Audit and Certification for Medical Technology Suppliers

Part of the HCPL Centre for Quality, Audit and Certification. Compliance, competence and trust in healthcare. We audit hospitals, medical technology suppliers and their staff, prepare them for certification and validate their competences against NIS2, GDPR, the AI Act, MDR and ESG. A positive outcome of the HCPL certification programme qualifies for a recommendation from the Polish Federation of Hospitals.

Why the Centre?

Healthcare organisations operate under overlapping regulations: cybersecurity (NIS2), data protection (GDPR), artificial intelligence (the AI Act), medical devices (MDR) and sustainability (ESG), which is increasingly used as a public procurement criterion. The Centre brings these areas together in one process: diagnosis, remediation plan, verification and confirmation. Instead of five separate audits, the organisation receives one picture of its risks and one path to compliance.

We work according to Just Culture principles. An audit serves to improve the system, not to assign blame. Every engagement discloses who performs each service and how conflicts of interest are managed.

Services

Services can be ordered in full or as individual modules, for a selected department, system or regulation.

01. NIS2, GDPR and ESG compliance audit

A review of information security systems, personal data protection policies and sustainability processes. The result is a gap report, a risk map and a prioritised remediation plan with a timeline. For: hospitals, essential and important entities under NIS2, and IT service providers to the healthcare sector.

02. AI Act and MDR readiness assessment for medtech suppliers

Risk classification of the AI system and a review of technical documentation, data governance, human oversight and post-market monitoring. The assessment prepares the manufacturer for conformity assessment by a notified body. It does not replace that procedure. For AI solution suppliers we also run the voluntary AICACT SDAI standard.

03. International accreditation readiness (JCI Readiness)

Gap analysis against Joint Commission International standards, implementation support and a mock survey. Accreditation is granted solely by Joint Commission International. HCPL prepares the hospital for it. International accreditation

04. HCPL certification programme and PFSz recommendation

Verification of suppliers’ products, services and processes against the HCPL programme criteria: security, data protection, quality and ESG. A positive outcome qualifies for a recommendation from the Polish Federation of Hospitals, a network of more than 250 member hospitals. This is an HCPL industry programme and not certification accredited by the Polish Centre for Accreditation.

05. Competence micro-credentials for healthcare staff

Short modular training with verified learning outcomes, covering cyber hygiene and NIS2 in ward practice, GDPR in medical records, safe use of AI in diagnostics and ESG in procurement. We design them in line with the European approach to micro-credentials (Council Recommendation of 16 June 2022, OJ C 243, 27.6.2022). HCPL Micro-credentials

06. Authorised training partners (manufacturers)

Manufacturers whose solutions have completed the HCPL certification programme can run authorised training for users of their products, ending with an HCPL micro-credential.

07. Public procurement support

For contracting authorities: specifications and quality criteria, including cybersecurity and ESG. For suppliers: preparing documents that demonstrate compliance.

08. Advisory and Data Governance

Implementing management systems (ISO/IEC 27001, ISO 9001), data governance, and telemedicine and HIS security. Financial and accounting analyses are performed by a partner holding statutory auditor qualifications. Data Governance

How we work

  1. Scoping. Initial conversation and definition of scope (full or modular).
  2. Audit. Document review, interviews and tests. The performer of each element is named.
  3. Report and remediation plan. Priorities, responsibilities, timeline.
  4. Verification. Follow-up audit after changes are implemented.
  5. Confirmation. HCPL programme certificate and PFSz recommendation, or micro-credentials for staff.

The Healthcare Poland ecosystem

The Centre is one of the value streams of the Healthcare Poland Foundation and works with the others:

Frequently asked questions

Does HCPL issue AI Act or MDR compliance certificates?

No. Compliance of medical devices and high-risk AI systems is confirmed through conformity assessment, often involving a notified body. HCPL carries out a readiness assessment that shortens and structures that procedure.

What is the HCPL certification programme?

An industry programme of the Foundation that verifies products, services and processes against transparent criteria for security, data protection, quality and ESG. A positive outcome qualifies for a recommendation from the Polish Federation of Hospitals.

What are micro-credentials?

A record of learning outcomes achieved in a short, self-contained learning experience. The 2022 Council Recommendation sets common standards for them, making them easier to compare and recognise across Europe.

Can services be ordered as modules?

Yes. Each module, for example a standalone NIS2 audit or a single course for one department, can be ordered separately.

Who performs the audits?

The Centre’s team and partners holding the required qualifications. Every engagement names the performers and sets out conflict-of-interest rules.

Does HCPL prepare hospitals for JCI accreditation?

Yes, through the JCI Readiness service: gap analysis, implementation support and a mock survey. The accreditation decision is made by Joint Commission International.

Let’s talk about your organisation’s compliance

Book a free initial consultation: global@healthcarepoland.pl · +48 787 000 827