top of page

Compliance & Regulatory
 

Effective Date: January 15, 2001
Last Updated: October 4, 2026

xBxBio develops connected cardiovascular intelligence, software, research technologies, data-integration capabilities, computational models, and related digital-health technologies.

xBxBio recognizes that healthcare and medical-technology development operates within complex regulatory, quality, privacy, cybersecurity, research, clinical, data-integrity, interoperability, and risk-management environments.

This Compliance & Regulatory statement describes the principles, regulatory frameworks, standards, and governance considerations that xBxBio may apply to its activities, products, research, software, services, vendors, and business relationships, depending on intended use, jurisdiction, product classification, deployment model, customer relationship, and applicable law.

xBxBio's objective is to develop and operate its technologies using a risk-based, evidence-aware, quality-focused approach consistent with applicable legal and regulatory requirements and recognized industry practices.

References on this page to a law, regulation, standard, agency, certification, or framework do not mean that every requirement applies to every xBxBio product or activity.

Applicability must be determined for each product, intended use, jurisdiction, configuration, deployment, customer relationship, research activity, and stage of development.

Except where xBxBio expressly states otherwise, references to standards or regulatory frameworks should not be interpreted as a representation that xBxBio currently holds a particular regulatory authorization, clearance, approval, certification, accreditation, or conformity mark.

Certain xBxBio technologies are research-stage, developmental, investigational, or pre-commercial and may not be authorized for clinical use.

1. Regulatory and Compliance Governance

xBxBio seeks to integrate regulatory and compliance considerations throughout the lifecycle of its technologies and business operations.

Depending on the activity, this may include:

  • Regulatory strategy

  • Product qualification and classification

  • Intended-use assessment

  • Quality-management planning

  • Risk management

  • Software lifecycle controls

  • Verification and validation

  • Clinical and scientific evaluation

  • Cybersecurity

  • Privacy and data protection

  • Human-factors and usability considerations

  • Supplier and vendor management

  • Configuration management

  • Change control

  • Data integrity

  • Documentation

  • Audit trails

  • Records management

  • Training

  • Corrective and preventive action

  • Complaint handling

  • Incident management

  • Post-market monitoring

  • Regulatory reporting

  • Artificial-intelligence governance

  • Interoperability

  • Evidence management

  • Regulatory submissions where required

Compliance activities are intended to be proportionate to the risk, intended use, maturity, and regulatory status of the relevant product or activity.

2. United States — FDA and Medical-Device Regulation

Where an xBxBio product or function qualifies as a medical device or otherwise falls within the jurisdiction of the U.S. Food and Drug Administration (“FDA”), xBxBio will evaluate and address applicable requirements under the Federal Food, Drug, and Cosmetic Act (“FD&C Act”), FDA regulations, and relevant FDA guidance.

Potentially applicable requirements may include, depending on the product:

  • Medical-device qualification

  • Device classification

  • Premarket notification or other premarket pathways

  • Premarket approval where required

  • De Novo classification where applicable

  • Registration and listing

  • Labeling

  • Quality-system requirements

  • Software documentation

  • Clinical evidence

  • Human-factors considerations

  • Medical-device reporting

  • Corrections and removals

  • Post-market surveillance

  • Cybersecurity

  • Unique Device Identification where applicable

  • Records and inspections

  • Other product-specific FDA requirements

No statement on xbxbio.com should be interpreted as representing FDA clearance, authorization, approval, or registration unless xBxBio expressly identifies the applicable product and authorization.

3. FDA Quality Management System Regulation — 21 CFR Part 820

For products subject to FDA medical-device manufacturing requirements, xBxBio will evaluate applicability of FDA's Quality Management System Regulation (“QMSR”), 21 CFR Part 820.

The QMSR incorporates by reference ISO 13485:2016 while retaining additional FDA requirements.

Where applicable, xBxBio's quality-system activities may address:

  • Quality-management responsibilities

  • Documented processes

  • Risk-based controls

  • Design and development

  • Supplier controls

  • Production and service controls where relevant

  • Identification and traceability

  • Monitoring and measurement

  • Nonconforming product

  • Corrective and preventive action

  • Complaint handling

  • Records

  • Management review

  • Internal audit

  • Training

  • Regulatory reporting

Application of these controls depends on regulatory status and the role xBxBio performs with respect to a particular regulated product.

4. Electronic Records and Electronic Signatures — 21 CFR Part 11

Where xBxBio creates, modifies, maintains, archives, retrieves, or transmits electronic records subject to FDA predicate rules, xBxBio will evaluate requirements under 21 CFR Part 11 — Electronic Records; Electronic Signatures.

Where applicable, controls may address:

  • System validation

  • Record accuracy

  • Record reliability

  • Record retrieval

  • Access controls

  • User authentication

  • Audit trails

  • Operational checks

  • Authority checks

  • Device checks

  • Electronic signatures

  • Record retention

  • Change control

  • Security

  • Documentation

Part 11 applicability depends on whether the electronic record is required by an applicable FDA predicate rule and the circumstances in which the system is used.

5. HIPAA and HITECH

xBxBio operates in healthcare technology, but HIPAA does not automatically apply to every xBxBio activity.

HIPAA generally applies to covered entities and qualifying business associates. HHS confirms that organizations outside those categories are not subject to HIPAA solely because they handle health-related technology. HHS.gov

Where xBxBio acts as a Business Associate or subcontractor and creates, receives, maintains, or transmits Protected Health Information (“PHI”), applicable requirements may include:

  • HIPAA Privacy Rule

  • HIPAA Security Rule

  • HIPAA Breach Notification Rule

  • HITECH Act requirements

  • Business Associate Agreements

  • Access controls

  • Risk analysis

  • Security safeguards

  • Incident response

  • Breach assessment

  • Workforce controls

  • Vendor and subcontractor requirements

PHI should be processed only within an environment authorized for that purpose.

The general public xbxbio.com website is not intended to function as a clinical PHI-submission portal.

6. Human-Subject Research — United States

Where xBxBio conducts, sponsors, supports, or participates in human-subject research, applicable research requirements will be evaluated.

Depending on the research, these may include:

  • HHS Common Rule under 45 CFR Part 46

  • FDA human-subject protection requirements

  • Institutional Review Board requirements

  • Informed consent requirements

  • Clinical investigation requirements

  • Investigational-device requirements

  • Research protocols

  • Investigator responsibilities

  • Data-monitoring requirements

  • Privacy protections

  • Research agreements

  • Records retention

HHS regulations at 45 CFR Part 46 include the Common Rule and additional protections for certain research populations. HHS.gov

No public description of xBxBio research should be interpreted as representing that an activity is a regulated clinical investigation unless expressly identified as such.

7. NIH, CDC, HHS, and Public-Health Requirements

xBxBio may interact with or monitor requirements, programs, funding opportunities, guidance, research policies, or public-health activities involving:

  • National Institutes of Health (“NIH”)

  • Centers for Disease Control and Prevention (“CDC”)

  • Department of Health and Human Services (“HHS”)

  • Office for Human Research Protections

  • Other federal or state agencies

NIH and CDC are not general-purpose product-certification authorities for xBxBio software.

Requirements associated with a particular NIH-funded study, CDC program, federal award, research activity, or public-health collaboration will be evaluated separately.

8. Medical-Device Cybersecurity — United States

Where an xBxBio product is a regulated medical device with cybersecurity risk, xBxBio will evaluate applicable FDA cybersecurity requirements and guidance.

Depending on applicability, this may include:

  • FD&C Act section 524B requirements for qualifying cyber devices

  • Secure product development

  • Threat modeling

  • Security risk management

  • Vulnerability management

  • Software Bill of Materials considerations

  • Authentication

  • Authorization

  • Encryption

  • Logging

  • Security monitoring

  • Secure updates

  • Patch management

  • Coordinated vulnerability disclosure

  • Incident response

  • Cybersecurity documentation for regulatory submissions

  • Post-market cybersecurity monitoring

Cybersecurity controls will be scaled to the product architecture, intended use, threat environment, and applicable regulatory requirements.

9. European Union — Medical Device Regulation

Where xBxBio software or technology is placed on the European Union or European Economic Area market and qualifies as a medical device, xBxBio will assess the EU Medical Device Regulation, Regulation (EU) 2017/745 (“MDR”).

The MDR expressly recognizes that software specifically intended for medical purposes can itself qualify as a medical device. EUR-Lex

Where applicable, xBxBio may address:

  • Medical-device qualification

  • Intended purpose

  • Risk classification

  • MDR Rule 11 for software

  • General Safety and Performance Requirements

  • Risk management

  • Clinical evaluation

  • Technical documentation

  • Software lifecycle documentation

  • Verification and validation

  • Information security

  • Usability

  • Conformity assessment

  • CE marking

  • Unique Device Identification

  • EUDAMED requirements

  • Post-market surveillance

  • Vigilance

  • Periodic safety reporting where applicable

  • Economic-operator requirements

xBxBio will not represent a product as CE marked unless the applicable conformity-assessment and regulatory requirements have been completed.

10. European Union — In Vitro Diagnostic Regulation

Where an xBxBio product qualifies as an in vitro diagnostic medical device or IVD software, xBxBio will evaluate Regulation (EU) 2017/746 (“IVDR”).

Relevant considerations may include:

  • Qualification

  • Classification

  • Performance evaluation

  • Scientific validity

  • Analytical performance

  • Clinical performance

  • Technical documentation

  • Quality management

  • Conformity assessment

  • Post-market performance follow-up

  • Vigilance

  • Registration

  • UDI requirements

Applicability depends on the intended purpose and regulatory classification of the product.

11. European Union — Artificial Intelligence Act

Where xBxBio develops or deploys artificial-intelligence systems within the scope of Regulation (EU) 2024/1689 (“EU AI Act”), xBxBio will assess obligations applicable to its role and system classification.

The AI Act treats certain AI systems associated with regulated products and third-party conformity assessment as high-risk systems. EUR-Lex

Potential areas of governance include:

  • AI-system classification

  • Risk management

  • Data governance

  • Technical documentation

  • Record keeping

  • Transparency

  • Instructions for use

  • Human oversight

  • Accuracy

  • Robustness

  • Cybersecurity

  • Quality management

  • Post-market monitoring

  • Incident reporting

  • Fundamental-rights considerations

  • Provider and deployer obligations

Requirements of the EU AI Act enter into application according to statutory transition periods, and xBxBio will evaluate applicable requirements as they become effective.

12. European Union — Data Protection

Where applicable, xBxBio will evaluate the General Data Protection Regulation (“GDPR”) and related EU privacy requirements.

Privacy-related obligations are described more fully in the xBxBio Privacy Policy.

Potential areas include:

  • Lawful basis

  • Transparency

  • Purpose limitation

  • Data minimization

  • Data-subject rights

  • Privacy by design and default

  • Security

  • Processor agreements

  • Data Protection Impact Assessments

  • International transfers

  • Breach notification

  • Automated decision-making requirements

13. United Kingdom — Medical Devices

Where xBxBio places regulated medical-device software on the Great Britain market, applicable requirements under the UK Medical Devices Regulations 2002, as amended, and related MHRA requirements will be evaluated.

The Medical Devices Regulations 2002 remain part of the UK medical-device framework and have been amended over time. Legislation.gov.uk

Potential requirements may include:

  • Medical-device qualification

  • Classification

  • Registration

  • Manufacturer obligations

  • UK Responsible Person requirements where applicable

  • Conformity assessment

  • Quality management

  • Clinical evaluation

  • Software evidence

  • Post-market surveillance

  • Vigilance

  • Cybersecurity

  • Labeling

  • Market-access requirements

Requirements applicable to Northern Ireland may differ because of the legal framework applicable there.

14. United Kingdom — Data Protection

Where applicable, xBxBio will evaluate:

  • UK GDPR

  • Data Protection Act 2018

  • Applicable Information Commissioner's Office guidance

  • International-transfer mechanisms

  • Data-subject rights

  • Privacy by design

  • Data security

  • Breach notification

Additional details are addressed in the xBxBio Privacy Policy.

15. Canada — Medical Devices and SaMD

Where an xBxBio product is marketed in Canada and qualifies as a medical device, xBxBio will evaluate Canada's:

  • Food and Drugs Act

  • Medical Devices Regulations

  • Health Canada guidance

  • Software as a Medical Device requirements

  • Device licensing requirements

  • Establishment licensing requirements where applicable

  • Quality-management requirements

  • Safety and effectiveness evidence

  • Labeling

  • Incident reporting

  • Recalls and corrective action

  • Post-market requirements

Health Canada treats qualifying software according to its intended purpose and risk and uses a risk-based device classification framework. Canada

16. Canada — Privacy and Health Information

Where applicable, xBxBio will evaluate:

  • Personal Information Protection and Electronic Documents Act (“PIPEDA”)

  • Applicable provincial privacy laws

  • Provincial personal-health-information requirements

  • Contractual privacy obligations

  • Cross-border processing requirements

Privacy requirements are addressed more fully in the xBxBio Privacy Policy.

17. Japan — PMD Act and Software as a Medical Device

Where xBxBio develops or markets medical software in Japan, xBxBio will evaluate the Act on Securing Quality, Efficacy and Safety of Products Including Pharmaceuticals and Medical Devices (“PMD Act”) and applicable requirements administered by MHLW and PMDA.

Japan regulates qualifying software intended to diagnose or treat disease as medical-device software. PMDA

Depending on the product, considerations may include:

  • SaMD qualification

  • Risk classification

  • Marketing authorization

  • Certification

  • Regulatory consultation

  • Quality management

  • Clinical evidence

  • Performance

  • Software lifecycle controls

  • Cybersecurity

  • Labeling

  • Post-market safety

  • Change management

  • AI-based medical-device considerations

18. Japan — Privacy

Where applicable, xBxBio will evaluate Japan's Act on the Protection of Personal Information (“APPI”), including requirements concerning collection, use, disclosure, security, individual rights, and cross-border transfers.

Additional information is contained in the xBxBio Privacy Policy.

19. Republic of Korea — Medical Devices

Where xBxBio products are developed, imported, distributed, or marketed in the Republic of Korea, xBxBio will evaluate requirements administered by the Ministry of Food and Drug Safety (“MFDS”).

Applicable legislation may include the Medical Devices Act, which expressly includes software within the statutory definition of medical devices. eLaw

Potential requirements may include:

  • Product qualification

  • Classification

  • Approval or certification

  • Manufacturing and import requirements

  • Quality-management requirements

  • Software documentation

  • Clinical evidence

  • Cybersecurity

  • Post-market surveillance

  • Adverse-event reporting

  • Change management

  • Labeling

20. Republic of Korea — Digital Medical Products

xBxBio will evaluate Korea's Digital Medical Products Act where applicable to digital medical devices, AI-enabled medical technologies, digital convergence products, or related products.

The Act establishes a regulatory framework for digital medical products, including digital medical devices incorporating technologies such as intelligent information and communications technology. eLaw

MFDS also maintains quality-management standards relevant to medical devices and digital medical devices. Food and Drug Administration

21. Republic of Korea — Privacy

Where applicable, xBxBio will evaluate Korea's Personal Information Protection Act (“PIPA”) and associated requirements relating to:

  • Collection

  • Processing

  • Consent

  • Sensitive information

  • Security

  • Data-subject rights

  • Retention

  • Cross-border transfers

  • Breach response

Additional information is provided in the xBxBio Privacy Policy.

22. International Medical-Device Principles

Where appropriate, xBxBio may consider internationally harmonized medical-device guidance and principles developed by organizations such as:

  • International Medical Device Regulators Forum (“IMDRF”)

  • Global Harmonization Task Force legacy guidance

  • International Organization for Standardization

  • International Electrotechnical Commission

International guidance does not replace jurisdiction-specific legal requirements.

23. Quality Management Standards

Depending on the product and applicable regulatory pathway, xBxBio may design processes with consideration of standards including:

  • ISO 13485 — Medical-device quality-management systems

  • ISO 14971 — Application of risk management to medical devices

  • Applicable regulatory quality-system requirements

  • Internal quality policies and procedures

Reference to a standard does not represent certification unless xBxBio expressly states that certification has been granted by an appropriate certification body.

24. Software Lifecycle and Validation

Depending on product classification and intended use, xBxBio may apply lifecycle and validation practices informed by standards and industry frameworks such as:

  • IEC 62304 — Medical-device software lifecycle processes

  • IEC 82304-1 — Health software product safety and security

  • IEC 62366-1 — Usability engineering

  • IEC 81001-5-1 — Health-software cybersecurity

  • FDA software guidance

  • IMDRF SaMD principles

  • Risk-based verification and validation

Lifecycle controls may include:

  • Requirements management

  • Architecture

  • Design documentation

  • Coding controls

  • Code review

  • Unit testing

  • Integration testing

  • System testing

  • Traceability

  • Defect management

  • Configuration management

  • Release controls

  • Change management

  • Regression testing

  • Verification

  • Validation

25. Clinical Evaluation and Clinical Investigation

Where required, xBxBio may implement processes addressing:

  • Clinical evaluation

  • Clinical evidence

  • Scientific validity

  • Analytical validation

  • Clinical validation

  • Performance evaluation

  • Clinical investigations

  • Human-subject protections

  • Good Clinical Practice

  • Protocol controls

  • Investigator responsibilities

  • Ethics or IRB review

  • Informed consent

  • Safety reporting

  • Statistical analysis

  • Evidence provenance

Where applicable, standards such as ISO 14155 may be considered for clinical investigations of medical devices.

26. Risk Management

xBxBio seeks to use a structured, lifecycle-based approach to risk management.

Where applicable, risk-management activities may include:

  • Hazard identification

  • Foreseeable misuse

  • Risk estimation

  • Risk evaluation

  • Risk control

  • Benefit-risk analysis

  • Residual-risk evaluation

  • Production and post-production information

  • Cybersecurity risk

  • Privacy risk

  • AI/model risk

  • Clinical risk

  • Supplier risk

  • Human-factors risk

Risk-management documentation may be maintained and updated throughout the relevant lifecycle.

27. Artificial Intelligence and Machine Learning Governance

Where artificial intelligence or machine learning is incorporated into an xBxBio product, research system, model, or service, governance may address:

  • Intended use

  • Model purpose

  • Training-data provenance

  • Dataset quality

  • Bias evaluation

  • Validation

  • Generalizability

  • Performance monitoring

  • Explainability where appropriate

  • Human oversight

  • Model-change control

  • Version control

  • Cybersecurity

  • Privacy

  • Drift monitoring

  • Failure modes

  • Clinical impact

  • Post-deployment monitoring

xBxBio does not assume that all AI systems are regulated identically.

Regulatory obligations depend on functionality, intended use, jurisdiction, risk, and product classification.

28. Cybersecurity Framework

xBxBio seeks to incorporate security throughout system design, development, deployment, maintenance, and retirement.

Relevant frameworks and standards may include, where appropriate:

  • FDA medical-device cybersecurity guidance

  • IEC 81001-5-1

  • ISO/IEC 27001

  • NIST Cybersecurity Framework

  • NIST Secure Software Development Framework

  • Secure-development practices

  • Vulnerability-management practices

  • Relevant contractual security requirements

Controls may include:

  • Identity and access management

  • Least privilege

  • Multifactor authentication

  • Encryption

  • Secure APIs

  • Network segmentation

  • Logging

  • Monitoring

  • Vulnerability scanning

  • Dependency management

  • Secure coding

  • Penetration testing

  • Backup

  • Recovery

  • Incident response

  • Patch management

  • Software component inventories

  • Supplier security

29. Privacy and Data Protection

Privacy and regulatory compliance are related but separate.

xBxBio maintains a separate Privacy Policy describing personal-information processing and applicable privacy requirements.

Depending on jurisdiction and activity, xBxBio may evaluate:

  • HIPAA and HITECH

  • GDPR

  • UK GDPR

  • CCPA/CPRA and applicable U.S. state privacy laws

  • PIPEDA and provincial Canadian laws

  • Japan APPI

  • Korea PIPA

  • Other applicable privacy and health-information requirements

30. Data Integrity — ALCOA+

Where xBxBio records support regulated, quality, research, scientific, or validation activities, xBxBio may apply data-integrity principles commonly expressed as ALCOA+.

Records should be designed, where applicable, to be:

  • Attributable

  • Legible

  • Contemporaneous

  • Original

  • Accurate

  • Complete

  • Consistent

  • Enduring

  • Available

Controls will depend on regulatory context and record criticality.

31. GAMP and Computerized-System Validation

Where xBxBio systems are used in regulated GxP environments, xBxBio may use risk-based computerized-system lifecycle and validation concepts informed by GAMP 5 and applicable regulatory requirements.

Possible activities include:

  • Intended-use definition

  • Risk assessment

  • Requirements

  • Configuration controls

  • Supplier assessment

  • Testing

  • Traceability

  • Validation

  • Change control

  • Periodic review

  • Incident management

  • Retirement planning

GAMP is an industry framework and should not be interpreted as a statute or regulatory certification.

32. Interoperability Standards

xBxBio may support healthcare-interoperability standards and specifications such as:

  • HL7

  • HL7 FHIR

  • DICOM

  • DICOMweb

  • Appropriate terminology standards

  • Standardized clinical coding systems

  • Secure healthcare interfaces

Interoperability support does not mean that every implementation automatically satisfies regulatory, privacy, security, or clinical requirements.

Each interface must be assessed in its deployment context.

33. Supplier, Vendor, and Third-Party Compliance

xBxBio may use vendors, cloud services, hosting providers, consultants, laboratories, software providers, technology suppliers, data providers, and other third parties.

Supplier governance may include:

  • Due diligence

  • Risk classification

  • Contractual requirements

  • Security requirements

  • Privacy requirements

  • Quality agreements

  • Business Associate Agreements where applicable

  • Data Processing Agreements where applicable

  • Confidentiality requirements

  • Subprocessor controls

  • Performance monitoring

  • Change notification

  • Incident notification

  • Audit rights where appropriate

  • Data-return and deletion provisions

  • Termination controls

The level of supplier oversight should be proportional to the risk and criticality of the supplied product or service.

34. Documentation and Traceability

xBxBio seeks to maintain documentation appropriate to product risk, lifecycle stage, and applicable requirements.

Documentation may include:

  • Requirements

  • Specifications

  • Architecture

  • Risk files

  • Design records

  • Test evidence

  • Validation records

  • Configuration records

  • Change records

  • Training records

  • Supplier records

  • Audit evidence

  • Clinical evidence

  • Cybersecurity records

  • Privacy assessments

  • Regulatory records

  • Release documentation

Traceability may be used to link requirements, risks, controls, implementation, tests, and evidence.

35. Verification and Validation

Where applicable, xBxBio may perform structured verification and validation to provide objective evidence that specified requirements have been met and that systems are fit for their intended use.

Testing may include:

  • Unit testing

  • Integration testing

  • System testing

  • Regression testing

  • Interface testing

  • Performance testing

  • Security testing

  • Usability testing

  • Data-integrity testing

  • Clinical or scientific validation where required

  • Installation and deployment testing

  • User acceptance activities where appropriate

Internal verification should not be represented as independent certification, regulatory approval, clinical validation, or external peer review unless it actually meets those criteria.

36. Change and Configuration Management

Changes to regulated or quality-relevant systems may be subject to controlled processes including:

  • Change request

  • Impact assessment

  • Risk assessment

  • Regulatory assessment

  • Cybersecurity review

  • Privacy review

  • Verification

  • Regression testing

  • Validation

  • Approval

  • Release management

  • Documentation updates

  • Configuration control

  • Post-implementation review

Significant changes may trigger additional regulatory evaluation or conformity assessment.

37. Audits and Assessments

Depending on applicable requirements and development stage, xBxBio may conduct:

  • Internal audits

  • Supplier audits

  • Quality reviews

  • Security assessments

  • Privacy assessments

  • Regulatory gap assessments

  • Software assessments

  • Risk reviews

  • Documentation reviews

  • Readiness assessments

An internal audit or assessment is not equivalent to external certification or regulatory inspection.

38. Corrective and Preventive Action

Where appropriate, xBxBio may use corrective and preventive action processes to identify, investigate, correct, and reduce recurrence of quality, regulatory, technical, security, or process problems.

Activities may include:

  • Issue identification

  • Containment

  • Investigation

  • Root-cause analysis

  • Corrective action

  • Preventive action

  • Effectiveness checks

  • Trend analysis

  • Documentation

39. Complaints, Safety Signals, and Incidents

For regulated products, xBxBio may establish procedures to receive, evaluate, investigate, and document:

  • Product complaints

  • Potential adverse events

  • Safety signals

  • Cybersecurity incidents

  • Performance problems

  • Data-integrity events

  • Field issues

Applicable regulatory reporting requirements will be evaluated based on jurisdiction and product status.

40. Post-Market Surveillance

Where xBxBio commercially markets a regulated medical device, post-market activities may include:

  • Complaint monitoring

  • Safety surveillance

  • Performance monitoring

  • Cybersecurity monitoring

  • Trend analysis

  • Literature review

  • Regulatory reporting

  • Corrective actions

  • Field safety actions

  • Periodic reports

  • Post-market clinical follow-up where required

Post-market obligations vary by jurisdiction and device classification.

41. Training and Competence

Personnel performing regulated, quality-critical, security-critical, clinical, or research activities should have appropriate education, training, experience, or qualifications for assigned responsibilities.

Training may address:

  • Quality systems

  • Privacy

  • Security

  • Regulatory requirements

  • Research ethics

  • Software development

  • Data integrity

  • Documentation

  • Incident response

  • Role-specific procedures

42. Records Retention

Records will be retained according to applicable:

  • Regulatory requirements

  • Research requirements

  • Quality requirements

  • Contractual requirements

  • Privacy requirements

  • Legal requirements

  • Litigation or investigation holds

  • Business requirements

Retention requirements may differ by record type, product, jurisdiction, and regulatory status.

43. Other Countries and Jurisdictions

xBxBio recognizes that additional jurisdictions may impose medical-device, software, AI, privacy, cybersecurity, clinical-research, data-localization, registration, or market-access requirements.

Before regulated commercialization or deployment in an additional jurisdiction, xBxBio will evaluate applicable local requirements.

Depending on market expansion, this may include requirements administered by authorities such as:

  • Australia's Therapeutic Goods Administration

  • Switzerland's Swissmedic

  • Singapore's Health Sciences Authority

  • Other national or regional medical-device authorities

  • Local privacy and cybersecurity regulators

Requirements will be assessed before claims of market authorization or compliance are made.

44. Regulatory Claims and Public Communications

xBxBio seeks to ensure that public regulatory statements are accurate and appropriately qualified.

xBxBio should not represent that a product is:

  • FDA cleared

  • FDA approved

  • CE marked

  • UK authorized

  • Health Canada licensed

  • PMDA approved

  • MFDS approved

  • ISO certified

  • HIPAA compliant

  • GDPR compliant

  • Clinically validated

unless the specific claim is accurate, applicable, documented, and authorized for public use.

Development against a standard is different from certification to a standard.

Internal testing is different from independent verification.

Research evidence is different from regulatory authorization.

45. Research-Stage and Pre-Commercial Technologies

Some xBxBio technologies described on xbxbio.com may be research-stage, developmental, investigational, prototype, or pre-commercial.

Such technologies should not be interpreted as available medical devices or as authorized for diagnosis or treatment unless specifically stated.

Demonstrations, simulations, models, white papers, and technical descriptions may represent ongoing development work.

46. No Substitution for Clinical Judgment

Unless a specific product has been developed, validated, authorized, and labeled for a defined clinical purpose, xBxBio technology should not be relied upon as a substitute for independent professional medical judgment.

Healthcare professionals remain responsible for clinical decisions within their professional scope and applicable standards of care.

47. Continuous Regulatory Monitoring

Medical-device, AI, privacy, cybersecurity, and digital-health regulation evolves rapidly.

xBxBio may periodically review:

  • New legislation

  • Regulatory amendments

  • Agency guidance

  • Standards revisions

  • Enforcement trends

  • Industry best practices

  • Cybersecurity threats

  • Scientific developments

Policies, procedures, product documentation, and this webpage may be revised when appropriate.

48. Relationship to the xBxBio Privacy Policy and Quality Statement

This Compliance & Regulatory page should be read together with:

  • xBxBio Privacy Policy

  • xBxBio Quality Statement

  • Any product-specific regulatory notices

  • Any research-specific consent or privacy documentation

  • Customer agreements

  • Business Associate Agreements

  • Data Processing Agreements

  • Security documentation

  • Applicable regulatory submissions

Where a specific binding agreement or applicable law imposes stricter requirements, those requirements control.

49. Contact xBxBio

Questions concerning xBxBio's regulatory, quality, compliance, privacy, or governance approach may be submitted through the contact mechanisms available at:

xBxBio
Website: www.xbxbio.com

For regulatory or compliance inquiries, identify the subject as:

REGULATORY / COMPLIANCE INQUIRY

50. Important Regulatory Disclaimer

This page is intended to communicate xBxBio's general regulatory and compliance approach.

It is not legal, regulatory, clinical, or certification advice.

It does not create contractual rights or obligations unless incorporated into a separate written agreement.

References to laws, regulations, standards, agencies, guidance documents, or industry frameworks do not imply that every referenced requirement applies to xBxBio or to every xBxBio product.

Regulatory applicability is determined based on factors including:

  • Intended use

  • Product functionality

  • Product claims

  • Device classification

  • Clinical role

  • Risk

  • Data processed

  • Customer relationship

  • Deployment model

  • Geographic market

  • Development stage

xBxBio will evaluate applicable requirements for each regulated product and market before commercial deployment or claims of regulatory authorization.

END OF COMPLIANCE & REGULATORY STATEMENT

bottom of page