Compliance

Questions about this page? Write to mednais@samplify.org.

Organisations that ask about compliance usually want to know two things: what we have been certified for, and what the product's records will and will not stand up as. Both answers are short.

Of the three things the product does — Educate, Assist and Monitor efficiency — it is the third that produces the records this page is about. The efficiency it names is a procedure's: how long the steps of a published version take in your own organisation. It is not a measurement of a person, there is no ranking of employees in the product and no productivity score, and what follows is what the records are and are not worth.

Certifications we hold

None. There is no ISO/IEC 27001 certificate, no SOC 2 report, no HIPAA attestation, no CE marking and no FDA clearance or registration, and MedNAIS™ is not a certified or validated system in any regulatory scheme. If you need one of those from a supplier, we are not that supplier today. We would rather you found that out on this page than in a procurement review.

Not a medical device

MedNAIS is general-purpose software for carrying out written procedures. It does not diagnose, treat, monitor or make any decision about an individual patient, and it must not be used as a medical device. Healthcare and laboratories are one of four kinds of work it is addressed to, alongside manufacturing and maintenance, logistics and warehousing, and construction and workplace safety. A checklist carried out in a hospital is not thereby a medical device, and we make no clinical claim of any kind.

Not an eIFU system

A procedure can be published to a printed QR code, which opens it in a reader's browser. That is a way to put instructions in somebody's hand, and it is not electronic instructions for use in the regulatory sense. We make no claim under the EU medical device or in-vitro diagnostic regulations, none to the FDA, and none under any comparable scheme elsewhere. Specifically, we do not undertake any of the duties that fall on a manufacturer who supplies instructions electronically: not the form or content the instructions must take, not the set of languages they must appear in, not the period for which they must remain available, not a paper copy supplied on request, and not notifying anybody when they change. If a rule obliges you to supply instructions in a particular way, MedNAIS does not discharge that obligation and does not assess whether you have discharged it.

Two properties of the feature follow from how it is built rather than from any regulatory intent, and a reviewer should have both. A printed code depends on a live publication licence and stops serving the procedure a few days after that term lapses, showing a page naming the publisher and how to reach them instead. And the code serves the version it was last published to — correcting a procedure does not move it until the publisher publishes to that code again. Neither is a guarantee of continuous availability, and we do not offer one.

What an execution record is

A record of what was entered into the product: which version of a procedure was performed, by whom, in what order, and how long each step took. It is useful evidence that a procedure was followed, and organisations reasonably keep it for incident reviews and inspections. It is not an audit, not a compliance certificate, and not proof of compliance on its own — and a device sending a heartbeat is not proof that somebody was standing at it.

Timing figures are calculated from your own organisation's recent runs. They describe your practice. They are not a norm, a target or a limit, they are never compared with an outside standard, and nothing in the product will present them as one.

Standards a procedure refers to

Procedures are written from documents your organisation supplies. Where MedNAIS suggests the document that ordinarily governs a piece of work, it puts the name to the register of the body that issues it and shows you the designation, title and edition that register returned — obtaining the document is yours to do. Citing a standard in a procedure is not certification against that standard, we claim no affiliation with any standards body, and a register's answer is that register's rather than ours.

Integrations

There is no HL7 FHIR interface, no LIS or LIMS connector and no hospital-information-system integration in MedNAIS. Earlier versions of this site said otherwise; they were wrong. Data leaves the product as CSV, exported from whatever the analytics filters select.

What we can give you

A data processing agreement; the list of everyone who processes data on our behalf and where they are, which is published in the privacy policy rather than kept for customers; and an answer to a security questionnaire as candid as our security page. Write to mednais@samplify.org.