Legal support for healthtech and medtech
We advise developers of health apps, medical devices, and telemedicine platforms on MDR/IVDR compliance, sensitive data protection, the AI Act, and copyright assignments.
From product classification to due diligence ahead of a funding round.
- We’ll analyse your platform and show you where regulations hold back growth and where they give you an edge.
- We’ll find the shortest route to MDR, GDPR, and AI Act compliance without disrupting your roadmap.
- We’ll protect your intellectual property and ensure your copyright assignments and agreements with software development companies are in order before the investment process begins.
Give your technology a foundation for success.
You don't know whether your product is a medical device
You're worried MDR certification will freeze development for years, while your lawyer sees nothing but risk.
We'll help identify the simplest route to compliance. Medical device regulations should be an asset in discussions with partners, not an obstacle to your plans.
You process sensitive data but aren't sure your procedures are sound
Medical data is a special category of personal data under the GDPR.
A missing DPIA, gaps in patient consent, or issues with data transfers to third countries destroy user trust and block market entry.
You're implementing AI in diagnostics and getting lost in the AI Act
Algorithms that support clinical decisions are usually high-risk systems.
The AI Act requires technical documentation, risk management, and human oversight. Without a compliance strategy, deployment stalls before the product reaches its first clinician.
Your funding round is on hold, and the IP audit is stalled
You have a chance to secure VC funding, but unclear assignments of developers' economic rights under copyright are holding up due diligence.
We put your intellectual property in order at the pace your investment process demands.
A software development company is writing your code without a clear transfer of rights
You're paying to develop the platform, but you're not sure whether you actually own the copyright in the code.
No one has read the licence agreements from start to finish, and the key copyright assignment clauses are unclear. Your company's intellectual property is in limbo.
Advertising of medical services under regulatory scrutiny
Advertising of medical services and medical devices is strictly regulated. Legal requirements govern the content, channels, and target audience.
A single ill-judged post can trigger proceedings, and you want to grow sales without unexpected intervention from URPL.
Lawyers who work
like your co-founders.
We take responsibility You don't know whether your product is a medical device
You get a clear decision, not a list of uncertainties. We provide a written classification of your product, setting out our reasoning, the device class, and the shortest conformity assessment route. You can present it to notified bodies, investors, and business partners.
We draw the line between a wellness app and a medical device based on the product's stated function and take responsibility for that classification, so your team can plan its roadmap with confidence.
Standards that give you the freedom to scale You process sensitive data but aren't sure your procedures are sound
Set up once, these procedures support every new feature. You receive a complete set of medical data protection documents, including a DPIA, records of processing activities, patient consent forms, and rules for transfers to third countries. Your developers and product owners also learn to identify risk at the design stage.
Your team handles the next implementation independently, without waiting for our advice at every sprint.
Recommendations that clear the way for growth You're implementing AI in diagnostics and getting lost in the AI Act
We don't just tell you what you can't do. We classify the system under the AI Act and turn the requirements, including technical documentation, risk management, and human oversight, into tasks your team can add directly to the backlog.
For SaMD products, we show you where the AI Act overlaps with the MDR, so one set of documentation can cover both regulatory regimes.
We work to your funding timeline Your funding round is on hold, and the IP audit is stalled
In a funding round, “in a month” means “too late”. We review licence agreements, medical documentation, and data room materials to your investment timetable, not our own.
We establish a clear chain of title to your code and algorithms before the fund has a chance to ask about it.
We speak your language A software development company is writing your code without a clear transfer of rights
We read your agreement with the software development company the way a developer would. We check what rights you actually have, where the licence ends and the assignment of economic rights under copyright begins, and what happens to the code after the engagement ends. You don't need to explain repositories, sprints, or the software lifecycle to us.
You receive our revisions as ready-to-send clauses for the other party.
Obsessed with healthtech and medtech Advertising of medical services under regulatory scrutiny
We work exclusively with technology companies, including developers of healthcare solutions, so we keep up to date with URPL's positions and amendments to the Medical Devices Act. Before launching a campaign, you know which messages are acceptable and which will trigger an inspection. We review the content, channel, and target audience alongside the graphics.
You grow sales with a clear understanding of the legal boundaries from the outset.
Your healthtech lawyer - comprehensive legal support.
Product classification and regulatory audit (MDR/IVDR) Product classification and MDR/IVDR audit
We'll determine whether your app or software qualifies as a medical device under the MDR.
We'll analyse the product's features, assign it to the correct class, and identify the shortest route to certification, preparing you for the conformity assessment process.
Medical data protection and GDPR audit Medical data protection and GDPR
We'll implement procedures for protecting sensitive data and conduct a data protection impact assessment (DPIA).
We'll design mechanisms for obtaining patients' informed consent and procedures for responding to personal data breaches, so data security doesn't hold back product development.
Cybersecurity and NIS2 compliance Cybersecurity and NIS2
We audit your NIS2 readiness and draft network security policies.
We also review supply chain security and prepare the documentation required by the supervisory authority.
IT agreements, licences, and copyright assignments IT agreements and copyright assignments
We draft and negotiate SaaS licence agreements, implementation agreements, and NDAs tailored to the medtech sector.
Precise clauses assigning the economic rights under copyright in code and algorithms protect your company's intellectual property ahead of the investment process.
AI in healthtech – AI Act compliance AI in healthtech and the AI Act
We support the implementation of AI systems used in diagnostics and medical decision support.
We classify your system under the AI Act and address training data quality, legal requirements for test results, and algorithm transparency. For SaMD (Software as a Medical Device) products, we also analyse how the AI Act and the MDR interact.
Legal support for telemedicine and e-health Telemedicine and e-health
We analyse platforms for remotely monitoring vital signs and providing medical consultations.
We advise on healthcare provider registration, maintaining medical records, and verifying patient identity.
Transaction support and due diligence Transaction support and due diligence
We prepare your healthtech company for a funding round by organising the data room documentation to address regulatory requirements and intellectual property protection.
We help negotiate investment agreements, including term sheets and shareholders' agreements (SHAs). Certification and data protection compliance boost your valuation in the eyes of VCs.Trade marks and intellectual property protection Trade marks and intellectual property
We register trade marks in Poland, across the EU, and worldwide.
We assess patentability and review strategies for protecting know-how. In medical technology, intellectual property is often a company's most valuable asset.
This won't be legal support as you know it
What is it like to work with us?
Frequently asked questions about legal support for healthtech and medtech
We provide individual quotes for one-off projects, such as MDR classification, a GDPR audit, or a contract package. Fees range from a few thousand to over ten thousand zlotys. Ongoing legal support under a subscription starts at PLN 3,000 excl. VAT per month. You receive the price upfront after a free consultation, with no hidden costs. Ask for a quote
Your dedicated lawyer knows your roadmap, assesses feature changes as they arise, and reviews medical documentation and agreements with business partners. No hourly billing, just a predictable budget.
Yes. We handle 99% of communication online, using Teams and Meet for calls, sharing documents electronically, and signing through Autenti. Our legal support for medical technology companies is fully remote.
Yes. We organise data room documentation, review licence agreements with developers and suppliers, draft shareholders’ agreement (SHA) clauses, and review term sheets. In medical technology transactions, we make sure regulatory status and intellectual property protection increase the valuation.
Yes. If medical data is breached, you have 72 hours to report it to UODO. We guide clients through risk assessment, documentation for the authority, and patient communications, in line with the heightened protection required under the GDPR.
MedTech, or medical technology, covers devices, software, and digital services used in diagnostics, treatment, patient monitoring, and healthcare facility management. Healthtech is a broader category that also includes health and wellness apps that are not medical devices. Medtech products are subject to the MDR and IVDR.
No. A product’s stated intended purpose is what matters. The MDR applies to medical devices “intended for medical use” as defined in the regulation. Wellness-only apps, such as step trackers with no diagnostic function, may fall outside the MDR. Apps that support medical decisions or diagnostics fall within its scope. Classification requires an analysis of the app’s functionality.
Yes. Medical data is a special category of personal data under the GDPR. It requires informed patient consent, a DPIA, privacy-by-design mechanisms, and higher data security standards. The data minimisation principle means you process only the information you need and keep it no longer than necessary.
Most AI solutions used in diagnostics and clinical decision support are high-risk AI systems under the AI Act. They require technical documentation, risk management, human oversight, and algorithm transparency. AI test results must be verifiable, and the interaction between the AI Act and the MDR creates additional obligations.
We draft clauses assigning economic rights under copyright in agreements with developers, review licence agreements, and register trade marks. In medical technology, intellectual property protection is often a company's most valuable asset, and putting the right safeguards in place increases the company's valuation during the investment process.
Maintaining medical records online requires data integrity and confidentiality. Technical measures must comply with the Polish Act on Patient Rights and the GDPR. These include secure storage, access controls, logs, and procedures for obtaining informed patient consent.
We represent clients in medical device matters before URPL, in data protection matters before UODO, and in proceedings before administrative courts. Drafting legal submissions, fulfilling regulatory obligations, and meeting legal requirements are part of our daily work. Our team has worked on healthtech projects for businesses ranging from startups to technology companies expanding globally. We preserve the integrity of evidence and meet procedural deadlines.
Preparing MDR/IVDR technical documentation is a key part of the certification process. We support every stage, including drafting SOPs, policies, instructions for use, data storage records, and training materials for teams. We tailor our work to each organisation and its products, from health apps to advanced SaMD systems. Our reviews cover compliance with the Polish Act on Medical Devices and the GDPR, and we stay involved throughout the process.
Let's discuss legal solutions for your business.
We'll get back to you within 12 hours (on business days).