EU Digital Health Firms Urged to Sync Rules with Revenue
- EU MedTech market faces strict MDR and AI compliance
- Germany's DiGA pathway offers fast-track reimbursement
- Notified body shortage delays market entry
- Experts urge early alignment of legal and commercial strategy
- Digital health investments hit record highs in 2026
Digital health companies entering the European market are facing a harsh reality check.
It is no longer enough to have a revolutionary piece of technology or a slick mobile application.
According to legal experts at Greenberg Traurig, success in the region now depends entirely on synchronising regulatory approval with reimbursement strategy from day one.
The firm released the second episode of its 'Big Law Redefined' digital health miniseries on Monday, analysing the critical hurdles for MedTech firms.
Host Charles C. Dunham, IV, sat down with Dr. Christian Rybak and Julian Bartholomä, LL.M., to dissect why so many promising startups stall after securing their CE mark.
The consensus among the experts is clear: a failure to plan for payment pathways while navigating the EU Medical Device Regulation (MDR) is a fatal error.
"Companies often focus solely on getting the regulatory clearance, but they forget to ask who will pay for it," Dunham said during the discussion.
This disconnect leaves clinically effective apps and devices stranded in a regulatory no-man's land, unable to reach patients because health systems will not cover the cost.
The European healthcare technology market is vast, yet it remains notoriously fragmented.
While the EU sets the baseline rules for safety and performance, the power to pay for treatments largely rests with the **27** individual member states.
This creates a complex maze for businesses used to more centralised systems.
The podcast highlights that without a cohesive strategy that addresses both the strict demands of the Brussels-based regulators and the budgetary constraints of national health insurers, companies will burn through their capital before generating a single euro of revenue.
The message comes at a critical time.
The digital health sector has seen explosive growth, yet the regulatory environment has tightened simultaneously.
Investors are growing impatient with startups that cannot scale beyond pilot programmes.
As the market matures, the 'move fast and break things' approach has been replaced by a need for meticulous, often expensive, compliance planning.
The experts argue that the era of treating regulatory strategy as an afterthought is officially over.
- The EU digital health market is projected to grow significantly, driven by aging populations and chronic disease management needs.
- Navigating the MDR requires substantial financial resources, often running into **€100,000 to €500,000** for larger companies.
- Reimbursement success varies wildly between nations, with Germany offering the most structured pathway for digital apps.
Inside the MDR Bottleneck: Why Notified Bodies Matter
The conversation quickly turned to the elephant in the room: the EU Medical Device Regulation.
Since its full application, the MDR has fundamentally reshaped the landscape for medical technology.
Intended to harmonise standards and improve patient safety across the bloc, the regulation has instead created a significant bottleneck.
Dr. Christian Rybak pointed out that the transition from the previous Medical Device Directive (MDD) to the MDR has been far more painful than anticipated.
"The requirements are much stricter, and the scrutiny is far more intense," Rybak explained.
The core issue lies with the 'Notified Bodies'—the independent organisations designated by EU member states to assess the conformity of certain medical devices before they can be placed on the market.
Under the old rules, there were over **50** of these bodies.
Under the MDR, many have lost their designation or opted out due to the increased liability and rigorous standards, reducing the pool to roughly **35**.
This scarcity has led to massive delays.
Companies can wait **12 to 24 months**, just to get a slot for an assessment.
For a digital health startup operating on a 12 to 18-month runway, this wait time can be catastrophic.
The podcast notes that the cost of conformity assessment has also skyrocketed.
It is not just a delay; it is a massive financial burden.
Rybak emphasised that selecting the right Notified Body is now a strategic decision in itself.
It is not simply about finding an available slot.
Companies must find a body that understands the specific nuances of software as a medical device (SaMD).
Traditional device assessors may not fully grasp the iterative nature of software development or the specific risks associated with AI algorithms.
This knowledge gap can lead to endless back-and-forth, further draining resources.
The experts warned that the MDR is here to stay.
There is no rolling back of these standards.
Therefore, companies must factor the specific requirements of the MDR into their product development lifecycle from the very beginning.
Retrofitting compliance onto a finished product is rarely successful and almost always prohibitively expensive.
The regulation demands a rigorous quality management system and extensive clinical evidence.
For software companies, this often means conducting randomised clinical trials—an endeavour traditionally reserved for pharmaceutical giants.
- The number of active Notified Bodies in the EU dropped significantly, falling from over **50** to approximately **35**.
- Wait times for conformity assessments can exceed 12 months for high-risk digital health devices.
- The MDR requires manufacturers to provide post-market surveillance data for the entire lifecycle of the product.
The AI Act Adds a New Layer of Compliance
Just as companies were beginning to grapple with the MDR, a new regulatory wave is building.
The EU's Artificial Intelligence Act represents the world's first comprehensive AI law.
For digital health companies relying on machine learning or algorithmic decision-making, this adds a second, overlapping layer of complexity.
Julian Bartholomä, LL.M., highlighted the intersection of these two regulatory frameworks.
"You have to look at the MDR for the device safety, but now you also have the AI Act for the underlying technology," Bartholomä noted.
This dual compliance requirement is causing confusion in the industry.
The AI Act classifies AI systems into **4** risk levels, with medical AI typically falling into the 'high-risk' category.
This triggers strict obligations regarding data governance, transparency, and human oversight.
The challenge is that the MDR and the AI Act do not always speak the same language.
While there is an effort to ensure that complying with the MDR counts towards complying with the AI Act for medical devices, gaps remain.
Bartholomä stressed that legal teams are currently working overtime to interpret how these laws interact.
The podcast discussion suggests that companies using AI need to be exceptionally transparent about their training data and algorithmic logic.
The 'black box' problem, where an AI makes a decision that cannot be easily explained, is a major red flag for European regulators.
If a doctor cannot understand *why* an AI diagnostic tool suggested a specific treatment, the regulator is unlikely to approve it.
This requirement for 'explainability' is forcing developers to change how they build their models.
It is no longer just about accuracy; it is about interpretability.
The experts also touched on the concept of 'continuous learning' systems.
In the AI world, algorithms are constantly updated with new data.
However, the MDR generally assumes a static device.
Every significant change to an algorithm could technically require a new conformity assessment.
This creates a tension between the agile nature of AI development and the rigid, slow-moving nature of medical device regulation.
Bartholomä advised firms to design their algorithms with regulatory constraints in mind, limiting the scope of automatic updates to avoid triggering costly re-certification processes.
- The EU AI Act classifies most medical AI systems as 'high-risk', **1 of 4** risk categories defined in the legislation.
- Companies must demonstrate 'explainability' in their AI algorithms to satisfy regulatory bodies.
- Continuous learning AI models face specific challenges under the current static device certification framework.
Germany's DiGA Pathway Offers a Route to Reimbursement
While the regulatory hurdles are high, the podcast also highlighted a beacon of hope for digital health firms: Germany.
Europe's largest economy has pioneered a specific reimbursement pathway for digital health applications known as DiGA, or 'Digital Health Applications'.
Dr. Christian Rybak described the DiGA pathway as a 'gold standard' that other countries are watching closely.
Unlike traditional reimbursement processes that can take years, the DiGA Fast-Track process allows manufacturers to get their app listed in the national directory within three to six months, provided they meet certain initial requirements.
This provisional listing allows doctors to prescribe the app, and **over 100** statutory health insurance funds to pay for it, for up to 12 months.
During this period, the company must generate real-world evidence to prove the app has positive healthcare outcomes.
If the evidence is convincing, the app receives permanent listing and a negotiated reimbursement price.
Rybak argued that this system is revolutionary because it decouples reimbursement from the traditional, lengthy clinical trial phase.
It allows for evidence generation *within* the healthcare system.
However, the experts cautioned that the DiGA pathway is not a 'free pass'.
The standards for evidence are rigorous.
The Federal Institute for Drugs and Medical Devices (BfArM), which oversees the process, has rejected numerous applications for failing to demonstrate sufficient patient benefit or for having poor study designs.
Julian Bartholomä added that success in Germany often serves as a springboard for the rest of Europe.
A DiGA listing provides a level of credibility that can be leveraged in negotiations with payers in France, Italy, or the UK.
"If you can prove value in the German market, you have a strong case elsewhere," Bartholomä said.
The podcast advises companies to look closely at the DiGA requirements early in the development process.
Designing a study that meets BfArM standards requires foresight.
Many companies fail because they collect the wrong type of data or use inappropriate control groups.