In the field of digital health, Medical Device Software (MDSW) apps are increasingly popular, used by patients and healthcare professionals to monitor diseases, interpret clinical data and support therapies. Some examples include epilepsy-monitoring apps that detect seizures by analysing movements and night sounds.
But what happens when these apps are distributed on online platforms such as the Apple App Store, Google Play or independent marketplaces? Who is responsible for their safety and compliance? Which regulations apply? Providing the answers is the new MDCG Guideline 2025-4 published on June 16, 2025, which finally offers clarity in such a dynamic and ever-changing context.
The responsibilities of platform providers
MDCG 2025-4 focuses on the ‘secure provision of MDSW apps on online platforms’ and directly addresses the responsibilities of providers who make them available in the EU market. The guide clarifies when and how digital platforms fall under the obligations of MDR (EU) 2017/745, IVDR (EU) 2017/746 and the Digital Services Act (DSA), what responsibilities they assume according to their role (distributor, importer, host), and how to make clear to users the distinction between apps certified as Medical Devices and generic fitness or wellness apps.
The MDCG 2025-4 distinguishes two main scenarios for platform providers:
- Provider as intermediary: When the provider merely puts manufacturers and users in contact with each other, it must apply the DSA and has no direct obligations under MDR/IVDR. An example is Amazon (or a similar marketplace) when an MDSW manufacturer uploads its software onto the platform. Amazon provides the digital ‘space’ and tools for the transaction, but the manufacturer remains solely responsible for the compliance of the MDSW, its CE certification and instructions for use, according to MDR/IVDR.
- Provider as distributor/importer: if the platform receives the software from the manufacturer and supplies it directly to the end user, it becomes part of the supply chain and assumes other responsibilities than in the previous case. In this case, the provider assumes the obligations of MDR (EU) 2017/745 and IVDR (EU) 2017/746, as if it were a distributor or importer. An example is a telemedicine platform or a specialised vertical app store that buys exclusive distribution rights for specific MDSWs (e.g. software for diabetes management or cardiac monitoring) and offers them directly to its users, also managing updates and support. Or, the provider could brand the software. In these situations, the platform is directly involved in making the medical device available on the EU market.
The guide emphasises that EU-based platforms hosting MDSW produced in non-EU countries can take on the role of importer (Section 2.2).
App Transparency and Categorisation
To ensure safety and clarity for users, platforms must ensure information transparency, i.e. make the device identifier, intended use, warnings and instructions for use visible to users (Section 2.3). This clarity is crucial for the end user.
In addition, apps should be organised by clearly distinguishing between apps that are CE-certified as Medical Devices (subject to MDR or IVDR) and generic fitness or wellness apps that do not qualify as Medical Devices.
How do MDR, IVDR and DSA coexist?
One of the most delicate and complex aspects addressed by MDCG 2025-4 is the co-existence of different regulations.
When a platform provider acts as a distributor/importer of MDSW (subject to MDR/IVDR) and is also an ‘online platform’ (subject to DSA), the guidance states that the MDR/IVDR obligations prevail, and that Article 6 of the DSA (exemption from liability) does not apply for compliant products. However, the (non-general) monitoring obligations of the DSA (Article 8) still apply.
Online platforms that allow contracts between users and MDSW manufacturers must:
- Have a mechanism to notify and take action on illegal content.
- Comply with transparency and compliance requirements (Article 31 DSA), in line with MDR/IVDR requirements for operating instructions and safety warnings.
Large online platforms designated by the Commission will have to implement a risk assessment framework and may be held liable for displaying illegal content. In all cases, the platform must cooperate with the competent authorities, ensure product traceability and conformity, and comply with surveillance and transparency obligations.
An essential reference for qualification and classification: MDCG 2019-11
To assess the compliance of software, Apps and Software as a Medical Device (SaMD) with current regulatory requirements, an essential reference remains the MDCG 2019-11 revision 1 (‘Guidance on Qualification and Classification of Software in Regulation (EU) 2017/745 (MDR) and Regulation (EU) 2017/746 (IVDR)’). This guidance, updated on June 17, 2025, is essential for determining whether software falls under the definition of a medical device or IVD and, if so, how to classify it correctly according to risk.
In conclusion, the new MDCG 2025-4 provides an indispensable regulatory framework for the safe distribution of medical device apps online, offering clarity on responsibilities and promoting a safer digital environment for all users.
👉We help you prove the regulatory compliance of your Medical Device Software in the European Union and the rest of the world. Contact us for more information.
07/17/2025

