---
title: Untangling HIPAA, HITRUST, and SOC 2
description: Learn the purpose of Corrective and Preventive Actions (CAPAs) for Medical Device Development
image: https://blog.scalehealth.com/hubfs/Hero-046.png
---

<https://www.facebook.com/sierralabs/> <https://twitter.com/Sierra_Labs> <https://www.linkedin.com/company/sierra-labs> <https://www.instagram.com/sierra.labs/>

[![Sierra Labs](https://blog.scalehealth.com/hubfs/Sierralabs_January2019%20Theme/Images/sierra-labs-logo.png)](https://www.sierralabs.com/)

- Products 
    - [Sierra Policies & Procedures](https://www.sierralabs.com/policies-procedures)
    - [Sierra Document Automation](https://www.sierralabs.com/document-automation)
    - [Sierra Quality Management](https://www.sierralabs.com/quality-management)
    - [Sierra GxP Cloud Validation](https://www.sierralabs.com/cloud-validation)
- [Services](https://www.sierralabs.com/services)
- [About Us](https://www.sierralabs.com/about)
- [Partner](https://campaign.sierralabs.com/partner-with-sierra-labs)
- [Blog](https://blog.scalehealth.com)
- [Contact Us](https://www.sierralabs.com/document-automation/#contact-us)

[Contact Us](https://www.sierralabs.com/document-automation/#contact-us)

 

## Sierra Labs Blog

This is a search field with an auto-suggest feature attached.

- There are no suggestions because the search field is empty.

# Untangling HIPAA, HITRUST, and SOC 2

Posted by [Sierra Labs](https://blog.scalehealth.com/author/sierra-labs) on Sep 14, 2023 11:42:00 AM

- [Tweet](https://twitter.com/share)

Explore the differences and benefits of the following regulatory frameworks for SaMD.

![Hero-046](https://blog.scalehealth.com/hs-fs/hubfs/Hero-046.png?width=1600&name=Hero-046.png)

In the past decade, the healthcare has experienced rapid implementation of regulations via various compliance frameworks. This has resulted in raising the bar for companies developing their medical devices or better yet, Software as a Medical Device (SAMD).

With new regulations sweeping the healthcare industry, it becomes more complex for companies in the space to market their medical devices. How does your product fit with these frameworks? How much time do you have? How much is it going to cost your company? This blog will breakdown the purpose of HIPAA, HITRUST, and SOC 2 as they pertain to your medical device. 

**HIPAA Compliance for SaMD**

Prior to the [Health Insurance Portability and Accountability Act (HIPAA),](https://blog.scalehealth.com/guidance-on-hipaa-compliance-for-medical-devices)companies developing a medical device that managed sensitive informations of patients had no clear regulatory boundaries. HIPAA established boundaries for these companies by defining the appropriate data as patient health information (PHI). Medical records are highly sought after due to their high worth and value, they could cost someone’s identity, insurance, medication, or even finances.

With a new baseline, HIPAA has improved the standards for medical device companies by making them more cautious when handling data to avoid penalties and scandals. There are multiple areas your organization should assess to become HIPAA compliant. To learn more about best practices and guidance steps to achieve HIPAA Compliance, check the link below:

[Check out our HIPAA Checklist to see if your company is ensuring optimal compliance with HIPAA Standards.](https://campaign.sierralabs.com/free-hipaa-compliance-checklist)

HIPAA allows flexibility in implementation of safeguards based on the size and complexity of the organization. That kind of flexibility is necessary but could also put your organization at risk! It can be easy to make subjective decisions based on misinformation and lack of expertise that may increase vulnerability  the impact and puts many healthcare organizations (and their patients) at risk.

**What is HITRUST?**

The Health Information Trust (HITRUST) framework was developed from current information security standards. It’s intention was to unify industry standards and give companies developing SaMD that handled sensitive data a specific set of controls. HITRUST framework’s purpose is to go beyond the requirements of HIPAA captivating regulatory standards from across the globe. With ongoing improvements by industry leaders, the HITRUST CSF has become the most popular and widely adopted security framework in the U.S. healthcare industry.

[Developing an eHealth application? Learn how to establish safeguards for HIPAA compliance with our FREE eBook!](https://campaign.sierralabs.com/free-hipaa-hitrust-ebook-ehealth)

**Breaking Down HITRUST Certification**

The HITRUST CSF maps the CSF controls to specific HIPAA standards and specifications. Since each CSF control contains multiple levels, organizations must implement the specific requirements for each control based on current systems and risks.

Organizations wanting to comply with HITRUST have three options within the CSF Security Framework known as Degrees of Assurance:

| **Degrees of Assurance** | **Description** | **Timeframe** |
| --- | --- | --- |
| . Self-Assessment | Companies can perform a self-assessment using the myCSF tool. This assessment will determine what areas your organization must focus on to become HITRUST compliant. | Taken Anytime |
| CSF Validated | Follows a "Self-assessment" and thorough implementation of CAPAs for any potential non-compliance issues identified. A HITRUST-approved CSF Assessor will then inspect all documentation gathered through the assessment with an **onsite visit**. A HITRUST CSF Validated Assessment Report will be generated based on the score criteria and allow you to be CSF Validated. | (Valid for one year after issuance) |
| CSF Certified | If all requirements are met by CSF Validation, the CSF Assessor will determine that your organization is HITRUST CSF Certified. Your organization must maintain policies and procedures, demonstrate implementation of controls and undergo an interim assessment at the one-year mark. | (Valid for 24 months) |

**What is the difference between HITRUST and HIPAA?**

While there currently doesn’t exist an official “HIPAA certification” to demonstrate HIPAA compliance, the HITRUST Alliance does in fact provide a certification for organizations that successfully undergo HITRUST assessments. The HITRUST certification is essentially a badge for your company demonstrating it understands and maintains activities under global regulatory standards like HIPAA.

Despite the level of penalties that come with HIPAA, HITRUST CSF Certification is a much more strict and rigorous process due to its global recognition. Completing HITRUST CSF Certification recognizes that your organization not only complies to the standards of HITRUST but also checks off every box to meet HIPAA compliance.

**Importance of SOC 2 for Healthcare**

Service Organization Control 2 (SOC 2) addresses third-party risk concerns by evaluating non-financial reporting controls, policies, and procedures that directly relate to the American Institute of Certified Public Accountants' (AICPA) Trust Services Criteria. Non-financial reporting controls include:

- Security – Is the system protected against unauthorized access?
- Availability – Is the system available for operation and use as agreed?
- Processing Integrity – Is the system processing complete, valid, accurate, timely, and authorized?
- Confidentiality – Is the information that’s designated as confidential protected as agreed?
- Privacy – Is personal information collected, used, retained, disclosed, and destroyed in accordance with the entity’s privacy notice?

These principles are all described within HIPAA’s Security Rule requirements as well. The SOC 2 audit and HITRUST CSF provides a streamlined and practical methodology for creating, accessing, storing or exchanging protected health information (PHI).

It’s become increasingly common for organizations to request that their vendors become SOC 2 compliant so they can ensure that the healthcare organizations they work with have strong security postures. If a client can’t be assured that you have reliable, secure processes for securing protected health information, why would they choose to work with you?

**Secure Compliance With Less Stress**

As you can infer by now, achieving compliance for each regulatory entity can require a significant amount of work especially when lacking any expertise in the subject matter. Here is what we can offer your business and team.

With Sierra Labs, you can fully understand the specific requirements and options to develop audit-ready actionable policies and procedures to become fully-compliant with HIPAA, HITRUST, or SOC 2. Our team will create a regulatory roadmap for your specific business size and type to uncover critical points that need to be improved for audits or assessments.

[Sierra Services](https://www.sierralabs.com/services/) is the first step to achieve regulatory compliance, speak with our regulatory experts and avoid the hassle of compliance obstacles for your medical device's journey to market. We will guide you every step of the way to ensure your team feels safe and confident for inspections and submissions.

**Need Help Achieving HIPAA, HITRUST, or SOC 2 Compliance?**

**Click Here for a Free Consultation!**

[![Sierra Services](https://hubspot-no-cache-na2-prod.s3.amazonaws.com/cta/default/5229980/8b72159a-cea0-450f-b00a-d0a76b01eba0.png)](https://hubspot-cta-redirect-na2-prod.s3.amazonaws.com/cta/redirect/5229980/8b72159a-cea0-450f-b00a-d0a76b01eba0)

It's that simple.

 Topics: [SaMD](https://blog.scalehealth.com/tag/samd), [Data Security](https://blog.scalehealth.com/tag/data-security), [Medical Device Company](https://blog.scalehealth.com/tag/medical-device-company), [Data Privacy](https://blog.scalehealth.com/tag/data-privacy), [Data Requirements](https://blog.scalehealth.com/tag/data-requirements), [SaMD Development](https://blog.scalehealth.com/tag/samd-development), [Software Requirement Specification](https://blog.scalehealth.com/tag/software-requirement-specification), [HIPAA](https://blog.scalehealth.com/tag/hipaa), [Personal Health Information](https://blog.scalehealth.com/tag/personal-health-information), [Health Data](https://blog.scalehealth.com/tag/health-data), [HIPAA Compliance](https://blog.scalehealth.com/tag/hipaa-compliance), [HIPAA Checklist](https://blog.scalehealth.com/tag/hipaa-checklist), [Covered Entities](https://blog.scalehealth.com/tag/covered-entities), [Business Associates](https://blog.scalehealth.com/tag/business-associates), [ePHI](https://blog.scalehealth.com/tag/ephi), [PHI](https://blog.scalehealth.com/tag/phi), [eHealth](https://blog.scalehealth.com/tag/ehealth), [Health Applications](https://blog.scalehealth.com/tag/health-applications), [SOC 2](https://blog.scalehealth.com/tag/soc-2), [HITRUST](https://blog.scalehealth.com/tag/hitrust), [SOC](https://blog.scalehealth.com/tag/soc), [HITRUST CSF](https://blog.scalehealth.com/tag/hitrust-csf)

## Featured posts

### Topics

- [FDA (42)](https://blog.scalehealth.com/tag/fda)
- [QMS (31)](https://blog.scalehealth.com/tag/qms)
- [Compliance (28)](https://blog.scalehealth.com/tag/compliance)
- [Medical Device (27)](https://blog.scalehealth.com/tag/medical-device)
- [Medical Device Company (26)](https://blog.scalehealth.com/tag/medical-device-company)
- [SaMD (26)](https://blog.scalehealth.com/tag/samd)
- [Data Security (17)](https://blog.scalehealth.com/tag/data-security)
- [Regulations (17)](https://blog.scalehealth.com/tag/regulations)
- [21 CFR Part 820 (15)](https://blog.scalehealth.com/tag/21-cfr-part-820)
- [Medical Devices (15)](https://blog.scalehealth.com/tag/medical-devices)
- [ISO (14)](https://blog.scalehealth.com/tag/iso)
- [FDA Approval (13)](https://blog.scalehealth.com/tag/fda-approval)
- [Agile (12)](https://blog.scalehealth.com/tag/agile)
- [Data Privacy (12)](https://blog.scalehealth.com/tag/data-privacy)
- [FDA Regulation (12)](https://blog.scalehealth.com/tag/fda-regulation)
- [ISO 13485 (11)](https://blog.scalehealth.com/tag/iso-13485)
- [SaMD Development (11)](https://blog.scalehealth.com/tag/samd-development)
- [CFR Part 820 (10)](https://blog.scalehealth.com/tag/cfr-part-820)
- [Data Requirements (10)](https://blog.scalehealth.com/tag/data-requirements)
- [Document Controls (10)](https://blog.scalehealth.com/tag/document-controls)
- [FDA Pre-Sub (10)](https://blog.scalehealth.com/tag/fda-pre-sub)
- [Health Technology (10)](https://blog.scalehealth.com/tag/health-technology)
- [Regulatory Pathway (10)](https://blog.scalehealth.com/tag/regulatory-pathway)
- [AI (9)](https://blog.scalehealth.com/tag/ai)
- [Documentation (9)](https://blog.scalehealth.com/tag/documentation)
- [GxP Cloud (9)](https://blog.scalehealth.com/tag/gxp-cloud)
- [Quality System Regulation (9)](https://blog.scalehealth.com/tag/quality-system-regulation)
- [Technology (9)](https://blog.scalehealth.com/tag/technology)
- [Validated Cloud (9)](https://blog.scalehealth.com/tag/validated-cloud)
- [risk (9)](https://blog.scalehealth.com/tag/risk)
- [Cloud (8)](https://blog.scalehealth.com/tag/cloud)
- [FDA Audit (8)](https://blog.scalehealth.com/tag/fda-audit)
- [GxP (8)](https://blog.scalehealth.com/tag/gxp)
- [Health Data (8)](https://blog.scalehealth.com/tag/health-data)
- [ISO 13485:2016 (8)](https://blog.scalehealth.com/tag/iso-134852016)
- [ISO 14971 (8)](https://blog.scalehealth.com/tag/iso-14971)
- [Manufacturing (8)](https://blog.scalehealth.com/tag/manufacturing)
- [PHI (8)](https://blog.scalehealth.com/tag/phi)
- [Personal Health Information (8)](https://blog.scalehealth.com/tag/personal-health-information)
- [Conformity (7)](https://blog.scalehealth.com/tag/conformity)
- [Healthcare (7)](https://blog.scalehealth.com/tag/healthcare)
- [Life Science QMS (7)](https://blog.scalehealth.com/tag/life-science-qms)
- [Medical Solutions (7)](https://blog.scalehealth.com/tag/medical-solutions)
- [Product Development (7)](https://blog.scalehealth.com/tag/product-development)
- [Regulatory Strategy (7)](https://blog.scalehealth.com/tag/regulatory-strategy)
- [SaMD QMS (7)](https://blog.scalehealth.com/tag/samd-qms)
- [Software Requirement Specification (7)](https://blog.scalehealth.com/tag/software-requirement-specification)
- [Standards (7)](https://blog.scalehealth.com/tag/standards)
- [21 CFR (6)](https://blog.scalehealth.com/tag/21-cfr)
- [Quality Management System (6)](https://blog.scalehealth.com/tag/quality-management-system)
- [Quality Processes (6)](https://blog.scalehealth.com/tag/quality-processes)
- [Regulatory Roadmap (6)](https://blog.scalehealth.com/tag/regulatory-roadmap)
- [eHealth (6)](https://blog.scalehealth.com/tag/ehealth)
- [21 CFR Part 11 (5)](https://blog.scalehealth.com/tag/21-cfr-part-11)
- [Artificial Intelligence (5)](https://blog.scalehealth.com/tag/artificial-intelligence)
- [CAPA (5)](https://blog.scalehealth.com/tag/capa)
- [COVID19 (5)](https://blog.scalehealth.com/tag/covid19)
- [Design Controls (5)](https://blog.scalehealth.com/tag/design-controls)
- [Digital Health (5)](https://blog.scalehealth.com/tag/digital-health)
- [Health Tech (5)](https://blog.scalehealth.com/tag/health-tech)
- [Jira Cloud (5)](https://blog.scalehealth.com/tag/jira-cloud)
- [Jira QMS (5)](https://blog.scalehealth.com/tag/jira-qms)
- [New Drugs (5)](https://blog.scalehealth.com/tag/new-drugs)
- [QMS healthcare (5)](https://blog.scalehealth.com/tag/qms-healthcare)
- [Sierra QMS (5)](https://blog.scalehealth.com/tag/sierra-qms)
- [training management (5)](https://blog.scalehealth.com/tag/training-management)
- [Automation (4)](https://blog.scalehealth.com/tag/automation)
- [Biopharma (4)](https://blog.scalehealth.com/tag/biopharma)
- [Business Associates (4)](https://blog.scalehealth.com/tag/business-associates)
- [Communication (4)](https://blog.scalehealth.com/tag/communication)
- [Covered Entities (4)](https://blog.scalehealth.com/tag/covered-entities)
- [Data Integrity (4)](https://blog.scalehealth.com/tag/data-integrity)
- [Development Change (4)](https://blog.scalehealth.com/tag/development-change)
- [Drug Approval (4)](https://blog.scalehealth.com/tag/drug-approval)
- [GAMP5 (4)](https://blog.scalehealth.com/tag/gamp5)
- [HIPAA (4)](https://blog.scalehealth.com/tag/hipaa)
- [HIPAA Compliance (4)](https://blog.scalehealth.com/tag/hipaa-compliance)
- [Health Applications (4)](https://blog.scalehealth.com/tag/health-applications)
- [Integrated QMS (4)](https://blog.scalehealth.com/tag/integrated-qms)
- [Medical Device Startups (4)](https://blog.scalehealth.com/tag/medical-device-startups)
- [Pre-Submission (4)](https://blog.scalehealth.com/tag/pre-submission)
- [Product Lifecycle (4)](https://blog.scalehealth.com/tag/product-lifecycle)
- [Quality Roadmap (4)](https://blog.scalehealth.com/tag/quality-roadmap)
- [Recall (4)](https://blog.scalehealth.com/tag/recall)
- [Regulatory Approach (4)](https://blog.scalehealth.com/tag/regulatory-approach)
- [Remote Work (4)](https://blog.scalehealth.com/tag/remote-work)
- [Scale-ups (4)](https://blog.scalehealth.com/tag/scale-ups)
- [Software (4)](https://blog.scalehealth.com/tag/software)
- [Streamline Workflows (4)](https://blog.scalehealth.com/tag/streamline-workflows)
- [document management (4)](https://blog.scalehealth.com/tag/document-management)
- [ePHI (4)](https://blog.scalehealth.com/tag/ephi)
- [510(k) (3)](https://blog.scalehealth.com/tag/510k)
- [COVID-19 Solution (3)](https://blog.scalehealth.com/tag/covid-19-solution)
- [Case Study (3)](https://blog.scalehealth.com/tag/case-study)
- [Compliance Process (3)](https://blog.scalehealth.com/tag/compliance-process)
- [Cybersecurity (3)](https://blog.scalehealth.com/tag/cybersecurity)
- [DTx (3)](https://blog.scalehealth.com/tag/dtx)
- [Design Verification (3)](https://blog.scalehealth.com/tag/design-verification)
- [Document Automation Tools (3)](https://blog.scalehealth.com/tag/document-automation-tools)
- [FDA Standard (3)](https://blog.scalehealth.com/tag/fda-standard)
- [GAMP (3)](https://blog.scalehealth.com/tag/gamp)
- [HIPAA Checklist (3)](https://blog.scalehealth.com/tag/hipaa-checklist)
- [Hardware-based (3)](https://blog.scalehealth.com/tag/hardware-based)
- [IEC 62304 (3)](https://blog.scalehealth.com/tag/iec-62304)
- [ISPE (3)](https://blog.scalehealth.com/tag/ispe)
- [Iterative Process (3)](https://blog.scalehealth.com/tag/iterative-process)
- [Life Science (3)](https://blog.scalehealth.com/tag/life-science)
- [Medical Technology (3)](https://blog.scalehealth.com/tag/medical-technology)
- [Pharma (3)](https://blog.scalehealth.com/tag/pharma)
- [Predicate Device (3)](https://blog.scalehealth.com/tag/predicate-device)
- [Product Requirements Document (3)](https://blog.scalehealth.com/tag/product-requirements-document)
- [QMS for SaMD Startups (3)](https://blog.scalehealth.com/tag/qms-for-samd-startups)
- [Risk Management (3)](https://blog.scalehealth.com/tag/risk-management)
- [SOC (3)](https://blog.scalehealth.com/tag/soc)
- [SOC 2 (3)](https://blog.scalehealth.com/tag/soc-2)
- [SOP (3)](https://blog.scalehealth.com/tag/sop)
- [SaMD Startups (3)](https://blog.scalehealth.com/tag/samd-startups)
- [Software Development (3)](https://blog.scalehealth.com/tag/software-development)
- [Telecare (3)](https://blog.scalehealth.com/tag/telecare)
- [Telehealth (3)](https://blog.scalehealth.com/tag/telehealth)
- [eQMS (3)](https://blog.scalehealth.com/tag/eqms)
- [AWS (2)](https://blog.scalehealth.com/tag/aws)
- [Audit Trails (2)](https://blog.scalehealth.com/tag/audit-trails)
- [CDER (2)](https://blog.scalehealth.com/tag/cder)
- [CE Marking (2)](https://blog.scalehealth.com/tag/ce-marking)
- [CFR (2)](https://blog.scalehealth.com/tag/cfr)
- [Center for Biologics Evaluation and Research (2)](https://blog.scalehealth.com/tag/center-for-biologics-evaluation-and-research)
- [Center for Drug Evaluation and Research (2)](https://blog.scalehealth.com/tag/center-for-drug-evaluation-and-research)
- [Clinical Evaluation (2)](https://blog.scalehealth.com/tag/clinical-evaluation)
- [Corrective Action Preventive Action (2)](https://blog.scalehealth.com/tag/corrective-action-preventive-action)
- [Document Automation (2)](https://blog.scalehealth.com/tag/document-automation)
- [Document Control (2)](https://blog.scalehealth.com/tag/document-control)
- [Documentation Automation (2)](https://blog.scalehealth.com/tag/documentation-automation)
- [Electronic Records (2)](https://blog.scalehealth.com/tag/electronic-records)
- [GMP (2)](https://blog.scalehealth.com/tag/gmp)
- [General Controls (2)](https://blog.scalehealth.com/tag/general-controls)
- [HITRUST (2)](https://blog.scalehealth.com/tag/hitrust)
- [HITRUST CSF (2)](https://blog.scalehealth.com/tag/hitrust-csf)
- [ML (2)](https://blog.scalehealth.com/tag/ml)
- [Machine Learning (2)](https://blog.scalehealth.com/tag/machine-learning)
- [New Draft (2)](https://blog.scalehealth.com/tag/new-draft)
- [Pharmaceutical (2)](https://blog.scalehealth.com/tag/pharmaceutical)
- [Pre-market approval (2)](https://blog.scalehealth.com/tag/pre-market-approval)
- [QS (2)](https://blog.scalehealth.com/tag/qs)
- [Risk Classification (2)](https://blog.scalehealth.com/tag/risk-classification)
- [Risk Managment (2)](https://blog.scalehealth.com/tag/risk-managment)
- [Sierra Policies (2)](https://blog.scalehealth.com/tag/sierra-policies)
- [Sierra Services (2)](https://blog.scalehealth.com/tag/sierra-services)
- [Standard Operating Procedure (2)](https://blog.scalehealth.com/tag/standard-operating-procedure)
- [fda submission (2)](https://blog.scalehealth.com/tag/fda-submission)
- [mHealth Wearables (2)](https://blog.scalehealth.com/tag/mhealth-wearables)
- [rta (2)](https://blog.scalehealth.com/tag/rta)
- [software as medical device (2)](https://blog.scalehealth.com/tag/software-as-medical-device)
- [21 cfr 807 (1)](https://blog.scalehealth.com/tag/21-cfr-807)
- [513G (1)](https://blog.scalehealth.com/tag/513g)
- [AAMI TIR45 (1)](https://blog.scalehealth.com/tag/aami-tir45)
- [AICPA (1)](https://blog.scalehealth.com/tag/aicpa)
- [ANVISA (1)](https://blog.scalehealth.com/tag/anvisa)
- [Agência Nacional de Vigilância Sanitária (1)](https://blog.scalehealth.com/tag/agência-nacional-de-vigilância-sanitária)
- [Amazon Web Services (1)](https://blog.scalehealth.com/tag/amazon-web-services)
- [Analytical Validation (1)](https://blog.scalehealth.com/tag/analytical-validation)
- [Annex 11 (1)](https://blog.scalehealth.com/tag/annex-11)
- [Australian Therapeutic Goods Administration (1)](https://blog.scalehealth.com/tag/australian-therapeutic-goods-administration)
- [BLA (1)](https://blog.scalehealth.com/tag/bla)
- [Backlog (1)](https://blog.scalehealth.com/tag/backlog)
- [Biologic Approval (1)](https://blog.scalehealth.com/tag/biologic-approval)
- [Business Goals (1)](https://blog.scalehealth.com/tag/business-goals)
- [CGMP (1)](https://blog.scalehealth.com/tag/cgmp)
- [Cannabis (1)](https://blog.scalehealth.com/tag/cannabis)
- [Cannabis Compliance (1)](https://blog.scalehealth.com/tag/cannabis-compliance)
- [Change Control (1)](https://blog.scalehealth.com/tag/change-control)
- [Client Reference (1)](https://blog.scalehealth.com/tag/client-reference)
- [Clinical Development (1)](https://blog.scalehealth.com/tag/clinical-development)
- [Clinical Validation (1)](https://blog.scalehealth.com/tag/clinical-validation)
- [Code Reviews (1)](https://blog.scalehealth.com/tag/code-reviews)
- [Conference (1)](https://blog.scalehealth.com/tag/conference)
- [Coronavirus (1)](https://blog.scalehealth.com/tag/coronavirus)
- [Current Good Manufacturing Practice (1)](https://blog.scalehealth.com/tag/current-good-manufacturing-practice)
- [Customer Complaint (1)](https://blog.scalehealth.com/tag/customer-complaint)
- [Data Transfer (1)](https://blog.scalehealth.com/tag/data-transfer)
- [Design Changes (1)](https://blog.scalehealth.com/tag/design-changes)
- [Design History File (1)](https://blog.scalehealth.com/tag/design-history-file)
- [Design Transfer (1)](https://blog.scalehealth.com/tag/design-transfer)
- [Development Team (1)](https://blog.scalehealth.com/tag/development-team)
- [Device Classification (1)](https://blog.scalehealth.com/tag/device-classification)
- [Device Software Functions (1)](https://blog.scalehealth.com/tag/device-software-functions)
- [Document Publishing (1)](https://blog.scalehealth.com/tag/document-publishing)
- [Drug Manufacturing (1)](https://blog.scalehealth.com/tag/drug-manufacturing)
- [EUA (1)](https://blog.scalehealth.com/tag/eua)
- [Electronic Signatures (1)](https://blog.scalehealth.com/tag/electronic-signatures)
- [Emergency Use Authorization (1)](https://blog.scalehealth.com/tag/emergency-use-authorization)
- [Enforcement Discretion (1)](https://blog.scalehealth.com/tag/enforcement-discretion)
- [Engineering (1)](https://blog.scalehealth.com/tag/engineering)
- [Ethos Automated System (1)](https://blog.scalehealth.com/tag/ethos-automated-system)
- [FDA Draft (1)](https://blog.scalehealth.com/tag/fda-draft)
- [HHS (1)](https://blog.scalehealth.com/tag/hhs)
- [Hand Sanitizer (1)](https://blog.scalehealth.com/tag/hand-sanitizer)
- [Hardware Development (1)](https://blog.scalehealth.com/tag/hardware-development)
- [IEC (1)](https://blog.scalehealth.com/tag/iec)
- [IEC 60601 (1)](https://blog.scalehealth.com/tag/iec-60601)
- [IEC 60601:1 (1)](https://blog.scalehealth.com/tag/iec-606011)
- [IEC 62366  (1)](https://blog.scalehealth.com/tag/iec-62366)
- [IFU (1)](https://blog.scalehealth.com/tag/ifu)
- [IND (1)](https://blog.scalehealth.com/tag/ind)
- [ISO 13485: 2003 (1)](https://blog.scalehealth.com/tag/iso-13485-2003)
- [ISO90003:2004 (1)](https://blog.scalehealth.com/tag/iso900032004)
- [Intellectual Property (1)](https://blog.scalehealth.com/tag/intellectual-property)
- [International Electrotechnical Commission (1)](https://blog.scalehealth.com/tag/international-electrotechnical-commission)
- [International Organization for Standardization (1)](https://blog.scalehealth.com/tag/international-organization-for-standardization)
- [Jira Server (1)](https://blog.scalehealth.com/tag/jira-server)
- [Key Terms (1)](https://blog.scalehealth.com/tag/key-terms)
- [Labeling (1)](https://blog.scalehealth.com/tag/labeling)
- [Liability (1)](https://blog.scalehealth.com/tag/liability)
- [MDSAP (1)](https://blog.scalehealth.com/tag/mdsap)
- [METRC (1)](https://blog.scalehealth.com/tag/metrc)
- [MHLW/PMDA (1)](https://blog.scalehealth.com/tag/mhlw-pmda)
- [Management Controls (1)](https://blog.scalehealth.com/tag/management-controls)
- [Masks (1)](https://blog.scalehealth.com/tag/masks)
- [Medical Device Single Audit Program (1)](https://blog.scalehealth.com/tag/medical-device-single-audit-program)
- [Medical Marijuana (1)](https://blog.scalehealth.com/tag/medical-marijuana)
- [Ministry of Health, Labour and Welfare (1)](https://blog.scalehealth.com/tag/ministry-of-health-labour-and-welfare)
- [Myths (1)](https://blog.scalehealth.com/tag/myths)
- [New Approach Directives (1)](https://blog.scalehealth.com/tag/new-approach-directives)
- [New Drug Application (1)](https://blog.scalehealth.com/tag/new-drug-application)
- [Nonconformity (1)](https://blog.scalehealth.com/tag/nonconformity)
- [PCCP (1)](https://blog.scalehealth.com/tag/pccp)
- [PRD (1)](https://blog.scalehealth.com/tag/prd)
- [Pandemic (1)](https://blog.scalehealth.com/tag/pandemic)
- [Part 11 (1)](https://blog.scalehealth.com/tag/part-11)
- [Part 820.30 (1)](https://blog.scalehealth.com/tag/part-820-30)
- [Performance Tests (1)](https://blog.scalehealth.com/tag/performance-tests)
- [Preliminary Screening (1)](https://blog.scalehealth.com/tag/preliminary-screening)
- [Project Deliverables (1)](https://blog.scalehealth.com/tag/project-deliverables)
- [Project Timeline (1)](https://blog.scalehealth.com/tag/project-timeline)
- [QA/RA (1)](https://blog.scalehealth.com/tag/qa-ra)
- [QMSR (1)](https://blog.scalehealth.com/tag/qmsr)
- [Regulatory Options (1)](https://blog.scalehealth.com/tag/regulatory-options)
- [SRS (1)](https://blog.scalehealth.com/tag/srs)
- [SaMD Risk Classification (1)](https://blog.scalehealth.com/tag/samd-risk-classification)
- [SaMD for QMS (1)](https://blog.scalehealth.com/tag/samd-for-qms)
- [SiMD (1)](https://blog.scalehealth.com/tag/simd)
- [Software Architecture (1)](https://blog.scalehealth.com/tag/software-architecture)
- [Sprints (1)](https://blog.scalehealth.com/tag/sprints)
- [Substantial Equivalence (1)](https://blog.scalehealth.com/tag/substantial-equivalence)
- [TGA (1)](https://blog.scalehealth.com/tag/tga)
- [TSC (1)](https://blog.scalehealth.com/tag/tsc)
- [Trust Services Criteria (1)](https://blog.scalehealth.com/tag/trust-services-criteria)
- [Valid Clinical Association (1)](https://blog.scalehealth.com/tag/valid-clinical-association)
- [Validation Testing (1)](https://blog.scalehealth.com/tag/validation-testing)
- [Waterfall Method (1)](https://blog.scalehealth.com/tag/waterfall-method)
- [Webinar (1)](https://blog.scalehealth.com/tag/webinar)
- [Workflow Transitions (1)](https://blog.scalehealth.com/tag/workflow-transitions)
- [abbreviated 510(k) (1)](https://blog.scalehealth.com/tag/abbreviated-510k)
- [administrative evaluation (1)](https://blog.scalehealth.com/tag/administrative-evaluation)
- [medical device quality management system (1)](https://blog.scalehealth.com/tag/medical-device-quality-management-system)
- [paperless quality processes (1)](https://blog.scalehealth.com/tag/paperless-quality-processes)
- [qms Samd (1)](https://blog.scalehealth.com/tag/qms-samd)
- [qms cloud (1)](https://blog.scalehealth.com/tag/qms-cloud)
- [refuse-to-accept (1)](https://blog.scalehealth.com/tag/refuse-to-accept)
- [rta letter (1)](https://blog.scalehealth.com/tag/rta-letter)
- [special 510(k) (1)](https://blog.scalehealth.com/tag/special-510k)
- [traditional 510(k) (1)](https://blog.scalehealth.com/tag/traditional-510k)

See all

### Subscribe Here

- ![sierra-labs](https://blog.scalehealth.com/hubfs/Sierralabs_January2019%20Theme/Images/sierra-labs-logo.png)
- © 2022 Sierra Labs, Inc.

- Contact Us
- [hello@sierralabs.com](mailto:hello@sierralabs.com)
- 3415 S. Sepulveda Blvd.   
  Suite 1000   
  Los Angeles, CA 90034
- (310) 437-8010

- Products

- Company
- [About Us](https://www.sierralabs.com/about)