Discovery for Regulatory Submission and Technical Design of Wound Treatment Device Apps
Summary
A European medtech startup had a working electromagnetic wound-treatment device but no software, and wanted compliant web and mobile apps for medical staff — ready for EMA and FDA submission and compliant with GDPR and HIPAA. After a previous vendor fell short, the startup chose INNERLUXES. Over a three-month discovery, INNERLUXES reworked the vague requirements and produced 25 deliverables across two packages — one for regulatory submission and one for the development roadmap — giving the Client strategic clarity and regulatory readiness.
About the Client
The Client is a European startup developing an electromagnetic medical device for wound treatment.
From Bare Hardware to Compliant Web and Mobile Apps
In its initial form, the device was a basic hardware solution with no software for treatment management or progress tracking. The Client wanted web and mobile apps for medical staff — primarily nurses — that connect to the device over Bluetooth or Wi-Fi, send it commands, play pre-designed therapy programs (binary files encoding electromagnetic wave sequences) for specific wound types, and log completed procedures.
Lacking the competencies in-house, the Client looked for a vendor experienced in medical-device software and healthcare compliance. Because it planned to sell the device globally — starting with the European and US markets — the apps had to meet EMA, GDPR, FDA, and HIPAA requirements. An earlier partnership with a familiar software company failed to meet expectations, so the Client assessed INNERLUXES rigorously through several interviews, including in-person meetings, before choosing it as a long-term development partner.
A Three-Month Discovery That Reworked Vague Requirements
The project began with a discovery phase. INNERLUXES initially proposed six weeks, but the Client preferred a slower pace and extended it to three months. The discovery team comprised a project manager, a compliance officer, a solution architect, and a business analyst who doubled as a healthcare IT consultant. A key challenge was that the original software requirements specification was vague — high- and low-level requirements had no clear hierarchy (nesting issues), multiple requirements overlapped and conflicted, and some were too broad while others were too narrow. INNERLUXES had to decompose and substantially rework the requirements, while following strict software-development and documentation guidelines for EMA and FDA submissions and GDPR and HIPAA compliance. In all, the team prepared 25 documents, organized into two clearly separated groups of deliverables.
Two Packages: Regulatory Submission and Development Roadmap
The regulatory submission package was compiled into a dossier with everything needed for regulatory review, including:
- An overview of key software features, inputs, outputs, and hardware platforms.
- Risk management documentation — a risk assessment plan and a risk mitigation plan.
- A complete software requirements specification (SRS) organized for traceability, plus a software design specification (SDS) mapped back to it.
- Solution architecture diagrams and a requirement traceability matrix.
- A project charter covering the development lifecycle, configuration, change, quality, and security management, and verification and validation plans.
- A draft IEC 62304 Declaration of Conformity, which simplifies submissions to both US and European regulators.
- Draft cybersecurity documentation based on current FDA guidance — threat model, risk assessment, security traceability matrix, and testing plans.
- Draft verification and validation documentation across unit, integration, and system levels.
The development roadmap package focused on internal planning and execution, including:
- A high-level software architecture overview and a prioritized feature list.
- First-sprint development tasks as user stories, and documentation of planned integrations.
- System entities defined in the FHIR format, with relationship diagrams.
- A comparison of development infrastructure and CI/CD options with total cost of ownership.
- Use case documentation, prototypes of three key user flows, and low-fidelity UI wireframes plus a first set of UI design files.
- A user-roles and access-control schema, a list of security requirements, a product-risk assessment, and an updated project roadmap.
25 Deliverables for Strategic Clarity and Regulatory Readiness
In three months, the Client received 25 deliverables that clarified the mobile and web app requirements and laid out a clear project roadmap. The documentation was instrumental in preparing the Client for future EMA and FDA submissions, improving the chances of approval once an early working version of the system is ready. The startup also plans to add personalized wound-treatment programs and EHR interoperability, and — satisfied with the discovery outcome — is ready to entrust the software development and new functionality design to INNERLUXES.
Technologies and Tools
Microsoft Office, Jira, Confluence, SharePoint.