SaMD

Cloud Infrastructure for SaMD

Software as a Medical Device needs infrastructure that can stand inside a regulated file: an IEC 62304 lifecycle behind every release, SOUP documentation your 62304 file can reference, certified security controls, and hosting where your market requires it. BioT provides that layer. Your software stays the medical device, and the clearance stays yours. BioT customers have achieved FDA clearance and CE marking on the platform.

Where the Platform Sits in Your SaMD Architecture

Your regulated software runs on top. The platform underneath handles what every SaMD needs and no SaMD differentiates on: connectivity, data pipelines, user management, audit logging and integrations.

The documentation package is mapped to the FDA eSTAR structure: requirements, architecture design, test reports, cybersecurity management plan, risk assessment, threat model and SBOM.

See the submission documentation

Your SaMD

What You Inherit and What Stays Yours

The obligation

What BioT provides

Quality management and software lifecycle

The same evidence for your own device software, with the platform recorded as a component.

ISO 13485 QMS, IEC 62304 DHF and an SBOM per release

Held for the platform, and available for you to reference in your own file.

Cybersecurity documentation for an FDA submission

Your threat model, risk assessment, vulnerability management plan and security testing.

Platform controls, architecture and SBOM

Documentation you can cite for the infrastructure layer of the system.

The full table, covering security certification, HIPAA and GDPR data protection and clearance ownership, is on the compliance page.

See the full table on the compliance page

The seam: SOUP documentation

BioT platform release, supplier DHF
├── SRS-0001            Software Requirements Specification
├── SDD-0001            System and Software Architecture Design
├── STD-001 / STR-001   Software Test Description and Report
├── SVD-0001            Software Version Description
├── SBOM.zip            Software bill of materials, per release
└── OTS-001             Off-the-Shelf Software Documentation

The supplier Design History File your IEC 62304 file references. Document names from the platform documentation.

The BioT platform

What SaMD Needs from Its Cloud Infrastructure

The requirement

What the platform provides

IEC 62304 lifecycle evidence

Your notified body and the FDA expect lifecycle documentation for every piece of software in the system, including the cloud it runs on.

A Design History File maintained per release

BioT develops under IEC 62304 and maintains a Design History File: requirements, architecture, test reports, risk analysis and a software version description, updated with each release.

SOUP documentation

In an IEC 62304 file, a cloud platform is software of unknown provenance unless its vendor documents it. Undocumented SOUP stalls regulatory reviews.

Evidence that turns the platform into documented SOUP

Specifications, validation reports, known-anomaly lists and an SBOM per release, packaged so your 62304 file can reference them directly.

Security certification buyers screen for

Hospitals, IDNs and enterprise buyers screen SaMD vendors on infrastructure security before clinical value gets discussed.

HITRUST r2, SOC 2 Type II, ISO 27001 and ISO 27799

Held and audited by BioT for the platform layer, including the healthcare-specific certifications US hospital procurement asks for.

Data residency and agreements

SaMD sold into the US and EU needs data hosted in the right region, under the right agreements, with a subprocessor list a privacy review can check.

Hosting in the US, EU and Asia, with a BAA and a DPA

Run in your own AWS account or on a BioT-managed dedicated environment. Both models come with a BAA, a DPA and a published subprocessor list.

Postmarket obligations

Clearance is the start. Section 524B and MDR postmarket surveillance both expect maintained vulnerability management and an SBOM across the product lifecycle.

Vulnerability management and an SBOM per release

Platform patching, monitoring and a machine-readable SBOM maintained per release, with scan reports available for your submissions.

Platform certificates and documentation are available on request.

Deployment Models and Data Location

BioT runs in one of two models. Which one you choose determines where your data sits, and both give you a dedicated production environment.

Certification Cost If You Build Instead

From BioT client engagement data, the direct certification bill for a do-it-yourself medical device cloud is $945,000 over three years, before headcount.

Subprocessors, Agreements and Common Questions

BioT publishes the third-party subprocessors used to host and process customer data, with their location and the service each one performs. A BAA and a DPA are available under both deployment models.

See the subprocessor list

What certifications does BioT hold?

BioT holds HITRUST r2 certification, SOC 2 Type II attestation, and ISO 27001, ISO 27799 and ISO 13485 certification. Software development follows IEC 62304, with a Design History File and an SBOM per release. The full documentation set is published at docs.biot-med.com.

Is BioT itself SaMD?

No. SaMD classification applies to your software, which performs the medical purpose. BioT is the cloud infrastructure underneath it, documented as SOUP in your IEC 62304 file. The classification, the submission and the clearance stay with your product.

How does the platform fit into an IEC 62304 file?

As documented SOUP with a supplier Design History File behind it. BioT provides specifications, validation evidence, known-anomaly reporting and an SBOM per release, packaged so your file can reference them. Your device-level requirements, risk analysis and testing stay yours. Details at docs.biot-med.com.

Where is customer data hosted?

On AWS, with availability in the US, EU and Asia. In the customer-account model the deployment sits in your own AWS account. In the managed model it runs on a BioT-managed account with a dedicated environment per customer.

Can I get the BAA and the DPA?

Yes. Both ship in the compliance pack, along with current certificates. Ask through the contact page and the team will send everything.

Bring us your SaMD architecture

Talk to a solution architect