Can We Use GitHub and Other SaaS For Our Software as a Medical Device?

Anonymous Technical Documentation Updated May 08, 2024 IEC 62304 , ISO 13485 , Software Validation
We’re currently using SaaS tools like GitHub to host our code. Our consultant told us that that’s not okay and we need to self-host everything. His reason was that we’re only allowed to use tools which we can “validate” ourselves. That would mean that any third-party-hosted software like GitHub would be prohibited. Help!

1 Answer

Accepted answer
Dr. Oliver Eidel
Dr. Oliver Eidel Founder & CEO, OpenRegulatory
Your consultant is wrong. You can use GitHub. And look for another consultant.

Long Answer

The ISO 13485 requires you to “validate” all quality-relevant software prior to use. That applies to GitHub, too. The fact that GitHub is hosted somewhere else and you don’t have full control over it is not a problem per se. You should just write down some sort of explanation why you’re okay with that.

The most obvious line of reasoning would be this: The availability of third-party-hosted software like GitHub is much higher if they take care of the hosting. So, it’s a good thing. On the other hand, what would the risks be? Data gets leaked or you lose access to the service, e.g. because you live in a country which is affected by U.S. export bans.

Include those points in your software validation and you’re good to go. See this answer to a similar question for a more in-depth explanation of what to.
Want to add your answer to this question?
Write an answer under your name by logging in or signing up, or post anonymously.

Still have a question? Ask a question here publicly - for free!

Or would you like to talk to one of our consultants? First calls are free. Check out our services and prices here.

And if you're looking to automate your regulatory work, check out our eQMS, Formwork. It's for lean, founder-led companies. It automates your compliance, and there's even a free version for you to try out!