SaMD
Software as a Medical Device needs infrastructure that can stand inside a regulated file: an IEC 62304 lifecycle behind every release, SOUP documentation your 62304 file can reference, certified security controls, and hosting where your market requires it. BioT provides that layer. Your software stays the medical device, and the clearance stays yours. BioT customers have achieved FDA clearance and CE marking on the platform.
Your regulated software runs on top. The platform underneath handles what every SaMD needs and no SaMD differentiates on: connectivity, data pipelines, user management, audit logging and integrations.
Your SaMD keeps its classification and its clearance. The platform is infrastructure underneath it, documented as SOUP in your file.
APIs and SDKs connect your device, companion app and clinician portal to one data layer.
EHR, analytics and algorithm integrations run through the same platform layer, inside the same audit scope. See how the EHR connection works.
The documentation package is mapped to the FDA eSTAR structure: requirements, architecture design, test reports, cybersecurity management plan, risk assessment, threat model and SBOM.
See the submission documentationYour SaMD
The obligation
What BioT provides
The same evidence for your own device software, with the platform recorded as a component.
Held for the platform, and available for you to reference in your own file.
Your threat model, risk assessment, vulnerability management plan and security testing.
Documentation you can cite for the infrastructure layer of the system.
The full table, covering security certification, HIPAA and GDPR data protection and clearance ownership, is on the compliance page.
See the full table on the compliance pageThe seam: SOUP documentation
The supplier Design History File your IEC 62304 file references. Document names from the platform documentation.
The BioT platform
The requirement
What the platform provides
Your notified body and the FDA expect lifecycle documentation for every piece of software in the system, including the cloud it runs on.
BioT develops under IEC 62304 and maintains a Design History File: requirements, architecture, test reports, risk analysis and a software version description, updated with each release.
In an IEC 62304 file, a cloud platform is software of unknown provenance unless its vendor documents it. Undocumented SOUP stalls regulatory reviews.
Specifications, validation reports, known-anomaly lists and an SBOM per release, packaged so your 62304 file can reference them directly.
Hospitals, IDNs and enterprise buyers screen SaMD vendors on infrastructure security before clinical value gets discussed.
Held and audited by BioT for the platform layer, including the healthcare-specific certifications US hospital procurement asks for.
SaMD sold into the US and EU needs data hosted in the right region, under the right agreements, with a subprocessor list a privacy review can check.
Run in your own AWS account or on a BioT-managed dedicated environment. Both models come with a BAA, a DPA and a published subprocessor list.
Clearance is the start. Section 524B and MDR postmarket surveillance both expect maintained vulnerability management and an SBOM across the product lifecycle.
Platform patching, monitoring and a machine-readable SBOM maintained per release, with scan reports available for your submissions.
Platform certificates and documentation are available on request.
BioT runs in one of two models. Which one you choose determines where your data sits, and both give you a dedicated production environment.
Installed into your own AWS account, so the deployment and its data stay in your account.
Hosted on a BioT-managed account, with a dedicated environment for production.
Hosted on AWS, with availability in the US, EU and Asia.
A BAA and a DPA are available under both models.
From BioT client engagement data, the direct certification bill for a do-it-yourself medical device cloud is $945,000 over three years, before headcount.
SOC 2 Type 2 and HITRUST r2 also need 18 to 24 months of documented operating history before certification is granted.
HITRUST r2 $341K, SOC 2 Type 2 $201K, DHF documentation $132K, vulnerability scanning $78K.
ISO 27001 $55K, SBOM $51K, ISO 13485 $45K, penetration testing $42K.
The cost compounds: roughly $189K in year one, $312K in year two and $444K in year three.
BioT publishes the third-party subprocessors used to host and process customer data, with their location and the service each one performs. A BAA and a DPA are available under both deployment models.
See the subprocessor listBioT holds HITRUST r2 certification, SOC 2 Type II attestation, and ISO 27001, ISO 27799 and ISO 13485 certification. Software development follows IEC 62304, with a Design History File and an SBOM per release. The full documentation set is published at docs.biot-med.com.
No. SaMD classification applies to your software, which performs the medical purpose. BioT is the cloud infrastructure underneath it, documented as SOUP in your IEC 62304 file. The classification, the submission and the clearance stay with your product.
As documented SOUP with a supplier Design History File behind it. BioT provides specifications, validation evidence, known-anomaly reporting and an SBOM per release, packaged so your file can reference them. Your device-level requirements, risk analysis and testing stay yours. Details at docs.biot-med.com.
On AWS, with availability in the US, EU and Asia. In the customer-account model the deployment sits in your own AWS account. In the managed model it runs on a BioT-managed account with a dedicated environment per customer.
Yes. Both ship in the compliance pack, along with current certificates. Ask through the contact page and the team will send everything.