topics and region)
Select Topics
Registration (please scroll down to set your data preferences)

Mondaq Ltd requires you to register and provide information that personally identifies you, including your content preferences, for three primary purposes (full details of Mondaq’s use of your personal data can be found in our Privacy and Cookies Notice):

  • To allow you to personalize the Mondaq websites you are visiting to show content ("Content") relevant to your interests.
  • To enable features such as password reminder, news alerts, email a colleague, and linking from Mondaq (and its affiliate sites) to your website.
  • To produce demographic feedback for our content providers ("Contributors") who contribute Content for free for your use.

Mondaq hopes that our registered users will support us in maintaining our free to view business model by consenting to our use of your personal data as described below.

Mondaq has a "free to view" business model. Our services are paid for by Contributors in exchange for Mondaq providing them with access to information about who accesses their content. Once personal data is transferred to our Contributors they become a data controller of this personal data. They use it to measure the response that their articles are receiving, as a form of market research. They may also use it to provide Mondaq users with information about their products and services.

Details of each Contributor to which your personal data will be transferred is clearly stated within the Content that you access. For full details of how this Contributor will use your personal data, you should review the Contributor’s own Privacy Notice.

Please indicate your preference below:

Yes, I am happy to support Mondaq in maintaining its free to view business model by agreeing to allow Mondaq to share my personal data with Contributors whose Content I access
No, I do not want Mondaq to share my personal data with Contributors

Also please let us know whether you are happy to receive communications promoting products and services offered by Mondaq:

Yes, I am happy to received promotional communications from Mondaq
No, please do not send me promotional communications from Mondaq
Terms & Conditions (the Website) is owned and managed by Mondaq Ltd (Mondaq). Mondaq grants you a non-exclusive, revocable licence to access the Website and associated services, such as the Mondaq News Alerts (Services), subject to and in consideration of your compliance with the following terms and conditions of use (Terms). Your use of the Website and/or Services constitutes your agreement to the Terms. Mondaq may terminate your use of the Website and Services if you are in breach of these Terms or if Mondaq decides to terminate the licence granted hereunder for any reason whatsoever.

Use of

To Use you must be: eighteen (18) years old or over; legally capable of entering into binding contracts; and not in any way prohibited by the applicable law to enter into these Terms in the jurisdiction which you are currently located.

You may use the Website as an unregistered user, however, you are required to register as a user if you wish to read the full text of the Content or to receive the Services.

You may not modify, publish, transmit, transfer or sell, reproduce, create derivative works from, distribute, perform, link, display, or in any way exploit any of the Content, in whole or in part, except as expressly permitted in these Terms or with the prior written consent of Mondaq. You may not use electronic or other means to extract details or information from the Content. Nor shall you extract information about users or Contributors in order to offer them any services or products.

In your use of the Website and/or Services you shall: comply with all applicable laws, regulations, directives and legislations which apply to your Use of the Website and/or Services in whatever country you are physically located including without limitation any and all consumer law, export control laws and regulations; provide to us true, correct and accurate information and promptly inform us in the event that any information that you have provided to us changes or becomes inaccurate; notify Mondaq immediately of any circumstances where you have reason to believe that any Intellectual Property Rights or any other rights of any third party may have been infringed; co-operate with reasonable security or other checks or requests for information made by Mondaq from time to time; and at all times be fully liable for the breach of any of these Terms by a third party using your login details to access the Website and/or Services

however, you shall not: do anything likely to impair, interfere with or damage or cause harm or distress to any persons, or the network; do anything that will infringe any Intellectual Property Rights or other rights of Mondaq or any third party; or use the Website, Services and/or Content otherwise than in accordance with these Terms; use any trade marks or service marks of Mondaq or the Contributors, or do anything which may be seen to take unfair advantage of the reputation and goodwill of Mondaq or the Contributors, or the Website, Services and/or Content.

Mondaq reserves the right, in its sole discretion, to take any action that it deems necessary and appropriate in the event it considers that there is a breach or threatened breach of the Terms.

Mondaq’s Rights and Obligations

Unless otherwise expressly set out to the contrary, nothing in these Terms shall serve to transfer from Mondaq to you, any Intellectual Property Rights owned by and/or licensed to Mondaq and all rights, title and interest in and to such Intellectual Property Rights will remain exclusively with Mondaq and/or its licensors.

Mondaq shall use its reasonable endeavours to make the Website and Services available to you at all times, but we cannot guarantee an uninterrupted and fault free service.

Mondaq reserves the right to make changes to the services and/or the Website or part thereof, from time to time, and we may add, remove, modify and/or vary any elements of features and functionalities of the Website or the services.

Mondaq also reserves the right from time to time to monitor your Use of the Website and/or services.


The Content is general information only. It is not intended to constitute legal advice or seek to be the complete and comprehensive statement of the law, nor is it intended to address your specific requirements or provide advice on which reliance should be placed. Mondaq and/or its Contributors and other suppliers make no representations about the suitability of the information contained in the Content for any purpose. All Content provided "as is" without warranty of any kind. Mondaq and/or its Contributors and other suppliers hereby exclude and disclaim all representations, warranties or guarantees with regard to the Content, including all implied warranties and conditions of merchantability, fitness for a particular purpose, title and non-infringement. To the maximum extent permitted by law, Mondaq expressly excludes all representations, warranties, obligations, and liabilities arising out of or in connection with all Content. In no event shall Mondaq and/or its respective suppliers be liable for any special, indirect or consequential damages or any damages whatsoever resulting from loss of use, data or profits, whether in an action of contract, negligence or other tortious action, arising out of or in connection with the use of the Content or performance of Mondaq’s Services.


Mondaq may alter or amend these Terms by amending them on the Website. By continuing to Use the Services and/or the Website after such amendment, you will be deemed to have accepted any amendment to these Terms.

These Terms shall be governed by and construed in accordance with the laws of England and Wales and you irrevocably submit to the exclusive jurisdiction of the courts of England and Wales to settle any dispute which may arise out of or in connection with these Terms. If you live outside the United Kingdom, English law shall apply only to the extent that English law shall not deprive you of any legal protection accorded in accordance with the law of the place where you are habitually resident ("Local Law"). In the event English law deprives you of any legal protection which is accorded to you under Local Law, then these terms shall be governed by Local Law and any dispute or claim arising out of or in connection with these Terms shall be subject to the non-exclusive jurisdiction of the courts where you are habitually resident.

You may print and keep a copy of these Terms, which form the entire agreement between you and Mondaq and supersede any other communications or advertising in respect of the Service and/or the Website.

No delay in exercising or non-exercise by you and/or Mondaq of any of its rights under or in connection with these Terms shall operate as a waiver or release of each of your or Mondaq’s right. Rather, any such waiver or release must be specifically granted in writing signed by the party granting it.

If any part of these Terms is held unenforceable, that part shall be enforced to the maximum extent permissible so as to give effect to the intent of the parties, and the Terms shall continue in full force and effect.

Mondaq shall not incur any liability to you on account of any loss or damage resulting from any delay or failure to perform all or any part of these Terms if such delay or failure is caused, in whole or in part, by events, occurrences, or causes beyond the control of Mondaq. Such events, occurrences or causes will include, without limitation, acts of God, strikes, lockouts, server and network failure, riots, acts of war, earthquakes, fire and explosions.

By clicking Register you state you have read and agree to our Terms and Conditions