DHT Governance · Clinical Trials · MDR · IVDR · AI Act · FDA · GCP

Govern the devices your trial relies on — before an inspector does.

Use a device outside its manufacturer's intended purpose and your protocol can make it investigational, make you its manufacturer, or trigger a clinical investigation. Data-integrity and data-protection rules apply whatever its status. We assess the perimeters every device and system in your trial opens, record the decision with its reasoning, and keep that record defensible for the life of the study.

7
regulatory perimeters — what a device is exposed to
8
assessment products, quoted in writing before work begins
43
regulatory position papers behind the method
2–3 weeks
to a Snapshot Regulatory Impact Assessment
1234567Protocol A — engagement onlyStep count shown to the participant. Feeds nothing.vs1234567Protocol B — secondary endpointDaily activity count is a protocol-defined endpoint.1 Medical device · 2 GxP & CSV · 3 Data protection · 4 Human factors · 5 Configuration & change · 6 Economic operator · 7 Protocol & endpointopened6 — depends on who ships itnot opened
Nothing about the hardware changed. The protocol did. That is why we assess use, not product category.

"No obligation" is a conclusion you earn by assessing — never a starting assumption.

Sponsors and CROs deploy wearables, biosensors, point-of-care devices, connected monitors, software as a medical device and participant-owned phones on the assumption that a device is out of scope because it is commercially available, or because it is not the investigational product. Neither fact settles the question.

What settles it is use. The moment a device informs an endpoint, a safety decision or a regulatory submission, obligations attach — and they do not attach one at a time. Medical device rules, GxP and computer system validation, data protection, human factors, configuration control, economic-operator duties and protocol design each open a perimeter, and the perimeters stack.

The same watch can carry almost no obligations in one protocol and a stack of them in the next. Nothing about the hardware changed — the protocol did. qointa is built for exactly that problem: one decision framework that reads EU MDR, IVDR, the EU AI Act, FDA requirements and ICH GCP together, across every class of technology a trial actually uses.

Nothing about the hardware changed. The protocol did. That is why we assess use, not product category.

1234567 1 Medical device2 GxP and computerised systems3 Data protection4 Human factors and use-safety5 Configuration and change6 Economic-operator role7 Protocol design and endpoint1 of 7 perimeters open
A consumer watch used to keep participants engaged. Not part of any endpoint.
2 of 7 perimeters open
The participant records outcomes on it. Its data is a regulated record.
6 of 7 perimeters open
The protocol relies on its measurements. Six of seven open — all but economic-operator role, which depends on who ships the device.
7 of 7 perimeters open
An algorithm scores the result. Every perimeter is open, and the AI Act stacks on top.
Pick a use and watch the perimeters open.

Seven perimeters. One controlled loop.

Every device in your trial is assessed against all seven. The result is a recorded, reproducible decision — not an opinion.

Medical device

Is it a device under EU MDR or IVDR, and under FDA rules? Classification, rule application and the justification behind it.

How we assess it →

GxP and computerised systems

Does it fall under GCP, 21 CFR Part 11, EU GMP Annex 11 or, for EU trials, the EMA 2023 guideline on computerised systems and electronic data? Validation scope, audit trails, ALCOA+ data integrity.

How we assess it →

Data protection

GDPR and cross-border transfer, data residency, participant rights and what the device actually transmits.

How we assess it →

Human factors and use-safety

Use error in an unsupervised home setting, usability engineering, and the training that prevents deviations.

How we assess it →

Configuration and change

Firmware, app and operating-system updates mid-study — and whether each one needs documentation only, bridging evidence or full revalidation.

How we assess it →

Economic-operator role

Manufacturer, authorised representative, importer, distributor, or system or procedure-pack producer: which role you hold, in which jurisdiction, and what it obliges you to do.

How we assess it →

Protocol design and endpoint

What the protocol asks the device to prove, and whether the device can defensibly prove it.

How we assess it →

Stacking

The perimeters interact. A device can be out of scope in one and squarely in scope in several others — the combination is the risk.

See the full method →
1 Medical device2 GxP & CSV3 Data protection—4 Human factors5 Configuration & change6 Economic operator—7 Protocol & endpoint
A device can be out of scope in one perimeter and squarely in scope in several others. The combination is the risk.

One controlled loop

The same loop for every technology in the trial, so the decision is reproducible and the evidence is already assembled when someone asks.

1. Inventory

Every technology the protocol relies on, including the ones nobody listed: the reminder app, the translation, the participant's own phone.

2. Assess

Each one against all seven perimeters, with the reasoning recorded rather than the conclusion asserted.

3. Register

The decision, its basis, who made it and when — versioned, dated and attributable.

4. Monitor

Against the trigger list the assessment produced. Run by a named specialist; automated monitoring is in development.

5. Re-assess

When a trigger fires — a firmware release, an OS update, a supplier change, a new country — not when someone remembers.

You probably need this now if one of these has happened

Each of these changes the regulatory position of a device already in your protocol.

A firmware, app or OS update landed mid-study

Someone has to decide this week whether it needs documentation only, bridging evidence or full revalidation — and write down why.

Mid-Study Change Assessment →

A consumer device is generating an endpoint

Fit-for-purpose is a question about your protocol, not the product page. It needs an evidence-backed answer before database lock.

Start with a Snapshot RIA →

BYOD is proposed, or a new country is added

Hardware you did not supply, or a market where the same device answers differently. Both reopen questions you may have closed. A Snapshot assesses one device in one setting; comparing several markets side by side is a wider assessment.

Start with a Snapshot RIA →

An inspection is coming and the evidence is scattered

The register, the classification rationale, the training records and the change history should be one retrieval, not a three-week reconstruction.

Inspection Readiness Review →

An algorithm or AI model is scoring an endpoint

The model is part of the measuring system. Its version, training data and change control need the same evidence chain as the device that produced the raw signal.

Fit-for-Purpose Review →

Your trial now lists more than one DHT

Each device was assessed in isolation. A portfolio needs a register, a trigger list and a view of which perimeters stack when devices interact.

Portfolio Governance →

The cheapest way to find out is free

Before you commission anything, run the DHT readiness scorecard. Ten minutes, no sign-up, no sales call attached to the result. It scores your programme across the same seven perimeters used above and tells you which of them are actually open — so the decision to bring anyone in is made on evidence rather than on unease.

Start with a Snapshot RIA: one device, one protocol, 2–3 weeks

The entry engagement. Defined scope, a written fee before work begins, and a stated delivery date — no work starts until you accept both.

What you provide

The device and its intended use in the study, the endpoints that depend on it, the participating countries, and who supplies and ships it. Ten minutes if you have the protocol to hand.

What you receive

A recorded decision per perimeter with its rationale, a decision register entry, the trigger list, an evidence index, and a 45-minute readout with the specialist who did the work.

What it is not

Not multiple devices or jurisdictions compared, not execution of remediation, not a regulatory filing, and not legal advice. It records a position and the reasoning behind it.

Full scope and exclusions →

Who is behind the assessment

qointa is a specialist practice, not a generalist firm with a digital health page. The people who run the assessments have sat on both sides of this problem: Phase II–IV trial management inside pharma and CRO organisations, founding and running an integrated eClinical platform, taking a device through EU MDR as a manufacturer, and holding accountable regulated roles — Qualified Person, PRRC, legal representative.

That record is prior experience held by members of the team, stated as such. qointa BV itself is young; what it inherits is the judgement, and a method that writes down its reasoning so you are not dependent on ours.

279 sensor-based medical devices are authorised for US marketing — up from 9 a year in 2015 to 51 in 2025.

FDA’s own list runs to 279 entries with final decisions between 30 January 2015 and 22 June 2026 — 263 510(k) clearances, 13 De Novo grants and 3 PMA approvals, held by 164 companies. Authorisations rose from 9 in 2015 to 51 in 2025. Cardiovascular and neurology devices account for 188 of the 279.

These are the devices arriving in your protocol. Authorisation is not the question — what your protocol asks the device to do is.

2015920167201782018172019252020172021252022272023372024392025512026*17Cardiovascular · 139Neurology · 49Clinical chemistry · 44Anesthesiology · 36Other panels · 11279 authorised devices263 510(k) · 13 De Novo · 3 PMA164 companiesFinal decisions 30 Jan 2015 – 22 Jun 2026FDA-authorised sensor-based digital health devices, by year of final decisionColoured by lead review panel · *2026 to 22 June
Source: FDA, Medical Devices that Incorporate Sensor-based Digital Health Technology (Digital Health Center of Excellence), content current as of 4 September 2026, retrieved 24 September 2026. A work of the US government, in the public domain.

What we do about it

Six service categories, delivered by people who have sat on both the sponsor side and the vendor side of this problem.

Digital Health Technologies in Trials

End-to-end DHT governance: assessment, classification, fit-for-purpose validation, logistics, data interoperability, training and inspection readiness.

Explore the service →

Quality & Regulatory Assurance

QMS implementation under ISO 13485 and FDA QMSR, pre-market submissions, risk management to ISO 14971, audits, mock inspections and PRRC services.

Explore the service →

Regulated Software & Data Systems

Medical device software under IEC 62304, computer system validation, 21 CFR Part 11 and EU GMP Annex 11 compliance, and ALCOA+ data integrity programmes.

Explore the service →

Patient Engagement Solutions

Education, remote monitoring, support programmes and patient-reported outcomes — designed so participants stay in and data keeps flowing.

Explore the service →

EU Authorised Representative

EU authorised representative services for non-EU manufacturers under EU MDR 2017/745 and IVDR 2017/746 — EUDAMED registration, verifying the technical documentation and keeping it available, and vigilance cooperation.

Explore the service →

Digital Transformation of Clinical Operations

Whole-estate governance: every system, device, integration and algorithm assessed inside one reproducible framework, delivered in five gated phases you fund one at a time.

Explore the service →

Start with one paper, free

The one-pager needs no account. The two beside it open with a free one — no approval step, no sales call attached.

DHT governance — the one-pager BrochuresFree

DHT governance — the one-pager

Govern the devices your trial relies on before an inspector does — the seven regulatory perimeters, on one page.

Download PDF →
Regulatory Impact Assessment (RIA) for Devices and Systems in Clinical Trials Position papersFree

Regulatory Impact Assessment (RIA) for Devices and Systems in Clinical Trials

Why a device’s role and triggers — not the hardware — determine whether an RIA is required

Read the summary →
The Trigger Register: A Controlled Instrument for Digital-Trial Compliance Position papers

The Trigger Register: A Controlled Instrument for Digital-Trial Compliance

Turning the per-stakeholder assessment into a living, inspection-ready artefact in the technical file, the validation plan and the TMF — grounded in the risk-based quality management GCP already expects.

Read the summary →

All papers in the library →

Bring one device and one protocol

A wearable, a sensor, an app, a participant's own phone. We will tell you which regulatory perimeters it opens, what it takes to close them, and what that costs — in writing, before any work starts.

Start with a Snapshot RIA