Search all 478 artefacts by title, document ID or content.
Disclosure | Family 3, Security, Privacy & Trust Disclosures
The answer, in one sentence: Pensieve is a hospital operating system, an administrative and record-management platform, and is not a medical device in India, the European Union and the European Economic Area, Australia, or the United Arab Emirates. This document states why, names the provision it relies on in each…
The answer, in one sentence: Pensieve is a hospital operating system, an administrative and
record-management platform, and is not a medical device in India, the European Union and the European
Economic Area, Australia, or the United Arab Emirates. This document states why, names the provision it
relies on in each jurisdiction, and publishes the feature-level boundary that keeps it true.
DM-1 Dedicated |
DM-2 Shared |
DM-3 Customer Cloud |
DM-4 On-Premise |
|---|---|---|---|
| Yes | Yes | Yes | Yes |
Regulatory status attaches to what the software does and what its manufacturer says it is for. It does not change with where it is hosted. The position is therefore identical in all four models.
A hospital's Director of Clinical Governance, quality manager or medical superintendent will ask whether the software is a regulated medical device. It is a question with real consequences: a regulated device requires registration, a licence or a conformity assessment before supply, a quality management system, post-market surveillance and adverse-event reporting. A vendor who has not thought about it is a risk to the hospital, because the hospital is the one deploying the software into clinical care.
This document exists so the answer is "no, and here is the provision" rather than "we don't think
so". It is also a binding internal design constraint: Section 7 is enforced at the design gate described in
DIS-GL-018 Section 5.1, before a feature is built, not after.
Every jurisdiction in Pensieve Labs's portfolio draws the line in substantially the same place, using
different words. Reduced to one test:
If a competent clinician can see the input, see the rule, and see the output, and would reach the same conclusion without the software, it is information management.
If the software applies a model or a clinical judgement of its own, and the clinician is expected to rely on the output without independently reviewing its basis, it is a medical device.
The corollary, and the design rule that follows from it: transparency is the safe harbour. Show the
source. Show the rule. Let the clinician decide. Pensieve is built to that rule, and the rule is
enforced at design review rather than argued after release.
The second principle, which is the one vendors get wrong: in every jurisdiction, intended purpose is determined by what the manufacturer says. A marketing sentence, a user-interface label, a data sheet, a tender response or a contract term can regulate a product that the code does not. Copy review is therefore part of the same gate (Section 8).
Position: Pensieve is outside the scope of the Medical Devices Rules, 2017. No CDSCO licence
is required and none is held.
Software is regulated in India as a medical device under the Medical Devices Rules, 2017, made under the
Drugs and Cosmetics Act, 1940. The Central Drugs Standard Control Organisation issued Draft Guidance on
Medical Device Software on 21 October 2025; stakeholder consultation is complete and it remains in draft
as at 31 July 2026. The guidance clarifies how the existing Rules apply to software across
its lifecycle and does not create new requirements
(Cyril Amarchand, Medical Device as Software: Has CDSCO Guidance Changed the Rules?;
Asia Actual: India releases draft guidance on medical device software).
That last point matters and is stated rather than glossed: because the guidance is clarificatory, the risk it describes existed before it was published. No vendor can say it was compliant until October 2025.
Pensieve relies onThe draft guidance explicitly excludes from medical-device scope:
A hospital operating system performing registration, admission, discharge and transfer, billing, revenue cycle, inventory, pharmacy stock, procurement, human resources, scheduling, theatre and bed management, claims, analytics and clinical record-keeping falls squarely inside that exclusion.
Software becoming Software as a Medical Device is classified on two criteria: the significance of the
information provided to the healthcare decision, and the seriousness of the healthcare situation
addressed. Software guiding treatment decisions in critical situations lands in Class C or D; software
supporting non-serious clinical management in Class A or B. Class A and B are licensed by the State
Licensing Authority, Class C and D by the Central Licensing Authority, through the Sugam portal, with
licences valid for five years subject to the retention fee.
[UNVERIFIED: the exact application and licence form mapping for domestic manufacture versus import across Class A/B and C/D should be confirmed against cdsco.gov.in before any filing.]
The consequence of crossing the line is not a form. It is a quality management system, a licence, post-
market surveillance, adverse-event reporting and a five-year licence cycle. That is a different company, and
Pensieve Labs says so plainly rather than implying the transition would be administrative.
The operative memorandum for an EU or EEA hospital is
DIS-EU-028(Clinical Safety Boundary Statement: EU), which carries the Rule 11 trigger list with the EEA-build exclusions named, the third-party device display rules, the customer-as-manufacturer consequence, and the boundary against the EHDS conformity regime. This section states the shared principle;DIS-EU-028is what a European medical device or quality function asks for.
Position: Pensieve is not a medical device under Regulation (EU) 2017/745. The platform is a
hospital information system, which the Medical Device Coordination Group's own guidance states is not
qualified as a medical device.
MDCG 2019-11 states that hospital information systems are not qualified as medical devices, while noting that they may be used together with other products that are (MDCG 2019-11). The classic carve-out covers software that only stores, archives, communicates, performs lossless compression or does simple search, which is the substrate a hospital operating system provides.
MDCG 2019-11 Rev.1 was published in June 2025. The revision matters to Pensieve
specifically because it updates the treatment of modules and their interplay with electronic health record
systems under the European Health Data Space, and adds artificial-intelligence examples
(BioSlice Blog;
GMP Insiders).
Rule 11 of Annex VIII classifies software intended to provide information used to take decisions for diagnostic or therapeutic purposes. Applied to the features a hospital asks for:
| Feature | Position |
|---|---|
| Storing, displaying, transmitting and searching a clinical record | Not a device |
| Registration, admission, billing, inventory, scheduling, theatre and bed management | Not a device |
| Population and cohort analytics not driving an outcome for an identified individual | Not a device |
| Dose calculation, including weight-based paediatric dosing | Device: Rule 11 |
| Interaction or allergy alerting beyond a straight lookup presented to a clinician | Device: likely Rule 11. The boundary is fact-specific and Pensieve Labs stays well inside it |
| Early-warning or deterioration scoring computed and surfaced as a recommendation | Device: Rule 11 |
| Triage or acuity scoring driving a clinical decision | Device: Rule 11 |
| Artificial-intelligence-assisted image interpretation or diagnostic suggestion | Device: Rule 11, higher class |
Pensieve Labs does not need itUnder the Rev.1 module guidance, a device module can be assessed separately from the non-device platform.
That is a legitimate architecture and it is the one Pensieve Labs would use if it ever built such a
module, as a separately assessed, separately branded product integrated by interface, so that the core
platform's regulatory status is not contaminated.
It does not build one today. Pensieve ships no feature in the right-hand column of Section 3.2, in
any market. A hospital in Denmark or Norway asking for the qualification memorandum should read this
document together with Section 7, which is the feature-level version of the same statement.
A note on the European Health Data Space. Regulation (EU) 2025/327 entered into force on 26 March 2025. It converts electronic-health-record-system conformity from a market expectation into a self-declaration regime with a manufacturer's declaration of conformity and technical documentation, which is a materially different obligation from medical device conformity assessment, and one
Pensieve Labsintends to meet on its statutory timetable. A claim circulating in secondary sources that electronic health record systems must be certified from January 2026 is not supported by the Regulation's own timeline andPensieve Labsdoes not repeat it.[UNVERIFIED: treat the secondary claim as wrong; the operative dates are in the Regulation.]
Position: Pensieve is EXCLUDED from TGA regulation, not exempt. It relies on five named
exclusion items in Schedule 1 of the Therapeutic Goods (Excluded Goods) Determination 2018.
| State | Legal effect | TGA oversight retained | ARTG inclusion required |
|---|---|---|---|
| Regulated | Full medical device framework applies | All | Yes |
| Exempt | Relieved of the inclusion requirement, subject to conditions | Advertising, adverse-event reporting and notification obligations remain | No, but the TGA must be notified |
| Excluded | Not regulated by the TGA at all | None | No |
Software-specific exclusions were inserted into Schedule 1 by the Therapeutic Goods (Excluded Goods) Amendment (Software-based Products) Determination 2021, alongside classification rules for software-based medical devices effective 25 February 2021. There are now 15 software exclusion categories in that Schedule (TGA: software-based medical device exclusions).
Pensieve stands on| Item | Covers | Pensieve function it covers |
|---|---|---|
| 14G | Software for the administration or management of health processes or facilities, including financial records, claims, billing, appointments, operating theatre management, hospital bed management, schedules, business analytics and admissions | Registration, admission/discharge/transfer, billing, revenue cycle, theatre and bed management, scheduling, procurement, inventory, human resources, rostering, operational analytics |
| 14M | Software that is an electronic health record, however named, intended for use in clinical practice by healthcare providers to collect, use, disclose and manage patient clinical data within or between healthcare facilities | The clinical record itself: notes, clinician-recorded observations, documents, results filing, orders as records |
| 14N | Data analytics for the collection and analysis of class, group or population data | Population dashboards, quality indicators, casemix and key-performance reporting, provided they do not drive an outcome for an identified individual |
| 14O | Laboratory information management systems, however named | Laboratory workflow, instrument integration, sample management, result reporting and annotation |
| 14I | Software for the sole purpose of providing alerts to health professionals in relation to patient care | Non-urgent clinical alerts, reminders and prompts |
Sources: TGA guidance on the
electronic health records exclusion,
the population-based analytics exclusion,
the laboratory information management exclusion,
and the health alert systems exclusion.
[UNVERIFIED: the item letters should be confirmed against the current Determination text before being cited in a tender response. The five items above were each corroborated from two independent retrievals.]
Software falls out of every one of these exclusions if it is intended by its manufacturer to diagnose, screen for, prevent, monitor, predict, make a prognosis of, alleviate, treat, or make a recommendation or decision about the treatment of, a disease, condition, defect or ailment, or if it is intended to replace the clinical judgement of a health professional.
Section 7 is the feature-level expression of that condition, and it is why Pensieve ships no scoring,
no dose calculation and no image analysis in any market, not only in Australia.
TGA guidance on item 14I is explicit that the exclusion does not apply to software that provides alarms to health professionals that must be actioned urgently; the example given is a ventilator alarm requiring an ICU nurse to act immediately.
Product rule, absolute: Pensieve is never the delivery path for a time-critical clinical
alarm. No physiological monitor alarm routing, no code-blue paging derived from device signals, no
deterioration escalation triggered by vital-sign thresholds. Where a hospital asks for it, the answer is
that Pensieve integrates with the system that does it and records the event; it does not
originate it. This one line preserves the entire exclusion position, and it appears in the exclusions list
on the Order Form, not only in this policy.
Pensieve Labs does not rely on the clinical decision support exemptionThe 2021 reforms also created an exemption for clinical decision support software. Exempt is not excluded: an exempt device is still a medical device, and the manufacturer remains subject to advertising restrictions, adverse-event reporting and TGA notification.
Pensieve Labs does not build to the exemption. Relying on it would convert Pensieve
from an unregulated product into a regulated-but-relieved one, import post-market vigilance obligations,
and, most damaging commercially, turn "is this a medical device?" into a question with a nuanced answer
instead of a one-word one. Pensieve Labs stays inside 14G, 14M, 14N, 14O and 14I, where the answer is
"no, and here is the item number."
Position: Pensieve is an administrative and record-management platform and is not marketed,
labelled or supplied as a medical device in the UAE. It performs no diagnostic, monitoring, scoring or
treatment-recommendation function, in the UAE or anywhere else.
The functional boundary in Section 7 is the same in every market, so the substantive answer does not change. What
differs in the UAE is the surrounding regulatory environment: health data localisation under Federal
Law No. 2 of 2019 Article 13, and health-authority licensing and health-information-exchange participation
requirements, and those are addressed in DIS-GL-008 Section 6 and DIS-GL-024, not here.
[UNVERIFIED: Pensieve Labshas not obtained a formal classification opinion from a UAE health authority. The position stated is that the product performs no function that would engage medical-device regulation in any ofPensieve Labs's markets. A UAE buyer requiring a formal local classification opinion should raise it at qualification; Pensieve Labs will support the application with the technical file and will not assert a position it has not obtained.]
DIS-AE-028 is the UAE cover note. It states the local registration frame, the evidence
Pensieve Labs puts forward in place of a local opinion, and the express distinction between an
interoperability vendor assessment and a medical-device registration. Send it, not this section, to a UAE
reviewer.
| Market | Status | Provision relied on | Registration held |
|---|---|---|---|
| India | Not a medical device | CDSCO Draft Guidance on Medical Device Software (21 October 2025): express exclusion of hospital management information systems and electronic medical records from medical-device scope | None required. None held |
| European Union / EEA (Denmark, Norway) | Not a medical device | MDCG 2019-11 Rev.1: hospital information systems are not qualified as medical devices; storage, archiving, communication and simple search are outside qualification | None required. None held. No CE marking as a medical device, and none claimed |
| Australia | Excluded, not exempt | Therapeutic Goods (Excluded Goods) Determination 2018, Schedule 1, items 14G, 14M, 14N, 14O, 14I | No ARTG inclusion required. None held. No Australian sponsor required |
| United Arab Emirates | Not a medical device | No diagnostic, monitoring, scoring or treatment-recommendation function (Section 5) | None held [UNVERIFIED: no formal local classification opinion obtained] |
Edsol Edtech Pvt. Ltd. holds no ISO 13485 certification and no IEC 62304 conformity declaration, and
seeks neither. They are the quality-system standards for medical device manufacture, and
Pensieve is not a medical device. WPR-GL-005 Section 6.1 records this in the same terms.
Pensieve will and will not doThis table is a binding product-design constraint, not a description. It is enforced at the design gate
in DIS-GL-018 Section 5.1, before a feature is built. A hospital may hold Pensieve Labs to every line of it,
and ADD-GL-005 carries the contractual use restrictions that correspond.
Pensieve does not doPensieve will not |
Why |
|---|---|
| Compute or display an early warning score, deterioration score, sepsis score, risk score or acuity score derived from patient observations | Monitoring the state or progression of a condition. Outside the Australian exclusions, inside EU Rule 11, and Software as a Medical Device in India |
| Produce a patient-specific dose calculation or dose recommendation (from weight, renal function, age or any other patient parameter) | A recommendation about treatment, and outside the general-calculator carve-outs |
| Run an interaction-severity engine that grades, ranks, suppresses or escalates by computed clinical severity | Moves from providing an alert to making a recommendation about treatment |
| Directly process or analyse a medical image, or a signal from another medical device | The explicit bright line in the classification rules and in the CDSS exemption. Storage, routing, non-diagnostic display and report authoring remain permitted |
| Triage, prioritise or order patients by predicted clinical risk | Prediction and prognosis |
| Select a clinical protocol or order set for a patient based on that patient's data | The software would be making the clinical determination |
| Interpret a result pattern into a suggested diagnosis or clinical impression | Diagnosis |
| Auto-generate a diagnosis, a clinical impression or a coded clinical conclusion without a clinician authoring it | Diagnosis |
| Compute a triage category | Prediction. Pensieve records the category a nurse assigns |
| Originate a time-critical clinical alarm: physiological monitor alarm routing, code-blue paging from device signals, vital-sign threshold escalation | Section 4.4. Pensieve integrates with the system that does this and records the event |
| Present an output a clinician is expected to act on without independently reviewing its basis | Replacing clinical judgement: the disqualifying condition common to every jurisdiction |
| Describe any feature using the words diagnose, screen, predict, prognose, triage, monitor (in the regulatory sense) or recommend treatment in marketing, documentation, a user-interface label, a tender response or a contract | Intended purpose is determined by what the manufacturer says. A sentence can regulate a product the code does not (Section 8) |
Pensieve does do, and why it stays inside the linePensieve may |
Why it stays outside regulation |
|---|---|
| Match a prescribed drug against an allergy recorded in that patient's own chart and surface it | Record retrieval. The input, the rule and the output are all visible to the clinician, and an accreditation standard requires the allergy to be ascertained before prescribing |
| Display a licensed third-party interaction monograph verbatim, attributed, with the source shown, as an information-only alert | The Australian regulator's own worked example of an excluded alert under item 14I: an information-only alert drawn from a published reference, sent to a health professional, which does not replace clinical judgement |
| Range-check a dose against the manufacturer's labelled dose or a hospital-configured formulary limit, with the source shown | Checking against a published or hospital-set number is not computing a patient-specific dose |
| Show rule-based administrative reminders: overdue observation, missing consent, unsigned note, allergy not recorded, incomplete discharge summary | Administrative prompts, not clinical determinations |
| Chart vital signs, trend them, and flag values against thresholds the hospital itself configures | The hospital sets the numbers; the software does the arithmetic and shows it |
| Display lab results against the laboratory's own reference ranges and flag out-of-range | The laboratory sets the range |
| Perform general calculations: body mass index, unit conversion, gestational age from a date, mean arterial pressure | General calculators are separately carved out and involve no clinical model |
| Store, route, display for review, and support report authoring for images, including a viewer | Storage, transmission and non-diagnostic display are outside qualification; analysis is not |
| Apply order sets and protocols authored and approved by the hospital's own clinicians, selected and applied by a clinician | The hospital's clinicians made the clinical decision; the software is the medium |
| Run population and cohort analytics that do not drive an outcome for an identified individual | Australian item 14N; equivalent treatment elsewhere |
| Record the triage category a nurse assigns | Record-keeping |
| Use machine learning for non-clinical functions: coding suggestions for billing, denial prediction, demand and stock forecasting, roster optimisation, document classification, transcription without clinical interpretation, natural-language search over the record | No therapeutic purpose. The intended purpose is administrative (DIS-GL-027) |
Because intended purpose is set by what the manufacturer says, language is a regulated surface and is controlled like one.
| Control | How |
|---|---|
| Banned vocabulary | Diagnose, screen, predict, prognose, triage, recommend treatment, clinical decision support, risk score, early warning, deterioration, sepsis detection, AI-assisted diagnosis: prohibited in marketing copy, product documentation, user-interface labels, release notes, tender responses, contracts and sales conversations |
| Where the control applies | Every artefact in this Trust Center, the marketing site (which consumes its compliance copy from here), the product's own strings, and every proposal |
| Who enforces it | The design and copy gate in DIS-GL-018 Section 5.1, and legal review before publication |
| Contractual reinforcement | ADD-GL-005 records the use restrictions, and MSA-IN-001 records that Pensieve is not supplied for use as a medical device |
| If a hospital asks for a prohibited feature | The answer is no, in writing, with this document attached, and with an offer to integrate the regulated system that does it |
Pensieve's regulatory status depends partly on how the hospital deploys and describes it.
| Hospital obligation | Why |
|---|---|
Do not represent Pensieve to a patient, an assessor or a regulator as performing a clinical function it does not perform |
The hospital's own description can create an expectation Pensieve Labs never made |
Do not configure a hospital-authored rule as though it were a Pensieve clinical determination |
A threshold the hospital sets is the hospital's clinical decision. The Platform shows it as such |
| Retain clinical decision-making with clinicians | Every output in Section 7.2 is information for a clinician, not a substitute for one |
Do not route time-critical alarms through Pensieve |
Section 4.4. This is a patient-safety boundary as well as a regulatory one |
| Maintain a downtime procedure | A clinical system that is unavailable must not stop care, per DIS-GL-015 Section B3 |
Tell Pensieve Labs if a regulator, insurer or accreditation body asks about device status |
Pensieve Labs will answer in writing, on letterhead, in the terms of this document |
Pensieve Labs ever wanted to cross the lineStated so that the boundary reads as a decision rather than an incapacity.
A clinical feature that falls outside these boundaries would be built as a separately licensed,
separately branded module with its own regulatory approval and its own risk classification, integrated by
interface. It would not be added to the core platform, because doing so would convert
Pensieve into a regulated medical device in four jurisdictions simultaneously, with a quality
management system, a licence or conformity assessment, post-market surveillance and adverse-event
reporting attached.
There is no such module today, no such module in development, and no commitment to build one. If that
changes, this document changes first, and the change is published in DIS-GL-010-style before the feature
ships, not after.
11.1 This is Edsol Edtech Pvt. Ltd.'s own regulatory position, not a regulator's ruling. No competent
authority in any of Pensieve Labs's markets has issued a formal classification decision on
Pensieve. The position is reasoned from published guidance and named provisions, which is the
normal basis on which a non-device software product operates, and it is not the same as a determination.
11.2 The Indian guidance is in draft. Section 2.1. It is clarificatory rather than new, so
Pensieve Labs's position does not depend on the draft being finalised in its current form, but a
material change on finalisation would be published here.
11.3 Item numbers and provision references should be verified before citation in a tender. Section 4.2 carries
an [UNVERIFIED] marker on the Australian item letters. Pensieve Labs will confirm them against the
current Determination on request, and does not want a buyer citing an item number that has moved.
11.4 No formal EU qualification memorandum has been issued yet. A Danish or Norwegian buyer will ask for
an MDR qualification and classification memorandum module by module. Pensieve Labs will produce one on
request; it is not published as a standing artefact today, and the position it will state is Section 3.
11.5 No UAE classification opinion. Section 5.
11.6 The boundary depends on continued enforcement. Section 7 is only true while the design gate holds. The
gate is described in DIS-GL-018 Section 5.1, it is not independently audited, and a hospital relying on this
document should note that its assurance is Pensieve Labs's process and its published word, not a third
party's verification.
11.7 This document is not legal or regulatory advice to the hospital. Whether a hospital's own use of
Pensieve, or its own configuration of it, engages an obligation on the hospital is a question
for the hospital and its advisers.
| Question | Document |
|---|---|
| Where machine learning is used and what it is not used for | DIS-GL-027 AI/ML Feature Disclosure |
| The design gate that enforces Section 7 | DIS-GL-018 Section 5.1 Secure SDLC Disclosure |
| Contractual use restrictions | ADD-GL-005 Use Case Restrictions, MSA-IN-001 |
| Standards, terminologies and how clinical data is represented | DIS-GL-029 Interoperability & Standards Disclosure |
What Edsol Edtech Pvt. Ltd. holds and does not hold |
WPR-GL-005 Trust & Assurance Overview Section 6 |
| The alerting and record-retrieval functions that stay inside the line | DIS-GL-013 Section 5.1 |
| Downtime procedure and clinical continuity | DIS-GL-015 Section B3 |
| Version | Date | Author | Summary |
|---|---|---|---|
| 1.0.0 | 31 July 2026 |
Pensieve Labs Legal |
First published edition. Position stated per market with the named provision in each. Australian exclusion items 14G, 14M, 14N, 14O and 14I named. Feature boundary published as a binding design constraint. Language control published. Unverified points marked. |