Trace the patient data before choosing the checklist.
Review data flows, access and service dependencies, then establish which privacy, security and product requirements apply.
Regulatory Landscape
A booking platform, a hospital system and medical-device software do not have the same scope. Begin with what the product does, who uses it and which organisations determine the purposes of processing. Map where health data is collected, accessed, stored, shared and deleted.
Where GDPR applies, health data is special-category data. Assess both the Article 6 lawful basis and the relevant Article 9 condition. A DPIA may be required for processing likely to create high risks, including large-scale processing of health data. Neither consent nor appointing a DPO is a universal answer to every healthtech privacy question.
ISO 27001 and SOC 2 can support security assurance where customers request them. They do not replace medical-device obligations or, where relevant, HIPAA requirements. AuditFront does not list dedicated medical-device or HIPAA assessments. Establish those obligations separately before relying on a general security review.
Key Compliance Frameworks
The frameworks most relevant to healthtech & digital health companies.
GDPR
Review health-data processing, roles, lawful basis, Article 9 conditions, rights and the need for a DPIA.
ISO 27001
Review the ISMS and controls supporting confidentiality, integrity and availability of the scoped service.
SOC 2
Use when a customer requests independent assurance over the relevant service controls.
NIS2
Check the entity type and applicable national law. Supplying software to healthcare does not by itself settle scope.
Industry Challenges
Common compliance obstacles facing healthtech & digital health companies.
Sensitive data crosses organisational boundaries
Clarify controller and processor roles and record which systems, staff and suppliers can access patient information.
Availability affects care delivery
Review recovery needs with the service owner. A generic uptime target may not reflect the consequences of an outage.
Customer questionnaires ask for more than a certificate
Keep evidence of access reviews, incident handling and supplier arrangements available for the specific service under review.
How AuditFront Helps
Use the assessments to organise your review and identify follow-up work.
Review privacy and security together
Use the GDPR and security assessments to identify related gaps while keeping their distinct requirements visible.
Record the evidence behind answers
Use references or appropriately redacted evidence. An assessment rarely needs a copy of identifiable patient records.
Prepare a clear handoff
Use the gap report to discuss unresolved issues with your security, privacy and clinical or product specialists.
Frequently Asked Questions
Where should we start?
Will an AuditFront assessment establish compliance?
What does the free plan cover?
Start with your review scope
Choose the relevant assessment, check the evidence and keep unresolved questions visible.
Start Free AssessmentFree plan · No credit card required